Illinois Data Breach Law: PIPA Notice Rules and BIPA Risks featured image

Illinois Data Breach Law: PIPA Notice Rules and BIPA Risks

by Eric Misterovich

Partner

Data Breach

Illinois’s data breach notification law, the Personal Information Protection Act (PIPA), 815 ILCS 530, requires any business or other data collector that owns or licenses personal information of an Illinois resident to notify affected residents of a breach “in the most expedient time possible and without unreasonable delay.” If a single breach requires notice to more than 500 Illinois residents, the data collector must also notify the Illinois Attorney General no later than when it notifies consumers. Businesses that handle fingerprints, face scans, or other biometrics face separate and far more expensive exposure under the Biometric Information Privacy Act (BIPA).

This guide walks through who PIPA covers, what counts as personal information, the notice rules, the 2024 BIPA amendment, and how Illinois law fits alongside federal breach requirements.

Who Must Comply With the Illinois Data Breach Law?

PIPA applies to “data collectors,” a term defined broadly to include government agencies, public and private universities, privately and publicly held corporations, financial institutions, retail operators, and any other entity that handles, collects, disseminates, or otherwise deals with nonpublic personal information. 815 ILCS 530/5. Location does not matter; what matters is whether you hold personal information about Illinois residents.

PIPA distinguishes between two roles:

  • Owners and licensees of personal information must notify affected Illinois residents. 815 ILCS 530/10(a).
  • Entities that maintain or store data they do not own, such as cloud hosts, payment processors, and IT vendors, must notify the owner or licensee immediately following discovery and cooperate with it, including by sharing the date and nature of the breach. 815 ILCS 530/10(b).

What Is a Breach Under PIPA?

A “breach of the security of the system data” means the unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by the data collector. Good-faith acquisition by an employee or agent for a legitimate business purpose is not a breach, as long as the information is not misused or further disclosed. 815 ILCS 530/5.

What Counts as Personal Information in Illinois?

PIPA defines personal information in two ways. The first is an individual’s first name or first initial and last name combined with any of the following data elements, when either the name or the data elements are not encrypted or redacted, or when the encryption keys were also acquired:

  • Social Security number
  • Driver’s license number or state identification card number
  • Account number or credit or debit card number, or an account or card number combined with any required security code, access code, or password that would permit access to a financial account
  • Medical information, including information provided to a website or mobile application
  • Health insurance information, such as policy or subscriber numbers and claims history
  • Unique biometric data used to authenticate an individual, such as a fingerprint, retina or iris image

The second is a user name or email address combined with a password or security question and answer that would permit access to an online account. Credentials alone can trigger notice, even without the person’s name. Information lawfully made available to the public from government records is excluded.

Illinois Breach Notice Requirements

Timing

Notice to residents must be given at no charge, in the most expedient time possible and without unreasonable delay, consistent with measures necessary to determine the scope of the breach and restore the integrity of the system. Notice may be delayed only if a law enforcement agency determines that notification would interfere with a criminal investigation and provides a written request for the delay. 815 ILCS 530/10(a), (b-5).

Content of the Notice

For breaches of name-plus-data-element information, the notice must include the toll-free numbers and addresses of the consumer reporting agencies; the toll-free number, address, and website of the Federal Trade Commission; and a statement that the individual can obtain information from these sources about fraud alerts and security freezes. For breaches of login credentials, notice may be given electronically and should direct the resident to change their user name, password, or security question, or take other steps to protect accounts that use the same credentials. The notice must not state the number of Illinois residents affected.

Method of Notice

  • Written notice
  • Electronic notice consistent with the federal E-SIGN Act, 15 U.S.C. § 7001
  • Substitute notice, if the cost of notice would exceed $250,000, the affected class exceeds 500,000 people, or the data collector lacks sufficient contact information. Substitute notice requires all of the following: email notice where addresses are available, conspicuous posting on the data collector’s website, and notification to major statewide media (or prominent local media if the breach is geographically concentrated).

A data collector that follows its own notification procedures under an information security policy is deemed compliant if those procedures are consistent with PIPA’s timing requirements. 815 ILCS 530/10(d).

When Must You Notify the Illinois Attorney General?

Since January 1, 2020 (Public Act 101-343), a data collector required to notify more than 500 Illinois residents as a result of a single breach must also notify the Attorney General. The notice must describe the nature of the breach, state the number of Illinois residents affected at the time of notification, and describe any steps the data collector has taken or plans to take. It must be made in the most expedient time possible and without unreasonable delay, and in no event later than notice to consumers. The Attorney General may publish the name of the data collector, the types of information compromised, and the date range of the breach. 815 ILCS 530/10(e).

HIPAA covered entities and business associates that comply with HIPAA and HITECH privacy and security standards are deemed compliant with PIPA, but if they must report a breach to the U.S. Department of Health and Human Services, they must also notify the Illinois Attorney General within five business days of notifying HHS. 815 ILCS 530/50.

Special Rules for Illinois State Agencies

State agencies face stricter obligations under 815 ILCS 530/12 and 530/25, including notifying the Attorney General of any breach affecting more than 250 Illinois residents within 45 days of discovery or when consumer notice is given, whichever is sooner; notifying the nationwide consumer reporting agencies when more than 1,000 people must be notified; reporting to the General Assembly within five business days of discovery; and, for agencies directly responsible to the Governor, notifying the Department of Innovation and Technology’s Chief Information Security Officer and the Attorney General within 72 hours of discovery.

Data Security, Disposal, and Enforcement

PIPA is not only a notice statute. Data collectors that own, license, maintain, or store Illinois residents’ personal information must implement and maintain reasonable security measures, and contracts disclosing that information must require the recipient to do the same. Entities in compliance with the Gramm-Leach-Bliley Act safeguards standards are deemed compliant. 815 ILCS 530/45. Improper disposal of materials containing personal information can result in civil penalties of up to $100 per affected individual, capped at $50,000 per instance. 815 ILCS 530/40.

A violation of PIPA constitutes an unlawful practice under the Illinois Consumer Fraud and Deceptive Business Practices Act, 815 ILCS 505, which is enforced by the Attorney General. 815 ILCS 530/20. Any waiver of PIPA’s protections is void. For a broader look at who bears responsibility after an incident, see our article on data breach liability.

Biometric Data: BIPA’s Separate and Costlier Risk

The Biometric Information Privacy Act, 740 ILCS 14, imposes obligations that apply whether or not a breach ever occurs. A private entity must publish a written retention and destruction policy; inform individuals in writing and obtain a written release before collecting biometric identifiers; refrain from selling or profiting from biometric data; limit disclosure; and protect biometric data using the reasonable standard of care within its industry. 740 ILCS 14/15.

BIPA gives individuals a private right of action for liquidated damages of $1,000 per negligent violation or $5,000 per intentional or reckless violation (or actual damages, if greater), plus attorneys’ fees. 740 ILCS 14/20. Key developments include:

  • Rosenbach v. Six Flags Entertainment Corp., 2019 IL 123186: a plaintiff need not allege actual injury beyond the violation of their rights to sue.
  • Tims v. Black Horse Carriers, Inc., 2023 IL 127801: a five-year limitations period applies to all BIPA claims.
  • Cothron v. White Castle System, Inc., 2023 IL 128004: a separate claim accrues each time a private entity scans or transmits biometric data in violation of sections 15(b) or 15(d).
  • Public Act 103-769 (SB 2979), effective August 2, 2024: repeated collection of the same biometric identifier from the same person using the same method, or repeated disclosure to the same recipient, is a single violation with at most one recovery. The amendment also confirms that an electronic signature satisfies the written release requirement.
  • Clay v. Union Pacific Railroad Co. (7th Cir. Apr. 1, 2026): the Seventh Circuit held the 2024 amendment applies retroactively to cases pending when it took effect. That ruling binds federal courts in the Seventh Circuit but not Illinois state courts.

Even with the per-person limit, exposure remains substantial for employers and consumer-facing businesses with large numbers of users. Facebook’s $650 million BIPA class settlement, approved in 2021, illustrates the scale. And because biometric authentication data is also a PIPA data element, a breach involving biometrics can trigger both statutes.

How Illinois Law Interacts With Federal and Other State Rules

A single incident can trigger several overlapping obligations:

  • HIPAA: covered entities must notify individuals without unreasonable delay and in no case later than 60 calendar days after discovery. 45 C.F.R. § 164.404(b).
  • FTC Safeguards Rule: non-bank financial institutions must notify the FTC as soon as possible, and no later than 30 days after discovery, of a notification event involving at least 500 consumers. 16 C.F.R. § 314.4(j).
  • Other states: notice obligations follow the residence of affected individuals, so a breach touching customers in multiple states requires compliance with each state’s statute. Compare, for example, Michigan’s data breach notification law.

Federal deadlines are outer limits. Illinois’s “most expedient time possible” standard may require notice sooner, so a response plan should be built around the strictest applicable rule. Our guide to responding to a customer data breach outlines the first steps.

Talk to an Illinois Data Breach Lawyer

The hours after discovering a breach shape everything that follows: whether notice is timely, whether the Attorney General is notified correctly, and whether the business faces regulatory enforcement or class action litigation. Businesses that collect biometric data should also audit BIPA compliance now, before a claim arrives.

If your business has experienced a data breach affecting Illinois residents, or you need to review your notification plan or biometric data practices, the data breach attorneys at Revision Legal can help you respond quickly and limit your exposure. Contact us through the form on this page or call (855) 473-8474.

Extra, Extra!
Related Posts

Put Revision Legal on your side