{
  "type": "practice-guide",
  "canonical": "https://openagreements.org/practice-guides/privacy/us/illinois",
  "links": [
    {
      "rel": "self",
      "href": "https://openagreements.org/practice-guides/privacy/us/illinois.json",
      "type": "application/json"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/illinois",
      "type": "text/html"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/illinois/markdown",
      "type": "text/markdown"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/illinois/json",
      "type": "application/json"
    }
  ],
  "data": {
    "topic": "privacy",
    "state": "illinois",
    "frontmatter": {
      "title": "Illinois Consumer Privacy Law (BIPA)",
      "description": "Illinois has no comprehensive consumer-privacy act, but the Biometric Information Privacy Act (740 ILCS 14) is the most litigated state privacy statute in the country — written consent and a public retention policy are required, and private plaintiffs can sue for liquidated damages without proving actual harm.",
      "state": "Illinois",
      "lastReviewed": "2026-06-11",
      "license": "CC BY 4.0",
      "authors": [
        "steven-obiajulu"
      ],
      "summary": {
        "keyLaw": "Biometric Information Privacy Act (BIPA), 740 ILCS 14 — Illinois has no comprehensive consumer-privacy law; BIPA sits alongside the Genetic Information Privacy Act (410 ILCS 513), the Personal Information Protection Act breach statute (815 ILCS 530), and the Consumer Fraud Act",
        "appliesTo": "BIPA reaches any private entity — any individual, partnership, corporation, LLC, association, or other group — that handles biometric identifiers or biometric information of people in Illinois, with no revenue or volume threshold; government agencies and GLBA financial institutions are carved out",
        "privacyPolicyRequired": "Yes for biometric data — BIPA § 15(a) requires a written, publicly available policy with a retention schedule and destruction guidelines; no Illinois statute fixes the contents of a general consumer privacy policy, so FTC Act § 5 and the Consumer Fraud Act truthfulness rules govern the rest",
        "privateRightOfAction": "Yes — BIPA § 20 allows suit without actual injury beyond the statutory violation under Rosenbach; GIPA § 40 separately provides a private right of action and liquidated damages of $2,500/$15,000 per violation",
        "regulator": "BIPA is enforced through private plaintiffs; GIPA has a private right of action, with insurer-related § 30 violations handled through the Illinois Insurance Code; PIPA is enforced through the Consumer Fraud and Deceptive Business Practices Act",
        "bottomLine": "Illinois has not enacted a comprehensive consumer-privacy law, but it is the highest-exposure privacy state in the country for one reason — the Biometric Information Privacy Act. Before collecting a fingerprint, face scan, or voiceprint, a business must publish a written retention-and-destruction policy and obtain informed written consent, and any person whose rights are violated can sue for $1,000 or $5,000 in liquidated damages per person without proving actual harm, on a five-year limitations period. A 2024 amendment capped repeated identical scans at one recovery per person per method of collection, and in April 2026 the Seventh Circuit held that cap applies retroactively to pending cases. Genetic data carries parallel private-suit exposure under GIPA, and breach notification under the Personal Information Protection Act is the Attorney General's lane.",
        "lawCoverage": "sectoral",
        "policyMandate": "sectoralPolicy",
        "consumersCanSue": "broad",
        "sensitiveDataConsent": "categorySpecific",
        "universalOptOutSignal": "notRequired"
      },
      "about": [
        "Illinois Biometric Information Privacy Act BIPA",
        "Illinois biometric consent fingerprint face scan",
        "BIPA written policy retention schedule requirements",
        "BIPA damages per person 1000 5000",
        "Rosenbach v Six Flags aggrieved person standing",
        "Cothron v White Castle per-scan accrual",
        "BIPA 2024 amendment single recovery retroactive",
        "Illinois Genetic Information Privacy Act GIPA employment",
        "Illinois data breach notification PIPA",
        "Illinois Attorney General privacy enforcement"
      ],
      "translations": [
        {
          "language": "中文",
          "status": "planned"
        },
        {
          "language": "Español",
          "status": "planned"
        },
        {
          "language": "Português",
          "status": "planned"
        },
        {
          "language": "Deutsch",
          "status": "planned"
        }
      ]
    },
    "questions": [
      {
        "slug": "which-privacy-laws-apply",
        "label": "Which privacy laws apply to your business in Illinois?",
        "heading": "Which privacy laws apply to your business in Illinois?",
        "answerText": "Illinois has no comprehensive consumer-privacy statute, but it is anything but a light-touch state. The headline law is the Biometric Information Privacy Act (BIPA), which the General Assembly enacted on the finding that the public welfare, security, and safety will be served by regulating the collection, use, safeguarding, handling, storage, retention, and destruction of biometric identifiers and information. BIPA applies to any private entity — any individual, partnership, corporation, limited liability company, association, or other group, however organized — with no revenue or data-volume threshold. Around it sit three more statutes: the Genetic Information Privacy Act (GIPA), which makes genetic testing information confidential and privileged; the Personal Information Protection Act (PIPA), the breach-notification statute that reaches essentially every entity handling nonpublic personal information of Illinois residents; and the Consumer Fraud and Deceptive Business Practices Act, which supplies the enforcement hook for deceptive privacy practices.",
        "sources": [
          {
            "id": "stat-bipa-5-findings",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "740 ILCS 14/5",
            "citation": "740 ILCS 14/5(g).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/074000140K5.htm",
            "proposition": "The General Assembly enacted BIPA on the finding that regulating the collection, use, safeguarding, handling, storage, retention, and destruction of biometric identifiers and information serves the public welfare, security, and safety.",
            "verbatimQuote": "The public welfare, security, and safety will be served by regulating the collection, use, safeguarding, handling, storage, retention, and destruction of biometric identifiers and information.",
            "date": "2008-10-03",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-bipa-5-findings"
          },
          {
            "id": "stat-bipa-10-private-entity",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "740 ILCS 14/10",
            "citation": "740 ILCS 14/10.",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/074000140K10.htm",
            "proposition": "BIPA applies to any private entity — any individual, partnership, corporation, limited liability company, association, or other group, however organized — but not to state or local government agencies or Illinois courts.",
            "verbatimQuote": "\"Private entity\" means any individual, partnership, corporation, limited liability company, association, or other group, however organized. A private entity does not include a State or local government agency. A private entity does not include any court of Illinois, a clerk of the court, or a judge or justice thereof.",
            "date": "2024-08-02",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-bipa-10-private-entity"
          },
          {
            "id": "stat-gipa-15-confidential",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "410 ILCS 513/15",
            "citation": "410 ILCS 513/15(a).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/041005130K15.htm",
            "proposition": "GIPA makes genetic testing and information derived from genetic testing confidential and privileged, releasable only to the tested individual and persons the individual specifically authorizes in writing.",
            "verbatimQuote": "Except as otherwise provided in this Act, genetic testing and information derived from genetic testing is confidential and privileged and may be released only to the individual tested and to persons specifically authorized, in writing in accordance with Section 30, by that individual to receive the information.",
            "date": "2009-01-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-gipa-15-confidential"
          },
          {
            "id": "stat-pipa-5-data-collector",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "815 ILCS 530/5",
            "citation": "815 ILCS 530/5.",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/081505300K5.htm",
            "proposition": "PIPA's breach-notification duties reach any data collector — a category that includes government agencies, universities, corporations, financial institutions, retailers, and any other entity that handles nonpublic personal information for any purpose.",
            "verbatimQuote": "\"Data collector\" may include, but is not limited to, government agencies, public and private universities, privately and publicly held corporations, financial institutions, retail operators, and any other entity that, for any purpose, handles, collects, disseminates, or otherwise deals with nonpublic personal information.",
            "date": "2017-01-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-pipa-5-data-collector"
          }
        ]
      },
      {
        "slug": "privacy-policy-contents",
        "label": "What must your Illinois privacy policy contain?",
        "heading": "What must your Illinois privacy policy contain?",
        "answerText": "It depends on whether you touch biometric data. If you possess biometric identifiers or biometric information — fingerprints, face geometry, voiceprints, retina or iris scans — BIPA § 15(a) imposes a specific, written-policy mandate: you must develop a written policy, made available to the public, establishing a retention schedule and guidelines for permanently destroying the data when the initial purpose for collecting it has been satisfied or within 3 years of the individual's last interaction with your business, whichever occurs first. You must then actually follow that schedule: absent a valid warrant or subpoena, a private entity must comply with its established retention schedule and destruction guidelines. For everything else, no Illinois statute fixes the contents of a general consumer privacy policy — the governing rule is that whatever you publish must be true, because a policy that misstates your practices is a deceptive act under FTC Act § 5 and under the Illinois Consumer Fraud Act.",
        "sources": [
          {
            "id": "stat-15a-written-policy",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "740 ILCS 14/15(a)",
            "citation": "740 ILCS 14/15(a).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/074000140K15.htm",
            "proposition": "A private entity in possession of biometric data must develop a written, publicly available policy establishing a retention schedule and destruction guidelines, with destruction when the collection purpose is satisfied or within 3 years of the individual's last interaction, whichever occurs first.",
            "verbatimQuote": "A private entity in possession of biometric identifiers or biometric information must develop a written policy, made available to the public, establishing a retention schedule and guidelines for permanently destroying biometric identifiers and biometric information when the initial purpose for collecting or obtaining such identifiers or information has been satisfied or within 3 years of the individual's last interaction with the private entity, whichever occurs first.",
            "date": "2008-10-03",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-15a-written-policy"
          },
          {
            "id": "stat-15a-comply",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "740 ILCS 14/15(a)",
            "citation": "740 ILCS 14/15(a).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/074000140K15.htm",
            "proposition": "Once the retention schedule and destruction guidelines exist, the private entity must actually comply with them, unless a valid court-issued warrant or subpoena provides otherwise.",
            "verbatimQuote": "Absent a valid warrant or subpoena issued by a court of competent jurisdiction, a private entity in possession of biometric identifiers or biometric information must comply with its established retention schedule and destruction guidelines.",
            "date": "2008-10-03",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-15a-comply"
          },
          {
            "id": "fed-ftc5-deceptive",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "FTC Act § 5",
            "citation": "15 U.S.C. § 45(a)(1).",
            "url": "https://www.law.cornell.edu/uscode/text/15/45",
            "deepLink": "https://www.law.cornell.edu/uscode/text/15/45#:~:text=Unfair%20methods%20of%20competition%20in,commerce%2C%20are%20hereby%20declared%20unlawful.",
            "proposition": "Section 5 of the FTC Act declares unfair or deceptive acts or practices in or affecting commerce unlawful, which reaches a privacy policy that misstates a business's actual data practices.",
            "verbatimQuote": "Unfair methods of competition in or affecting commerce, and unfair or deceptive acts or practices in or affecting commerce, are hereby declared unlawful.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-fed-ftc5-deceptive"
          },
          {
            "id": "stat-icfa-2-deceptive",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "815 ILCS 505/2",
            "citation": "815 ILCS 505/2.",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/081505050K2.htm",
            "proposition": "The Illinois Consumer Fraud Act declares deceptive acts or practices — including concealment, suppression, or omission of material facts — unlawful in trade or commerce, which reaches privacy representations that do not match actual practice.",
            "verbatimQuote": "Unfair methods of competition and unfair or deceptive acts or practices, including but not limited to the use or employment of any deception fraud, false pretense, false promise, misrepresentation or the concealment, suppression or omission of any material fact, with intent that others rely upon the concealment, suppression or omission of such material fact, or the use or employment of any practice described in Section 2 of the \"Uniform Deceptive Trade Practices Act\", approved August 5, 1965, in the conduct of any trade or commerce are hereby declared unlawful whether any person has in fact been misled, deceived or damaged thereby.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-icfa-2-deceptive"
          }
        ]
      },
      {
        "slug": "biometric-consent",
        "label": "Do you need written consent to collect fingerprints or face scans in Illinois?",
        "heading": "Do you need written consent to collect fingerprints or face scans in Illinois?",
        "answerText": "Yes — before collection, in writing, and after specific disclosures. BIPA § 15(b) prohibits a private entity from collecting, capturing, purchasing, receiving through trade, or otherwise obtaining a person's biometric identifier or biometric information unless it first informs the person in writing that the data is being collected or stored, informs the person in writing of the specific purpose and length of term of the collection, and receives a written release executed by the subject. A biometric identifier means a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry. Three companion duties travel with the data: no private entity may sell, lease, trade, or otherwise profit from a person's biometric data; disclosure to anyone else requires the subject's consent or another narrow statutory basis; and the data must be stored and protected using the reasonable standard of care within the entity's industry, at least as protectively as other confidential and sensitive information.",
        "sources": [
          {
            "id": "stat-15b-consent",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "740 ILCS 14/15(b)",
            "citation": "740 ILCS 14/15(b).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/074000140K15.htm",
            "proposition": "Before obtaining biometric data, a private entity must first give written notice that the data is being collected or stored, give written notice of the specific purpose and length of term of the collection, and receive a written release from the subject.",
            "verbatimQuote": "No private entity may collect, capture, purchase, receive through trade, or otherwise obtain a person's or a customer's biometric identifier or biometric information, unless it first: (1) informs the subject or the subject's legally authorized representative in writing that a biometric identifier or biometric information is being collected or stored; (2) informs the subject or the subject's legally authorized representative in writing of the specific purpose and length of term for which a biometric identifier or biometric information is being collected, stored, and used; and (3) receives a written release executed by the subject of the biometric identifier or biometric information or the subject's legally authorized representative.",
            "date": "2008-10-03",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-15b-consent"
          },
          {
            "id": "stat-10-biometric-identifier",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "740 ILCS 14/10",
            "citation": "740 ILCS 14/10.",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/074000140K10.htm",
            "proposition": "A biometric identifier is a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry; the definition excludes photographs, physical descriptions, patient information captured in health care settings, and health care treatment, payment, or operations information under HIPAA.",
            "verbatimQuote": "\"Biometric identifier\" means a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry. Biometric identifiers do not include writing samples, written signatures, photographs, human biological samples used for valid scientific testing or screening, demographic data, tattoo descriptions, or physical descriptions such as height, weight, hair color, or eye color. Biometric identifiers do not include donated organs, tissues, or parts as defined in the Illinois Anatomical Gift Act or blood or serum stored on behalf of recipients or potential recipients of living or cadaveric transplants and obtained or stored by a federally designated organ procurement agency. Biometric identifiers do not include biological materials regulated under the Genetic Information Privacy Act. Biometric identifiers do not include information captured from a patient in a health care setting or information collected, used, or stored for health care treatment, payment, or operations under the federal Health Insurance Portability and Accountability Act of 1996.",
            "date": "2024-08-02",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-10-biometric-identifier"
          },
          {
            "id": "stat-15c-no-profit",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "740 ILCS 14/15(c)",
            "citation": "740 ILCS 14/15(c).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/074000140K15.htm",
            "proposition": "A private entity in possession of biometric data may not sell, lease, trade, or otherwise profit from it — a flat prohibition with no consent exception.",
            "verbatimQuote": "No private entity in possession of a biometric identifier or biometric information may sell, lease, trade, or otherwise profit from a person's or a customer's biometric identifier or biometric information.",
            "date": "2008-10-03",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-15c-no-profit"
          },
          {
            "id": "stat-15d-disclosure",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "740 ILCS 14/15(d)",
            "citation": "740 ILCS 14/15(d).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/074000140K15.htm",
            "proposition": "A private entity may not disclose, redisclose, or disseminate a person's biometric data unless the subject consents, the disclosure completes a transaction the subject authorized, or law or legal process requires it.",
            "verbatimQuote": "No private entity in possession of a biometric identifier or biometric information may disclose, redisclose, or otherwise disseminate a person's or a customer's biometric identifier or biometric information unless: (1) the subject of the biometric identifier or biometric information or the subject's legally authorized representative consents to the disclosure or redisclosure; (2) the disclosure or redisclosure completes a financial transaction requested or authorized by the subject of the biometric identifier or the biometric information or the subject's legally authorized representative; (3) the disclosure or redisclosure is required by State or federal law or municipal ordinance; or (4) the disclosure is required pursuant to a valid warrant or subpoena issued by a court of competent jurisdiction.",
            "date": "2008-10-03",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-15d-disclosure"
          },
          {
            "id": "stat-15e-safeguards",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "740 ILCS 14/15(e)",
            "citation": "740 ILCS 14/15(e).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/074000140K15.htm",
            "proposition": "A private entity must store, transmit, and protect biometric data using the reasonable standard of care in its industry, and at least as protectively as it protects other confidential and sensitive information.",
            "verbatimQuote": "A private entity in possession of a biometric identifier or biometric information shall: (1) store, transmit, and protect from disclosure all biometric identifiers and biometric information using the reasonable standard of care within the private entity's industry; and (2) store, transmit, and protect from disclosure all biometric identifiers and biometric information in a manner that is the same as or more protective than the manner in which the private entity stores, transmits, and protects other confidential and sensitive information.",
            "date": "2008-10-03",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-15e-safeguards"
          },
          {
            "id": "stat-10-written-release",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "740 ILCS 14/10",
            "citation": "740 ILCS 14/10.",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/074000140K10.htm",
            "proposition": "A written release under BIPA means informed written consent or an electronic signature, and in the employment context it may be a release executed by an employee as a condition of employment.",
            "verbatimQuote": "\"Written release\" means informed written consent, electronic signature, or, in the context of employment, a release executed by an employee as a condition of employment.",
            "date": "2024-08-02",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-10-written-release"
          },
          {
            "id": "q3-stat-bipa-10-private-entity",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "740 ILCS 14/10",
            "citation": "740 ILCS 14/10.",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/074000140K10.htm",
            "proposition": "BIPA's private-entity definition excludes state and local government agencies.",
            "verbatimQuote": "\"Private entity\" means any individual, partnership, corporation, limited liability company, association, or other group, however organized. A private entity does not include a State or local government agency. A private entity does not include any court of Illinois, a clerk of the court, or a judge or justice thereof.",
            "date": "2024-08-02",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-q3-stat-bipa-10-private-entity"
          },
          {
            "id": "stat-bipa-25-glba",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "740 ILCS 14/25(c)",
            "citation": "740 ILCS 14/25(c).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/074000140K25.htm",
            "proposition": "BIPA does not apply to financial institutions, or affiliates of financial institutions, subject to Title V of the Gramm-Leach-Bliley Act.",
            "verbatimQuote": "Nothing in this Act shall be deemed to apply in any manner to a financial institution or an affiliate of a financial institution that is subject to Title V of the federal Gramm-Leach-Bliley Act of 1999 and the rules promulgated thereunder.",
            "date": "2008-10-03",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-bipa-25-glba"
          },
          {
            "id": "stat-bipa-25-contractors",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "740 ILCS 14/25(e)",
            "citation": "740 ILCS 14/25(e).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/074000140K25.htm",
            "proposition": "BIPA does not apply to a contractor, subcontractor, or agent of a state agency or local unit of government while working for that agency or unit.",
            "verbatimQuote": "Nothing in this Act shall be construed to apply to a contractor, subcontractor, or agent of a State agency or local unit of government when working for that State agency or local unit of government.",
            "date": "2008-10-03",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-bipa-25-contractors"
          }
        ]
      },
      {
        "slug": "bipa-lawsuit-exposure",
        "label": "Can someone sue your business under BIPA without proving actual harm?",
        "heading": "Can someone sue your business under BIPA without proving actual harm?",
        "answerText": "Yes — this is the feature that makes Illinois unlike any other state. BIPA § 20 gives any person aggrieved by a violation a right of action in state circuit court or as a supplemental claim in federal court, with liquidated damages of $1,000 per negligent violation or $5,000 per intentional or reckless violation (or actual damages if greater), plus attorneys' fees and costs. In Rosenbach v. Six Flags Entertainment Corp., the Illinois Supreme Court held that an individual need not allege some actual injury or adverse effect, beyond violation of his or her rights under the Act, in order to qualify as an “aggrieved” person and be entitled to seek liquidated damages and injunctive relief pursuant to the Act. And the window is long: in Tims v. Black Horse Carriers, Inc., the court held that the five-year catchall limitations period of section 13-205 of the Code of Civil Procedure controls claims under the Act.",
        "sources": [
          {
            "id": "stat-20a-damages",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "740 ILCS 14/20(a)",
            "citation": "740 ILCS 14/20(a).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/074000140K20.htm",
            "proposition": "Any person aggrieved by a BIPA violation may sue and recover, per violation, liquidated damages of $1,000 for negligent violations or $5,000 for intentional or reckless violations (or actual damages if greater), plus attorneys' fees.",
            "verbatimQuote": "Any person aggrieved by a violation of this Act shall have a right of action in a State circuit court or as a supplemental claim in federal district court against an offending party. A prevailing party may recover for each violation: (1) against a private entity that negligently violates a provision of this Act, liquidated damages of $1,000 or actual damages, whichever is greater; (2) against a private entity that intentionally or recklessly violates a provision of this Act, liquidated damages of $5,000 or actual damages, whichever is greater;",
            "date": "2024-08-02",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-20a-damages"
          },
          {
            "id": "case-rosenbach",
            "authorityType": "case-law",
            "tier": "primary-source-backed",
            "title": "Rosenbach v. Six Flags Entertainment Corp., 2019 IL 123186",
            "citation": "Rosenbach v. Six Flags Entertainment Corp., 2019 IL 123186, ¶ 40.",
            "url": "https://www.courtlistener.com/opinion/4658484/rosenbach-v-six-flags-entertainment-corp/",
            "deepLink": "https://www.courtlistener.com/opinion/4658484/rosenbach-v-six-flags-entertainment-corp/#:~:text=Contrary%20to%20the%20appellate%20court%E2%80%99s,relief%20pursuant%20to%20the%20Act.",
            "proposition": "The Illinois Supreme Court held that a person is aggrieved under BIPA — and may seek liquidated damages and injunctive relief — without alleging any actual injury beyond the violation of his or her statutory rights.",
            "verbatimQuote": "Contrary to the appellate court’s view, an individual need not allege some actual injury or adverse effect, beyond violation of his or her rights under the Act, in order to qualify as an “aggrieved” person and be entitled to seek liquidated damages and injunctive relief pursuant to the Act.",
            "date": "2019-01-25",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-case-rosenbach"
          },
          {
            "id": "case-rosenbach-deterrence",
            "authorityType": "case-law",
            "tier": "primary-source-backed",
            "title": "Rosenbach v. Six Flags Entertainment Corp., 2019 IL 123186",
            "citation": "Rosenbach v. Six Flags Entertainment Corp., 2019 IL 123186, ¶ 37.",
            "url": "https://www.courtlistener.com/opinion/4658484/rosenbach-v-six-flags-entertainment-corp/",
            "deepLink": "https://www.courtlistener.com/opinion/4658484/rosenbach-v-six-flags-entertainment-corp/#:~:text=When%20private%20entities%20face%20liability,occur%20and%20cannot%20be%20undone.",
            "proposition": "The court explained that no-injury liability is BIPA's deterrence design: liability without proof of further injury gives private entities the strongest possible incentive to comply before biometric harms occur and cannot be undone.",
            "verbatimQuote": "When private entities face liability for failure to comply with the law’s requirements without requiring affected individuals or customers to show some injury beyond violation of their statutory rights, those entities have the strongest possible incentive to conform to the law and prevent problems before they occur and cannot be undone.",
            "date": "2019-01-25",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-case-rosenbach-deterrence"
          },
          {
            "id": "case-rosenbach-no-agency",
            "authorityType": "case-law",
            "tier": "primary-source-backed",
            "title": "Rosenbach v. Six Flags Entertainment Corp., 2019 IL 123186",
            "citation": "Rosenbach v. Six Flags Entertainment Corp., 2019 IL 123186, ¶ 37.",
            "url": "https://www.courtlistener.com/opinion/4658484/rosenbach-v-six-flags-entertainment-corp/",
            "deepLink": "https://www.courtlistener.com/opinion/4658484/rosenbach-v-six-flags-entertainment-corp/#:~:text=Other%20than%20the%20private%20right,other%20enforcement%20mechanism%20is%20available.",
            "proposition": "The Illinois Supreme Court stated that BIPA has no enforcement mechanism other than the private right of action authorized in section 20.",
            "verbatimQuote": "Other than the private right of action authorized in section 20 of the Act, no other enforcement mechanism is available.",
            "date": "2019-01-25",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-case-rosenbach-no-agency"
          },
          {
            "id": "case-tims",
            "authorityType": "case-law",
            "tier": "primary-source-backed",
            "title": "Tims v. Black Horse Carriers, Inc., 2023 IL 127801",
            "citation": "Tims v. Black Horse Carriers, Inc., 2023 IL 127801, ¶ 42.",
            "url": "https://www.courtlistener.com/opinion/9372460/tims-v-black-horse-carriers-inc/",
            "deepLink": "https://www.courtlistener.com/opinion/9372460/tims-v-black-horse-carriers-inc/#:~:text=For%20the%20aforementioned%20reasons%2C%20we,controls%20claims%20under%20the%20Act.",
            "proposition": "The Illinois Supreme Court held that the five-year catchall limitations period of 735 ILCS 5/13-205 governs all claims under BIPA, rejecting a one-year period for the publication-based subsections.",
            "verbatimQuote": "For the aforementioned reasons, we find that the five-year limitations period contained in section 13-205 of the Code controls claims under the Act.",
            "date": "2023-02-02",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-case-tims"
          },
          {
            "id": "q4-cothron-invitation",
            "authorityType": "case-law",
            "tier": "primary-source-backed",
            "title": "Cothron v. White Castle System, Inc., 2023 IL 128004",
            "citation": "Cothron v. White Castle System, Inc., 2023 IL 128004, ¶ 43.",
            "url": "https://www.courtlistener.com/opinion/9413971/cothron-v-white-castle-system-inc/",
            "deepLink": "https://www.courtlistener.com/opinion/9413971/cothron-v-white-castle-system-inc/#:~:text=We%20respectfully%20suggest%20that%20the,of%20damages%20under%20the%20Act.",
            "proposition": "While adhering to its per-scan accrual reading, the Illinois Supreme Court expressly invited the legislature to review the policy concerns about excessive damages awards and clarify its intent on the assessment of damages under BIPA.",
            "verbatimQuote": "We respectfully suggest that the legislature review these policy concerns and make clear its intent regarding the assessment of damages under the Act.",
            "date": "2023-02-17",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-q4-cothron-invitation"
          }
        ]
      },
      {
        "slug": "per-scan-damages",
        "label": "How are BIPA damages counted — per person or per scan — after the 2024 amendment?",
        "heading": "How are BIPA damages counted in Illinois — per person or per scan — after the 2024 amendment?",
        "answerText": "For repeated, identical collections: one recovery per person, per method — and that cap now governs pending cases too. The sequence matters. In Cothron v. White Castle System, Inc. (Feb. 17, 2023), the Illinois Supreme Court held that a separate claim accrues under the Act each time a private entity scans or transmits an individual’s biometric identifier or information in violation of section 15(b) or 15(d) — the per-scan reading that produced multibillion-dollar class exposure. The General Assembly answered with Public Act 103-0769, effective August 2, 2024, which added subsections 20(b) and 20(c): an entity that repeatedly collects the same biometric identifier from the same person using the same method of collection has committed a single violation, for which the aggrieved person is entitled to, at most, one recovery, with the same rule for repeated disclosures of the same data to the same recipient. And on April 1, 2026, the Seventh Circuit in Gregg v. Central Transport LLC held that this amendment applies retroactively because it impacts only the statutory damages available to plaintiﬀs—it does not change BIPA’s substantive standards of liability.",
        "sources": [
          {
            "id": "case-cothron-per-scan",
            "authorityType": "case-law",
            "tier": "primary-source-backed",
            "title": "Cothron v. White Castle System, Inc., 2023 IL 128004",
            "citation": "Cothron v. White Castle System, Inc., 2023 IL 128004, ¶ 1.",
            "url": "https://www.courtlistener.com/opinion/9413971/cothron-v-white-castle-system-inc/",
            "deepLink": "https://www.courtlistener.com/opinion/9413971/cothron-v-white-castle-system-inc/#:~:text=We%20hold%20that%20a%20separate,of%20section%2015(b)%20or%2015(d).",
            "proposition": "The Illinois Supreme Court held that a separate BIPA claim accrues each time a private entity scans or transmits a person's biometric identifier or information in violation of section 15(b) or 15(d) — not only on the first collection.",
            "verbatimQuote": "We hold that a separate claim accrues under the Act each time a private entity scans or transmits an individual’s biometric identifier or information in violation of section 15(b) or 15(d).",
            "date": "2023-02-17",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-case-cothron-per-scan"
          },
          {
            "id": "stat-20b-single-recovery",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "740 ILCS 14/20(b)",
            "citation": "740 ILCS 14/20(b), added by P.A. 103-0769 (eff. Aug. 2, 2024).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/074000140K20.htm",
            "proposition": "Under the 2024 amendment (P.A. 103-0769), repeated collection of the same biometric identifier from the same person by the same method is a single violation of section 15(b), entitling the aggrieved person to at most one recovery.",
            "verbatimQuote": "For purposes of subsection (b) of Section 15, a private entity that, in more than one instance, collects, captures, purchases, receives through trade, or otherwise obtains the same biometric identifier or biometric information from the same person using the same method of collection in violation of subsection (b) of Section 15 has committed a single violation of subsection (b) of Section 15 for which the aggrieved person is entitled to, at most, one recovery under this Section.",
            "date": "2024-08-02",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-20b-single-recovery"
          },
          {
            "id": "stat-20c-single-disclosure",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "740 ILCS 14/20(c)",
            "citation": "740 ILCS 14/20(c), added by P.A. 103-0769 (eff. Aug. 2, 2024).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/074000140K20.htm",
            "proposition": "The 2024 amendment applies the same single-recovery rule to repeated disclosures: disseminating the same person's biometric data to the same recipient in violation of section 15(d) is one violation with at most one recovery, regardless of how many times it occurs.",
            "verbatimQuote": "For purposes of subsection (d) of Section 15, a private entity that, in more than one instance, discloses, rediscloses, or otherwise disseminates the same biometric identifier or biometric information from the same person to the same recipient using the same method of collection in violation of subsection (d) of Section 15 has committed a single violation of subsection (d) of Section 15 for which the aggrieved person is entitled to, at most, one recovery under this Section regardless of the number of times the private entity disclosed, redisclosed, or otherwise disseminated the same biometric identifier or biometric information of the same person to the same recipient.",
            "date": "2024-08-02",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-20c-single-disclosure"
          },
          {
            "id": "case-gregg-retroactive",
            "authorityType": "case-law",
            "tier": "primary-source-backed",
            "title": "Gregg v. Central Transport LLC (7th Cir. Apr. 1, 2026)",
            "citation": "Gregg v. Central Transport LLC, Nos. 25-2185, 25-2761, 25-2762 (7th Cir. Apr. 1, 2026).",
            "url": "https://www.courtlistener.com/opinion/10831566/john-gregg-v-central-transport-llc/",
            "deepLink": "https://www.courtlistener.com/opinion/10831566/john-gregg-v-central-transport-llc/#:~:text=We%20hold%20that%20this%20amendment%20applies,BIPA%E2%80%99s%20substantive%20standards%20of%20liability.",
            "proposition": "The Seventh Circuit held that the 2024 single-recovery amendment to BIPA section 20 applies retroactively to cases pending when it was enacted, because it affects only the statutory damages available — not BIPA's substantive standards of liability.",
            "verbatimQuote": "We hold that this amendment applies retroactively because it impacts only the statutory damages available to plaintiﬀs—it does not change BIPA’s substantive standards of liability.",
            "date": "2026-04-01",
            "pullQuoteLocator": "We hold that this amendment applies|BIPA’s substantive standards of liability.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-case-gregg-retroactive"
          },
          {
            "id": "case-gregg-remedial",
            "authorityType": "case-law",
            "tier": "primary-source-backed",
            "title": "Gregg v. Central Transport LLC (7th Cir. Apr. 1, 2026)",
            "citation": "Gregg v. Central Transport LLC, Nos. 25-2185, 25-2761, 25-2762 (7th Cir. Apr. 1, 2026).",
            "url": "https://www.courtlistener.com/opinion/10831566/john-gregg-v-central-transport-llc/",
            "deepLink": "https://www.courtlistener.com/opinion/10831566/john-gregg-v-central-transport-llc/#:~:text=The%20amendment%20to%20BIPA%20Section,time%20the%20statute%20was%20enacted.",
            "proposition": "The panel classified the amendment as a remedial change — procedural under Illinois retroactivity law — so courts should apply it to cases that were pending when the statute was enacted.",
            "verbatimQuote": "The amendment to BIPA Section 20 is a remedial change. That makes it “procedural” under Illinois law, so courts should apply the amendment to cases pending at the time the statute was enacted.",
            "date": "2026-04-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-case-gregg-remedial"
          }
        ]
      },
      {
        "slug": "genetic-information-employment",
        "label": "Can you ask Illinois employees or job applicants for genetic tests or genetic information?",
        "heading": "Can you ask Illinois employees or job applicants for genetic tests or genetic information?",
        "answerText": "No. The Genetic Information Privacy Act (GIPA) prohibits an employer, employment agency, labor organization, or licensing agency from directly or indirectly soliciting, requesting, requiring, or purchasing genetic testing or genetic information of a person or a person's family member — or administering a genetic test — as a condition of employment, a preemployment application, membership, or licensure. GIPA provides private-suit exposure: any person aggrieved by a violation may sue and recover liquidated damages of $2,500 per negligent violation or $15,000 per intentional or reckless violation (or actual damages if greater), plus attorneys' fees, subject to the Illinois Insurance Code remedy for insurer violations of section 30.",
        "sources": [
          {
            "id": "stat-gipa-25-employment",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "410 ILCS 513/25",
            "citation": "410 ILCS 513/25(c).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/041005130K25.htm",
            "proposition": "GIPA prohibits employment-related solicitation, requests, requirements, purchases, administration, use, classification, and retaliation involving genetic testing or genetic information of a person or family member.",
            "verbatimQuote": "An employer, employment agency, labor organization, and licensing agency shall not directly or indirectly do any of the following: (1) solicit, request, require or purchase genetic testing or genetic information of a person or a family member of the person, or administer a genetic test to a person or a family member of the person as a condition of employment, preemployment application, labor organization membership, or licensure; (2) affect the terms, conditions, or privileges of employment, preemployment application, labor organization membership, or licensure, or terminate the employment, labor organization membership, or licensure of any person because of genetic testing or genetic information with respect to the employee or family member, or information about a request for or the receipt of genetic testing by such employee or family member of such employee; (3) limit, segregate, or classify employees in any way that would deprive or tend to deprive any employee of employment opportunities or otherwise adversely affect the status of the employee as an employee because of genetic testing or genetic information with respect to the employee or a family member, or information about a request for or the receipt of genetic testing or genetic information by such employee or family member of such employee; and (4) retaliate through discharge or in any other manner against any person alleging a violation of this Act or participating in any manner in a proceeding under this Act.",
            "date": "2018-01-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-gipa-25-employment"
          },
          {
            "id": "stat-gipa-40-damages",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "410 ILCS 513/40",
            "citation": "410 ILCS 513/40(a)-(b).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/041005130K40.htm",
            "proposition": "Any person aggrieved by a GIPA violation has a private right of action and may recover liquidated damages, attorneys' fees, costs, and other relief; Article XL of the Illinois Insurance Code is the exclusive remedy for insurer violations of section 30.",
            "verbatimQuote": "Any person aggrieved by a violation of this Act shall have a right of action in a State circuit court or as a supplemental claim in a federal district court against an offending party. A prevailing party may recover for each violation: (1) Against any party who negligently violates a provision of this Act, liquidated damages of $2,500 or actual damages, whichever is greater. (2) Against any party who intentionally or recklessly violates a provision of this Act, liquidated damages of $15,000 or actual damages, whichever is greater. (3) Reasonable attorney's fees and costs, including expert witness fees and other litigation expenses. (4) Such other relief, including an injunction, as the State or federal court may deem appropriate. (b) Article XL of the Illinois Insurance Code shall provide the exclusive remedy for violations of Section 30 by insurers.",
            "date": "2015-01-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-gipa-40-damages"
          },
          {
            "id": "stat-gipa-10-definitions",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "410 ILCS 513/10",
            "citation": "410 ILCS 513/10.",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/041005130K10.htm",
            "proposition": "GIPA defines genetic testing by reference to HIPAA and expressly extends the definition to direct-to-consumer commercial genetic testing.",
            "verbatimQuote": "\"Genetic testing\" and \"genetic test\" have the meaning ascribed to \"genetic test\" under HIPAA, as specified in 45 CFR 160.103. \"Genetic testing\" includes direct-to-consumer commercial genetic testing.",
            "date": "2025-08-15",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-gipa-10-definitions"
          },
          {
            "id": "stat-gipa-25-pay-benefit",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "410 ILCS 513/25(d)",
            "citation": "410 ILCS 513/25(d).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/041005130K25.htm",
            "proposition": "GIPA prohibits employment-related agreements offering employment, membership, licensure, pay, or benefits in return for taking a genetic test.",
            "verbatimQuote": "An agreement between a person and an employer, prospective employer, employment agency, labor organization, or licensing agency, or its employees, agents, or members offering the person employment, labor organization membership, licensure, or any pay or benefit in return for taking a genetic test is prohibited.",
            "date": "2018-01-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-gipa-25-pay-benefit"
          },
          {
            "id": "stat-gipa-25-wellness",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "410 ILCS 513/25(e)",
            "citation": "410 ILCS 513/25(e).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/041005130K25.htm",
            "proposition": "GIPA allows use of genetic information or testing in a workplace wellness program only if statutory authorization, access, confidentiality, and no-penalty conditions are met.",
            "verbatimQuote": "An employer shall not use genetic information or genetic testing in furtherance of a workplace wellness program benefiting employees unless (1) health or genetic services are offered by the employer, (2) the employee provides written authorization in accordance with Section 30 of this Act, (3) only the employee or family member if the family member is receiving genetic services and the licensed health care professional or licensed genetic counselor involved in providing such services receive individually identifiable information concerning the results of such services, and (4) any individually identifiable information is only available for purposes of such services and shall not be disclosed to the employer except in aggregate terms that do not disclose the identity of specific employees. An employer shall not penalize an employee who does not disclose his or her genetic information or does not choose to participate in a program requiring disclosure of the employee's genetic information.",
            "date": "2018-01-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-gipa-25-wellness"
          },
          {
            "id": "stat-gipa-25-workers-comp",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "410 ILCS 513/25(f)",
            "citation": "410 ILCS 513/25(f).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/041005130K25.htm",
            "proposition": "GIPA does not prohibit genetic testing requested and authorized by an employee for the purpose of initiating a workers' compensation claim.",
            "verbatimQuote": "Nothing in this Act shall be construed to prohibit genetic testing of an employee who requests a genetic test and who provides written authorization, in accordance with Section 30 of this Act, from taking a genetic test for the purpose of initiating a workers' compensation claim under the Workers' Compensation Act.",
            "date": "2018-01-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-gipa-25-workers-comp"
          },
          {
            "id": "stat-gipa-25-toxic-monitoring",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "410 ILCS 513/25(i)",
            "citation": "410 ILCS 513/25(i).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/041005130K25.htm",
            "proposition": "GIPA does not prohibit workplace toxic-substance genetic monitoring if notice, authorization or legal requirement, individual results, regulatory compliance, and aggregate-only employer-result conditions are met.",
            "verbatimQuote": "Nothing in this Act shall be construed to prohibit an employer from requesting or requiring genetic information to be used for genetic monitoring of the biological effects of toxic substances in the workplace, but only if (1) the employer provides written notice of the genetic monitoring to the employee; (2) the employee provides written authorization under Section 30 of this Act or the genetic monitoring is required by federal or State law; (3) the employee is informed of individual monitoring results; (4) the monitoring is in compliance with any federal genetic monitoring regulations or State genetic monitoring regulations under the authority of the federal Occupational Safety and Health Act of 1970; and (5) the employer, excluding any health care provider, health care professional, or health facility that is involved in the genetic monitoring program, receives the results of the monitoring only in aggregate terms that do not disclose the identity of specific employees.",
            "date": "2018-01-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-gipa-25-toxic-monitoring"
          }
        ]
      },
      {
        "slug": "consumer-rights-opt-outs",
        "label": "Do Illinois residents have rights to access, delete, or opt out of the sale of their data?",
        "heading": "Do Illinois residents have rights to access, delete, or opt out of the sale of their data?",
        "answerText": "Not as general rights — Illinois has no omnibus statute granting access, correction, deletion, portability, or sale opt-outs across all personal data, and no Illinois law requires businesses to honor universal opt-out preference signals such as Global Privacy Control. What Illinois residents have instead are targeted, data-type-specific controls with unusual force: biometric data cannot be collected at all without prior written notice and a written release, and it must be destroyed when the collection purpose is satisfied or within 3 years of the person's last interaction with the business; genetic test results cannot be disclosed in identifiable form except to the tested person and those the person authorizes.",
        "sources": [
          {
            "id": "q7-stat-15b-consent",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "740 ILCS 14/15(b)",
            "citation": "740 ILCS 14/15(b).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/074000140K15.htm",
            "proposition": "Biometric data may not be collected or otherwise obtained without prior written notice and a written release — a consent-before-collection right rather than an after-the-fact request right.",
            "verbatimQuote": "No private entity may collect, capture, purchase, receive through trade, or otherwise obtain a person's or a customer's biometric identifier or biometric information, unless it first: (1) informs the subject or the subject's legally authorized representative in writing that a biometric identifier or biometric information is being collected or stored; (2) informs the subject or the subject's legally authorized representative in writing of the specific purpose and length of term for which a biometric identifier or biometric information is being collected, stored, and used; and (3) receives a written release executed by the subject of the biometric identifier or biometric information or the subject's legally authorized representative.",
            "date": "2008-10-03",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-q7-stat-15b-consent"
          },
          {
            "id": "q7-stat-15a-destruction",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "740 ILCS 14/15(a)",
            "citation": "740 ILCS 14/15(a).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/074000140K15.htm",
            "proposition": "Illinois law imposes an automatic biometric-data destruction deadline — when the collection purpose is satisfied or within 3 years of the individual's last interaction, whichever occurs first — rather than a consumer-initiated deletion request.",
            "verbatimQuote": "establishing a retention schedule and guidelines for permanently destroying biometric identifiers and biometric information when the initial purpose for collecting or obtaining such identifiers or information has been satisfied or within 3 years of the individual's last interaction with the private entity, whichever occurs first",
            "date": "2008-10-03",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-q7-stat-15a-destruction"
          },
          {
            "id": "q7-stat-gipa-30-disclosure",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "410 ILCS 513/30",
            "citation": "410 ILCS 513/30(a)(1)-(2).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/041005130K30.htm",
            "proposition": "No person may disclose, or be compelled to disclose, the identity of a person tested or genetic test results in identifiable form, except to the tested person and recipients the person specifically authorizes in writing.",
            "verbatimQuote": "No person may disclose or be compelled to disclose the identity of any person upon whom a genetic test is performed or the results of a genetic test in a manner that permits identification of the subject of the test, except to the following persons: (1) The subject of the test or the subject's legally authorized representative. This paragraph does not create a duty or obligation under which a health care provider must notify the subject's spouse or legal guardian of the test results, and no such duty or obligation shall be implied. No civil liability or criminal sanction under this Act shall be imposed for any disclosure or nondisclosure of a test result to a spouse by a physician acting in good faith under this paragraph. For the purpose of any proceedings, civil or criminal, the good faith of any physician acting under this paragraph shall be presumed. (2) Any person designated in a specific written legally effective authorization for release of the test results executed by the subject of the test or the subject's legally authorized representative.",
            "date": "2016-01-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-q7-stat-gipa-30-disclosure"
          }
        ]
      },
      {
        "slug": "breach-notification",
        "label": "When must you notify people of a data breach in Illinois?",
        "heading": "When must you notify people of a data breach in Illinois?",
        "answerText": "In the most expedient time possible and without unreasonable delay. Under the Personal Information Protection Act (PIPA), any data collector that owns or licenses personal information concerning an Illinois resident must notify the resident, at no charge, following discovery or notification of a breach — with delay tolerated only for measures necessary to determine the breach's scope and restore the system's integrity, security, and confidentiality. A breach means unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information. If a single breach requires notice to more than 500 Illinois residents, the data collector must also notify the Attorney General, and a violation of the Act is an unlawful practice under the Consumer Fraud and Deceptive Business Practices Act.",
        "sources": [
          {
            "id": "stat-pipa-10-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "815 ILCS 530/10",
            "citation": "815 ILCS 530/10(a).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/081505300K10.htm",
            "proposition": "A data collector that owns or licenses personal information of an Illinois resident must notify the resident of a breach in the most expedient time possible and without unreasonable delay, allowing only for scope determination and system restoration.",
            "verbatimQuote": "Any data collector that owns or licenses personal information concerning an Illinois resident shall notify the resident at no charge that there has been a breach of the security of the system data following discovery or notification of the breach. The disclosure notification shall be made in the most expedient time possible and without unreasonable delay, consistent with any measures necessary to determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system.",
            "date": "2020-01-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-pipa-10-notice"
          },
          {
            "id": "stat-pipa-5-breach",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "815 ILCS 530/5",
            "citation": "815 ILCS 530/5.",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/081505300K5.htm",
            "proposition": "A reportable breach is the unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by the data collector.",
            "verbatimQuote": "\"Breach of the security of the system data\" or \"breach\" means unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by the data collector.",
            "date": "2017-01-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-pipa-5-breach"
          },
          {
            "id": "stat-pipa-10e-ag",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "815 ILCS 530/10(e)",
            "citation": "815 ILCS 530/10(e)(2).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/081505300K10.htm",
            "proposition": "A breach requiring notice to more than 500 Illinois residents also requires notice to the Attorney General, describing the breach, the number of residents affected, and the steps taken.",
            "verbatimQuote": "Any data collector required to issue notice pursuant to this Section to more than 500 Illinois residents as a result of a single breach of the security system shall provide notice to the Attorney General of the breach, including: (A) A description of the nature of the breach of security or unauthorized acquisition or use. (B) The number of Illinois residents affected by such incident at the time of notification. (C) Any steps the data collector has taken or plans to take relating to the incident. Such notification must be made in the most expedient time possible and without unreasonable delay but in no event later than when the data collector provides notice to consumers pursuant to this Section. If the date of the breach is unknown at the time the notice is sent to the Attorney General, the data collector shall send the Attorney General the date of the breach as soon as possible. Upon receiving notification from a data collector of a breach of personal information, the Attorney General may publish the name of the data collector that suffered the breach, the types of personal information compromised in the breach, and the date range of the breach.",
            "date": "2020-01-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-pipa-10e-ag"
          },
          {
            "id": "stat-pipa-20-icfa",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "815 ILCS 530/20",
            "citation": "815 ILCS 530/20.",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/081505300K20.htm",
            "proposition": "A PIPA violation constitutes an unlawful practice under the Consumer Fraud and Deceptive Business Practices Act, which is the statute's enforcement mechanism.",
            "verbatimQuote": "A violation of this Act constitutes an unlawful practice under the Consumer Fraud and Deceptive Business Practices Act.",
            "date": "2006-01-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-pipa-20-icfa"
          },
          {
            "id": "stat-pipa-5-personal-info",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "815 ILCS 530/5",
            "citation": "815 ILCS 530/5.",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/081505300K5.htm",
            "proposition": "PIPA's definition of personal information includes name-plus-sensitive-data categories, biometric authentication data, and online-account credentials, with encrypted or redacted data outside the definition unless the keys were acquired without authorization through the breach.",
            "verbatimQuote": "\"Personal information\" means either of the following: (1) An individual's first name or first initial and last name in combination with any one or more of the following data elements, when either the name or the data elements are not encrypted or redacted or are encrypted or redacted but the keys to unencrypt or unredact or otherwise read the name or data elements have been acquired without authorization through the breach of security: (A) Social Security number. (B) Driver's license number or State identification card number. (C) Account number or credit or debit card number, or an account number or credit card number in combination with any required security code, access code, or password that would permit access to an individual's financial account. (D) Medical information. (E) Health insurance information. (F) Unique biometric data generated from measurements or technical analysis of human body characteristics used by the owner or licensee to authenticate an individual, such as a fingerprint, retina or iris image, or other unique physical representation or digital representation of biometric data. (2) User name or email address, in combination with a password or security question and answer that would permit access to an online account, when either the user name or email address or password or security question and answer are not encrypted or redacted or are encrypted or redacted but the keys to unencrypt or unredact or otherwise read the data elements have been obtained through the breach of security. \"Personal information\" does not include publicly available information that is lawfully made available to the general public from federal, State, or local government records.",
            "date": "2017-01-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-pipa-5-personal-info"
          },
          {
            "id": "stat-pipa-10-credential-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "815 ILCS 530/10(a)(2)",
            "citation": "815 ILCS 530/10(a)(2).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/081505300K10.htm",
            "proposition": "For a breach of username or email credentials, PIPA allows electronic or other notice directing residents to change credentials and take appropriate account-protection steps.",
            "verbatimQuote": "With respect to personal information defined in Section 5 in paragraph (2) of the definition of \"personal information\", notice may be provided in electronic or other form directing the Illinois resident whose personal information has been breached to promptly change his or her user name or password and security question or answer, as applicable, or to take other steps appropriate to protect all online accounts for which the resident uses the same user name or email address and password or security question and answer.",
            "date": "2020-01-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-pipa-10-credential-notice"
          },
          {
            "id": "stat-pipa-5-biometric",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "815 ILCS 530/5",
            "citation": "815 ILCS 530/5.",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/081505300K5.htm",
            "proposition": "PIPA's definition of personal information includes unique biometric data — such as a fingerprint or retina or iris image — used by the owner or licensee to authenticate an individual.",
            "verbatimQuote": "Unique biometric data generated from measurements or technical analysis of human body characteristics used by the owner or licensee to authenticate an individual, such as a fingerprint, retina or iris image, or other unique physical representation or digital representation of biometric data.",
            "date": "2017-01-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-pipa-5-biometric"
          },
          {
            "id": "stat-pipa-15-waiver",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "815 ILCS 530/15",
            "citation": "815 ILCS 530/15.",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/081505300K15.htm",
            "proposition": "PIPA's duties cannot be waived by contract — any waiver of the Act is contrary to public policy and void.",
            "verbatimQuote": "Any waiver of the provisions of this Act is contrary to public policy and is void and unenforceable.",
            "date": "2006-01-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-pipa-15-waiver"
          },
          {
            "id": "stat-icfa-10a-actual",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "815 ILCS 505/10a",
            "citation": "815 ILCS 505/10a(a).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/081505050K10a.htm",
            "proposition": "A private Consumer Fraud Act action — the consumer's route for a PIPA violation — requires actual damage as a result of the violation, unlike the liquidated-damages regimes of BIPA and GIPA.",
            "verbatimQuote": "Any person who suffers actual damage as a result of a violation of this Act committed by any other person may bring an action against such person.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-icfa-10a-actual"
          }
        ]
      },
      {
        "slug": "vendor-contracts",
        "label": "What must your contracts with vendors say in Illinois?",
        "heading": "What must your contracts with vendors say in Illinois?",
        "answerText": "Illinois has no omnibus data-processing-agreement statute — no state law prescribes controller-processor terms, audit rights, or subprocessor flow-downs for general personal data. But two Illinois statutes put hard edges on vendor arrangements. Under BIPA, handing biometric data to a vendor is a disclosure that requires the subject's consent or another narrow statutory basis, so the consent paperwork and the vendor contract have to be designed together. Under PIPA, a vendor that maintains or stores personal information it does not own must notify the owner of any breach immediately following discovery and cooperate in the response.",
        "sources": [
          {
            "id": "q9-stat-15d-disclosure",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "740 ILCS 14/15(d)",
            "citation": "740 ILCS 14/15(d).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/074000140K15.htm",
            "proposition": "Disclosing or disseminating a person's biometric data — including to a service vendor — requires the subject's consent, completion of an authorized financial transaction, a legal requirement, or a warrant or subpoena.",
            "verbatimQuote": "No private entity in possession of a biometric identifier or biometric information may disclose, redisclose, or otherwise disseminate a person's or a customer's biometric identifier or biometric information unless: (1) the subject of the biometric identifier or biometric information or the subject's legally authorized representative consents to the disclosure or redisclosure; (2) the disclosure or redisclosure completes a financial transaction requested or authorized by the subject of the biometric identifier or the biometric information or the subject's legally authorized representative; (3) the disclosure or redisclosure is required by State or federal law or municipal ordinance; or (4) the disclosure is required pursuant to a valid warrant or subpoena issued by a court of competent jurisdiction.",
            "date": "2008-10-03",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-q9-stat-15d-disclosure"
          },
          {
            "id": "q9-stat-20c-single-disclosure",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "740 ILCS 14/20(c)",
            "citation": "740 ILCS 14/20(c), added by P.A. 103-0769 (eff. Aug. 2, 2024).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/074000140K20.htm",
            "proposition": "The 2024 BIPA amendment caps repeated disclosures of the same person's biometric data to the same recipient as one section 15(d) violation with at most one recovery.",
            "verbatimQuote": "For purposes of subsection (d) of Section 15, a private entity that, in more than one instance, discloses, rediscloses, or otherwise disseminates the same biometric identifier or biometric information from the same person to the same recipient using the same method of collection in violation of subsection (d) of Section 15 has committed a single violation of subsection (d) of Section 15 for which the aggrieved person is entitled to, at most, one recovery under this Section regardless of the number of times the private entity disclosed, redisclosed, or otherwise disseminated the same biometric identifier or biometric information of the same person to the same recipient.",
            "date": "2024-08-02",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-q9-stat-20c-single-disclosure"
          },
          {
            "id": "stat-pipa-10b-vendor",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "815 ILCS 530/10(b)",
            "citation": "815 ILCS 530/10(b).",
            "url": "https://www.ilga.gov/documents/legislation/ilcs/documents/081505300K10.htm",
            "proposition": "A vendor that maintains or stores personal information it does not own or license must notify the owner or licensee of a breach immediately following discovery and must cooperate in the breach response.",
            "verbatimQuote": "Any data collector that maintains or stores, but does not own or license, computerized data that includes personal information that the data collector does not own or license shall notify the owner or licensee of the information of any breach of the security of the data immediately following discovery, if the personal information was, or is reasonably believed to have been, acquired by an unauthorized person. In addition to providing such notification to the owner or licensee, the data collector shall cooperate with the owner or licensee in matters relating to the breach. That cooperation shall include, but need not be limited to, (i) informing the owner or licensee of the breach, including giving notice of the date or approximate date of the breach and the nature of the breach, and (ii) informing the owner or licensee of any steps the data collector has taken or plans to take relating to the breach. The data collector's cooperation shall not, however, be deemed to require either the disclosure of confidential business information or trade secrets or the notification of an Illinois resident who may have been affected by the breach.",
            "date": "2020-01-01",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-stat-pipa-10b-vendor"
          },
          {
            "id": "fed-glba-safeguards",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "GLBA Safeguards Rule",
            "citation": "16 C.F.R. § 314.4(f)(2).",
            "url": "https://www.law.cornell.edu/cfr/text/16/314.4",
            "deepLink": "https://www.law.cornell.edu/cfr/text/16/314.4#:~:text=Requiring%20your%20service%20providers%20by,implement%20and%20maintain%20such%20safeguards",
            "proposition": "The GLBA Safeguards Rule requires a financial institution to oversee its service providers, including by requiring them by contract to implement and maintain appropriate safeguards for customer information.",
            "verbatimQuote": "Requiring your service providers by contract to implement and maintain such safeguards",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-fed-glba-safeguards"
          },
          {
            "id": "fed-hipaa-baa",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "HIPAA Business Associate Contracts",
            "citation": "45 C.F.R. § 164.504(e)(2).",
            "url": "https://www.law.cornell.edu/cfr/text/45/164.504",
            "deepLink": "https://www.law.cornell.edu/cfr/text/45/164.504#:~:text=A%20contract%20between%20the%20covered,provided%20for%20by%20its%20contract%3B",
            "proposition": "HIPAA requires a written business-associate contract that establishes the permitted uses and disclosures of protected health information and binds the business associate to safeguard it.",
            "verbatimQuote": "A contract between the covered entity and a business associate must: (i) Establish the permitted and required uses and disclosures of protected health information by the business associate. The contract may not authorize the business associate to use or further disclose the information in a manner that would violate the requirements of this subpart, if done by the covered entity, except that: (A) The contract may permit the business associate to use and disclose protected health information for the proper management and administration of the business associate, as provided in paragraph (e)(4) of this section; and (B) The contract may permit the business associate to provide data aggregation services relating to the health care operations of the covered entity. (ii) Provide that the business associate will: (A) Not use or further disclose the information other than as permitted or required by the contract or as required by law; (B) Use appropriate safeguards and comply, where applicable, with subpart C of this part with respect to electronic protected health information, to prevent use or disclosure of the information other than as provided for by its contract;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/illinois#src-fed-hipaa-baa"
          }
        ]
      }
    ]
  }
}
