Employee Monitoring Law Planner
Laws

Employee monitoring laws in Illinois

What Employee Monitoring Law Planner sets out for a monitoring practice at a site in Illinois: the notice, the written policy, the representative step, recording consent and what is not allowed, each cited to the law or the official guidance behind it. This is not every law that applies there.

Location
Illinois
Laws placed
US Electronic Communications Privacy Act, Title I (Wiretap Act, 18 USC 2510 to 2523); US Stored Communications Act (18 USC 2701 to 2713); Illinois Biometric Information Privacy Act (BIPA); Illinois Eavesdropping Act (720 ILCS 5, Article 14)
Guidance placed
ILO Code of Practice on the Protection of Workers' Personal Data 1997 official guidance, not law
Read on
30 Sep 2026

What each practice needs here

20 practice classes
PracticeRepresentative stepNotice and policyRecording consentNot allowedPaperwork
AI emotion or sentiment detectionnone heldnone heldnone heldnone heldnone held
Keystroke loggingnone heldnone heldnone heldnone heldnone held
Screenshots or screen recordingnone heldnone heldnone heldnone heldnone held
Productivity or activity scoringnone heldnone heldnone heldnone heldnone held
Idle-time trackingnone heldnone heldnone heldnone heldnone held
Webcam or presence checksnone heldnone heldnone heldnone heldnone held
Email and messaging reviewnone heldnone heldnone heldnone heldnone held
DLP and email content filteringnone heldnone heldnone heldnone heldnone held
Website or email blockingnone heldnone heldnone heldnone heldnone held
Web and app usage loggingnone heldnone heldnone heldnone heldnone held
Biometric time clocknone heldnone heldnone heldnone heldstatutory requirementwritten release, public schedulethree years at most
Access control logsnone heldnone heldnone heldnone heldnone held
CCTV (break, change or wash rooms)none heldnone heldnone heldnone heldnone held
CCTV (work areas)none heldnone heldnone heldnone heldnone held
GPS or vehicle telematicsnone heldnone heldnone heldnone heldnone held
Mobile device locationnone heldnone heldnone heldnone heldnone held
Call or speech analyticsnone heldverification requiredemployees told, signsstatutory requirementone party's consentverification requiredevery party, or the business exemptionnone heldnone held
Call recordingnone heldverification requiredemployees told, signsstatutory requirementone party's consentverification requiredevery party, or the business exemptionnone heldnone held
Social media monitoringnone heldnone heldnone heldnone heldnone held
Background checks as ongoing monitoringnone heldnone heldnone heldnone heldnone held

Every requirement held here

Findings a line here can raise

9 of 13

Named, not quoted

Named so you know to open them. We do not hold their text and the page does not state what they require beyond the subject.

The provisions cited here

27 provisions
ILO code para 12.2(b)Inform and consult representatives before introducing electronic monitoring official guidance, not law

Where workers' representatives exist, and in line with national law and practice, inform and consult them before electronic surveillance of how workers act at work is brought in.

What a reviewer asks to see: Consultation record for each monitoring system, dated before introduction, with the representatives' views and the employer's response
Where monitoring plans usually fall short: Monitoring tool piloted without consulting the representatives
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
Illinois Eavesdropping Act 14-3(j)Business telephone monitoring: notice to current and prospective employees and workplace signage Text not verified against the current consolidation; open the Act before relying on it.

A business using telephone monitoring or recording under this exemption must tell current and prospective employees that monitoring or recording may happen during their employment, including by prominent signs in the workplace.

What a reviewer asks to see: Job advertisement or offer-letter wording telling candidates about call monitoring; Photographs of prominent workplace signs about call monitoring or recording
Where monitoring plans usually fall short: Notice given to employees but not to prospective employees; Signage missing at remote or satellite sites
Source: Illinois Eavesdropping Act (720 ILCS 5, Article 14), read 30 Sep 2026
ILO code para 6.14(1)Tell workers in advance about monitoring and minimize intrusion official guidance, not law

Before any monitoring starts, workers should learn why it is done, when it runs, how it works (methods and techniques) and which data it gathers, and the employer must keep the intrusion on workers' privacy as small as possible.

What a reviewer asks to see: Monitoring notice per system stating reasons, schedule, methods and data collected, issued before monitoring starts; Proportionality assessment showing less intrusive options considered
Where monitoring plans usually fall short: Notice states only that monitoring may occur, without schedule or methods; Screenshots captured continuously when sampling would serve the purpose
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ILO code para 5.8Keep workers and representatives informed official guidance, not law

Workers and their representatives should be told about every data collection process, the rules governing it and their rights.

What a reviewer asks to see: Worker privacy notice covering each collection process, its rules and workers' rights; Record of the information given to worker representatives
Where monitoring plans usually fall short: Notice covers HR records but not monitoring systems
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ILO code para 6.14(2)Secret monitoring only where national law allows it or on reasonable suspicion official guidance, not law

Covert monitoring should be allowed only where national law permits it or where there are reasonable grounds to suspect a crime or other grave misconduct.

What a reviewer asks to see: Authorization record for each covert monitoring exercise with the suspicion and grounds, or the legal provision relied on; End date and review of each exercise
Where monitoring plans usually fall short: Covert monitoring used for general performance concerns
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
Illinois Eavesdropping Act 14-2(a)(1)No surreptitious overhearing or recording of others' private conversations without all-party consent Text not verified against the current consolidation; open the Act before relying on it.

A person must not knowingly and intentionally use an eavesdropping device in a surreptitious manner to overhear, transmit or record any part of a private conversation to which that person is not a party, unless all parties to the conversation consent. For an employer this covers covert listening devices and silent monitoring of employees' private conversations.

What a reviewer asks to see: Inventory of audio capture in Illinois workplaces (CCTV audio, meeting recorders, call listening) with how each is disclosed to all parties; Legal review record before any covert audio monitoring, confirming all-party consent or a statutory exemption
Where monitoring plans usually fall short: CCTV audio recording break-room conversations without notice; Supervisors silently listening to employee calls outside an exemption
Source: Illinois Eavesdropping Act (720 ILCS 5, Article 14), read 30 Sep 2026
Illinois Eavesdropping Act 14-2(a)(2)No surreptitious recording of a private conversation one is party to without the others' consent Text not verified against the current consolidation; open the Act before relying on it.

A person must not knowingly and intentionally use an eavesdropping device in a surreptitious manner to transmit or record any part of a private conversation to which that person is a party, unless all other parties consent. Recording one's own calls or meetings openly, with the other parties aware, is not surreptitious.

What a reviewer asks to see: Recording announcement or banner used on calls and virtual meetings with Illinois participants; Policy on managers or HR recording interviews and disciplinary meetings, requiring notice to all participants
Where monitoring plans usually fall short: Manager records a disciplinary meeting on a phone without telling the employee; AI note-taker joins meetings without notice to external participants
Source: Illinois Eavesdropping Act (720 ILCS 5, Article 14), read 30 Sep 2026
Illinois Eavesdropping Act 14-2(a)(3)No surreptitious interception of others' private electronic communications without all-party consent Text not verified against the current consolidation; open the Act before relying on it.

A person must not knowingly and intentionally intercept, record or transcribe, in a surreptitious manner, a private electronic communication to which that person is not a party, unless all parties to it consent.

What a reviewer asks to see: Register of tools that intercept or capture message content in transit (chat, email, messaging) covering Illinois staff, with the notice or consent relied on; Monitoring notice or policy acknowledged by employees making the monitoring not surreptitious
Where monitoring plans usually fall short: Covert capture of employees' personal messaging on work devices; Keylogging that captures the content of private messages without notice
Source: Illinois Eavesdropping Act (720 ILCS 5, Article 14), read 30 Sep 2026
Illinois Eavesdropping Act 14-3(j)Business telephone monitoring: only for quality, training or research, with one active party's consent Text not verified against the current consolidation; open the Act before relying on it.

A business engaged in telephone solicitation by live operators (soliciting sales, taking orders, helping customers use goods or services, or soliciting, administering or collecting bank or retail credit accounts) or in marketing or opinion research may use a telephone monitoring device to record or listen to those conversations by its employees only for service quality control, education or training of the employees or contractors doing that work, or internal research on it, and only with the consent of at least one active party to the conversation monitored.

What a reviewer asks to see: Written statement of the business activity (live-operator sales, orders, customer assistance, credit accounts, research) on the monitored lines; Monitoring purpose statement limited to quality, training or internal research, and the source of one active party's consent
Where monitoring plans usually fall short: Exemption relied on for lines not used for the listed activities; Monitoring data used for discipline or passed to others
Source: Illinois Eavesdropping Act (720 ILCS 5, Article 14), read 30 Sep 2026
Illinois Eavesdropping Act 14-3(j)Business telephone monitoring: personal lines, stop and destroy, no onward use Text not verified against the current consolidation; open the Act before relying on it.

A business using the exemption must give employees access to personal telephone lines that are not monitored or recorded; must stop listening or recording at once, and destroy the recording as soon as practicable, when a monitored conversation turns out not to concern the solicitation or research work; and must not furnish anything obtained under the exemption to law enforcement, use it in any inquiry, investigation or administrative, judicial or other proceeding, or divulge it to any third party.

What a reviewer asks to see: Location and description of unmonitored personal phone lines available to employees; Procedure and log for stopping and deleting recordings of personal or unrelated calls; Rule barring release of monitoring recordings to third parties, with access controls
Where monitoring plans usually fall short: No unmonitored line available on the call floor; Personal calls kept in the recording archive
Source: Illinois Eavesdropping Act (720 ILCS 5, Article 14), read 30 Sep 2026
ECPA 2511(1)(a)Do not intercept wire, oral or electronic communications

Unless the chapter specifically provides otherwise, no person may intentionally intercept, try to intercept, or procure anyone else to intercept or try to intercept, any wire, oral or electronic communication. For an employer this covers real-time capture of calls, email or messages in transit, keystroke or screen tools that acquire message contents as they are sent, and listening devices, unless an exception (provider, business extension, consent) applies.

What a reviewer asks to see: Register of every tool that captures communication contents in real time (call recording, voice analytics, email or chat journaling, DLP inspection, keyloggers), with the exception relied on for each; Legal sign-off per tool recording why the interception is lawful (party consent, provider exception or business-extension use)
Where monitoring plans usually fall short: Monitoring software deployed with no documented legal basis; Personal accounts or personal calls captured by the same tools as business traffic
Source: US Electronic Communications Privacy Act, Title I (Wiretap Act, 18 USC 2510 to 2523), read 30 Sep 2026
ECPA 2511(2)(d)One-party consent: be a party or have a party's prior consent, and never for a criminal or tortious purpose

A person not acting under color of law may intercept a wire, oral or electronic communication where that person is a party to it or one of the parties has given prior consent, unless the interception is for the purpose of committing a criminal or tortious act against the Constitution or the laws of the United States or any State. Employers commonly obtain the employee's prior consent through a signed monitoring policy; consent must cover the monitoring actually carried out, and state all-party consent laws can still apply.

What a reviewer asks to see: Signed or electronically accepted monitoring consent from each employee, describing the communications and methods monitored; Mapping of the consent wording to each monitoring tool in the register; Check of state law for locations where all-party consent is required
Where monitoring plans usually fall short: Consent wording covers email but the tool also captures calls or personal messaging; Consent relied on for calls with outside parties in all-party consent states
Source: US Electronic Communications Privacy Act, Title I (Wiretap Act, 18 USC 2510 to 2523), read 30 Sep 2026
ECPA 2510(5)(a)Business-extension exclusion: provider-furnished equipment used in the ordinary course of business

The prohibition turns on the use of an electronic, mechanical or other device. Telephone or telegraph equipment or facilities, or their components, furnished to the subscriber or user by a provider in the ordinary course of its business and used by the subscriber or user in the ordinary course of its business (or furnished by the subscriber or user to connect to the service and so used), and equipment used by a provider in the ordinary course of its business, are not such a device. An employer's use of its phone system to monitor business calls can fall outside the prohibition where the monitoring is in the ordinary course of business; hearing aids are also excluded.

What a reviewer asks to see: Description of the phone system and the monitoring features used, showing they are part of the service equipment; Business justification for call monitoring (quality, training, compliance) and the rule for ending monitoring once a call is personal
Where monitoring plans usually fall short: Monitoring continues after a call is identified as personal; Add-on recording hardware not furnished as part of the service relied on as business extension
Source: US Electronic Communications Privacy Act, Title I (Wiretap Act, 18 USC 2510 to 2523), read 30 Sep 2026
BIPA s 15(a)Written, public retention schedule and destruction guidelines, applied

A private entity in possession of biometric identifiers or biometric information must develop a written policy, made available to the public, that establishes a retention schedule and guidelines for permanently destroying the identifiers and information when the initial purpose for collecting or obtaining them has been satisfied or within three years of the individual's last interaction with the entity, whichever comes first. Absent a valid warrant or subpoena issued by a court of competent jurisdiction, the entity must comply with its own established schedule and guidelines. The duty attaches on possession, so an entity that holds biometric data collected by a vendor on its behalf must publish the policy as well.

What a reviewer asks to see: The published retention and destruction policy (web page or posted notice) with its retention schedule and the destruction trigger of purpose satisfied or three years since last interaction; Destruction records showing the schedule is followed, including for departed employees and closed customer accounts; Any warrant or subpoena relied on to retain data past the schedule
Where monitoring plans usually fall short: A retention policy that exists internally but was never made available to the public; No destruction of employee templates after termination, so three-year clocks run out unnoticed; A vendor holding the templates with no policy published by the entity that uses them
Source: Illinois Biometric Information Privacy Act (BIPA), read 30 Sep 2026
BIPA s 15(b)(1)Written notice that a biometric identifier or information is being collected or stored

Before collecting, capturing, purchasing, receiving through trade or otherwise obtaining a person's or customer's biometric identifier or biometric information, the private entity must inform the subject, or the subject's legally authorized representative, in writing that a biometric identifier or biometric information is being collected or stored. The notice must precede the first collection; a notice given after enrolment does not cure the collection already made.

What a reviewer asks to see: The written notice (enrolment screen, form, employee notice) stating that a biometric identifier or information is collected or stored, dated before first collection; Evidence of delivery to each subject or representative before enrolment
Where monitoring plans usually fall short: Biometric timeclocks or access systems rolled out with no written notice to employees; Notice buried in a privacy policy that says nothing about biometrics specifically; Notice given at the first scan rather than before it
Source: Illinois Biometric Information Privacy Act (BIPA), read 30 Sep 2026
BIPA s 15(b)(2)Written notice of the specific purpose and length of term of collection, storage and use

Before obtaining a biometric identifier or biometric information, the private entity must inform the subject or the subject's legally authorized representative in writing of the specific purpose for which, and the length of term for which, the identifier or information is being collected, stored and used. The purpose must be specific to the use (timekeeping, facility access, identity verification for a transaction) and the term must be stated, which in practice ties the notice to the retention schedule of 15(a).

What a reviewer asks to see: The written notice naming the specific purpose and the length of term of collection, storage and use; Consistency between the stated term and the published retention schedule
Where monitoring plans usually fall short: A purpose stated as generally as security or business operations; No length of term stated at all; A stated term that contradicts the published retention policy
Source: Illinois Biometric Information Privacy Act (BIPA), read 30 Sep 2026
BIPA s 15(b)(3)Written release executed by the subject or representative before collection

Before obtaining a biometric identifier or biometric information, the private entity must receive a written release executed by the subject of the identifier or information or by the subject's legally authorized representative. A written release is informed written consent, an electronic signature (a checkbox, click-through or other electronic process executed with intent to sign, confirmed by the 2024 amendment) or, in employment, a release executed by an employee as a condition of employment. For a minor the release comes from the parent or guardian.

What a reviewer asks to see: Executed written releases or electronic signature records for every enrolled subject, retained for the life of the data and the limitations period; Employment releases executed as a condition of employment where that basis is used; Parent or guardian releases for minors
Where monitoring plans usually fall short: Enrolment with no release at all, the most litigated BIPA violation; A release obtained from a vendor's terms rather than executed by the subject; Electronic consent with no record of who signed, when and with what intent
Source: Illinois Biometric Information Privacy Act (BIPA), read 30 Sep 2026
BIPA s 15(d)No disclosure, redisclosure or dissemination except on four grounds

No private entity in possession of a biometric identifier or biometric information may disclose, redisclose or otherwise disseminate a person's or customer's biometric identifier or biometric information unless the subject or the subject's legally authorized representative consents to the disclosure or redisclosure; or the disclosure completes a financial transaction requested or authorized by the subject or representative; or the disclosure is required by State or federal law or municipal ordinance; or the disclosure is required by a valid warrant or subpoena issued by a court of competent jurisdiction. Transfer to a vendor or cloud provider is a disclosure that needs consent. Under section 20(c) as amended in 2024, repeated disclosure of the same identifier from the same person to the same recipient by the same method is a single violation with at most one recovery.

What a reviewer asks to see: Register of every recipient of biometric data (vendors, processors, affiliates, cloud services) with the ground for each disclosure; Consents covering disclosure to named recipients; Legal, warrant or subpoena records for compelled disclosures
Where monitoring plans usually fall short: Templates sent to a timekeeping or access-control vendor with consent covering collection only; Sharing between affiliates treated as internal; No record of who has received biometric data
Source: Illinois Biometric Information Privacy Act (BIPA), read 30 Sep 2026
ILO code para 6.14(3)Continuous monitoring only for health and safety or protection of property official guidance, not law

Monitoring that never stops should be allowed only where it is needed for workplace health and safety or to protect property.

What a reviewer asks to see: Register of continuous monitoring (CCTV, telematics, always-on tracking) with the health, safety or property ground for each
Where monitoring plans usually fall short: Always-on webcam or activity tracking for remote staff justified by productivity
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ILO code para 5.6Monitoring data not the sole basis of performance evaluation official guidance, not law

Output from electronic surveillance should never be the sole input when a worker's performance is judged.

What a reviewer asks to see: Appraisal procedure listing the evidence sources considered besides monitoring data; Sample appraisals showing other inputs (manager review, outputs, feedback)
Where monitoring plans usually fall short: Productivity scores from activity tracking used as the whole appraisal
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ILO code para 8.5Retain only as long as the purpose justifies official guidance, not law

Keep personal data only as long as the specific purposes of collection justify, unless a worker asks to stay on a candidate list for a set period, national law requires retention, or the employer or worker needs the data for legal proceedings about an existing or former employment relationship.

What a reviewer asks to see: Retention schedule for worker data including monitoring records, citing purpose, legal requirement or proceedings; Deletion logs
Where monitoring plans usually fall short: Monitoring recordings kept indefinitely; Unsuccessful applicants' data kept without their agreement
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
SCA 2701(a)Do not access a communication service facility without authorization to reach stored communications

Unless subsection (c) applies, no person may intentionally access without authorization a facility through which an electronic communication service is provided, or intentionally exceed an authorization to access it, and thereby obtain, alter or prevent authorized access to a wire or electronic communication while it is in electronic storage in that system. Penalties (2701(b)): for commercial advantage, malicious destruction, private gain or in furtherance of a criminal or tortious act, up to 5 years (10 for a repeat); otherwise up to 1 year (5 for a repeat after a prior conviction). For an employer this reaches logging into an employee's personal email, social media or messaging account, for example with a saved password on a work device, without the employee's authorization.

What a reviewer asks to see: Investigation procedure prohibiting access to employees' personal accounts (webmail, social media, messaging) without their authorization; Record of the authority for each access to stored communications made in an investigation (employer-provided system, user consent); Guidance to IT on handling personal account sessions or saved credentials found on work devices
Where monitoring plans usually fall short: Manager reads an employee's personal webmail left logged in on a work laptop; Former employee's personal account accessed with a remembered password after departure
Source: US Stored Communications Act (18 USC 2701 to 2713), read 30 Sep 2026
SCA 2701(c)(1)Authorization by the service provider: access to the employer's own communication service

Subsection (a) does not apply to conduct authorized by the person or entity providing the wire or electronic communications service. An employer that provides its own email or messaging service to employees can authorize access to communications stored on that service; the authorization does not extend to services the employer does not provide, such as an employee's personal webmail.

What a reviewer asks to see: List of communication services the organization itself provides (email, chat, voicemail) and who may authorize access to stored content; Access authorization records for reviews of stored communications on those services
Where monitoring plans usually fall short: Provider authorization relied on for a third-party personal account; No record of who authorized a mailbox search
Source: US Stored Communications Act (18 USC 2701 to 2713), read 30 Sep 2026
SCA 2701(c)(2)Authorization by the user for that user's own communications

Subsection (a) does not apply to conduct authorized by a user of the service with respect to a communication of, or intended for, that user. Access to an employee's stored messages with that employee's authorization is outside the offense; access to a third party's messages needs that user's authorization or another exception.

What a reviewer asks to see: Written authorization from the account user for access to the user's stored communications, stating the scope; Check that the person authorizing is the user of the communications accessed
Where monitoring plans usually fall short: Authorization obtained from a coworker to read another employee's private messages; Authorization obtained by pressure or as a condition of employment without legal review
Source: US Stored Communications Act (18 USC 2701 to 2713), read 30 Sep 2026
ILO code para 5.1Fair, employment-related processing within the law official guidance, not law

5.1 Lawful, fair and employment-related processing. Handle workers' data lawfully and fairly, and solely for reasons that bear directly on the person's job.

What a reviewer asks to see: Register of worker data processing activities, each with its employment-related reason and legal basis
Where monitoring plans usually fall short: Data collected for reasons unrelated to the job, such as off-duty social media activity
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ILO code para 6.5No data on sex life, beliefs or convictions, save exceptionally official guidance, not law

Employers should not collect data on a worker's sex life, political, religious or other beliefs, or criminal convictions, except in rare cases where national law permits it and the information bears directly on a decision about the job.

What a reviewer asks to see: Data inventory confirming these categories are not collected, or the documented exception and legal basis where they are
Where monitoring plans usually fall short: Criminal record checks for every role regardless of relevance
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026
ILO code para 6.6No data on union membership or activities unless required official guidance, not law

Employers should not collect data on a worker's membership of a workers' organization or trade union activities unless the law or a collective agreement requires or permits it.

What a reviewer asks to see: Review of HR and monitoring systems confirming union data are not collected except under a stated legal or agreement basis
Where monitoring plans usually fall short: Monitoring tools flag union-related email or chat
Source: ILO Code of Practice on the Protection of Workers' Personal Data 1997 (official guidance, not law), read 30 Sep 2026

See the specimen plan run Plan your own list