USPrivacyAtlasState Privacy & Data Security Law Matcher

State Guide

Illinois Privacy & Data Security Laws

Every statute below can apply to a business handling Illinois residents' data, depending on your revenue, the number of Illinois consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Data Security & Breach Notification · 1

Varies by state
Illinois data breach notification law
IL Breach Notification

Requires notifying affected residents (and often the state AG/regulator) after a breach of unencrypted personal information such as SSNs, driver's license/state ID numbers, or financial account numbers. Applies regardless of company size whenever you hold covered personal information about a resident of this state.

815 Ill. Comp. Stat. 530/1 et seq. (Personal Information Protection Act)Read statute →

Biometric Privacy · 1

Requires written notice and consent before collecting fingerprints, faceprints, iris/retina scans, or voiceprints. One of the strictest US privacy statutes — includes a private right of action with statutory damages, so violations carry real litigation exposure.

740 Ill. Comp. Stat. 14/1 et seq.

Genetic Privacy · 1

1998 (DTC provisions added 2019)
Illinois Genetic Information Privacy Act
IL GIPA

Regulates direct-to-consumer genetic testing companies and/or genetic data generally — typically requiring express consent before collecting, using, or disclosing genetic data, and consent (or destruction) requirements for biological samples. BIPA-like private right of action: $2,500 (negligent) / $15,000 (intentional/reckless) per violation.

410 Ill. Comp. Stat. 513, as amended 2019Read statute →

Student Data Privacy · 1

Requires data-sharing agreements with schools, breach notification, and restricts use of student data for advertising.

105 Ill. Comp. Stat. 85/1 et seq.Read statute →