Law / United States / Illinois

Personal Information Protection Act, data breach notification

815 ILCS 530/1 et seq. (P.A. 94-36, eff. 2006-01-01)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 1 January 2006.

A breach notification rule binding public and private bodies.

As of 23 August 2026.

What it requires

  • Notify affected Illinois residents of a data breach in the most expedient time possible and without unreasonable delay after discovering unauthorized acquisition of their computerized personal information, which includes unique biometric data used to authenticate an individual.
  • Notify the Illinois Attorney General once a single breach affects more than 500 Illinois residents, or more than 250 residents for a State agency.

If you get it wrong

Criminal exposureNo

Private right of actionYes

Penalty structure

815 ILCS 530/20 makes a PIPA violation an unlawful practice under the Consumer Fraud and Deceptive Business Practices Act; the civil penalty is stated in 815 ILCS 505/7(b), not in PIPA itself. The Attorney General or a State's Attorney may seek a civil penalty of up to $50,000 for the practice found unlawful (recorded here as fixed_cap), or up to $50,000 per violation where the court finds the practice was entered into with intent to defraud (recorded here as per_violation_amount). No PIPA-specific or Consumer Fraud Act provision states a fixed per-person private-plaintiff damages figure; a private plaintiff recovers actual damages only under 815 ILCS 505/10a, so statutory_damages is not recorded here.

Rule
Per violation only
As of
1 September 2026
Currency
USD
Fixed cap
50,000
Per violation unit
Violation
Per violation amount
50,000

Who enforces it

Enforcement body

Illinois Attorney General or a State's Attorney, enforcing a PIPA violation as an unlawful practice under the Consumer Fraud and Deceptive Business Practices Act.

Enforcement record

The Illinois Attorney General's own press-release register is dated and public, but it lists every area of the Office's work in one chronological feed rather than by the statute enforced, so it states no count of actions taken under this Act specifically. The closest data-security matter in the twelve months to September 2026 is a July 13, 2026 multistate settlement of bankruptcy claims against 23andMe over a genetic data breach; the Office's own announcement grounds that claim in unreasonable data-security practices generally, not in a stated violation of this Act, so it is not counted here. The yearly count is left unrecorded rather than estimated from an enforcement archive that does not break out this Act's own actions.

As of
17 September 2026
Source link
https://illinoisattorneygeneral.gov/News-Room/index

What it reaches

Obligation class

Breach notice, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Requires a data collector, government agency or private entity, holding computerized personal information of Illinois residents to notify affected residents of a security breach in the most expedient time possible and without unreasonable delay.

Personal information expressly includes unique biometric data used to authenticate an individual, such as a fingerprint, retina or iris image, or other physical or digital biometric representation, alongside a name paired with a Social Security number, account number, or medical information.

A data collector must notify the Illinois Attorney General once a single breach affects more than 500 Illinois residents, and a State agency must do so above 250 residents; a violation is an unlawful practice under the Consumer Fraud and Deceptive Business Practices Act.

When LexLint raises it

  • processes_biometrics
  • processes_voice
  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach

Read the law

Illinois Compiled Statutes, official code site (current codified text)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app