Back to docs
Research Operations

Interview Recording Consent Laws: One-Party, All-Party, and Biometric Rules (2026)

Federal law allows one-party consent recording, but roughly a dozen US states require all-party consent - and biometric laws like Illinois BIPA add a separate written-consent duty for voiceprints. Here is how research teams stay on the safe side of both.

The short answer

Get affirmative, on-the-record consent from every participant before recording starts. Always. Everywhere.

That one rule resolves nearly every legal question on this page, because it satisfies the strictest standard that could apply to you. The reason it matters:

  • Federal law (the Electronic Communications Privacy Act, 18 U.S.C. § 2511, originally the Wiretap Act of 1968) sets a one-party consent baseline — recording is permitted if at least one party to the conversation consents. As the person recording, you are that party.
  • Roughly a dozen states require all-party consent instead, and violations there can be criminal, not merely civil.
  • Biometric privacy laws are a completely separate regime. Illinois BIPA requires written notice and a written release before collecting a voiceprint — and consent to record is not the same as consent to create a biometric identifier.

This guide is written for research and product teams and is not legal advice. State law changes, and several of the distinctions below are genuinely unsettled. Confirm current requirements with counsel before rolling out a recording program — especially a multi-state one.

One-party vs all-party consent

A one-party consent jurisdiction requires only one participant in the conversation to agree to the recording. A two-party — more accurately all-party — jurisdiction requires everyone.

As of 2026, the states commonly listed as all-party consent are:

California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Oregon, Pennsylvania, and Washington.

Treat that list as a starting point rather than gospel. Published lists disagree at the margins because several statutes distinguish between types of communication, and courts keep refining the boundaries. Two documented examples of exactly that:

  • Connecticut requires all-party consent for recording phone calls, but follows a one-party rule for in-person conversations under its criminal statute.
  • Oregon requires all-party consent for in-person oral communications, but applies a one-party rule to electronic communications.

This is precisely why "which list is right?" is the wrong question for a research team to spend time on.

The rule that makes the map irrelevant

In research you almost never know a participant's physical location with legal certainty. Someone recruited as a New York customer may take the session from a hotel in Seattle. Remote panels cross state lines constantly, and cross-border sessions can pull in foreign law entirely.

So do not build a compliance program that depends on geolocating participants. Apply the strictest applicable standard to everyone:

  1. State the recording intent in the invitation, before anyone joins
  2. Capture explicit consent as a discrete step before the session begins
  3. Restate it on the record at the start of the session
  4. Give a genuine way to decline that still lets the person participate — or to withdraw partway through
  5. Log the consent with a timestamp alongside the recording

Step 4 carries more weight than teams expect. Consent that is a precondition to getting paid is not obviously "freely given," which matters a great deal under GDPR and is a fair criticism of many incentive-driven panels. Offer a text-only or notes-only path for people who decline recording.

Biometrics: the duty most teams miss

Here is the distinction that catches sophisticated teams: an audio recording is not automatically a voiceprint.

Illinois BIPA governs biometric identifiers — fingerprints, iris scans, face geometry, and voiceprints. A voiceprint is a template derived from a voice for the purpose of identifying a person. Simply storing an audio file of someone answering questions is generally not that. Running that audio through a system that builds a speaker template to recognize who is talking is.

BIPA's requirements, when it applies:

  • Written notice that a biometric identifier is being collected, why, and for how long it will be retained
  • A written release — obtained before collection
  • A published retention and destruction schedule

The exposure is significant: statutory damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation, plus attorney fees and injunctive relief. A 2024 amendment (Public Act 103-769) softened the arithmetic considerably by treating repeated collections of the same biometric from the same person as a single violation rather than one per scan — but the per-person exposure remains real.

Two 2026 developments worth knowing. First, litigation has expanded sharply: in May 2026, Illinois voice actors, narrators, podcasters, and journalists filed suits against a long list of major technology and AI companies, framing the claim around the extraction of voiceprints rather than copyright — a theory that travels further for class treatment. Second, practitioners have flagged that passively building voiceprints from ordinary call audio, with no enrollment step, is arguably higher risk than an explicit enrollment flow, because there is no consent moment at all.

A spoken disclosure at the top of a call does not satisfy BIPA. The statute asks for a written release — an SMS link, an email confirmation, or a signed portal step.

Illinois is the sharpest instrument, but not the only one: Texas and Washington have their own biometric statutes, and most of the 20 US state comprehensive privacy laws now treat biometric data as sensitive personal information requiring opt-in consent.

Outside the US

GDPR does not have a one-party/all-party concept. A recording of an identifiable person is personal data, so you need a lawful basis (usually consent for research), purpose limitation, minimization, a retention limit, and a route for participants to exercise their rights. Voice data processed to uniquely identify someone is special category data under Article 9 and requires a stronger basis. See GDPR-compliant AI user research.

From 2 August 2026, the EU AI Act adds a separate transparency duty when people interact with an AI system — a disclosure obligation about the AI itself, independent of anything recording law requires.

A practical policy you can adopt

ElementWhat to do
Default standardAll-party consent, applied to every participant regardless of location
TimingConsent captured before recording begins, never retroactively
Record of consentTimestamped, stored with the session
Decline pathText-based or notes-only participation, no loss of incentive
VoiceprintsDo not create them for research. If a vendor does, demand written notice and release
Speaker identificationOff unless there is a documented need
RetentionPublished schedule with automatic deletion — see research data retention
MinorsParental consent plus child assent — see research with children
Sensitive topicsExtra care on withdrawal rights — see trauma-informed research

How Koji is structured around this

The mechanics of AI-moderated research remove several of the sharpest edges — not because the law differs, but because the workflow does.

  • Participants start the session themselves. There is no bot silently joining a meeting already in progress, which is the fact pattern generating most of the current recording-consent litigation.
  • Consent is a structured step before the interview begins, not a verbal aside a moderator may forget under time pressure. See intake forms and consent.
  • Text mode sidesteps voice capture entirely. For sensitive studies, multi-state panels, or Illinois participants, running text interviews means no audio and therefore no voiceprint question at all. Voice vs text interviews covers the tradeoffs — voice yields richer affect and detail, text yields cleaner compliance and faster review.
  • Analysis works from the transcript, not from the voice. Koji derives themes, quality scores, and a sentiment label from what the participant said — not from vocal timbre, prosody, or a speaker template. No voiceprints are created for identification and no biometric categorisation is performed.
  • Structured questions reduce your reliance on inferred signal. With six question types — open_ended, scale, single_choice, multiple_choice, ranking, yes_no — you can measure how strongly someone feels by asking them on a scale and letting the AI probe why, rather than inferring it from their voice. The structured questions guide shows how to build that instrument.
  • Every session produces a verbatim transcript with a consent record attached, which is exactly the artifact you want if a participant later asks what you hold about them.

Confirm current configuration, sub-processors, and retention settings during procurement — see enterprise security for AI research platforms.

Common mistakes

  1. Geolocating participants to pick a legal standard. Fragile, and it fails the moment someone travels. Apply the strictest rule universally.
  2. Treating a spoken "is it okay if I record?" as sufficient for biometrics. BIPA wants written notice and a written release.
  3. Assuming a recording is a voiceprint, or that it never is. The trigger is whether a template is derived to identify someone.
  4. Making consent a condition of payment. Undermines the "freely given" requirement and reads badly to regulators.
  5. Leaving speaker identification enabled by default because a vendor ships it that way.
  6. No published retention schedule. BIPA explicitly asks for one, and GDPR storage limitation expects it.
  7. Recording first and asking later. In an all-party state this can be a criminal exposure, not a paperwork problem.

Related Resources

Related Articles

Anonymizing Customer Interview Data: A Practical Guide for Privacy-Safe Research

Five operational techniques for handling PII in AI customer interviews — from intake-time anonymization to stakeholder-safe quote sharing — without sacrificing research signal.

Enterprise Security for AI Customer Research Platforms: SOC 2, SSO, and Vendor Review

A procurement-ready guide to evaluating the security of an AI customer research platform — SOC 2, encryption, SSO/SAML, data residency, sub-processors, and the questions your security team should ask.

FERPA-Compliant User Research: Interviewing Students, Parents, and Educators

How FERPA, PPRA, and state student-privacy laws apply to edtech user research — when the school official exception covers you, when PPRA consent kicks in, and how to run compliant student interviews.

GDPR-Compliant AI User Research: A Practical Guide

How to run AI-moderated customer interviews under GDPR. Lawful basis, consent flows, data minimization, retention, sub-processors, and how Koji handles each requirement.

How to Record Customer Interviews (Consent, Tools & Transcription)

A complete guide to recording customer interviews the right way: getting consent, choosing tools, capturing clean audio, transcribing accurately, and skipping recording entirely with AI-moderated interviews.

Intake Forms and Consent

Collect participant information and consent before interviews begin with customizable form fields.

Research Consent Form Templates: GDPR-Compliant Forms for Every Study

Ready-to-use consent form templates for user research, UX studies, and AI interviews. Covers GDPR compliance, informed consent best practices, and how to collect consent automatically with Koji.

Research Data Retention and Deletion: How Long Should You Keep Interview Data?

There is no universal legal number - which is exactly why having no retention schedule is itself the compliance failure. A tiered, per-artifact schedule for recordings, transcripts, quotes, and reports, plus how to handle deletion requests without losing your insights.

Structured Questions in AI Interviews

Mix quantitative data collection — scales, ratings, multiple choice, ranking — with AI-powered conversational follow-up in a single interview.

Voice vs Text Interview: When to Use Each Mode

Choosing between voice and text mode for your AI interview? This guide breaks down response depth, completion rate, audience fit, and cost — plus a decision matrix that tells you which mode wins for each research scenario.