WorkMonitor.
Specific practices restrictedThe law or the regulator treats some monitoring, usually continuous screen capture or keystroke logging, as off the table regardless of consent.

Employee monitoring law · Illinois

BIPA carries a private right of action. This is the state where monitoring gets sued.

Avoid biometric capture without written BIPA consent. This is the state where monitoring gets sued.

Region
North America
Instruments
2 governing
Employer duties
3 listed
Last reviewed
August 22, 2026

Illinois · what the law requires

Specific practices restricted

Illinois is a special case not because of monitoring notice rules but because of the Biometric Information Privacy Act. BIPA requires written notice and a signed release before collecting a biometric identifier, and it gives individuals a private right of action with statutory damages per violation. Class actions have driven very large settlements. Any feature touching fingerprints, facial geometry or voiceprints is the exposure; ordinary activity monitoring is not, and keeping it that way is the point.

Audit log
Hash-chained, including who read what
Chain verified to entry 48,210 — no gaps, no rewritesChain intactChecked 2 min ago
EVENTSOURCETIMEHASH
  • AKAria K. viewed screenshotsLena M. · 3 capturesScreen capturemacOS · London09:42a91f…4c023d7b…91ee
  • JMJon M. exported time reportDesign team · CSVmacOS · Berlin09:313d7b…91ee77c5…0ba4
  • SDSara D. opened capture reviewRavi P. · one flagged frameWindows · Manchester09:1877c5…0ba4e208…5f13
  • wm_live_7f2… read /v1/deliverablesScoped key · read onlyPublic API · allowlisted IP08:57e208…5f13b64a…2d90
  • LMLena M. viewed her own recordWhat We SeemacOS · London08:44b64a…2d901cf9…8e77
  • AKAria K. changed capture policyBlur set to alwaysmacOS · London08:261cf9…8e7705d2…ae31
Each entry carries the hash of the one before it, so an edit anywhere breaks everything after it.48,210 entries

The instruments, and which control answers each duty

  • Biometric Information Privacy Act: 740 ILCS 14. Written notice and signed release before collecting biometric identifiers; private right of action with statutory damages of $1,000 negligent / $5,000 intentional or reckless.
  • Right to Privacy in the Workplace Act: 820 ILCS 55. Restricts employer demands for personal account credentials and regulates lawful-activity discrimination.

No product does this part

What you must still do yourself

Compliance is a property of your deployment. These are the steps in Illinois that no vendor can complete on your behalf, and skipping them is what turns a rollout into a finding.

  1. 1Verify that no adjacent system in your stack introduces biometric collection. Badge readers and timeclocks are the usual source.
  2. 2Publish the retention and destruction policy BIPA requires if any biometric data exists anywhere.
  3. 3Never ask employees for personal account credentials.
  4. If you get it wrongBIPA: $1,000 per negligent violation, $5,000 per intentional or reckless violation, plus attorneys' fees, enforced privately through class actions.

Verify the claim

Every control above, on the page that describes it

Sources and review date

Last reviewed August 22, 2026

This is a summary of how employee-monitoring rules generally work in this jurisdiction, written to help you scope a rollout and brief your own advisers. It is not legal advice, it is not a substitute for it, and law changes. Verify against the primary sources listed and take local counsel before you deploy.

Nearby jurisdictions

Monitoring law elsewhere in North America

Point it at one team for a week.

Create the account, put the agent on a handful of desks, and leave it alone. On Friday you read the week instead of reconstructing it: hours against their projects, focus and idle per person, and the timesheets already filled in.

Free for two seats. No card, and no sales call to sit through.