Whether you’re building a social media policy for employees from scratch or tightening up what you already have, the consequences of getting it wrong can be significant. For example, if an employee posts confidential client information or makes a discriminatory comment about a coworker, a poorly written or nonexistent policy leaves you with limited options for responding consistently and defensibly.
Why Employers Need a Social Media Policy
A social media policy for employees serves the company on several fronts simultaneously.
- Brand Protection: Employees who post about work, whether positively or negatively, connect their content to your organization. A policy sets the standard for how the company is represented publicly.
- Confidentiality: Without clear rules, employees may share client details, pricing, or business strategies without realizing the disclosure is a problem.
- Harassment and Discrimination Liability: Off-hours posts targeting coworkers based on protected characteristics can support hostile work environment cases, and an employer who knew about the conduct and did nothing faces exposure.
- Enforcement Consistency: A written policy with defined consequences makes it possible to discipline one employee for a violation without creating a discrimination issue when you don’t discipline another for different conduct.
- Recruitment: How employees talk about their workplace online affects who applies. A policy that encourages employees to share accurate, positive experiences gives you some influence over that narrative.
- PR Crisis Response: A policy can pre-assign responsibility for responding to public social media situations and cut down the time it takes to get an organized response out.
Core Sections Every Social Media Policy for Employees Needs
Scope: Who the Policy Covers and When
Define who the policy applies to. Full-time employees are obvious, but contractors, part-time staff, and interns frequently get left out of initial drafts. Also define when the policy applies, including activity on personal accounts when employees identify themselves as working for your company or post about work-related topics, regardless of whether they’re on the clock.
Scope gaps become enforcement gaps. For example, if the policy doesn’t specify that it covers contractors, you have no documented basis for addressing a contractor’s post.
Confidentiality and Proprietary Information
Employees need to know exactly what they cannot share publicly. Spell out specific categories rather than relying on general language:
- Client names, contact information, and project details
- Internal financial data, pricing, or business strategies
- Personnel situations, including HR investigations or terminations
- Anything related to pending litigation or government proceedings
- Proprietary processes, formulas, or unreleased products
If confidentiality obligations also exist in an employment agreement or NDA, reference those documents in the policy directly so employees understand the social media rules and the contract obligations connect.
Employee Personal Accounts and Brand Representation
Employees who list their employer on a personal profile, or who post about clients, coworkers, or work events, create a public association between their content and your organization. A policy can address this without overreaching into personal speech.
A standard practice is to ask employees to add a disclaimer such as “views are my own and do not reflect those of my employer” on profiles or posts where they discuss industry topics or work-related content. The policy should also address posts that misrepresent a company position or appear to speak on the company’s behalf, since those create the same exposure as an official statement regardless of which account they come from.
State Privacy Laws
State laws on employee social media privacy vary significantly. According to a 50-state survey by Justia, more than half of U.S. states have enacted laws restricting employer access to employee personal social media accounts. (justia.com) Policies covering multiple states need to be reviewed against the law of each state where the company has employees.
Brand Voice on Company-Owned Accounts
If employees post on behalf of the company, the policy needs to spell out exactly what that means. It should cover more than prohibited content and needs to define how the company communicates publicly.
Address the following in any sections covering this topic:
- Tone and language standards: whether the brand voice is formal or conversational, what topics are on-brand, and what language or phrasing is off-limits
- Prohibited content types: political statements, competitor references, unverified statistics, or content that hasn’t been approved
- Response standards: how employees should handle negative comments, complaints, or questions they’re not equipped to answer
- Referral procedures: who receives escalated inquiries, particularly from media or from customers with active complaints
Employees who manage company accounts are functioning as brand representatives with every post and your policy should reflect that.
NLRA Protections and Permissible Policy Language
One of the most common drafting errors in a social media policy for employees is language broad enough to restrict activity employees have a right to engage in under the National Labor Relations Act. The NLRA protects employees’ rights to discuss wages, working conditions, and workplace concerns with coworkers, and those protections extend to social media.
A blanket prohibition on discussing pay or working conditions with coworkers online can constitute an unfair labor practice, even in non-union workplaces.The NLRB has taken enforcement action against policies containing language that could reasonably be interpreted to restrict protected concerted activity, and the agency’s guidance has shifted under different administrations, so it’s a good idea for employers to have an employment attorney review the policy before publishing it.
Harassment and Discrimination
Workplace anti-harassment and anti-discrimination standards extend to social media. A post targeting a coworker based on race, gender, religion, national origin, or another protected characteristic can support a hostile work environment case even when the post happens outside work hours on a personal account. Employers who learned of the conduct and took no action have faced liability.
The policy needs to connect existing harassment standards to social media explicitly. Employees otherwise tend to assume that conduct on personal accounts outside work hours falls outside the employer’s reach.
Company Account Security and Offboarding
Assign account ownership and access controls in the policy and connect them to the offboarding process. Without a defined offboarding procedure, departed employees can retain access to company accounts they originally set up, sometimes without anyone realizing it until a post goes out. This part of your policy needs to address:
- Who holds administrative access to each platform
- Password management procedures, including changes after an employee with access leaves
- What access gets revoked on the last day of employment and who is responsible for the revocation
- How account content is archived or preserved during a transition
Industry-Specific Regulations
Employers in regulated industries need to address sector-specific rules in the policy. Healthcare, financial services, and public companies are examples where the stakes are particularly high. HIPAA restricts what healthcare employees can reference online about patients or their care, even in general terms. FINRA rules govern recordkeeping and supervision of social media communications for broker-dealers and investment advisers. SEC restrictions prohibit public company employees from disclosing material non-public information online.
If your industry carries regulatory requirements that touch on employee communications, those requirements belong in the policy, along with a directive to contact compliance or employment counsel before posting on regulated topics.
The Approval Process for Company Account Posts
For employers with employees who post on company-owned social media accounts, a documented approval process reduces the risk of off-brand, inaccurate, or policy-violating posts going public.
A basic approval chain:
- Employee drafts the proposed content, including copy, images or video, and any hashtags or links
- Draft is submitted to a designated reviewer via email or an internal tool
- Reviewer approves, requests changes, or rejects with a reason
- Employee posts only after written approval is received
- Post is logged with the date, approving reviewer, and platform
The policy should also specify who has authority to post without approval in time-sensitive situations, and what that authority is limited to.
Handling Violations
Documentation
When a potential violation surfaces, preserve the content immediately. Take a timestamped screenshot before the post is deleted, edited, or made private. Note who flagged the situation, when, and through what channel. Posts disappear quickly, and having a preserved copy with metadata is necessary for any subsequent investigation or disciplinary process.
Investigation Steps
Before taking any disciplinary action:
- Confirm the post came from the employee in question
- Determine whether the content falls under a defined policy provision
- Assess whether NLRA-protected activity is involved
- Review how comparable conduct has been handled with other employees
Inconsistent enforcement creates discrimination exposure. If two employees post comparable content and only one faces discipline, the disparity will face scrutiny if the disciplined employee brings a complaint.
Progressive Discipline vs. Immediate Termination
Severity determines the response. A post that reveals confidential client data or makes discriminatory statements targeting a coworker may warrant immediate termination, depending on existing policies and employment agreements. A first-time minor violation may call for a written warning and a policy reminder.
Whatever the response, it needs to be consistent with how comparable situations have been handled previously, and it needs to be documented in the employee’s record.
An Example Social Media Policy Outline
Employers can adapt the structure below to fit their organization. Employment counsel should review the final language before distribution.
| Section | Contents |
| 1. Purpose | A brief statement of why the policy exists and what it covers. |
| 2. Scope | Who the policy applies to (employees, contractors, interns) and when (during and outside work hours). |
| 3. Company-Owned Accounts | Access controls, posting authorization, brand voice standards, approval process, and offboarding procedures. |
| 4. Employee Personal Accounts | Disclosure requirements when identifying as an employee, confidentiality obligations, prohibited content, and disclaimer language. |
| 5. Confidential and Proprietary Information | Specific categories of information employees may not disclose, with reference to any applicable NDAs or employment agreements. |
| 6. Harassment and Discrimination | Extension of existing workplace conduct standards to social media, with examples. |
| 7. NLRA-Protected Activity | Explicit carve-out confirming the policy does not restrict employees’ rights to discuss wages, working conditions, or workplace concerns. |
| 8. Industry-Specific Rules | Any sector-specific regulatory requirements applicable to the company. |
| 9. Violations and Disciplinary Action | How violations are documented, investigated, and addressed, including the range of possible consequences. |
| 10. Acknowledgment | Employee signature, date, and confirmation of receipt. |
Rollout and Training
Writing the policy is only part of the job. Employees who receive a 40-page handbook and sign the last page have not necessarily read the social media section.
Effective rollout:
- Distribute the policy as a standalone document, separate from a general handbook update, when introducing it for the first time
- Require a signed acknowledgment confirming the employee received and read the policy
- Build a brief review of the policy into onboarding for new hires
- Train managers separately, since they are the first point of contact when a violation surfaces and need to know how to document and escalate correctly
- Revisit the policy at least once a year, and also after any significant NLRB guidance, platform change, or internal situation that exposes a gap in the current language
Get Employment Counsel Review of Your Policy
Before distributing any social media policy, have employment counsel review the final language. Conn Maciel Carey LLP’s Labor & Employment Practice works with employers to draft, review, and update workplace policies that reflect current NLRB standards and state-specific requirements. Contact us to speak with an attorney.
Disclaimer: This article is for informational purposes only and does not constitute legal advice. Laws and regulations change, errors may occur, and this content may not address every aspect of the relevant legal requirements. Reading this article does not create an attorney-client relationship. For guidance on your specific situation, consult your attorney.
References and Additional Reading
NLRB — Employee Rights: https://www.nlrb.gov/about-nlrb/rights-we-protect/your-rights
NLRA Section 7, 29 U.S.C. § 157: https://www.law.cornell.edu/uscode/text/29/157
Stericycle, Inc., 372 NLRB No. 113: https://www.uschamber.com/assets/documents/Board-Decision-Stericycle-Inc.pdf
FINRA Regulatory Notice 11-39: https://www.finra.org/rules-guidance/notices/11-39
FINRA Rule 2210: https://www.finra.org/rules-guidance/rulebooks/finra-rules/2210
HHS / HIPAA Privacy Rule: https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html
Justia 50-State Survey: https://www.justia.com/employment/employment-laws-50-state-surveys/social-media-privacy-laws-in-the-workplace-50-state-survey/
Nolo — State Laws on Social Media Password Requests: https://www.nolo.com/legal-encyclopedia/state-laws-on-social-media-password-requests-by-employers.html