Employee Monitoring Law Planner
Laws

Employee monitoring laws in Connecticut

What Employee Monitoring Law Planner sets out for a monitoring practice at a site in Connecticut: the notice, the written policy, the representative step, recording consent and what is not allowed, each cited to the law or the official guidance behind it. This is not every law that applies there.

Location
Connecticut
Laws placed
US Electronic Communications Privacy Act, Title I (Wiretap Act, 18 USC 2510 to 2523); US Stored Communications Act (18 USC 2701 to 2713); Connecticut General Statutes section 31-48d (electronic monitoring of employees)
Guidance placed
ILO Code of Practice on the Protection of Workers' Personal Data 1997 official guidance, not law
Read on
30 Sep 2026

What each practice needs here

20 practice classes
PracticeRepresentative stepNotice and policyRecording consentNot allowedPaperwork
AI emotion or sentiment detectionnone heldstatutory requirementnotice of types and locations, posted (the replacement text takes effect 1 October 2026 (Public Act 26-73); before that date it is not in force)none heldnone heldnone held
Keystroke loggingnone heldstatutory requirementnotice of types and locations, posted (the replacement text takes effect 1 October 2026 (Public Act 26-73); before that date it is not in force)none heldnone heldnone held
Screenshots or screen recordingnone heldstatutory requirementnotice of types and locations, posted (the replacement text takes effect 1 October 2026 (Public Act 26-73); before that date it is not in force)none heldnone heldnone held
Productivity or activity scoringnone heldstatutory requirementnotice of types and locations, posted (the replacement text takes effect 1 October 2026 (Public Act 26-73); before that date it is not in force)none heldnone heldnone held
Idle-time trackingnone heldstatutory requirementnotice of types and locations, posted (the replacement text takes effect 1 October 2026 (Public Act 26-73); before that date it is not in force)none heldnone heldnone held
Webcam or presence checksnone heldstatutory requirementnotice of types and locations, posted (the replacement text takes effect 1 October 2026 (Public Act 26-73); before that date it is not in force)none heldstatutory requirementnot in rest rooms, locker rooms, lounges (where it covers toilets or washrooms, change or locker rooms, showers or bathing areas and break rooms or staff lounges)none held
Email and messaging reviewnone heldstatutory requirementnotice of types and locations, posted (the replacement text takes effect 1 October 2026 (Public Act 26-73); before that date it is not in force)none heldnone heldnone held
DLP and email content filteringnone heldstatutory requirementnotice of types and locations, posted (the replacement text takes effect 1 October 2026 (Public Act 26-73); before that date it is not in force)none heldnone heldnone held
Website or email blockingnone heldstatutory requirementnotice of types and locations, posted (the replacement text takes effect 1 October 2026 (Public Act 26-73); before that date it is not in force)none heldnone heldnone held
Web and app usage loggingnone heldstatutory requirementnotice of types and locations, posted (the replacement text takes effect 1 October 2026 (Public Act 26-73); before that date it is not in force)none heldnone heldnone held
Biometric time clocknone heldstatutory requirementnotice of types and locations, posted (the replacement text takes effect 1 October 2026 (Public Act 26-73); before that date it is not in force)none heldnone heldnone held
Access control logsnone heldstatutory requirementnotice of types and locations, posted (the replacement text takes effect 1 October 2026 (Public Act 26-73); before that date it is not in force)none heldnone heldnone held
CCTV (break, change or wash rooms)none heldstatutory requirementnotice of types and locations, posted (the replacement text takes effect 1 October 2026 (Public Act 26-73); before that date it is not in force)none heldstatutory requirementnot in rest rooms, locker rooms, lounges (where it covers toilets or washrooms, change or locker rooms, showers or bathing areas and break rooms or staff lounges)none held
CCTV (work areas)none heldstatutory requirementnotice of types and locations, posted (the replacement text takes effect 1 October 2026 (Public Act 26-73); before that date it is not in force)none heldstatutory requirementnot in rest rooms, locker rooms, lounges (where it covers toilets or washrooms, change or locker rooms, showers or bathing areas and break rooms or staff lounges)none held
GPS or vehicle telematicsnone heldstatutory requirementnotice of types and locations, posted (the replacement text takes effect 1 October 2026 (Public Act 26-73); before that date it is not in force)none heldnone heldnone held
Mobile device locationnone heldstatutory requirementnotice of types and locations, posted (the replacement text takes effect 1 October 2026 (Public Act 26-73); before that date it is not in force)none heldnone heldnone held
Call or speech analyticsnone heldstatutory requirementnotice of types and locations, posted (the replacement text takes effect 1 October 2026 (Public Act 26-73); before that date it is not in force)statutory requirementone party's consentstatutory requirementnot in rest rooms, locker rooms, lounges (where it covers toilets or washrooms, change or locker rooms, showers or bathing areas and break rooms or staff lounges)none held
Call recordingnone heldstatutory requirementnotice of types and locations, posted (the replacement text takes effect 1 October 2026 (Public Act 26-73); before that date it is not in force)statutory requirementone party's consentstatutory requirementnot in rest rooms, locker rooms, lounges (where it covers toilets or washrooms, change or locker rooms, showers or bathing areas and break rooms or staff lounges)none held
Social media monitoringnone heldnone heldnone heldnone heldnone held
Background checks as ongoing monitoringnone heldnone heldnone heldnone heldnone held

Every requirement held here

Findings a line here can raise

9 of 13

Named, not quoted

Named so you know to open them. We do not hold their text and the page does not state what they require beyond the subject.

The provisions cited here

21 provisions
ILO code para 12.2(b)Inform and consult representatives before introducing electronic monitoring official guidance, not law

Where workers' representatives exist, and in line with national law and practice, inform and consult them before electronic surveillance of how workers act at work is brought in.

What a reviewer asks to see: Consultation record for each monitoring system, dated before introduction, with the representatives' views and the employer's response
Where monitoring plans usually fall short: Monitoring tool piloted without consulting the representatives
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
Conn. Gen. Stat. 31-48d(b)(1)Give prior written notice of the types and specific locations of monitoring This is the text of Public Act 26-73, in force from 1 October 2026.

Unless an exception in (b)(2) or (b)(3) applies, an employer that engages in any type of electronic monitoring must give prior written notice to all employees who may be affected, informing them of the types of monitoring that may occur and the specific locations on the employer's premises where it may occur.

What a reviewer asks to see: Written monitoring notice listing each type of monitoring (email, computer activity, telephone, video, access control) and the premises locations covered; Monitoring inventory by site and location reconciled to the notice; Record of the date each affected employee received the notice, before monitoring began
Where monitoring plans usually fall short: Notice lists types of monitoring but not the locations, as the pre-October 2026 text allowed; New cameras or tools added without updating the notice; Notice not given to employees at a newly opened site
Source: Connecticut General Statutes section 31-48d (electronic monitoring of employees), read 30 Sep 2026
Conn. Gen. Stat. 31-48d(b)(1)Post the notice conspicuously, including where monitoring occurs This is the text of Public Act 26-73, in force from 1 October 2026.

The employer must post, in a conspicuous place readily available for employees to view, including the specific locations on the premises where monitoring may occur, a notice of the types of electronic monitoring it may engage in and those specific locations. The posting constitutes the prior written notice.

What a reviewer asks to see: Photographs or site checklist showing the notice posted in a common area and at each monitored location; Current poster text naming the monitoring types and locations
Where monitoring plans usually fall short: Single poster in a break room, none at the monitored locations; Poster still in the old P.A. 98-142 form without locations
Source: Connecticut General Statutes section 31-48d (electronic monitoring of employees), read 30 Sep 2026
Conn. Gen. Stat. 31-48d(b)(1)Give new hires a plain-language statement before they start This is the text of Public Act 26-73, in force from 1 October 2026.

An employer that engages in any electronic monitoring must give each employee hired on or after 1 October 2026, before the employee starts work, a plain-language written statement advising which activities are prohibited and may be monitored without prior written notice under (b)(2).

What a reviewer asks to see: Plain-language statement of prohibited activities that may be monitored without notice, as issued to new hires; Onboarding records for hires from 1 October 2026 showing the statement was given before the start date
Where monitoring plans usually fall short: Statement given on the first day or later rather than before work starts; Legalistic wording that does not tell employees which activities are prohibited
Source: Connecticut General Statutes section 31-48d (electronic monitoring of employees), read 30 Sep 2026
Conn. Gen. Stat. 31-48d(b)(3)Location disclosure exemption: airports and security and safety grounds This is the text of Public Act 26-73, in force from 1 October 2026.

The duty to disclose the specific locations of monitoring does not apply where the premises are an airport, or where the employer has reasonable grounds to conduct the monitoring for security and employee safety purposes. The duty to give notice of the types of monitoring still applies.

What a reviewer asks to see: Documented basis for withholding locations (airport premises, or the security and safety grounds relied on) per monitored location; Notice showing monitoring types are still disclosed where locations are withheld
Where monitoring plans usually fall short: Exemption used to withhold locations for productivity monitoring; Types of monitoring also left out of the notice under the exemption
Source: Connecticut General Statutes section 31-48d (electronic monitoring of employees), read 30 Sep 2026
ILO code para 6.14(1)Tell workers in advance about monitoring and minimize intrusion official guidance, not law

Before any monitoring starts, workers should learn why it is done, when it runs, how it works (methods and techniques) and which data it gathers, and the employer must keep the intrusion on workers' privacy as small as possible.

What a reviewer asks to see: Monitoring notice per system stating reasons, schedule, methods and data collected, issued before monitoring starts; Proportionality assessment showing less intrusive options considered
Where monitoring plans usually fall short: Notice states only that monitoring may occur, without schedule or methods; Screenshots captured continuously when sampling would serve the purpose
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ILO code para 5.8Keep workers and representatives informed official guidance, not law

Workers and their representatives should be told about every data collection process, the rules governing it and their rights.

What a reviewer asks to see: Worker privacy notice covering each collection process, its rules and workers' rights; Record of the information given to worker representatives
Where monitoring plans usually fall short: Notice covers HR records but not monitoring systems
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
Conn. Gen. Stat. 31-48d(b)(2)Monitor without prior notice only on reasonable grounds of misconduct This is the text of Public Act 26-73, in force from 1 October 2026.

An employer may monitor without prior written notice only when it has reasonable grounds to believe employees are engaged in conduct that violates the law, violates the legal rights of the employer or its employees, or creates a hostile workplace environment, and electronic monitoring may produce evidence of that misconduct.

What a reviewer asks to see: Investigation file recording the grounds for belief, the suspected conduct and why monitoring may produce evidence, dated before covert monitoring began; Approval record naming who authorized the covert monitoring and its scope and end date
Where monitoring plans usually fall short: Covert monitoring started on a general suspicion with no recorded grounds; Covert monitoring widened beyond the employees and conduct under investigation
Source: Connecticut General Statutes section 31-48d (electronic monitoring of employees), read 30 Sep 2026
ILO code para 6.14(2)Secret monitoring only where national law allows it or on reasonable suspicion official guidance, not law

Covert monitoring should be allowed only where national law permits it or where there are reasonable grounds to suspect a crime or other grave misconduct.

What a reviewer asks to see: Authorization record for each covert monitoring exercise with the suspicion and grounds, or the legal provision relied on; End date and review of each exercise
Where monitoring plans usually fall short: Covert monitoring used for general performance concerns
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ECPA 2511(1)(a)Do not intercept wire, oral or electronic communications

Unless the chapter specifically provides otherwise, no person may intentionally intercept, try to intercept, or procure anyone else to intercept or try to intercept, any wire, oral or electronic communication. For an employer this covers real-time capture of calls, email or messages in transit, keystroke or screen tools that acquire message contents as they are sent, and listening devices, unless an exception (provider, business extension, consent) applies.

What a reviewer asks to see: Register of every tool that captures communication contents in real time (call recording, voice analytics, email or chat journaling, DLP inspection, keyloggers), with the exception relied on for each; Legal sign-off per tool recording why the interception is lawful (party consent, provider exception or business-extension use)
Where monitoring plans usually fall short: Monitoring software deployed with no documented legal basis; Personal accounts or personal calls captured by the same tools as business traffic
Source: US Electronic Communications Privacy Act, Title I (Wiretap Act, 18 USC 2510 to 2523), read 30 Sep 2026
ECPA 2511(2)(d)One-party consent: be a party or have a party's prior consent, and never for a criminal or tortious purpose

A person not acting under color of law may intercept a wire, oral or electronic communication where that person is a party to it or one of the parties has given prior consent, unless the interception is for the purpose of committing a criminal or tortious act against the Constitution or the laws of the United States or any State. Employers commonly obtain the employee's prior consent through a signed monitoring policy; consent must cover the monitoring actually carried out, and state all-party consent laws can still apply.

What a reviewer asks to see: Signed or electronically accepted monitoring consent from each employee, describing the communications and methods monitored; Mapping of the consent wording to each monitoring tool in the register; Check of state law for locations where all-party consent is required
Where monitoring plans usually fall short: Consent wording covers email but the tool also captures calls or personal messaging; Consent relied on for calls with outside parties in all-party consent states
Source: US Electronic Communications Privacy Act, Title I (Wiretap Act, 18 USC 2510 to 2523), read 30 Sep 2026
ECPA 2510(5)(a)Business-extension exclusion: provider-furnished equipment used in the ordinary course of business

The prohibition turns on the use of an electronic, mechanical or other device. Telephone or telegraph equipment or facilities, or their components, furnished to the subscriber or user by a provider in the ordinary course of its business and used by the subscriber or user in the ordinary course of its business (or furnished by the subscriber or user to connect to the service and so used), and equipment used by a provider in the ordinary course of its business, are not such a device. An employer's use of its phone system to monitor business calls can fall outside the prohibition where the monitoring is in the ordinary course of business; hearing aids are also excluded.

What a reviewer asks to see: Description of the phone system and the monitoring features used, showing they are part of the service equipment; Business justification for call monitoring (quality, training, compliance) and the rule for ending monitoring once a call is personal
Where monitoring plans usually fall short: Monitoring continues after a call is identified as personal; Add-on recording hardware not furnished as part of the service relied on as business extension
Source: US Electronic Communications Privacy Act, Title I (Wiretap Act, 18 USC 2510 to 2523), read 30 Sep 2026
ILO code para 6.14(3)Continuous monitoring only for health and safety or protection of property official guidance, not law

Monitoring that never stops should be allowed only where it is needed for workplace health and safety or to protect property.

What a reviewer asks to see: Register of continuous monitoring (CCTV, telematics, always-on tracking) with the health, safety or property ground for each
Where monitoring plans usually fall short: Always-on webcam or activity tracking for remote staff justified by productivity
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ILO code para 5.6Monitoring data not the sole basis of performance evaluation official guidance, not law

Output from electronic surveillance should never be the sole input when a worker's performance is judged.

What a reviewer asks to see: Appraisal procedure listing the evidence sources considered besides monitoring data; Sample appraisals showing other inputs (manager review, outputs, feedback)
Where monitoring plans usually fall short: Productivity scores from activity tracking used as the whole appraisal
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ILO code para 8.5Retain only as long as the purpose justifies official guidance, not law

Keep personal data only as long as the specific purposes of collection justify, unless a worker asks to stay on a candidate list for a set period, national law requires retention, or the employer or worker needs the data for legal proceedings about an existing or former employment relationship.

What a reviewer asks to see: Retention schedule for worker data including monitoring records, citing purpose, legal requirement or proceedings; Deletion logs
Where monitoring plans usually fall short: Monitoring recordings kept indefinitely; Unsuccessful applicants' data kept without their agreement
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
SCA 2701(a)Do not access a communication service facility without authorization to reach stored communications

Unless subsection (c) applies, no person may intentionally access without authorization a facility through which an electronic communication service is provided, or intentionally exceed an authorization to access it, and thereby obtain, alter or prevent authorized access to a wire or electronic communication while it is in electronic storage in that system. Penalties (2701(b)): for commercial advantage, malicious destruction, private gain or in furtherance of a criminal or tortious act, up to 5 years (10 for a repeat); otherwise up to 1 year (5 for a repeat after a prior conviction). For an employer this reaches logging into an employee's personal email, social media or messaging account, for example with a saved password on a work device, without the employee's authorization.

What a reviewer asks to see: Investigation procedure prohibiting access to employees' personal accounts (webmail, social media, messaging) without their authorization; Record of the authority for each access to stored communications made in an investigation (employer-provided system, user consent); Guidance to IT on handling personal account sessions or saved credentials found on work devices
Where monitoring plans usually fall short: Manager reads an employee's personal webmail left logged in on a work laptop; Former employee's personal account accessed with a remembered password after departure
Source: US Stored Communications Act (18 USC 2701 to 2713), read 30 Sep 2026
SCA 2701(c)(1)Authorization by the service provider: access to the employer's own communication service

Subsection (a) does not apply to conduct authorized by the person or entity providing the wire or electronic communications service. An employer that provides its own email or messaging service to employees can authorize access to communications stored on that service; the authorization does not extend to services the employer does not provide, such as an employee's personal webmail.

What a reviewer asks to see: List of communication services the organization itself provides (email, chat, voicemail) and who may authorize access to stored content; Access authorization records for reviews of stored communications on those services
Where monitoring plans usually fall short: Provider authorization relied on for a third-party personal account; No record of who authorized a mailbox search
Source: US Stored Communications Act (18 USC 2701 to 2713), read 30 Sep 2026
SCA 2701(c)(2)Authorization by the user for that user's own communications

Subsection (a) does not apply to conduct authorized by a user of the service with respect to a communication of, or intended for, that user. Access to an employee's stored messages with that employee's authorization is outside the offense; access to a third party's messages needs that user's authorization or another exception.

What a reviewer asks to see: Written authorization from the account user for access to the user's stored communications, stating the scope; Check that the person authorizing is the user of the communications accessed
Where monitoring plans usually fall short: Authorization obtained from a coworker to read another employee's private messages; Authorization obtained by pressure or as a condition of employment without legal review
Source: US Stored Communications Act (18 USC 2701 to 2713), read 30 Sep 2026
ILO code para 5.1Fair, employment-related processing within the law official guidance, not law

5.1 Lawful, fair and employment-related processing. Handle workers' data lawfully and fairly, and solely for reasons that bear directly on the person's job.

What a reviewer asks to see: Register of worker data processing activities, each with its employment-related reason and legal basis
Where monitoring plans usually fall short: Data collected for reasons unrelated to the job, such as off-duty social media activity
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ILO code para 6.5No data on sex life, beliefs or convictions, save exceptionally official guidance, not law

Employers should not collect data on a worker's sex life, political, religious or other beliefs, or criminal convictions, except in rare cases where national law permits it and the information bears directly on a decision about the job.

What a reviewer asks to see: Data inventory confirming these categories are not collected, or the documented exception and legal basis where they are
Where monitoring plans usually fall short: Criminal record checks for every role regardless of relevance
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ILO code para 6.6No data on union membership or activities unless required official guidance, not law

Employers should not collect data on a worker's membership of a workers' organization or trade union activities unless the law or a collective agreement requires or permits it.

What a reviewer asks to see: Review of HR and monitoring systems confirming union data are not collected except under a stated legal or agreement basis
Where monitoring plans usually fall short: Monitoring tools flag union-related email or chat
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026

See the specimen plan run Plan your own list