Skip to main content

Data Protection Map

Illinois

Data Breach Requirements: 815 ILCS § 530/1 et seq.

The numbering and internal citations herein are derived from the applicable state statute.

Personal Information

The term “personal information” means either of the following:
(1) An individual’s first name or first initial and last name in combination with any one or more of the following data elements, when either the name or the data elements are not encrypted or redacted or are encrypted or redacted but the keys to unencrypt or unredact or otherwise read the name or data elements have been acquired without authorization through the breach of security:
(A) Social Security number.
(B) Driver’s license number or state identification card number.
(C) Account number or credit or debit card number, or an account number or credit card number in combination with any required security code, access code, or password that would permit access to an individual’s financial account.
(D) Medical information.
(E) Health insurance information.
(F) Unique biometric data generated from measurements or technical analysis of human body characteristics used by the owner or licensee to authenticate an individual, such as a fingerprint, retina or iris image, or other unique physical representation or digital representation of biometric data.
(2) Username or email address, in combination with a password or security question and answer that would permit access to an online account, when either the username or email address or password or security question and answer are not encrypted or redacted or are encrypted or redacted but the keys to unencrypt or unredact or otherwise read the data elements have been obtained through the breach of security.


Security Breach Definition

The term “breach of the security of the system data” or “breach” means unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by the data collector.


Good Faith Exception

A breach does not include good faith acquisition of personal information by an employee or agent of the data collector for a legitimate purpose of the data collector, provided that the personal information is not used for a purpose unrelated to the data collector’s business or subject to further unauthorized disclosure.


Risk of Harm Analysis

N/A


Notification Timeline

A data breach notification shall be made in the most expedient time possible and without unreasonable delay, consistent with any measures necessary to determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system.


Security and Investigation Exceptions

The breach notification may be delayed if an appropriate law enforcement agency determines that notification will interfere with a criminal investigation and provides the data collector with a written request for the delay. However, the data collector must notify the Illinois resident as soon as notification will no longer interfere with the investigation.


Notification Content Requirements

The disclosure notification to an Illinois resident shall include, but need not be limited to, information as follows:
(1) With respect to personal information as defined in Section 5 in paragraph (1) of the definition of “personal information”:
(A) The toll-free numbers and addresses for consumer reporting agencies;
(B) The toll-free number, address, and website address for the Federal Trade Commission; and
(C) A statement that the individual can obtain information from these sources about fraud alerts and security freezes.

(2) With respect to personal information defined in Section 5 in paragraph (2) of the definition of “personal information,” notice may be provided in electronic or other form directing the Illinois resident whose personal information has been breached to promptly change his or her username or password and security question or answer, as applicable, or to take other steps appropriate to protect all online accounts for which the resident uses the same username or email address and password or security question and answer.


Delivery Methods

A breach notice may be provided by one of the following methods:
(1) Written notice;
(2) Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures for notices legally required to be in writing as set forth in 15 U.S.C. § 7001 (The Electronic Signatures in Global and National Commerce Act); or
(3) Substitute notice, if the data collector demonstrates that the cost of providing notice would exceed $250,000, or that the affected class of subject persons to be notified exceeds 500,000, or the data collector does not have sufficient contact information.


Substitute Notice

Substitute notice shall consist of all of the following:

(i) email notice if the data collector has an email address for the subject persons;

(ii) conspicuous posting of the notice on the data collector’s website page if the data collector maintains one; and (iii) notification to major statewide media or, if the breach impacts residents in one geographic area, to prominent local media in areas where affected individuals are likely to reside if such notice is reasonably calculated to give actual notice to persons whose notice is required.


Notice to Government Agencies

Any data collector required to issue a data breach notice to more than 500 Illinois residents as a result of a single breach of the security system shall provide notice to the attorney general of the breach, including:

(A) A description of the nature of the breach of security or unauthorized acquisition or use.

(B) The number of Illinois residents affected by such incident at the time of notification.

(C) Any steps the data collector has taken or plans to take relating to the incident. Such notification must be made in the most expedient time possible and without unreasonable delay, but in no event later than when the data collector provides notice to consumers. If the date of the breach is unknown at the time the notice is sent to the attorney general, the data collector shall send the attorney general the date of the breach as soon as possible.


Consumer Reporting Agencies

N/A to private sector.


Preemption and Compliance

Any covered entity or business associate that is subject to and in compliance with the privacy and security standards for the protection of electronic health information established pursuant to Health Insurance Portability and Accountability HIPAA and the Health Information Technology for Economic and Clinical Health Act (HITECH) shall be deemed to be in compliance with the provisions of this act, provided that any covered entity or business associate required to provide notification of a breach to the secretary of Health and Human Services pursuant to HITECH also provides such notification to the attorney general within five business days of notifying the secretary of Health and Human Services.


The notification “delivery” requirements to consumers do not apply to data collectors that are covered entities or business associates and are in compliance with the above.


Data Processor Obligations

Any data collector that maintains or stores, but does not own or license, computerized data that includes personal information that the data collector does not own or license shall notify the owner or licensee of the information of any breach of the security of the data immediately following discovery, if the personal information was, or is reasonably believed to have been, acquired by an unauthorized person. In addition to providing such notification to the owner or licensee, the data collector shall cooperate with the owner or licensee in matters relating to the breach. That cooperation shall include, but need not be limited to, (i) informing the owner or licensee of the breach, including giving notice of the date or approximate date of the breach and the nature of the breach, and (ii) informing the owner or licensee of any steps the data collector has taken or plans to take relating to the breach. The data collector’s cooperation shall not, however, be deemed to require either the disclosure of confidential business information or trade secrets or the notification of an Illinois resident who may have been affected by the breach.


Other Information

A data breach notification must be given at no charge.


The breach notification to Illinois residents must not include information concerning the number of Illinois residents affected by the breach


Upon receiving notification from a data collector of a breach of personal information, the attorney general may publish the name of the data collector that suffered the breach, the types of personal information compromised in the breach, and the date range of the breach.


Data Disposal and Security: 815 ILCS §§ 530/5, 530/40, and 530/45.

The numbering and internal citations herein are derived from the applicable state statute. See statute for any applicable exceptions or exemptions.

Key Terms

The term “person” means: a natural person; a corporation, partnership, association, or other legal entity; a unit of local government or any agency, department, division, bureau, board, commission, or committee thereof; or the State of Illinois or any constitutional officer, agency, department, division, bureau, board, commission, or committee thereof.


The term “personal information” means either of the following:
(1) An individual’s first name or first initial and last name in combination with any one or more of the following data elements, when either the name or the data elements are not encrypted or redacted or are encrypted or redacted but the keys to unencrypt or unredact or otherwise read the name or data elements have been acquired without authorization through the breach of security:
(A) Social Security number.
(B) Driver’s license number or state identification card number.
(C) Account, credit, or debit card number, or an account number or credit card number in combination with any required security code, access code, or password that would permit access to an individual’s financial account.
(D) Medical information.
(E) Health insurance information.
(F) Unique biometric data generated from measurements or technical analysis of human body characteristics used by the owner or licensee to authenticate an individual, such as a fingerprint, retina or iris image, or other unique physical representation or digital representation of biometric data.
(2) Username or email address, in combination with a password or security question and answer that would permit access to an online account, when either the username, email address, password, or security question and answer are not encrypted or redacted or are encrypted or redacted but the keys to unencrypt or unredact or otherwise read the data elements have been obtained through the breach of security.


Security Requirements

A data collector that owns, licenses, maintains, or stores but does not own or license records that contain personal information concerning an Illinois resident shall implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification, or disclosure.


A contract for the disclosure of personal information concerning an Illinois resident that is maintained by a data collector must include a provision requiring the person to whom the information is disclosed to implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification, or disclosure.


Written Policy

See Data Disposal (third parties must implement and monitor compliance with policies and procedures).


Data Disposal

A person must dispose of the materials containing personal information in a manner that renders the personal information unreadable, unusable, and undecipherable. Proper disposal methods include, but are not limited to, the following:
(1) Paper documents containing personal information may be either redacted, burned, pulverized, or shredded so that personal information cannot practicably be read or reconstructed.
(2) Electronic media and other non-paper media containing personal information may be destroyed or erased so that personal information cannot practicably be read or reconstructed.


(c) Any person disposing of materials containing personal information may contract with a third party to dispose of such materials. Any third party that contracts with a person to dispose of materials containing personal information must implement and monitor compliance with policies and procedures that prohibit unauthorized access to or acquisition of or use of personal information during the collection, transportation, and disposal of materials containing personal information.


Other Information

If a state or federal law requires a data collector to provide greater protection to records that contain personal information concerning an Illinois resident that are maintained by the data collector and the data collector is in compliance with the provisions of that state or federal law, the data collector shall be deemed to be in compliance with the provisions herein.