Surveillance Laws in the United States

Table of Contents

Surveillance law in the United States is not one law. It is a patchwork of federal statutes written across five decades, fifty different state consent regimes, and, increasingly, a body of litigation that has nothing to do with cameras at all. Most guides to this topic stop at the traditional picture: wiretap statutes, CCTV, workplace cameras. That picture is incomplete in a way that matters directly to any business running a website, an app, a call center, or a customer support chat, because the fastest-growing category of surveillance litigation right now isn’t about hidden cameras. It’s about tracking pixels, session replay tools, and chat widgets being prosecuted under decades-old wiretapping statutes never written with the internet in mind.

We have been the most proactive company in both alerting businesses about the different privacy litigation risks as well as providing a privacy software solution to protect against these claims while keeping your business compliant. This guide covers both halves: the federal and state framework governing physical and audio surveillance, and the digital surveillance exposure that has become a board-level litigation risk for any consumer-facing business.

Federal Laws That Govern Surveillance

1. The Wiretap Act (Title III of the Omnibus Crime Control and Safe Streets Act of 1968)

The foundational federal statute governing interception of oral, wire, and electronic communications. Government interception generally requires a warrant, and unauthorized interception of a private communication, meaning recording without at least one party’s consent, can constitute a federal crime. Courts have increasingly had to decide whether this 1968-era statute applies to modern digital interception, including website chat and tracking tools, a question that has fueled a wave of state-level litigation discussed further below.

2. Electronic Communications Privacy Act (ECPA) of 1986

The ECPA extended wiretap-style protections to email, online chat, and stored voicemail. It contains two components businesses should know by name: the Stored Communications Act, which governs access to stored electronic communications, and the Pen Register Act, which restricts the use of devices or tools that record call or communication metadata without capturing content. The Pen Register Act specifically has become legally significant in recent years, as several state-law equivalents of it have been used as the basis for lawsuits against businesses using certain tracking and analytics tools on their websites.

3. USA PATRIOT Act (2001)

Passed in response to the September 11 attacks, the PATRIOT Act significantly expanded federal surveillance authority, including broader collection of communications and loosened restrictions on government access to financial and communications records for national security investigations. While focused on counterterrorism, several of its authorities have found their way into broader law enforcement use over time.

4. Video Voyeurism Prevention Act of 2004

Makes it a federal crime to record individuals in spaces where they have a reasonable expectation of privacy, including bathrooms, dressing rooms, and hotel rooms. Consent is never implied in these spaces, and violations carry criminal penalties.

5. Video Privacy Protection Act (VPPA) of 1988

Originally passed to prevent video rental history disclosure, the VPPA has become one of the most actively litigated federal privacy statutes of the last several years. Plaintiffs have applied it to modern video-streaming features on websites, arguing that tracking tools sharing a visitor’s video viewing history with third-party ad platforms without consent violates the statute. Any business embedding video content alongside analytics or advertising pixels should treat this as live litigation risk, not a historical footnote.

6. Children’s Online Privacy Protection Act (COPPA)

Restricts the collection of personal information, including through tracking and analytics tools, from children under 13 without verifiable parental consent. Surveillance and tracking technology deployed on any platform reasonably likely to be accessed by children carries independent COPPA exposure on top of any general surveillance law analysis.

State-Level Laws: Why the Patchwork Is the Real Compliance Challenge

Federal law sets a floor. State law is where most surveillance compliance risk actually lives, because states diverge sharply on consent requirements, and several apply their wiretapping and eavesdropping statutes far more aggressively than federal law does.

One-Party vs. All-Party Consent: The Full State Picture

Most guides to this topic list a handful of example states. The table below covers all fifty states plus the District of Columbia. A note on accuracy: several states apply different standards depending on whether the recording is in-person or over the phone, and statutes are amended periodically, so this table should be treated as a starting reference, verified against current statutory text or counsel before it drives a compliance decision.

Surveillance Consent Map USA

State Consent Standard State Consent Standard
Alabama One-party Montana All-party
Alaska One-party Nebraska One-party
Arizona One-party Nevada Context-dependent*
Arkansas One-party New Hampshire All-party
California All-party New Jersey One-party
Colorado One-party New Mexico One-party
Connecticut All-party New York One-party
Delaware All-party North Carolina One-party
Florida All-party North Dakota One-party
Georgia One-party Ohio One-party
Hawaii One-party Oklahoma One-party
Idaho One-party Oregon Context-dependent*
Illinois All-party Pennsylvania All-party
Indiana One-party Rhode Island One-party
Iowa One-party South Carolina One-party
Kansas One-party South Dakota One-party
Kentucky One-party Tennessee One-party
Louisiana One-party Texas One-party
Maine One-party Utah One-party
Maryland All-party Vermont No statute (common law)*
Massachusetts All-party Virginia One-party
Michigan Context-dependent* Washington All-party
Minnesota One-party West Virginia One-party
Mississippi One-party Wisconsin One-party
Missouri One-party Wyoming One-party
District of Columbia One-party

*Nevada, Oregon, and Michigan apply different standards depending on the recording context (in-person versus telephonic, or whether the recorder is a participant), and Vermont has no dedicated wiretapping statute, relying instead on common-law privacy claims. Treat these four as requiring individual review rather than a simple one-party or all-party label.

Specific Surveillance Contexts

Public Surveillance and CCTV Use

CCTV in public areas, streets, parks, government buildings, and public transit, is broadly permitted where there is no reasonable expectation of privacy. Semi-public spaces such as restaurants, gyms, and office lobbies occupy a genuine gray zone, where signage, posted notice, and specific state law all affect the analysis.

Surveillance in the Workplace

Employers can generally use cameras for legitimate business purposes like safety and theft prevention, but restrictions apply. Surveillance in private areas such as restrooms and locker rooms is prohibited. Several states require employee notification or consent, particularly where audio is captured, and unionized workplaces may require bargaining over surveillance policy under federal labor law.

Surveillance in Schools

Video-only recording in public hallways and cafeterias is generally permitted; recording in classrooms or restrooms, especially with audio, is typically prohibited. Once video surveillance footage becomes part of a student’s education record, FERPA governs its handling and disclosure.

Law Enforcement Surveillance

Body cameras, license plate readers, and facial recognition tools are all subject to a growing body of oversight. Many jurisdictions now require warrants for long-term surveillance or drone use, and cities including San Francisco require public approval before local law enforcement can expand surveillance capability.

The Digital Surveillance Gap Most Guides Miss Entirely

Here is the piece of this landscape that has generated more active litigation over the past three years than every category above combined, and that most surveillance law overviews leave out entirely: state wiretapping and eavesdropping statutes are now being applied to ordinary website technology.

Tracking pixels, session replay tools that record how a visitor moves through a page, and embedded chat widgets have all become defendants’ exhibit A in a wave of class action lawsuits brought under state wiretap and eavesdropping statutes, most prominently California’s Invasion of Privacy Act, Illinois’s eavesdropping statute, Florida’s Security of Communications Act, and Pennsylvania’s Wiretapping and Electronic Surveillance Control Act. The theory in these cases is straightforward: if a third-party tool captures a website visitor’s interactions and transmits them to an outside party without the visitor’s consent, plaintiffs argue that qualifies as an illegal interception of an electronic communication, the same legal concept the Wiretap Act and its state equivalents were built around, just applied to a browser session instead of a phone line.

This matters because the same all-party versus one-party consent distinction that governs whether you can legally record a phone call also governs whether a website operating in an all-party consent state needs affirmative visitor consent before a session replay tool or certain tracking pixels can lawfully run. A business that has never installed a physical camera can still carry meaningful surveillance law exposure purely through its website’s analytics and advertising stack, and the states with the strictest all-party consent standards in the table above, California, Illinois, Florida, and Pennsylvania among them, are also the states generating the most active litigation on exactly this theory.

Digital surveillance gap diagram

How to Stay Compliant: A Practical Framework

  1. Map your consent obligations state by state, not as a single national policy. A one-party consent assumption that works in Texas will not hold up in California, Illinois, or any other all-party jurisdiction.
  2. Inventory every tracking pixel, session replay tool, and chat widget on your public-facing properties. This is the modern equivalent of knowing where your cameras are, and it is the exact inventory plaintiffs’ firms are testing businesses on right now.
  3. Post visible signage and disclosures anywhere physical surveillance occurs. Notice requirements are a recurring element across nearly every state framework, physical or digital.
  4. Disable audio capture on physical surveillance systems unless it is specifically legally justified. Audio interception carries meaningfully higher legal exposure than video alone under almost every state statute.
  5. Implement a consent mechanism for tracking technologies operating in all-party consent states. A cookie banner alone is often not sufficient if the underlying tool is later characterized as an interception device; the consent needs to be specific, informed, and obtained before the tool activates.
  6. Write a surveillance and tracking technology policy covering purpose, retention, access, and usage, and make sure it covers digital tools with the same rigor traditionally reserved for physical cameras.
  7. Audit your systems on a recurring basis, not just at deployment. Marketing and analytics teams add new tracking tools far more often than security teams add new cameras, and scope creep here is the norm rather than the exception.
  8. Train employees managing both physical surveillance systems and website analytics stacks on the applicable legal standards, since the same organization is often running both without a shared compliance owner.
  9. Work with legal counsel and a compliance partner to review exposure across every state where you operate or have website visitors, since digital surveillance exposure follows your visitors’ location, not just your headquarters.

Final Thoughts

Surveillance law has quietly split into two enforcement tracks running in parallel: the traditional physical and audio surveillance framework this topic has always covered, and a fast-moving digital surveillance litigation track built on the exact same legal foundations, applied to websites instead of phone lines. Getting the physical side wrong exposes an organization to regulatory penalties and lawsuits. Getting the digital side wrong, given how routinely tracking pixels and session replay tools get deployed without legal review, is currently the more common and more expensive mistake. Treating both as one compliance program, rather than two separate afterthoughts, is what separates organizations that stay ahead of this from the ones that end up as the next class action defendant.

Frequently Asked Questions

What is the difference between one-party and all-party consent states?

In one-party consent states, only one participant in a conversation needs to consent to it being recorded, meaning you can legally record your own conversations without informing the other party. In all-party consent states, every participant must be aware of and consent to the recording, whether audio or video capturing sound, and recording without that consent can result in civil or criminal liability.

Can tracking pixels and session replay tools violate wiretapping laws?

Yes. A growing body of litigation argues that tracking pixels and session replay software that capture and transmit a website visitor’s interactions to a third party without consent can qualify as an illegal interception under state wiretapping and eavesdropping statutes, particularly in all-party consent states like California, Illinois, Florida, and Pennsylvania.

Do businesses need signage for CCTV surveillance?

Signage requirements vary by state and context, but posting visible notice of video surveillance is a widely recommended and, in several states, legally required practice, particularly in workplaces and semi-public spaces where an expectation of privacy may otherwise exist.

Is workplace audio recording legal?

It depends on the state. Employers can generally use video surveillance for legitimate business purposes, but audio recording carries a higher compliance bar, often requiring employee notification or consent, and unionized workplaces may additionally require bargaining over surveillance policy.

What federal law applies to surveillance of stored emails and messages?

The Electronic Communications Privacy Act, specifically its Stored Communications Act component, governs access to stored electronic communications such as email and voicemail, separately from the real-time interception rules under the Wiretap Act.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.