How Much Do Data Breaches Cost Businesses?
Data breaches cost businesses millions in fines, lawsuits, and lost customers. Learn the true financial impact and how to reduce your risk.
Read more about How Much Do Data Breaches Cost Businesses?
Partner
Illinois’s data breach notification law, the Personal Information Protection Act (PIPA), 815 ILCS 530, requires any business or other data collector that owns or licenses personal information of an Illinois resident to notify affected residents of a breach “in the most expedient time possible and without unreasonable delay.” If a single breach requires notice to more than 500 Illinois residents, the data collector must also notify the Illinois Attorney General no later than when it notifies consumers. Businesses that handle fingerprints, face scans, or other biometrics face separate and far more expensive exposure under the Biometric Information Privacy Act (BIPA).
This guide walks through who PIPA covers, what counts as personal information, the notice rules, the 2024 BIPA amendment, and how Illinois law fits alongside federal breach requirements.
PIPA applies to “data collectors,” a term defined broadly to include government agencies, public and private universities, privately and publicly held corporations, financial institutions, retail operators, and any other entity that handles, collects, disseminates, or otherwise deals with nonpublic personal information. 815 ILCS 530/5. Location does not matter; what matters is whether you hold personal information about Illinois residents.
PIPA distinguishes between two roles:
A “breach of the security of the system data” means the unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by the data collector. Good-faith acquisition by an employee or agent for a legitimate business purpose is not a breach, as long as the information is not misused or further disclosed. 815 ILCS 530/5.
PIPA defines personal information in two ways. The first is an individual’s first name or first initial and last name combined with any of the following data elements, when either the name or the data elements are not encrypted or redacted, or when the encryption keys were also acquired:
The second is a user name or email address combined with a password or security question and answer that would permit access to an online account. Credentials alone can trigger notice, even without the person’s name. Information lawfully made available to the public from government records is excluded.
Notice to residents must be given at no charge, in the most expedient time possible and without unreasonable delay, consistent with measures necessary to determine the scope of the breach and restore the integrity of the system. Notice may be delayed only if a law enforcement agency determines that notification would interfere with a criminal investigation and provides a written request for the delay. 815 ILCS 530/10(a), (b-5).
For breaches of name-plus-data-element information, the notice must include the toll-free numbers and addresses of the consumer reporting agencies; the toll-free number, address, and website of the Federal Trade Commission; and a statement that the individual can obtain information from these sources about fraud alerts and security freezes. For breaches of login credentials, notice may be given electronically and should direct the resident to change their user name, password, or security question, or take other steps to protect accounts that use the same credentials. The notice must not state the number of Illinois residents affected.
A data collector that follows its own notification procedures under an information security policy is deemed compliant if those procedures are consistent with PIPA’s timing requirements. 815 ILCS 530/10(d).
Since January 1, 2020 (Public Act 101-343), a data collector required to notify more than 500 Illinois residents as a result of a single breach must also notify the Attorney General. The notice must describe the nature of the breach, state the number of Illinois residents affected at the time of notification, and describe any steps the data collector has taken or plans to take. It must be made in the most expedient time possible and without unreasonable delay, and in no event later than notice to consumers. The Attorney General may publish the name of the data collector, the types of information compromised, and the date range of the breach. 815 ILCS 530/10(e).
HIPAA covered entities and business associates that comply with HIPAA and HITECH privacy and security standards are deemed compliant with PIPA, but if they must report a breach to the U.S. Department of Health and Human Services, they must also notify the Illinois Attorney General within five business days of notifying HHS. 815 ILCS 530/50.
State agencies face stricter obligations under 815 ILCS 530/12 and 530/25, including notifying the Attorney General of any breach affecting more than 250 Illinois residents within 45 days of discovery or when consumer notice is given, whichever is sooner; notifying the nationwide consumer reporting agencies when more than 1,000 people must be notified; reporting to the General Assembly within five business days of discovery; and, for agencies directly responsible to the Governor, notifying the Department of Innovation and Technology’s Chief Information Security Officer and the Attorney General within 72 hours of discovery.
PIPA is not only a notice statute. Data collectors that own, license, maintain, or store Illinois residents’ personal information must implement and maintain reasonable security measures, and contracts disclosing that information must require the recipient to do the same. Entities in compliance with the Gramm-Leach-Bliley Act safeguards standards are deemed compliant. 815 ILCS 530/45. Improper disposal of materials containing personal information can result in civil penalties of up to $100 per affected individual, capped at $50,000 per instance. 815 ILCS 530/40.
A violation of PIPA constitutes an unlawful practice under the Illinois Consumer Fraud and Deceptive Business Practices Act, 815 ILCS 505, which is enforced by the Attorney General. 815 ILCS 530/20. Any waiver of PIPA’s protections is void. For a broader look at who bears responsibility after an incident, see our article on data breach liability.
The Biometric Information Privacy Act, 740 ILCS 14, imposes obligations that apply whether or not a breach ever occurs. A private entity must publish a written retention and destruction policy; inform individuals in writing and obtain a written release before collecting biometric identifiers; refrain from selling or profiting from biometric data; limit disclosure; and protect biometric data using the reasonable standard of care within its industry. 740 ILCS 14/15.
BIPA gives individuals a private right of action for liquidated damages of $1,000 per negligent violation or $5,000 per intentional or reckless violation (or actual damages, if greater), plus attorneys’ fees. 740 ILCS 14/20. Key developments include:
Even with the per-person limit, exposure remains substantial for employers and consumer-facing businesses with large numbers of users. Facebook’s $650 million BIPA class settlement, approved in 2021, illustrates the scale. And because biometric authentication data is also a PIPA data element, a breach involving biometrics can trigger both statutes.
A single incident can trigger several overlapping obligations:
Federal deadlines are outer limits. Illinois’s “most expedient time possible” standard may require notice sooner, so a response plan should be built around the strictest applicable rule. Our guide to responding to a customer data breach outlines the first steps.
The hours after discovering a breach shape everything that follows: whether notice is timely, whether the Attorney General is notified correctly, and whether the business faces regulatory enforcement or class action litigation. Businesses that collect biometric data should also audit BIPA compliance now, before a claim arrives.
If your business has experienced a data breach affecting Illinois residents, or you need to review your notification plan or biometric data practices, the data breach attorneys at Revision Legal can help you respond quickly and limit your exposure. Contact us through the form on this page or call (855) 473-8474.
Data breaches cost businesses millions in fines, lawsuits, and lost customers. Learn the true financial impact and how to reduce your risk.
Read more about How Much Do Data Breaches Cost Businesses?
Ransomware dominated 2020’s biggest data breaches. A look at the most damaging incidents and the cybersecurity lessons every business should learn.
Read more about Top Data Breaches of 2020: Ransomware on the Rise
Data collected during the COVID pandemic for one purpose cannot simply be repurposed. Here’s what businesses need to know about the legal risks.
Read more about Repurposing Pandemic Data: Legal Risks Businesses Face