Employee monitoring law · Illinois
BIPA carries a private right of action. This is the state where monitoring gets sued.
Avoid biometric capture without written BIPA consent. This is the state where monitoring gets sued.
- Region
- North America
- Instruments
- 2 governing
- Employer duties
- 3 listed
- Last reviewed
- August 22, 2026
Illinois · what the law requires
Specific practices restricted
Illinois is a special case not because of monitoring notice rules but because of the Biometric Information Privacy Act. BIPA requires written notice and a signed release before collecting a biometric identifier, and it gives individuals a private right of action with statutory damages per violation. Class actions have driven very large settlements. Any feature touching fingerprints, facial geometry or voiceprints is the exposure; ordinary activity monitoring is not, and keeping it that way is the point.
- No biometrics without notice and a signed releaseThe written release must be obtained before collection. Retroactive consent does not cure a BIPA claim.
- A published retention and destruction scheduleBIPA requires a publicly available written policy setting the retention schedule and destruction guidelines for biometric data.
- Assume you will be sued, not finedEnforcement is private and class-based. The compliance question is what a plaintiff's firm can allege, not what a regulator will inspect.
- Proof Ledger
- Outcomes
- Certificates
- Audit log
- Data access
- Disputes
- Data egress
- Export
- What We See
- Controls
- AKAria K. viewed screenshotsLena M. · 3 capturesScreen capturemacOS · London09:42a91f…4c023d7b…91ee
- JMJon M. exported time reportDesign team · CSVmacOS · Berlin09:313d7b…91ee77c5…0ba4
- SDSara D. opened capture reviewRavi P. · one flagged frameWindows · Manchester09:1877c5…0ba4e208…5f13
- wm_live_7f2… read /v1/deliverablesScoped key · read onlyPublic API · allowlisted IP08:57e208…5f13b64a…2d90
- LMLena M. viewed her own recordWhat We SeemacOS · London08:44b64a…2d901cf9…8e77
- AKAria K. changed capture policyBlur set to alwaysmacOS · London08:261cf9…8e7705d2…ae31
The instruments, and which control answers each duty
- Biometric Information Privacy Act: 740 ILCS 14. Written notice and signed release before collecting biometric identifiers; private right of action with statutory damages of $1,000 negligent / $5,000 intentional or reckless.
- Right to Privacy in the Workplace Act: 820 ILCS 55. Restricts employer demands for personal account credentials and regulates lawful-activity discrimination.
No product does this part
What you must still do yourself
Compliance is a property of your deployment. These are the steps in Illinois that no vendor can complete on your behalf, and skipping them is what turns a rollout into a finding.
- 1Verify that no adjacent system in your stack introduces biometric collection. Badge readers and timeclocks are the usual source.
- 2Publish the retention and destruction policy BIPA requires if any biometric data exists anywhere.
- 3Never ask employees for personal account credentials.
- If you get it wrongBIPA: $1,000 per negligent violation, $5,000 per intentional or reckless violation, plus attorneys' fees, enforced privately through class actions.
Verify the claim
Every control above, on the page that describes it
- No biometric identifiers are collectedStay outside BIPA's scope entirely
- Per-app deny-lists enforced on the device before transmissionKeep credential-bearing tools out of the record
- Configurable retention and deletion with the governing policy version recorded per dayEvidence your retention schedule was applied
Sources and review date
Last reviewed August 22, 2026This is a summary of how employee-monitoring rules generally work in this jurisdiction, written to help you scope a rollout and brief your own advisers. It is not legal advice, it is not a substitute for it, and law changes. Verify against the primary sources listed and take local counsel before you deploy.
Nearby jurisdictions
Monitoring law elsewhere in North America
- Canada (federal)Reasonableness is the statutory test, and the OPC applies a four-part necessity analysis.
- OntarioA written electronic monitoring policy is mandatory at 25+ employees, refreshed annually.
- QuebecLaw 25 adds privacy by default, impact assessments and a right to explanation.
- United States (federal)Federal law is permissive; the real constraints are state law and the NLRA.
- New YorkWritten notice on hire, signed acknowledgement, and a posted notice, all three.
- CaliforniaEmployees have full CCPA rights since 2023, including deletion and correction.
Point it at one team for a week.
Create the account, put the agent on a handful of desks, and leave it alone. On Friday you read the week instead of reconstructing it: hours against their projects, focus and idle per person, and the timesheets already filled in.
Free for two seats. No card, and no sales call to sit through.