{
 "jurisdiction_id": "US-IL",
 "jurisdiction": "United States – Illinois",
 "url": "https://dataprotection.gi/jurisdictions/united-states-illinois/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-06",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 38,
  "sub_modules": 57,
  "source_register": 19
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-illinois/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "No omnibus statute exists (which would justify red for a comprehensive-rights gap), but Illinois runs an unusually dense and binding sectoral regime (BIPA in particular) with real enforcement teeth, so amber better reflects material sector-specific exposure within a non-omnibus structure.",
   "claims": [
    {
     "statement": "Illinois has no comprehensive consumer data-protection/privacy statute; data-protection obligations arise from a patchwork of sectoral statutes (BIPA, PIPA breach-notification, GIPA, SOPPA) plus federal FTC Act Section 5 enforcement.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/illinois",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Illinois Attorney General is the primary state enforcement authority for privacy-adjacent statutes including BIPA, PIPA, and GIPA, and coordinates breach-notification enforcement.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/illinois-attorney-general-kwame-raoul-on-changes-to-states-data-breach-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Biometric Information Privacy Act (740 ILCS 14), in effect since 2008, is the first comprehensive biometric-privacy statute in the United States and imposes written-consent, retention, and disclosure requirements on private entities handling biometric identifiers of Illinois residents.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/bipa-legislation-introduced-in-2021",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "BIPA does not expressly define its territorial scope but has been applied to any private entity, established or not in Illinois, that collects or possesses biometric identifiers or information of Illinois residents.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/bipa-legislation-introduced-in-2021",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Illinois' Personal Information Protection Act (815 ILCS 530) requires data collectors to notify affected Illinois residents and, since a 2019 amendment (SB 1624, effective 1 January 2020), the Illinois Attorney General for breaches affecting more than 500 residents.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/illinois-attorney-general-kwame-raoul-on-changes-to-states-data-breach-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-illinois/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Sector-specific consent regimes are strong (BIPA written-release standard) but there is no general lawful-basis architecture, producing an amber (partial) rating rather than green.",
   "claims": [
    {
     "statement": "Illinois has no general omnibus lawful-basis framework analogous to GDPR Article 6; lawful processing obligations exist only within sector-specific statutes such as BIPA and GIPA.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/illinois",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "BIPA requires private entities to obtain a written release from the subject, informed of the purpose and length of collection/storage, before collecting or capturing biometric identifiers or biometric information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/bipa-legislation-introduced-in-2021",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Genetic Information Privacy Act (410 ILCS 513), as amended by HB 2189 effective 1 January 2020, prohibits direct-to-consumer genetic-testing companies from sharing genetic test information or other personally identifiable information with a health or life insurance company without the consumer's written consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/illinois-bills-genetic-information-and-data-breaches",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "BIPA's 2024 amendment (via Senate Bill 2979, signed by the Governor) added a statutory definition of 'electronic signature' to satisfy the written-release/consent requirement.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/illinois-bill-amending-bipa-passes-third-reading-senate",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "red",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-illinois/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Absence of any general data-subject-rights framework outside narrow sectoral carve-outs justifies red.",
   "claims": [
    {
     "statement": "Illinois has no general statutory right of access, rectification, erasure, restriction, objection, or portability for consumers' personal data outside of narrow sectoral contexts.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/illinois",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "BIPA requires private entities to develop a publicly available written policy establishing a retention schedule and guidelines for permanently destroying biometric identifiers and biometric information when the initial purpose for collection has been satisfied or within 3 years of the individual's last interaction, whichever occurs first.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/bipa-legislation-introduced-in-2021",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Illinois' Student Online Personal Protection Act (105 ILCS 85), as amended, requires operators to notify parents about the type and purpose of student data collected, giving parents visibility into data held about their children.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/ill-passes-bill-to-improve-student-data-protection/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-illinois/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Breach-notification and biometric security/retention duties are binding and enforced, but no general accountability infrastructure (DPO, ROPA, DPIA) exists — mixed picture warrants amber.",
   "claims": [
    {
     "statement": "PIPA (815 ILCS 530) requires data collectors that own or license personal information to implement and maintain reasonable security measures to protect the data from unauthorized access, acquisition, destruction, use, modification, or disclosure.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/illinois-attorney-general-kwame-raoul-on-changes-to-states-data-breach-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Following the 2019 amendment (SB 1624, effective 1 January 2020), data collectors reporting a breach affecting more than 500 Illinois residents must notify the Illinois Attorney General with a description of the breach, the number of residents affected, and remedial steps taken or planned.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://dataguidance.com/news/illinois-governor-approves-bills-amending-student-privacy-act-and-breach-notification",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "BIPA requires private entities to store, transmit, and protect biometric identifiers and biometric information using the reasonable standard of care within the entity's industry and in a manner at least as protective as that used for other confidential and sensitive information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/bipa-legislation-introduced-in-2021",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Illinois has no general DPO-appointment threshold, ROPA-filing duty, or DPIA-triggering mechanism analogous to GDPR Articles 30, 35, or 37-39; these obligations are absent outside of the pending AI Safety Measures Act's pre-deployment reporting, which is not yet in force.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/illinois",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "red",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-illinois/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "No transfer mechanism, adequacy, SCC/BCR, TIA, or localisation regime exists at the state level.",
   "claims": [
    {
     "statement": "Illinois has no state-level data-transfer mechanism, adequacy regime, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate; cross-border transfer is unregulated at the state level absent sector-specific federal overlays (e.g., HIPAA, GLBA).",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/illinois",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-illinois/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Meaningful Illinois-specific sectoral rules exist in insurance, employment, and education, but telecoms/eprivacy and credit-scoring have no distinct state overlay.",
   "claims": [
    {
     "statement": "Federal sectoral statutes — HIPAA (health) and GLBA (financial) — apply in Illinois as in all US states in the absence of a distinct Illinois-specific overlay, per FTC-anchored federal baseline enforcement.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Genetic Information Privacy Act prohibits life and health insurers in Illinois from using genetic test results or family medical history for underwriting purposes, as illustrated by a class action against Northwestern Mutual Life Insurance Company alleging GIPA violations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/life-insurance-company-sued-for-violating-illinois-privacy-law/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "House Bill 3773 amends the Illinois Human Rights Act to prohibit employers from using artificial intelligence that discriminates based on protected characteristics, explicitly banning the use of ZIP codes as a proxy for protected classes in employment decisions, effective 1 January 2026.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "arXiv",
     "source_url": "https://arxiv.org/pdf/2512.02046",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Under HB 3773, employers must notify employees when AI is used for recruitment, hiring, promotion, training selection, discharge, discipline, or tenure decisions; the Illinois Department of Human Rights postponed a June 2026 rulemaking hearing on specific notice-content requirements to coordinate with other state agencies.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/illinois-idhr-postpones-hearing-and-temporarily",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Illinois' Student Online Personal Protection Act imposes education-sector-specific breach-notification timelines requiring operators to notify schools within the most expedient time and without unreasonable delay, no later than 30 days after determining a breach occurred.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://dataguidance.com/news/illinois-governor-approves-bills-amending-student-privacy-act-and-breach-notification",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-illinois/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "No enacted adtech/commercial-privacy regime exists; the one relevant bill (SB 340) remains unenacted at time of research.",
   "claims": [
    {
     "statement": "Illinois has no state cookie-consent law, dark-pattern prohibition, recognized opt-out signal (e.g., Global Privacy Control) requirement, or clean-room/data-collaboration rule at present.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/illinois",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Senate Bill 340, which advanced to third reading in the Illinois General Assembly in 2026, would introduce consumer data rights, limits on sensitive-data use, and safeguards against algorithmic profiling, with a stated effective date of 1 January 2027, but had not been confirmed signed into law as of the most recent tracked update.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/illinois",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-illinois/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Biometric and genetic regimes are green-level mature and binding; AI-risk-assessment and ADM-transparency components remain pending enactment, pulling the module average to amber.",
   "claims": [
    {
     "statement": "BIPA constitutes Illinois' comprehensive statutory regime for biometric identifiers, covering consent, retention, disclosure restrictions, and a private right of action with liquidated damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/bipa-legislation-introduced-in-2021",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "GIPA governs genetic data collection, retention, and disclosure in Illinois, including consent requirements for insurer access to genetic test results.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/illinois-bills-genetic-information-and-data-breaches",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Senate Bill 315 (Artificial Intelligence Safety Measures Act), passed by both chambers of the Illinois General Assembly in May 2026 and awaiting the Governor's signature, would require 'frontier developers' and 'large frontier developers' of high-compute foundation models to conduct annual third-party audits, produce pre-deployment risk reports, and implement governance and cybersecurity risk-mitigation measures, with an anticipated effective date of 1 January 2027 once signed.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/notable-ai-privacy-bills-hit-finish-line-in-illinois-connecticut-and-new-york",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Senate Bill 317, advanced alongside other AI measures in the 2026 Illinois legislative session, would require clear disclosure when consumers interact with AI chat interfaces in commercial contexts.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/illinois",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "House Bill 3773's ban on using ZIP code as a proxy for protected characteristics in AI-driven employment decisions functions as Illinois' primary statutory profiling restriction outside biometric and genetic contexts.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "arXiv",
     "source_url": "https://arxiv.org/pdf/2512.02046",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-illinois/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Education-sector protections (SOPPA) are binding and in force, but general parental-consent and minor-profiling-ban coverage outside education is absent or pending.",
   "claims": [
    {
     "statement": "SOPPA requires parental notification of student-data collection purposes and mandates breach notification to parents within 30 days, or 60 days where a third-party operator is responsible for the breach.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/ill-passes-bill-to-improve-student-data-protection/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Illinois has no state-level parental-consent statute for minors' general data processing; parental-consent obligations applicable in Illinois arise from the federal Children's Online Privacy Protection Act (COPPA), which is scoped to the US-federal JID rather than Illinois specifically.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/illinois",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "SB 416, advanced in the 2026 Illinois legislative session, bans AI-based grading in Illinois schools and requires school-district approval for classroom AI use beginning the 2027-2028 school year.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/illinois",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-illinois/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Private litigation enforcement (BIPA) is unusually intense and high-value (class actions reaching billions in potential exposure), but general regulator-led enforcement capacity/funding data specific to privacy was not identified, and several 2026 legislative developments remain unconfirmed as enacted.",
   "claims": [
    {
     "statement": "BIPA's private right of action allows any aggrieved person to sue for liquidated damages of $1,000 per negligent violation or $5,000 per intentional or reckless violation, plus actual damages, injunctive relief, and attorneys' fees.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/bipa-legislation-introduced-in-2021",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Illinois Supreme Court's Cothron v. White Castle decision held that separate BIPA claims accrue for every biometric scan taken from an individual, and Tims v. Black Horse Carriers established a 5-year statute of limitations for BIPA claims, together substantially increasing class-action damages exposure, with White Castle's potential liability estimated at up to $17 billion under the per-scan standard.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/the-rise-of-us-state-level-bipa-illinois-leads-others-catching-up",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "In response to Cothron, the Illinois General Assembly passed SB 2979, signed by the Governor in 2024, amending BIPA so that repeated collection or disclosure of the same biometric identifier from the same person via the same method of collection constitutes a single violation, limiting an aggrieved person to one recovery for such repeated conduct.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/illinois-bill-amending-bipa-passes-third-reading-senate",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "In 2026, the Illinois Attorney General joined multistate coalitions in litigation and advocacy actions concerning sensitive personal data, including lawsuits blocking USDA collection of SNAP recipients' data, opposition to a federal demand for Minnesota data, an amicus brief against a federal demand for voter-registration data, and efforts to block HHS from sharing Medicaid data with ICE.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/illinois",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Illinois General Assembly passed HB 5295 in 2026 to strengthen protections for abortion-related and reproductive-health data.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/illinois",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Senate Bill 315 (Artificial Intelligence Safety Measures Act) cleared both chambers of the Illinois General Assembly on 27 May 2026 and awaits the Governor's signature, with Governor Pritzker having publicly indicated he will sign it.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/notable-ai-privacy-bills-hit-finish-line-in-illinois-connecticut-and-new-york",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  }
 ]
}