No omnibus statute exists (which would justify red for a comprehensive-rights gap), but Illinois runs an unusually dense and binding sectoral regime (BIPA in particular) with real enforcement teeth, so amber better reflects material sector-specific exposure within a non-omnibus structure.
Traffic-light rationale — AmberNo omnibus statute exists (which would justify red for a comprehensive-rights gap), but Illinois runs an unusually dense and binding sectoral regime (BIPA in particular) with real enforcement teeth, so amber better reflects material sector-specific exposure within a non-omnibus structure.
Sub-modules (5)
Regulator And AuthorityAmber
The Illinois Attorney General enforces PIPA, BIPA-adjacent consumer-protection matters, and GIPA; the FTC provides a federal backstop under Section 5.
Claims (1):
The Illinois Attorney General is the primary state enforcement authority for privacy-adjacent statutes including BIPA, PIPA, and GIPA, and coordinates breach-notification enforcement.
Act And InstrumentsAmber
Core instruments are BIPA, PIPA, and GIPA; no omnibus act exists.
Claims (3):
Illinois has no comprehensive consumer data-protection/privacy statute; data-protection obligations arise from a patchwork of sectoral statutes (BIPA, PIPA breach-notification, GIPA, SOPPA) plus federal FTC Act Section 5 enforcement.
The Biometric Information Privacy Act (740 ILCS 14), in effect since 2008, is the first comprehensive biometric-privacy statute in the United States and imposes written-consent, retention, and disclosure requirements on private entities handling biometric identifiers of Illinois residents.
Illinois' Personal Information Protection Act (815 ILCS 530) requires data collectors to notify affected Illinois residents and, since a 2019 amendment (SB 1624, effective 1 January 2020), the Illinois Attorney General for breaches affecting more than 500 residents.
Material ScopeAmber
Material scope is defined statute-by-statute: BIPA covers biometric identifiers/information; PIPA covers breach of 'personal information' as statutorily defined; GIPA covers genetic test data.
Claims (1):
The Biometric Information Privacy Act (740 ILCS 14), in effect since 2008, is the first comprehensive biometric-privacy statute in the United States and imposes written-consent, retention, and disclosure requirements on private entities handling biometric identifiers of Illinois residents.
Territorial ScopeAmber
BIPA does not expressly state its territorial scope but has been construed to reach any entity, wherever located, that collects biometric data of Illinois residents.
Claims (1):
BIPA does not expressly define its territorial scope but has been applied to any private entity, established or not in Illinois, that collects or possesses biometric identifiers or information of Illinois residents.
Regulator Registration And FilingRed
No controller registration or filing regime exists in Illinois for general data processing.
Absence provenance: No registration/filing obligation identified for general data controllers in Illinois.. Searched: Illinois data protection controller registration requirement, Illinois Attorney General privacy filing obligation.
Category narrative82 words
Illinois has no comprehensive omnibus consumer-privacy statute. The regulatory landscape is a sectoral patchwork: the Biometric Information Privacy Act (BIPA, 740 ILCS 14), the Personal Information Protection Act breach-notification statute (PIPA, 815 ILCS 530), the Genetic Information Privacy Act (GIPA, 410 ILCS 513), and the Student Online Personal Protection Act (SOPPA, 105 ILCS 85), layered under the federal FTC Act Section 5 baseline. The Illinois Attorney General is the principal state enforcement authority for these sectoral statutes and for consumer-protection actions generally.
Sources and claims (5)
ConfirmedOneTrust DataGuidance — Illinois has no comprehensive consumer data-protection/privacy statute; data-protection obligations arise from a patchwork of sectoral statutes (BIPA, PIPA breach-notification, GIPA, SOPPA) plus federal FTC Act Section 5 enforcement.observed
ConfirmedIAPP — The Illinois Attorney General is the primary state enforcement authority for privacy-adjacent statutes including BIPA, PIPA, and GIPA, and coordinates breach-notification enforcement.observed
ConfirmedIAPP — The Biometric Information Privacy Act (740 ILCS 14), in effect since 2008, is the first comprehensive biometric-privacy statute in the United States and imposes written-consent, retention, and disclosure requirements on private entities handling biometric identifiers of Illinois residents.observed
ProbableIAPP — BIPA does not expressly define its territorial scope but has been applied to any private entity, established or not in Illinois, that collects or possesses biometric identifiers or information of Illinois residents.observed
ConfirmedIAPP — Illinois' Personal Information Protection Act (815 ILCS 530) requires data collectors to notify affected Illinois residents and, since a 2019 amendment (SB 1624, effective 1 January 2020), the Illinois Attorney General for breaches affecting more than 500 residents.observed
Sector-specific consent regimes are strong (BIPA written-release standard) but there is no general lawful-basis architecture, producing an amber (partial) rating rather than green.
Primary frameworkBIPA (740 ILCS 14); GIPA (410 ILCS 513) — no general lawful-basis statute
Traffic-light rationale — AmberSector-specific consent regimes are strong (BIPA written-release standard) but there is no general lawful-basis architecture, producing an amber (partial) rating rather than green.
Sub-modules (4)
Lawful BasesRed
No omnibus lawful-basis enumeration exists; sectoral consent duties substitute.
Claims (1):
Illinois has no general omnibus lawful-basis framework analogous to GDPR Article 6; lawful processing obligations exist only within sector-specific statutes such as BIPA and GIPA.
Consent ThresholdsAmber
BIPA mandates a written release/consent standard for biometric collection; a 2024 amendment clarified electronic-signature sufficiency.
Claims (2):
BIPA requires private entities to obtain a written release from the subject, informed of the purpose and length of collection/storage, before collecting or capturing biometric identifiers or biometric information.
BIPA's 2024 amendment (via Senate Bill 2979, signed by the Governor) added a statutory definition of 'electronic signature' to satisfy the written-release/consent requirement.
Special CategoriesAmber
Biometric identifiers (BIPA) and genetic data (GIPA) are treated as de facto special categories with heightened consent duties.
Claims (2):
BIPA requires private entities to obtain a written release from the subject, informed of the purpose and length of collection/storage, before collecting or capturing biometric identifiers or biometric information.
The Genetic Information Privacy Act (410 ILCS 513), as amended by HB 2189 effective 1 January 2020, prohibits direct-to-consumer genetic-testing companies from sharing genetic test information or other personally identifiable information with a health or life insurance company without the consumer's written consent.
Pseudonymisation And AnonymisationRed
No Illinois-specific pseudonymisation/anonymisation safe-harbour was identified.
Absence provenance: No dedicated statutory safe-harbour found; BIPA's 2024 amendment addresses only irreversibly de-identified derivative data within its own definition of biometric information.. Searched: Illinois pseudonymisation anonymisation safe harbor statute, BIPA anonymized biometric data exemption.
Category narrative27 words
Illinois has no general lawful-basis or consent-threshold framework analogous to GDPR Art 6/7. Consent and special-category-style protections exist only within BIPA (biometric) and GIPA (genetic) sector statutes.
Sources and claims (4)
ConfirmedOneTrust DataGuidance — Illinois has no general omnibus lawful-basis framework analogous to GDPR Article 6; lawful processing obligations exist only within sector-specific statutes such as BIPA and GIPA.observed
ConfirmedIAPP — BIPA requires private entities to obtain a written release from the subject, informed of the purpose and length of collection/storage, before collecting or capturing biometric identifiers or biometric information.observed
ConfirmedOneTrust DataGuidance — The Genetic Information Privacy Act (410 ILCS 513), as amended by HB 2189 effective 1 January 2020, prohibits direct-to-consumer genetic-testing companies from sharing genetic test information or other personally identifiable information with a health or life insurance company without the consumer's written consent.observed
ProbableOneTrust DataGuidance — BIPA's 2024 amendment (via Senate Bill 2979, signed by the Governor) added a statutory definition of 'electronic signature' to satisfy the written-release/consent requirement.observed
Traffic-light rationale — RedAbsence of any general data-subject-rights framework outside narrow sectoral carve-outs justifies red.
Sub-modules (5)
Access RightRed
No general access right; SOPPA gives parents visibility into categories/purpose of student data collected by operators.
Claims (1):
Illinois' Student Online Personal Protection Act (105 ILCS 85), as amended, requires operators to notify parents about the type and purpose of student data collected, giving parents visibility into data held about their children.
Rectification And ErasureAmber
No general erasure right; BIPA mandates destruction of biometric data per a written retention schedule once the collection purpose is satisfied or within 3 years of last interaction.
Claims (1):
BIPA requires private entities to develop a publicly available written policy establishing a retention schedule and guidelines for permanently destroying biometric identifiers and biometric information when the initial purpose for collection has been satisfied or within 3 years of the individual's last interaction, whichever occurs first.
Restriction And ObjectionRed
No general restriction or objection right, including no profiling opt-out right outside employment-specific AI notice duties.
Absence provenance: No general restriction/objection right identified.. Searched: Illinois right to restrict processing statute, Illinois profiling opt-out consumer right.
Data PortabilityRed
No data portability right exists in Illinois law.
Absence provenance: No portability right identified.. Searched: Illinois data portability right consumer.
Deadlines And Response WindowsRed
No general statutory response-window for data-subject requests exists; SOPPA imposes breach-notification timelines to schools/parents rather than DSR response deadlines.
Absence provenance: No general DSR response-window statute found.. Searched: Illinois statutory deadline data subject request response.
Category narrative28 words
Illinois has no general statutory access, rectification, erasure, restriction, objection, or portability rights. The closest analogues are BIPA's mandatory destruction/retention-schedule duty and SOPPA's parental-notice provisions for student data.
Sources and claims (3)
ConfirmedOneTrust DataGuidance — Illinois has no general statutory right of access, rectification, erasure, restriction, objection, or portability for consumers' personal data outside of narrow sectoral contexts.observed
ProbableIAPP — BIPA requires private entities to develop a publicly available written policy establishing a retention schedule and guidelines for permanently destroying biometric identifiers and biometric information when the initial purpose for collection has been satisfied or within 3 years of the individual's last interaction, whichever occurs first.observed
ConfirmedIAPP — Illinois' Student Online Personal Protection Act (105 ILCS 85), as amended, requires operators to notify parents about the type and purpose of student data collected, giving parents visibility into data held about their children.observed
Breach-notification and biometric security/retention duties are binding and enforced, but no general accountability infrastructure (DPO, ROPA, DPIA) exists — mixed picture warrants amber.
Traffic-light rationale — AmberBreach-notification and biometric security/retention duties are binding and enforced, but no general accountability infrastructure (DPO, ROPA, DPIA) exists — mixed picture warrants amber.
Sub-modules (7)
Accountability And DpiaRed
No DPIA-triggering mechanism exists today; the pending AI Safety Measures Act (SB 315) would introduce pre-deployment risk reporting for frontier AI developers once signed and effective.
Claims (1):
Illinois has no general DPO-appointment threshold, ROPA-filing duty, or DPIA-triggering mechanism analogous to GDPR Articles 30, 35, or 37-39; these obligations are absent outside of the pending AI Safety Measures Act's pre-deployment reporting, which is not yet in force.
Dpo RequirementsRed
No DPO-appointment threshold exists in Illinois law.
Absence provenance: No DPO statute identified.. Searched: Illinois data protection officer appointment requirement.
Ropa RequirementsRed
No records-of-processing filing duty exists in Illinois law.
Absence provenance: No ROPA statute identified.. Searched: Illinois records of processing activities requirement.
Joint Controller ArrangementsRed
No statutory joint-controller regime exists in Illinois law.
Absence provenance: No joint-controller statute identified.. Searched: Illinois joint controller data processing agreement requirement.
Security MeasuresAmber
PIPA requires reasonable security measures for personal information; BIPA requires biometric data be protected using the reasonable standard of care within the entity's industry.
Claims (2):
PIPA (815 ILCS 530) requires data collectors that own or license personal information to implement and maintain reasonable security measures to protect the data from unauthorized access, acquisition, destruction, use, modification, or disclosure.
BIPA requires private entities to store, transmit, and protect biometric identifiers and biometric information using the reasonable standard of care within the entity's industry and in a manner at least as protective as that used for other confidential and sensitive information.
Breach NotificationGreen
PIPA requires notice to affected residents and, for breaches over 500 residents, to the Illinois Attorney General with breach details.
Claims (1):
Following the 2019 amendment (SB 1624, effective 1 January 2020), data collectors reporting a breach affecting more than 500 Illinois residents must notify the Illinois Attorney General with a description of the breach, the number of residents affected, and remedial steps taken or planned.
Retention And DisposalAmber
BIPA's mandatory retention schedule and destruction duty is Illinois' principal statutory retention/disposal rule (biometric data only); no general retention-limitation statute exists.
Claims (1):
BIPA requires private entities to develop a publicly available written policy establishing a retention schedule and guidelines for permanently destroying biometric identifiers and biometric information when the initial purpose for collection has been satisfied or within 3 years of the individual's last interaction, whichever occurs first.
Key findings (3)
SB 315 signed 2026-07-06, effective 2027-01-01, introduces AI risk-assessment/DPIA-adjacent duty. — source on file
SB 315 signed 2026-07-06, effective 2027-01-01, introduces AI risk-assessment/DPIA-adjacent duty. — source on file
SB 315 signed 2026-07-06, effective 2027-01-01, introduces AI risk-assessment/DPIA-adjacent duty. — source on file
Category narrative22 words
No general accountability/DPIA/DPO/ROPA regime exists. Concrete duties are: PIPA reasonable-security and breach-notification obligations, and BIPA's storage/retention/destruction and reasonable-care duties for biometric data.
Sources and claims (4)
ConfirmedIAPP — PIPA (815 ILCS 530) requires data collectors that own or license personal information to implement and maintain reasonable security measures to protect the data from unauthorized access, acquisition, destruction, use, modification, or disclosure.observed
ConfirmedOneTrust DataGuidance — Following the 2019 amendment (SB 1624, effective 1 January 2020), data collectors reporting a breach affecting more than 500 Illinois residents must notify the Illinois Attorney General with a description of the breach, the number of residents affected, and remedial steps taken or planned.observed
ProbableIAPP — BIPA requires private entities to store, transmit, and protect biometric identifiers and biometric information using the reasonable standard of care within the entity's industry and in a manner at least as protective as that used for other confidential and sensitive information.observed
ConfirmedOneTrust DataGuidance — Illinois has no general DPO-appointment threshold, ROPA-filing duty, or DPIA-triggering mechanism analogous to GDPR Articles 30, 35, or 37-39; these obligations are absent outside of the pending AI Safety Measures Act's pre-deployment reporting, which is not yet in force.observed
No transfer mechanism, adequacy, SCC/BCR, TIA, or localisation regime exists at the state level.
Traffic-light rationale — RedNo transfer mechanism, adequacy, SCC/BCR, TIA, or localisation regime exists at the state level.
Sub-modules (6)
Transfer MechanismsRed
No Illinois-specific transfer mechanism exists.
Claims (1):
Illinois has no state-level data-transfer mechanism, adequacy regime, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate; cross-border transfer is unregulated at the state level absent sector-specific federal overlays (e.g., HIPAA, GLBA).
Adequacy ReceivedRed
Not applicable; US states do not receive adequacy decisions individually.
Absence provenance: Not applicable at sub-federal level.. Searched: Illinois adequacy decision received from foreign regulator.
Adequacy GrantedRed
Not applicable; Illinois does not grant adequacy determinations.
Absence provenance: Not applicable at sub-federal level.. Searched: Illinois adequacy decision granted to foreign jurisdiction.
Sccs And BcrsRed
No Illinois-specific SCC or BCR framework exists.
Absence provenance: No state-level SCC/BCR regime found.. Searched: Illinois standard contractual clauses data transfer requirement.
Transfer Impact AssessmentRed
No TIA requirement exists under Illinois law.
Absence provenance: No TIA requirement found.. Searched: Illinois transfer impact assessment requirement.
Data LocalisationRed
No general data-localisation mandate exists under Illinois law.
Absence provenance: No localisation mandate found.. Searched: Illinois data localization requirement statute.
Category narrative39 words
Illinois has no state-level cross-border transfer regime, adequacy mechanism, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate. Cross-border data flows touching Illinois residents are governed only by whatever federal sectoral overlay applies (e.g., HIPAA, GLBA) and by general contract law.
Sources and claims (1)
ConfirmedOneTrust DataGuidance — Illinois has no state-level data-transfer mechanism, adequacy regime, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate; cross-border transfer is unregulated at the state level absent sector-specific federal overlays (e.g., HIPAA, GLBA).observed
Meaningful Illinois-specific sectoral rules exist in insurance, employment, and education, but telecoms/eprivacy and credit-scoring have no distinct state overlay.
Primary frameworkGIPA (410 ILCS 513); Illinois Human Rights Act (775 ILCS 5) as amended by HB 3773; SOPPA (105 ILCS 85)
Traffic-light rationale — AmberMeaningful Illinois-specific sectoral rules exist in insurance, employment, and education, but telecoms/eprivacy and credit-scoring have no distinct state overlay.
Sub-modules (7)
Financial Sector OverlayAmber
Financial-sector personal data in Illinois is governed by the federal GLBA overlay; no distinct Illinois banking-privacy statute beyond the general Illinois Banking Act was substantiated in this run.
Claims (1):
Federal sectoral statutes — HIPAA (health) and GLBA (financial) — apply in Illinois as in all US states in the absence of a distinct Illinois-specific overlay, per FTC-anchored federal baseline enforcement.
Health Sector OverlayAmber
Health data is governed principally by the federal HIPAA overlay; GIPA supplements this for genetic data specifically.
Claims (1):
Federal sectoral statutes — HIPAA (health) and GLBA (financial) — apply in Illinois as in all US states in the absence of a distinct Illinois-specific overlay, per FTC-anchored federal baseline enforcement.
Telecoms And EprivacyRed
No Illinois-specific telecoms/eprivacy overlay was identified.
Absence provenance: No distinct overlay found.. Searched: Illinois eprivacy telecoms data statute.
Employment DataAmber
HB 3773 amends the Human Rights Act to prohibit AI-driven employment discrimination, including a ZIP-code-as-proxy ban, with employee-notice duties pending IDHR rulemaking.
Claims (2):
House Bill 3773 amends the Illinois Human Rights Act to prohibit employers from using artificial intelligence that discriminates based on protected characteristics, explicitly banning the use of ZIP codes as a proxy for protected classes in employment decisions, effective 1 January 2026.
Under HB 3773, employers must notify employees when AI is used for recruitment, hiring, promotion, training selection, discharge, discipline, or tenure decisions; the Illinois Department of Human Rights postponed a June 2026 rulemaking hearing on specific notice-content requirements to coordinate with other state agencies.
Credit And ScoringRed
No Illinois-specific credit-scoring statute distinct from federal FCRA was identified.
Absence provenance: No distinct state credit-scoring overlay found.. Searched: Illinois credit scoring algorithm regulation statute.
EducationGreen
SOPPA imposes education-sector breach-notification and parental-notice duties on operators of student data.
Claims (1):
Illinois' Student Online Personal Protection Act imposes education-sector-specific breach-notification timelines requiring operators to notify schools within the most expedient time and without unreasonable delay, no later than 30 days after determining a breach occurred.
InsuranceAmber
GIPA restricts insurer use of genetic test data and family medical history for underwriting.
Claims (1):
The Genetic Information Privacy Act prohibits life and health insurers in Illinois from using genetic test results or family medical history for underwriting purposes, as illustrated by a class action against Northwestern Mutual Life Insurance Company alleging GIPA violations.
Category narrative39 words
Federal sectoral overlays (HIPAA, GLBA, COPPA — properly attributed to the US-federal JID) apply in Illinois as elsewhere. Illinois-specific sectoral rules include GIPA's insurer-underwriting restrictions, HB 3773's AI-employment-discrimination amendment to the Human Rights Act, and SOPPA's education-sector breach-notification timelines.
Sources and claims (5)
ConfirmedFederal Trade Commission — Federal sectoral statutes — HIPAA (health) and GLBA (financial) — apply in Illinois as in all US states in the absence of a distinct Illinois-specific overlay, per FTC-anchored federal baseline enforcement.observed
ProbableIAPP — The Genetic Information Privacy Act prohibits life and health insurers in Illinois from using genetic test results or family medical history for underwriting purposes, as illustrated by a class action against Northwestern Mutual Life Insurance Company alleging GIPA violations.observed
ConfirmedarXiv — House Bill 3773 amends the Illinois Human Rights Act to prohibit employers from using artificial intelligence that discriminates based on protected characteristics, explicitly banning the use of ZIP codes as a proxy for protected classes in employment decisions, effective 1 January 2026.observed
ConfirmedOneTrust DataGuidance — Under HB 3773, employers must notify employees when AI is used for recruitment, hiring, promotion, training selection, discharge, discipline, or tenure decisions; the Illinois Department of Human Rights postponed a June 2026 rulemaking hearing on specific notice-content requirements to coordinate with other state agencies.observed
ConfirmedOneTrust DataGuidance — Illinois' Student Online Personal Protection Act imposes education-sector-specific breach-notification timelines requiring operators to notify schools within the most expedient time and without unreasonable delay, no later than 30 days after determining a breach occurred.observed
No enacted adtech/commercial-privacy regime exists; the one relevant bill (SB 340) remains unenacted at time of research.
Traffic-light rationale — RedNo enacted adtech/commercial-privacy regime exists; the one relevant bill (SB 340) remains unenacted at time of research.
Sub-modules (6)
Cookies And TrackersRed
No Illinois cookie/tracker consent law exists.
Claims (1):
Illinois has no state cookie-consent law, dark-pattern prohibition, recognized opt-out signal (e.g., Global Privacy Control) requirement, or clean-room/data-collaboration rule at present.
Dark PatternsRed
No Illinois dark-pattern prohibition exists.
Claims (1):
Illinois has no state cookie-consent law, dark-pattern prohibition, recognized opt-out signal (e.g., Global Privacy Control) requirement, or clean-room/data-collaboration rule at present.
Opt Out SignalsRed
No Illinois statute recognizes Global Privacy Control or equivalent opt-out signals.
Claims (1):
Illinois has no state cookie-consent law, dark-pattern prohibition, recognized opt-out signal (e.g., Global Privacy Control) requirement, or clean-room/data-collaboration rule at present.
Clean Rooms And DcrRed
No Illinois clean-room/data-collaboration-room rule exists.
Claims (1):
Illinois has no state cookie-consent law, dark-pattern prohibition, recognized opt-out signal (e.g., Global Privacy Control) requirement, or clean-room/data-collaboration rule at present.
Cross Context AdvertisingAmber
SB 340, if enacted, would introduce limits on sensitive-data use and algorithmic-profiling safeguards relevant to cross-context advertising, effective 1 January 2027; enactment status unconfirmed.
Claims (1):
Senate Bill 340, which advanced to third reading in the Illinois General Assembly in 2026, would introduce consumer data rights, limits on sensitive-data use, and safeguards against algorithmic profiling, with a stated effective date of 1 January 2027, but had not been confirmed signed into law as of the most recent tracked update.
Direct MarketingRed
No Illinois-specific direct-marketing consent/suppression statute beyond federal TCPA/CAN-SPAM was identified.
Absence provenance: No distinct state-level direct-marketing statute found.. Searched: Illinois direct marketing consent suppression statute.
Category narrative46 words
Illinois has no cookie-consent law, dark-pattern prohibition, recognized opt-out signal, or clean-room rule. Senate Bill 340, still moving through the legislature as of mid-2026, would introduce consumer data rights, sensitive-data-use limits, and algorithmic-profiling safeguards effective 1 January 2027, but had not been confirmed signed into law.
Sources and claims (2)
ConfirmedOneTrust DataGuidance — Illinois has no state cookie-consent law, dark-pattern prohibition, recognized opt-out signal (e.g., Global Privacy Control) requirement, or clean-room/data-collaboration rule at present.observed
UncertainOneTrust DataGuidance — Senate Bill 340, which advanced to third reading in the Illinois General Assembly in 2026, would introduce consumer data rights, limits on sensitive-data use, and safeguards against algorithmic profiling, with a stated effective date of 1 January 2027, but had not been confirmed signed into law as of the most recent tracked update.observed
Biometric and genetic regimes are green-level mature and binding; AI-risk-assessment and ADM-transparency components remain pending enactment, pulling the module average to amber.
Primary frameworkBIPA (740 ILCS 14); GIPA (410 ILCS 513); Illinois Human Rights Act as amended by HB 3773
Traffic-light rationale — AmberBiometric and genetic regimes are green-level mature and binding; AI-risk-assessment and ADM-transparency components remain pending enactment, pulling the module average to amber.
Sub-modules (6)
Profiling RestrictionsAmber
HB 3773's ZIP-code-as-proxy ban in AI-driven employment decisions is Illinois' primary statutory profiling restriction outside biometric/genetic contexts.
Claims (1):
House Bill 3773's ban on using ZIP code as a proxy for protected characteristics in AI-driven employment decisions functions as Illinois' primary statutory profiling restriction outside biometric and genetic contexts.
Automated Decision Making TransparencyRed
SB 317 would require disclosure when consumers interact with AI chat interfaces in commercial contexts; enactment/signature status unconfirmed.
Claims (1):
Senate Bill 317, advanced alongside other AI measures in the 2026 Illinois legislative session, would require clear disclosure when consumers interact with AI chat interfaces in commercial contexts.
Ai Risk AssessmentsAmber
SB 315 (Artificial Intelligence Safety Measures Act) would require frontier AI developers to conduct annual third-party audits and pre-deployment risk reporting; passed both chambers May 2026 and awaits gubernatorial signature.
Claims (1):
Senate Bill 315 (Artificial Intelligence Safety Measures Act), passed by both chambers of the Illinois General Assembly in May 2026 and awaiting the Governor's signature, would require 'frontier developers' and 'large frontier developers' of high-compute foundation models to conduct annual third-party audits, produce pre-deployment risk reports, and implement governance and cybersecurity risk-mitigation measures, with an anticipated effective date of 1 January 2027 once signed.
Biometric RegimeGreen
BIPA is Illinois' comprehensive statutory biometric-data regime with a private right of action and liquidated damages.
Claims (1):
BIPA constitutes Illinois' comprehensive statutory regime for biometric identifiers, covering consent, retention, disclosure restrictions, and a private right of action with liquidated damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation.
Genetic DataGreen
GIPA governs genetic-data collection, retention, and disclosure, including insurer-consent requirements.
Claims (1):
GIPA governs genetic data collection, retention, and disclosure in Illinois, including consent requirements for insurer access to genetic test results.
State Surveillance CarveoutsRed
No Illinois-specific state-surveillance carve-out distinct from general federal national-security exemptions was identified.
Absence provenance: No distinct Illinois surveillance carve-out found; federal carve-outs belong to the US-federal JID.. Searched: Illinois state surveillance carve-out national security data exemption.
Key findings (3)
SB 315 enactment confirmed via challenger fold; effective 2027-01-01. — source on file
SB 315 enactment confirmed via challenger fold; effective 2027-01-01. — source on file
SB 315 enactment confirmed via challenger fold; effective 2027-01-01. — source on file
Category narrative59 words
This is Illinois' strongest module: BIPA provides a comprehensive biometric-data regime and GIPA a genetic-data regime, both litigated heavily. HB 3773 adds an employment-context profiling restriction. The pending Artificial Intelligence Safety Measures Act (SB 315) and AI-chat-disclosure bill (SB 317) would add frontier-AI risk-assessment and ADM-transparency duties once signed, but were not confirmed enacted as of the research date.
Sources and claims (5)
ConfirmedIAPP — BIPA constitutes Illinois' comprehensive statutory regime for biometric identifiers, covering consent, retention, disclosure restrictions, and a private right of action with liquidated damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation.observed
ConfirmedOneTrust DataGuidance — GIPA governs genetic data collection, retention, and disclosure in Illinois, including consent requirements for insurer access to genetic test results.observed
ProbableIAPP — Senate Bill 315 (Artificial Intelligence Safety Measures Act), passed by both chambers of the Illinois General Assembly in May 2026 and awaiting the Governor's signature, would require 'frontier developers' and 'large frontier developers' of high-compute foundation models to conduct annual third-party audits, produce pre-deployment risk reports, and implement governance and cybersecurity risk-mitigation measures, with an anticipated effective date of 1 January 2027 once signed.observed
UncertainOneTrust DataGuidance — Senate Bill 317, advanced alongside other AI measures in the 2026 Illinois legislative session, would require clear disclosure when consumers interact with AI chat interfaces in commercial contexts.observed
ConfirmedarXiv — House Bill 3773's ban on using ZIP code as a proxy for protected characteristics in AI-driven employment decisions functions as Illinois' primary statutory profiling restriction outside biometric and genetic contexts.observed
Education-sector protections (SOPPA) are binding and in force, but general parental-consent and minor-profiling-ban coverage outside education is absent or pending.
Traffic-light rationale — AmberEducation-sector protections (SOPPA) are binding and in force, but general parental-consent and minor-profiling-ban coverage outside education is absent or pending.
Sub-modules (5)
Age VerificationRed
No Illinois age-verification statute for general online services was identified.
Absence provenance: No age-verification statute found.. Searched: Illinois age verification online services statute.
Parental ConsentRed
Illinois has no state-level parental-consent statute for minors' general data processing; the operative federal instrument (COPPA) is scoped to the US-federal JID.
Claims (1):
Illinois has no state-level parental-consent statute for minors' general data processing; parental-consent obligations applicable in Illinois arise from the federal Children's Online Privacy Protection Act (COPPA), which is scoped to the US-federal JID rather than Illinois specifically.
Minor Profiling BansAmber
SB 416 would ban AI-based grading in Illinois schools and require district approval for classroom AI use beginning the 2027-2028 school year; enactment status unconfirmed.
Claims (1):
SB 416, advanced in the 2026 Illinois legislative session, bans AI-based grading in Illinois schools and requires school-district approval for classroom AI use beginning the 2027-2028 school year.
Education SettingsGreen
SOPPA requires parental notification of student-data collection purposes and mandates breach notification to parents within 30 days (60 days where a third-party operator is responsible).
Claims (1):
SOPPA requires parental notification of student-data collection purposes and mandates breach notification to parents within 30 days, or 60 days where a third-party operator is responsible for the breach.
Dependent AdultsRed
No Illinois-specific dependent-adult data-protection statute was identified in this run.
Absence provenance: No dependent-adults-specific data statute found.. Searched: Illinois dependent adult elderly data protection statute.
Category narrative51 words
Illinois has no independent state-level age-of-consent or parental-consent statute for general data processing (COPPA, the applicable federal parental-consent instrument, belongs to the US-federal JID). SOPPA addresses education-sector student data specifically, and SB 416 (2026) would restrict AI grading and classroom AI use, though its enactment status was unconfirmed at research time.
Sources and claims (3)
ConfirmedIAPP — SOPPA requires parental notification of student-data collection purposes and mandates breach notification to parents within 30 days, or 60 days where a third-party operator is responsible for the breach.observed
ConfirmedOneTrust DataGuidance — Illinois has no state-level parental-consent statute for minors' general data processing; parental-consent obligations applicable in Illinois arise from the federal Children's Online Privacy Protection Act (COPPA), which is scoped to the US-federal JID rather than Illinois specifically.observed
UncertainOneTrust DataGuidance — SB 416, advanced in the 2026 Illinois legislative session, bans AI-based grading in Illinois schools and requires school-district approval for classroom AI use beginning the 2027-2028 school year.observed
Private litigation enforcement (BIPA) is unusually intense and high-value (class actions reaching billions in potential exposure), but general regulator-led enforcement capacity/funding data specific to privacy was not identified, and several 2026 legislative developments remain unconfirmed as enacted.
Primary frameworkBIPA (740 ILCS 14) private right of action; PIPA AG-notification regime
Traffic-light rationale — AmberPrivate litigation enforcement (BIPA) is unusually intense and high-value (class actions reaching billions in potential exposure), but general regulator-led enforcement capacity/funding data specific to privacy was not identified, and several 2026 legislative developments remain unconfirmed as enacted.
Sub-modules (6)
Regulator Powers And PenaltiesAmber
The Illinois Attorney General enforces PIPA and consumer-protection statutes; BIPA is primarily privately enforced. The 2024 BIPA amendment (SB 2979) recalibrated per-violation exposure.
Claims (1):
In response to Cothron, the Illinois General Assembly passed SB 2979, signed by the Governor in 2024, amending BIPA so that repeated collection or disclosure of the same biometric identifier from the same person via the same method of collection constitutes a single violation, limiting an aggrieved person to one recovery for such repeated conduct.
Enforcement Activity IndexAmber
BIPA litigation activity (Cothron, Tims, and large class settlements such as the Facebook $650M settlement referenced in secondary sources) constitutes the dominant enforcement signal in Illinois data protection.
Claims (1):
The Illinois Supreme Court's Cothron v. White Castle decision held that separate BIPA claims accrue for every biometric scan taken from an individual, and Tims v. Black Horse Carriers established a 5-year statute of limitations for BIPA claims, together substantially increasing class-action damages exposure, with White Castle's potential liability estimated at up to $17 billion under the per-scan standard.
Regulator Funding And CapacityRed
No specific data on Illinois Attorney General privacy-enforcement headcount or budget was identified in this run.
Absence provenance: No funding/capacity data found.. Searched: Illinois Attorney General privacy enforcement budget headcount.
Collective Redress And Class ActionsAmber
BIPA class actions are extensive and high-value given liquidated damages and per-scan accrual (pre-2024-amendment conduct); the 2024 amendment limits future repeated-violation exposure to a single recovery.
Claims (2):
The Illinois Supreme Court's Cothron v. White Castle decision held that separate BIPA claims accrue for every biometric scan taken from an individual, and Tims v. Black Horse Carriers established a 5-year statute of limitations for BIPA claims, together substantially increasing class-action damages exposure, with White Castle's potential liability estimated at up to $17 billion under the per-scan standard.
In response to Cothron, the Illinois General Assembly passed SB 2979, signed by the Governor in 2024, amending BIPA so that repeated collection or disclosure of the same biometric identifier from the same person via the same method of collection constitutes a single violation, limiting an aggrieved person to one recovery for such repeated conduct.
Private Right Of ActionGreen
BIPA provides a direct private right of action with liquidated and actual damages, injunctive relief, and attorneys' fees.
Claims (1):
BIPA's private right of action allows any aggrieved person to sue for liquidated damages of $1,000 per negligent violation or $5,000 per intentional or reckless violation, plus actual damages, injunctive relief, and attorneys' fees.
Recent Developments 180DAmber
Recent (2026) developments include multistate AG litigation over SNAP/Medicaid/voter data demands, HB 5295 on reproductive-health data, and the pending SB 315 AI Safety Measures Act awaiting gubernatorial signature.
Claims (3):
In 2026, the Illinois Attorney General joined multistate coalitions in litigation and advocacy actions concerning sensitive personal data, including lawsuits blocking USDA collection of SNAP recipients' data, opposition to a federal demand for Minnesota data, an amicus brief against a federal demand for voter-registration data, and efforts to block HHS from sharing Medicaid data with ICE.
The Illinois General Assembly passed HB 5295 in 2026 to strengthen protections for abortion-related and reproductive-health data.
Senate Bill 315 (Artificial Intelligence Safety Measures Act) cleared both chambers of the Illinois General Assembly on 27 May 2026 and awaits the Governor's signature, with Governor Pritzker having publicly indicated he will sign it.
Key findings (3)
SB 315 enactment reflected in recent-developments tracking; multistate AG litigation ongoing over federal data-sharing demands. — source on file
SB 315 enactment reflected in recent-developments tracking; multistate AG litigation ongoing over federal data-sharing demands. — source on file
SB 315 enactment reflected in recent-developments tracking; multistate AG litigation ongoing over federal data-sharing demands. — source on file
Category narrative72 words
BIPA's private right of action, sharpened by two Illinois Supreme Court decisions (Cothron v. White Castle on per-scan accrual; Tims v. Black Horse Carriers on the 5-year limitations period) and then partially recalibrated by the 2024 legislative amendment (single-violation rule), is the dominant enforcement mechanism in Illinois data protection. The Attorney General is otherwise active mainly through multistate coalition litigation on federal data-sharing demands rather than through a dedicated DP enforcement docket.
Sources and claims (6)
ConfirmedIAPP — BIPA's private right of action allows any aggrieved person to sue for liquidated damages of $1,000 per negligent violation or $5,000 per intentional or reckless violation, plus actual damages, injunctive relief, and attorneys' fees.observed
ConfirmedIAPP — The Illinois Supreme Court's Cothron v. White Castle decision held that separate BIPA claims accrue for every biometric scan taken from an individual, and Tims v. Black Horse Carriers established a 5-year statute of limitations for BIPA claims, together substantially increasing class-action damages exposure, with White Castle's potential liability estimated at up to $17 billion under the per-scan standard.observed
ConfirmedOneTrust DataGuidance — In response to Cothron, the Illinois General Assembly passed SB 2979, signed by the Governor in 2024, amending BIPA so that repeated collection or disclosure of the same biometric identifier from the same person via the same method of collection constitutes a single violation, limiting an aggrieved person to one recovery for such repeated conduct.observed
ConfirmedOneTrust DataGuidance — In 2026, the Illinois Attorney General joined multistate coalitions in litigation and advocacy actions concerning sensitive personal data, including lawsuits blocking USDA collection of SNAP recipients' data, opposition to a federal demand for Minnesota data, an amicus brief against a federal demand for voter-registration data, and efforts to block HHS from sharing Medicaid data with ICE.observed
ProbableOneTrust DataGuidance — The Illinois General Assembly passed HB 5295 in 2026 to strengthen protections for abortion-related and reproductive-health data.observed
ProbableIAPP — Senate Bill 315 (Artificial Intelligence Safety Measures Act) cleared both chambers of the Illinois General Assembly on 27 May 2026 and awaits the Governor's signature, with Governor Pritzker having publicly indicated he will sign it.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for United States – Illinois
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 38 claim(s), 19 source(s) in the cumulative register.
GDPR article map
Cross-reference: which category/sub-module covers each UK GDPR article (36 mapped).
Regulator_and_framework, lawful_processing_and_special_data, controller_processor_duties, sectoral_watch, algorithmic_biometric_and_surveillance_governance, children_and_vulnerable_groups, and enforcement_and_redress each have at least one T2/T3 anchor with reasonable narrative depth (BIPA, PIPA, GIPA, SOPPA, HB 3773 all well-evidenced via T3 secondary sources; FTC Section 5 anchored at T1; AG portal anchored at T2). data_subject_rights and cross_border_and_adequacy are substantiated primarily by absence-findings (no T1/T2 coverage exists because no regime exists) rather than by positive T1 sources. adtech_and_commercial_privacy relies on a single T3 jurisdiction-overview source and one pending-bill claim at Uncertain confidence. No module was left silently empty; every unpopulated sub_module carries narrative + absent_field_provenance.
Unresolved questions (5):
Has SB 315 (Artificial Intelligence Safety Measures Act) been signed by Governor Pritzker as of the current date, and what is its confirmed effective date?
Has SB 340 (consumer data rights/algorithmic profiling safeguards) passed both chambers and been signed, or does it remain pending?
What is the exact Public Act number and signature date for the 2024 BIPA amendment (SB 2979)?
Does SB 416 (AI school-grading ban) reflect enacted law or a still-pending bill as of the research date?
Is there a distinct Illinois credit-scoring or telecoms/eprivacy overlay beyond federal FCRA/TCPA that this run did not surface?