Law / United States /
Illinois
Personal Information Protection Act, data breach notification
815 ILCS 530/1 et seq. (P.A. 94-36, eff. 2006-01-01)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 January 2006.
A breach notification rule binding public and private bodies.
As of 23 August 2026.
What it requires
- Notify affected Illinois residents of a data breach in the most expedient time possible and without unreasonable delay after discovering unauthorized acquisition of their computerized personal information, which includes unique biometric data used to authenticate an individual.
- Notify the Illinois Attorney General once a single breach affects more than 500 Illinois residents, or more than 250 residents for a State agency.
If you get it wrong
Criminal exposureNo
Private right of actionYes
Penalty structure
815 ILCS 530/20 makes a PIPA violation an unlawful practice under the Consumer Fraud and Deceptive Business Practices Act; the civil penalty is stated in 815 ILCS 505/7(b), not in PIPA itself. The Attorney General or a State's Attorney may seek a civil penalty of up to $50,000 for the practice found unlawful (recorded here as fixed_cap), or up to $50,000 per violation where the court finds the practice was entered into with intent to defraud (recorded here as per_violation_amount). No PIPA-specific or Consumer Fraud Act provision states a fixed per-person private-plaintiff damages figure; a private plaintiff recovers actual damages only under 815 ILCS 505/10a, so statutory_damages is not recorded here.
- Rule
- Per violation only
- As of
- 1 September 2026
- Currency
- USD
- Fixed cap
- 50,000
- Per violation unit
- Violation
- Per violation amount
- 50,000
Who enforces it
Enforcement body
Illinois Attorney General or a State's Attorney, enforcing a PIPA violation as an unlawful practice under the Consumer Fraud and Deceptive Business Practices Act.
Enforcement record
The Illinois Attorney General's own press-release register is dated and public, but it lists every area of the Office's work in one chronological feed rather than by the statute enforced, so it states no count of actions taken under this Act specifically. The closest data-security matter in the twelve months to September 2026 is a July 13, 2026 multistate settlement of bankruptcy claims against 23andMe over a genetic data breach; the Office's own announcement grounds that claim in unreasonable data-security practices generally, not in a stated violation of this Act, so it is not counted here. The yearly count is left unrecorded rather than estimated from an enforcement archive that does not break out this Act's own actions.
- As of
- 17 September 2026
- Source link
- https://illinoisattorneygeneral.gov/News-Room/index
What it reaches
Obligation class
Breach notice, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Requires a data collector, government agency or private entity, holding computerized personal information of Illinois residents to notify affected residents of a security breach in the most expedient time possible and without unreasonable delay.
Personal information expressly includes unique biometric data used to authenticate an individual, such as a fingerprint, retina or iris image, or other physical or digital biometric representation, alongside a name paired with a Social Security number, account number, or medical information.
A data collector must notify the Illinois Attorney General once a single breach affects more than 500 Illinois residents, and a State agency must do so above 250 residents; a violation is an unlawful practice under the Consumer Fraud and Deceptive Business Practices Act.
When LexLint raises it
processes_biometricsprocesses_voicecrawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
Illinois Compiled Statutes, official code site (current codified text)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.