Skip to content

Compliance

Compliance Corner: No Place Like Home? Fine-Tuning Your Remote Work Strategies

Unbelievably it has been almost five years since the world undertook one of the largest work-from-home experiments ever. Ready or not, in the days and weeks following the World Health Organization's March 2020 declaration that COVID-19 was a pandemic, employers throughout the world grappled with how to securely and productively have their workforces work remotely.

← All articles
Leslie Bender

By Leslie Bender

Senior Counsel, Eversheds Sutherland (US) LLP

1/7/2025

Filed under Compliance

It has been almost five years since the world ran one of the largest work-from-home experiments ever. In March 2020, the World Health Organization declared COVID-19 a pandemic. In the days and weeks that followed, employers around the world scrambled to have their workforces work remotely, securely, and productively.

Now in 2025, many organizations and government entities are still weighing when, if, and how to bring people back into offices, whether hybrid or full-time. Meanwhile, regulators, especially at the state level, have built their own guardrails. These standards apply to financial services, including collection agencies, and to employees working remotely. The issue stays challenging. Study after study shows that employees want to keep working remotely, at least part of the time. The same research shows they are productive when they do.

State regulators treat each employee's work-from-home (WFH) location as an extension of the employer's approved principal place of business for licensing and oversight. As a result, any employer that offers WFH must know the wide range of state and federal remote work, privacy, and data security laws that could apply. The integrity and confidentiality of consumer data matters a great deal to regulators. Any effective WFH program should rest on a sound foundation of data protection and information security.

Whether you allow full-time remote work or a hybrid arrangement, the checklist below covers key compliance topics to review. It is not legal advice. It is a summary compiled after reviewing many key states' WFH laws and data security standards, notably Maryland, Massachusetts, Nevada, and Washington. Review both federal and state laws that, depending on your business, may be relevant to your WFH program.

The WFH Agreement: Training, Readiness, and Knowledge of Your Program

To confirm that an employee is ready to work from home, many regulators expect a straightforward written agreement. It should spell out the key terms and conditions for a successful WFH arrangement. Tailor the agreement to the type of work your company does, and consider including the following:

  • Training period: explain how long a new WFH employee is expected to train and work in a company office before working remotely. Some states require employees to work in the office under existing staff for a set period first. Others set their own limits. They may cap how far from a company office a WFH employee can live, restrict work from outside the United States, or strongly prefer that certain employees, such as the compliance officer, work from a physical office.
  • Scope of work: describe the work you expect, and consider attaching the job description for each role. Spell out exactly what the employee may do from home and what may only be done in the office. Make clear that every company policy and procedure applies with equal force, wherever the employee works.
  • Equipment inventory: list all computing, telephony, and other key equipment the company provides. If the employee leaves, they must return it in good working order. Include any credentials for company or client software. As equipment is issued, HR or IT should catalog what each employee receives. On delivery, the employee should confirm they have read and will follow all company policies, including security policies and any policy that protects the equipment.
  • Approved location: confirm and certify a specific site as the employee's approved WFH location. The agreement can explain how to request a move and what makes a site approvable or not.

An approvable site is typically one that is:

  • quiet, private, and safe, where only one company employee conducts business (no coffee shops with free Wi-Fi and foot traffic);
  • equipped with reasonable utilities such as Wi-Fi, electricity, and surge protection;
  • set up so other household members cannot view monitors or work information, or overhear calls and video conferences;
  • secured, with company resources locked down at the end of every workday;
  • open to ongoing monitoring and oversight, potentially including site visits to verify the arrangement;
  • free from distractions and interference, such as other people and televisions;
  • fully connectable to the employer's technology systems, including any office computer system;
  • subject to full recording of all calls to and from the location, and real-time call monitoring;
  • accessed with unique user IDs, passwords, and credentials for all telephony and computing systems; and
  • covered by the employer's written information security program.

Privacy and Data Protection

  • Sharing is not caring when it comes to consumer nonpublic information or your company's proprietary information. Have the WFH agreement clearly describe each employee's duty to safeguard the integrity, availability, and confidentiality of any consumer or company information in their care. State and federal privacy and data protection laws apply to WFH work, whether at the office or an approved home site.
  • See something, say something. The flip side of confidentiality is reporting. Include "who to contact" information in the agreement, and encourage employees to speak up if they learn of any unexpected use or disclosure of consumer or company information.
  • Clarify what data may be kept at home. Spell out exactly what consumer data may and may not be maintained in the WFH environment. Consider a role-based matrix that defines whether any employee needs print capability or any consumer data, financial information, or company proprietary information in physical form at home.
  • No in-person consumer visits. WFH employees should not meet consumers at the employee's home or the consumer's. For collections, state laws are strict. They generally bar WFH employees from telling consumers they work remotely or that the home is a place of business. They also bar inviting consumers to their homes or visiting consumers' homes.

Written Information Security Program (WISP)

Under a wide range of federal and state laws, companies that handle consumer nonpublic information must maintain and enforce a written information security policy or plan. A WISP should include, but is not limited to, the following:

  • Access to technology systems only through a virtual private network or similar tool that uses multifactor authentication, data encryption, and frequent, complex password changes. The system should automatically lock an employee out if it detects suspicious activity.
  • Documented procedures for updates and repairs to the security network or system, so current security technologies stay in use.
  • Storage of consumer data on designated drives that are safe, secure, and expandable.
  • Antivirus software, firewalls, and other reasonable software and hardware protections on any device a WFH employee uses.
  • A rule that employees may not access company data, systems, or resources with devices used for personal purposes.
  • Immediate reporting to the employer of any unusual, suspicious, or unexpected use or disclosure of consumer or company data, especially where the law requires it.
  • Protection for data during a natural disaster or other emergency, plus recovery of that data afterward.
  • Specific procedures for secure retention and destruction of data, consistent with applicable laws.
  • Regular risk or gap assessments, with plans to make updates and improvements based on the results.
  • Controls that change or end an employee's access when they leave the company or change roles, so former employees can no longer reach any company or client systems.

Oversight and Management of WFH Employees

Regulators expect companies to maintain a thorough oversight and management program for WFH employees and their work. The program should include, but is not limited to:

  • Ongoing training and meetings, plus accessible supervisors and resources, so employees can meet their responsibilities.
  • Recording of all calls and work done servicing consumer accounts in company systems. Retain call recordings for at least four years, and other records potentially longer under applicable state and federal law.
  • Real-time monitoring of WFH employees' calls and activities on a regular, meaningful basis.
  • Confirmation that employees give consumers the company's proper address, email, and contact information.
  • Publication of company addresses to the public in marketing materials, never WFH employee addresses.
  • Current records of WFH employees, their approved locations, assigned equipment, job descriptions, and the work they are authorized to perform from home.
  • Monitoring to ensure employees work remotely without acting in any illegal, unethical, or unsafe way.
  • A review of all remote-work policies and procedures at least once a year for compliance with changing federal and state laws.
Navigating state-specific and ever-changing regulations can be overwhelming. Connect with Cornerstone for expert guidance tailored to your business.

Found This Useful? Let's Get You Set Up.

Start an application and an expert will tailor the next steps to your situation.

Related reading

15 Licensing Application Process Facts That Delay Approvals

Compliance

15 Licensing Application Process Facts That Delay Approvals

Most licensing delays come from small misses. A payment method that does not work, a stale certificate, the wrong signature, a missing ownership detail. These are the things that slow down filings, trigger deficiencies, and force teams to redo work they thought was finished. We pulled these from the webinar because they came up naturally [...]

California Delete Act: DROP Deadline and Data Broker Rules

Compliance

California Delete Act: DROP Deadline and Data Broker Rules

Property managers in Maryland are running into a question that is getting more attention and creating real operational risk. Does collecting rent, especially when a tenant is past due, trigger Maryland's collection agency licensing requirements?

The Changing Compliance Landscape for Consumer Lenders

Compliance

The Changing Compliance Landscape for Consumer Lenders

Explore evolving compliance rules for consumer lenders, CFPB updates, and strategies to stay compliant in 2025 and beyond.

Compliance Corner: Updates to FTC's Safeguards Rule

Compliance

Compliance Corner: Updates to FTC's Safeguards Rule

The FTC has now updated its Safeguards Rule to add breach notification requirements. It plans to host a new public database of instances in which consumers' nonpublic information has been subjected to unauthorized access. Effective May 13, 2024 Key features Financial institutions subject to the FTC's jurisdiction, which include mortgage lenders, payday lenders, collection agencies, [...]

Compliance Corner: What Regulators May Expect You To Know About the AI Tools You're Using in Your Collection Agency

Debt Collection & Buying

Compliance Corner: What Regulators May Expect You To Know About the AI Tools You're Using in Your Collection Agency

AI keeps reshaping financial services, and collection agencies are adding AI tools to streamline operations, strengthen compliance, and improve consumer engagement. With that innovation comes responsibility and a growing need for clarity on legal, ethical, and regulatory questions. Emerging technology like AI is top of mind for state financial services regulators, who increasingly ask how licensees use these tools.

Connecticut to License US Locations Only

Licensing

Connecticut to License US Locations Only

Update regarding new law: Connecticut to take a NO ACTION POSITION for Qualified Collection Agencies Earlier in August we reported that Connecticut had signed into law an Act that, among other things, stated that the Connecticut Department of Banking would no longer issue consumer collection agency licenses to an office outside of the United States [...]

Browse the full insights library, meet our editorial team, or download our whitepapers.

Insights

Found This Useful? Let's Get You Set Up.

An expert will respond within one business day.