Illinois Eavesdropping Act & Website Tracking Litigation
What This Statute Says (Plain Language)
Illinois' eavesdropping statute generally requires all-party consent for the surreptitious interception or recording of private conversations and private electronic communications. Illinois is also home to the Biometric Information Privacy Act (BIPA), which — while a distinct statute — has shaped the state's active privacy plaintiff bar and class action infrastructure.
Why It Appears in Website Tracking Litigation
Website tracking claims in Illinois have drawn on both the eavesdropping statute and BIPA (for technologies alleged to process biometric identifiers, such as certain session replay or voice features). The established privacy litigation ecosystem in Illinois means new website tracking theories tend to be tested there relatively quickly.
Practical Implications for Website Operators
Illinois occupies an unusual position: its eavesdropping statute appears in website tracking matters less often than the California or Pennsylvania statutes, because post-2014 amendments focus the act on surreptitious interception of 'private conversations' and private electronic communications — a framing that gives routine web analytics more room. What makes Illinois consequential anyway is its privacy litigation infrastructure. The plaintiff bar built around the Biometric Information Privacy Act (BIPA) is experienced, well-funded, and quick to test new website tracking theories in Illinois courts.
In practice, Illinois web tracking matters cluster in two areas. First, features that plausibly capture conversation-like content — chat widgets, voice interfaces, and call-recording integrations — where the eavesdropping act's private-conversation framing has the most purchase. Second, technologies alleged to process biometric identifiers — voiceprints in call or chat features, facial geometry in virtual try-on tools — where BIPA's per-violation statutory damages ($1,000 negligent / $5,000 reckless or intentional) drive the economics even though BIPA is a distinct statute from the eavesdropping act.
Litigation Risk in Plain Language
The eavesdropping act's post-amendment structure means defenses against ordinary browsing-analytics claims are comparatively strong: plaintiffs must fit website interactions into 'private conversation' or private electronic communication, surreptitiously intercepted. Risk therefore concentrates in audio, voice, and genuinely conversational features rather than page-view tracking.
The realistic exposure driver for Illinois-facing operators is the combination of an active plaintiff bar and BIPA adjacency: the same scan that detects a chat widget or session recorder also flags voice and biometric-capable features, and complaints frequently plead both statutes together. Reviewing them as one surface — rather than treating BIPA as someone else's problem — matches how claims actually arrive.
What Operators Commonly Review
These are the configuration reviews we most often see performed by operators of websites serving visitors in this jurisdiction — informational starting points, not legal requirements and not legal advice:
- Identify any feature that captures audio, voice, or biometric-capable data: voice search, call tracking and recording, video chat, virtual try-on.
- Review chat implementations for transcript routing and typing-preview transmission — the most conversation-like data flows on a typical site.
- Confirm session replay and recording tools are consent-gated for Illinois visitors and masked on form-heavy pages.
- Verify the privacy policy names the vendors receiving conversational or biometric-adjacent data.
- If any biometric processing is plausible, treat BIPA's written-consent and retention-policy requirements as a separate, additional review item with counsel.
How This Statute Compares
Consent standard, private right of action, and statutory damages are the structural features that most shape where website tracking claims are filed. Here is how the other electronic interception statutes we track compare:
| Statute | Consent Standard | Private Right of Action | Statutory Damages |
|---|---|---|---|
| California Invasion of Privacy Act (CIPA) | All-party | Yes | $5,000 per violation or three times actual damages (Cal. Penal Code § 637.2) |
| Federal Wiretap Act (ECPA Title I) | One-party | Yes | The greater of actual damages, $100 per day of violation, or $10,000 (18 U.S.C. § 2520) |
| Florida Security of Communications Act (FSCA) | All-party | Yes | The greater of actual damages, $100 per day of violation, or $1,000 (Fla. Stat. § 934.10) |
| Maryland Wiretapping and Electronic Surveillance Act | All-party | Yes | The greater of actual damages, $100 per day of violation, or $1,000, plus punitive damages and fees (§ 10-410) |
| Massachusetts Wiretap Act | All-party | Yes | Actual damages, not less than $100 per day of violation or $1,000, plus punitive damages and fees |
| Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA) | All-party | Yes | The greater of actual damages, $100 per day of violation, or $1,000, plus punitive damages and fees (18 Pa. C.S. § 5725) |
| Washington Privacy Act | All-party | Yes | Actual damages including mental pain and suffering, or liquidated damages of $100 per day up to $1,000 (RCW 9.73.060) |
Jurisdiction Context
See the full Illinois website tracking litigation page for the current risk guideline (Moderate), tracked matter counts, and trend data.
Tracked Cases Invoking This Statute
No tracked cases currently link to this statute in our source set. This reflects our tracked sources, not an absence of litigation.
Common Questions
Is the Eavesdropping Act the main website tracking risk in Illinois?
It appears in tracked matters, but Illinois exposure often centers on BIPA where any biometric processing is alleged, because BIPA carries per-violation statutory damages and a mature plaintiff bar. The two statutes have different elements, but complaints frequently combine them, so operators generally review the whole surface together.
Does the Eavesdropping Act cover website session recording?
After the 2014 amendments, the act targets surreptitious interception of private conversations and private electronic communications. Whether ordinary website interactions qualify is contested, and public web-specific decisions are sparse compared to California. Conversational features like chat and voice present the closer question. This is an informational summary, not legal advice.
What damages are available under these Illinois statutes?
The Eavesdropping Act provides actual and punitive damages plus injunctive relief. BIPA — a separate statute — provides $1,000 per negligent violation and $5,000 per reckless or intentional violation, which is what makes Illinois class actions economically significant when biometric processing is alleged.
Related Intelligence
Further Reading
- Your website may be sharing more than you think — our plain-language overview of hidden tracking, wiretap exposure, and Global Privacy Control.
- Website wiretap lawsuits by state — risk guidelines and tracked matter counts for all 50 states.
Sources
Statutory text and public commentary are the basis for this page; tracked litigation sources will be listed as the intelligence engine links them to this statute.
About This Page
Publisher: Inspection-Ready Institute, Inc. (DBA Crandall Consulting), an independent website compliance and risk consultancy. We are not a law firm and nothing on this page is legal advice.
How this content is produced: Facts are extracted from publicly available sources — court and government materials, recognized legal press, professional analysis, and industry reports — by our litigation intelligence engine, stored with full source provenance, and rendered from the database. Risk guidelines are computed by a deterministic formula, never by an AI model directly. See the full methodology.
Limitations: Counts labeled "Tracked" reflect matters identified in our source set and are not official court statistics. We report what courts decided and did not decide; we do not predict outcomes.
Corrections: If you believe anything on this page is inaccurate, contact us via the contact page and we will review the underlying sources promptly.
Is Your Website Creating Hidden Tracking Risk?
Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.
Scan My Website