Employee monitoring laws in Illinois
What Employee Monitoring Law Planner sets out for a monitoring practice at a site in Illinois: the notice, the written policy, the representative step, recording consent and what is not allowed, each cited to the law or the official guidance behind it. This is not every law that applies there.
- Location
- Illinois
- Laws placed
- US Electronic Communications Privacy Act, Title I (Wiretap Act, 18 USC 2510 to 2523); US Stored Communications Act (18 USC 2701 to 2713); Illinois Biometric Information Privacy Act (BIPA); Illinois Eavesdropping Act (720 ILCS 5, Article 14)
- Guidance placed
- ILO Code of Practice on the Protection of Workers' Personal Data 1997 official guidance, not law
- Read on
- 30 Sep 2026
What each practice needs here
20 practice classes| Practice | Representative step | Notice and policy | Recording consent | Not allowed | Paperwork |
|---|---|---|---|---|---|
| AI emotion or sentiment detection | none held | none held | none held | none held | none held |
| Keystroke logging | none held | none held | none held | none held | none held |
| Screenshots or screen recording | none held | none held | none held | none held | none held |
| Productivity or activity scoring | none held | none held | none held | none held | none held |
| Idle-time tracking | none held | none held | none held | none held | none held |
| Webcam or presence checks | none held | none held | none held | none held | none held |
| Email and messaging review | none held | none held | none held | none held | none held |
| DLP and email content filtering | none held | none held | none held | none held | none held |
| Website or email blocking | none held | none held | none held | none held | none held |
| Web and app usage logging | none held | none held | none held | none held | none held |
| Biometric time clock | none held | none held | none held | none held | statutory requirementwritten release, public schedulethree years at most |
| Access control logs | none held | none held | none held | none held | none held |
| CCTV (break, change or wash rooms) | none held | none held | none held | none held | none held |
| CCTV (work areas) | none held | none held | none held | none held | none held |
| GPS or vehicle telematics | none held | none held | none held | none held | none held |
| Mobile device location | none held | none held | none held | none held | none held |
| Call or speech analytics | none held | verification requiredemployees told, signs | statutory requirementone party's consentverification requiredevery party, or the business exemption | none held | none held |
| Call recording | none held | verification requiredemployees told, signs | statutory requirementone party's consentverification requiredevery party, or the business exemption | none held | none held |
| Social media monitoring | none held | none held | none held | none held | none held |
| Background checks as ongoing monitoring | none held | none held | none held | none held | none held |
Every requirement held here
- Noticeverification requiredWhere the business telephone monitoring exemption is relied on: tell current and prospective employees, including by prominent signs. Illinois Eavesdropping Act 14-3(j)
- Recording consentverification requiredNo surreptitious recording of a private conversation without the consent of every party; a business doing telephone sales, service or research may monitor its employees' calls for quality, training or research only with one active party's consent, with unmonitored personal lines, and with no onward use. Illinois Eavesdropping Act 14-2(a)(1)Illinois Eavesdropping Act 14-2(a)(2)Illinois Eavesdropping Act 14-2(a)(3)Illinois Eavesdropping Act 14-3(j)Illinois Eavesdropping Act 14-3(j)
- Recording consentstatutory requirementNo interception of calls or messages unless an exception applies: a party's prior consent (never for a criminal or tortious purpose), or equipment used in the ordinary course of business. Both are conditions to show, not a default. ECPA 2511(1)(a)ECPA 2511(2)(d)ECPA 2510(5)(a)
- Biometric datastatutory requirementBefore the first collection: written notice that a biometric identifier is collected, the specific purpose and term in writing, and a written release; a public retention schedule with destruction when the purpose is met or within three years of the last interaction; no disclosure without consent. BIPA s 15(a)BIPA s 15(b)(1)BIPA s 15(b)(2)BIPA s 15(b)(3)BIPA s 15(d)
- Personal devicesstatutory requirementAn employer can authorise access to messages on a service it provides; that does not reach an employee's personal webmail or accounts, which need the user's authorisation. (if personal devices are monitored) SCA 2701(a)SCA 2701(c)(1)SCA 2701(c)(2)
- Assessmentofficial guidance, not lawContinuous monitoring only for health and safety or the protection of property; monitoring output never the sole basis of a performance judgement. ILO code para 6.14(3)ILO code para 5.6 official guidance, not law
- Retentionstatutory requirementDestroyed when the purpose is met or within three years of the last interaction, whichever comes first. BIPA s 15(a)
- Retentionofficial guidance, not lawKept only as long as the purpose justifies. ILO code para 8.5 official guidance, not law
Findings a line here can raise
9 of 13- 1 Representative step before start not recorded
- 2 Notice not recorded, or its period not met
- 4 Covert monitoring
- 7 Call recording consent
- 8 Biometric data
- 10 Continuous, keystroke or screenshot monitoring with no assessment recorded
- 11 Retention not set, or above the period you set
- 12 Personal devices monitored
- 13 Lawful basis not recorded for an EU or UK line
Named, not quoted
- National Labor Relations Act section 7: employees' rights to organise and act together (the United States; named, not quoted)
Named so you know to open them. We do not hold their text and the page does not state what they require beyond the subject.
The provisions cited here
27 provisionsILO code para 12.2(b)Inform and consult representatives before introducing electronic monitoring official guidance, not lawWhere workers' representatives exist, and in line with national law and practice, inform and consult them before electronic surveillance of how workers act at work is brought in.
Illinois Eavesdropping Act 14-3(j)Business telephone monitoring: notice to current and prospective employees and workplace signage Text not verified against the current consolidation; open the Act before relying on it.A business using telephone monitoring or recording under this exemption must tell current and prospective employees that monitoring or recording may happen during their employment, including by prominent signs in the workplace.
ILO code para 6.14(1)Tell workers in advance about monitoring and minimize intrusion official guidance, not lawBefore any monitoring starts, workers should learn why it is done, when it runs, how it works (methods and techniques) and which data it gathers, and the employer must keep the intrusion on workers' privacy as small as possible.
ILO code para 5.8Keep workers and representatives informed official guidance, not lawWorkers and their representatives should be told about every data collection process, the rules governing it and their rights.
ILO code para 6.14(2)Secret monitoring only where national law allows it or on reasonable suspicion official guidance, not lawCovert monitoring should be allowed only where national law permits it or where there are reasonable grounds to suspect a crime or other grave misconduct.
Illinois Eavesdropping Act 14-2(a)(1)No surreptitious overhearing or recording of others' private conversations without all-party consent Text not verified against the current consolidation; open the Act before relying on it.A person must not knowingly and intentionally use an eavesdropping device in a surreptitious manner to overhear, transmit or record any part of a private conversation to which that person is not a party, unless all parties to the conversation consent. For an employer this covers covert listening devices and silent monitoring of employees' private conversations.
Illinois Eavesdropping Act 14-2(a)(2)No surreptitious recording of a private conversation one is party to without the others' consent Text not verified against the current consolidation; open the Act before relying on it.A person must not knowingly and intentionally use an eavesdropping device in a surreptitious manner to transmit or record any part of a private conversation to which that person is a party, unless all other parties consent. Recording one's own calls or meetings openly, with the other parties aware, is not surreptitious.
Illinois Eavesdropping Act 14-2(a)(3)No surreptitious interception of others' private electronic communications without all-party consent Text not verified against the current consolidation; open the Act before relying on it.A person must not knowingly and intentionally intercept, record or transcribe, in a surreptitious manner, a private electronic communication to which that person is not a party, unless all parties to it consent.
Illinois Eavesdropping Act 14-3(j)Business telephone monitoring: only for quality, training or research, with one active party's consent Text not verified against the current consolidation; open the Act before relying on it.A business engaged in telephone solicitation by live operators (soliciting sales, taking orders, helping customers use goods or services, or soliciting, administering or collecting bank or retail credit accounts) or in marketing or opinion research may use a telephone monitoring device to record or listen to those conversations by its employees only for service quality control, education or training of the employees or contractors doing that work, or internal research on it, and only with the consent of at least one active party to the conversation monitored.
Illinois Eavesdropping Act 14-3(j)Business telephone monitoring: personal lines, stop and destroy, no onward use Text not verified against the current consolidation; open the Act before relying on it.A business using the exemption must give employees access to personal telephone lines that are not monitored or recorded; must stop listening or recording at once, and destroy the recording as soon as practicable, when a monitored conversation turns out not to concern the solicitation or research work; and must not furnish anything obtained under the exemption to law enforcement, use it in any inquiry, investigation or administrative, judicial or other proceeding, or divulge it to any third party.
ECPA 2511(1)(a)Do not intercept wire, oral or electronic communications Unless the chapter specifically provides otherwise, no person may intentionally intercept, try to intercept, or procure anyone else to intercept or try to intercept, any wire, oral or electronic communication. For an employer this covers real-time capture of calls, email or messages in transit, keystroke or screen tools that acquire message contents as they are sent, and listening devices, unless an exception (provider, business extension, consent) applies.
ECPA 2511(2)(d)One-party consent: be a party or have a party's prior consent, and never for a criminal or tortious purpose A person not acting under color of law may intercept a wire, oral or electronic communication where that person is a party to it or one of the parties has given prior consent, unless the interception is for the purpose of committing a criminal or tortious act against the Constitution or the laws of the United States or any State. Employers commonly obtain the employee's prior consent through a signed monitoring policy; consent must cover the monitoring actually carried out, and state all-party consent laws can still apply.
ECPA 2510(5)(a)Business-extension exclusion: provider-furnished equipment used in the ordinary course of business The prohibition turns on the use of an electronic, mechanical or other device. Telephone or telegraph equipment or facilities, or their components, furnished to the subscriber or user by a provider in the ordinary course of its business and used by the subscriber or user in the ordinary course of its business (or furnished by the subscriber or user to connect to the service and so used), and equipment used by a provider in the ordinary course of its business, are not such a device. An employer's use of its phone system to monitor business calls can fall outside the prohibition where the monitoring is in the ordinary course of business; hearing aids are also excluded.
BIPA s 15(a)Written, public retention schedule and destruction guidelines, applied A private entity in possession of biometric identifiers or biometric information must develop a written policy, made available to the public, that establishes a retention schedule and guidelines for permanently destroying the identifiers and information when the initial purpose for collecting or obtaining them has been satisfied or within three years of the individual's last interaction with the entity, whichever comes first. Absent a valid warrant or subpoena issued by a court of competent jurisdiction, the entity must comply with its own established schedule and guidelines. The duty attaches on possession, so an entity that holds biometric data collected by a vendor on its behalf must publish the policy as well.
BIPA s 15(b)(1)Written notice that a biometric identifier or information is being collected or stored Before collecting, capturing, purchasing, receiving through trade or otherwise obtaining a person's or customer's biometric identifier or biometric information, the private entity must inform the subject, or the subject's legally authorized representative, in writing that a biometric identifier or biometric information is being collected or stored. The notice must precede the first collection; a notice given after enrolment does not cure the collection already made.
BIPA s 15(b)(2)Written notice of the specific purpose and length of term of collection, storage and use Before obtaining a biometric identifier or biometric information, the private entity must inform the subject or the subject's legally authorized representative in writing of the specific purpose for which, and the length of term for which, the identifier or information is being collected, stored and used. The purpose must be specific to the use (timekeeping, facility access, identity verification for a transaction) and the term must be stated, which in practice ties the notice to the retention schedule of 15(a).
BIPA s 15(b)(3)Written release executed by the subject or representative before collection Before obtaining a biometric identifier or biometric information, the private entity must receive a written release executed by the subject of the identifier or information or by the subject's legally authorized representative. A written release is informed written consent, an electronic signature (a checkbox, click-through or other electronic process executed with intent to sign, confirmed by the 2024 amendment) or, in employment, a release executed by an employee as a condition of employment. For a minor the release comes from the parent or guardian.
BIPA s 15(d)No disclosure, redisclosure or dissemination except on four grounds No private entity in possession of a biometric identifier or biometric information may disclose, redisclose or otherwise disseminate a person's or customer's biometric identifier or biometric information unless the subject or the subject's legally authorized representative consents to the disclosure or redisclosure; or the disclosure completes a financial transaction requested or authorized by the subject or representative; or the disclosure is required by State or federal law or municipal ordinance; or the disclosure is required by a valid warrant or subpoena issued by a court of competent jurisdiction. Transfer to a vendor or cloud provider is a disclosure that needs consent. Under section 20(c) as amended in 2024, repeated disclosure of the same identifier from the same person to the same recipient by the same method is a single violation with at most one recovery.
ILO code para 6.14(3)Continuous monitoring only for health and safety or protection of property official guidance, not lawMonitoring that never stops should be allowed only where it is needed for workplace health and safety or to protect property.
ILO code para 5.6Monitoring data not the sole basis of performance evaluation official guidance, not lawOutput from electronic surveillance should never be the sole input when a worker's performance is judged.
ILO code para 8.5Retain only as long as the purpose justifies official guidance, not lawKeep personal data only as long as the specific purposes of collection justify, unless a worker asks to stay on a candidate list for a set period, national law requires retention, or the employer or worker needs the data for legal proceedings about an existing or former employment relationship.
SCA 2701(a)Do not access a communication service facility without authorization to reach stored communications Unless subsection (c) applies, no person may intentionally access without authorization a facility through which an electronic communication service is provided, or intentionally exceed an authorization to access it, and thereby obtain, alter or prevent authorized access to a wire or electronic communication while it is in electronic storage in that system. Penalties (2701(b)): for commercial advantage, malicious destruction, private gain or in furtherance of a criminal or tortious act, up to 5 years (10 for a repeat); otherwise up to 1 year (5 for a repeat after a prior conviction). For an employer this reaches logging into an employee's personal email, social media or messaging account, for example with a saved password on a work device, without the employee's authorization.
SCA 2701(c)(1)Authorization by the service provider: access to the employer's own communication service Subsection (a) does not apply to conduct authorized by the person or entity providing the wire or electronic communications service. An employer that provides its own email or messaging service to employees can authorize access to communications stored on that service; the authorization does not extend to services the employer does not provide, such as an employee's personal webmail.
SCA 2701(c)(2)Authorization by the user for that user's own communications Subsection (a) does not apply to conduct authorized by a user of the service with respect to a communication of, or intended for, that user. Access to an employee's stored messages with that employee's authorization is outside the offense; access to a third party's messages needs that user's authorization or another exception.
ILO code para 5.1Fair, employment-related processing within the law official guidance, not law5.1 Lawful, fair and employment-related processing. Handle workers' data lawfully and fairly, and solely for reasons that bear directly on the person's job.
ILO code para 6.5No data on sex life, beliefs or convictions, save exceptionally official guidance, not lawEmployers should not collect data on a worker's sex life, political, religious or other beliefs, or criminal convictions, except in rare cases where national law permits it and the information bears directly on a decision about the job.
ILO code para 6.6No data on union membership or activities unless required official guidance, not lawEmployers should not collect data on a worker's membership of a workers' organization or trade union activities unless the law or a collective agreement requires or permits it.