🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-IL · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 16 sources retrieved model claude-sonnet-5 ·

United States – Illinois

US-IL schema gdpri-v2 trajectory: not recordedregulated (sectoral)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 38 claims · 16 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
38Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

No omnibus statute exists (which would justify red for a comprehensive-rights gap), but Illinois runs an unusually dense and binding sectoral regime (BIPA in particular) with real enforcement teeth, so amber better reflects material sector-specific exposure within a non-omnibus structure.

Primary frameworkNo comprehensive Illinois statute; sectoral framework: BIPA (740 ILCS 14), PIPA (815 ILCS 530), GIPA (410 ILCS 513), SOPPA (105 ILCS 85); federal baseline: FTC Act Section 5
Supervisory authorityIllinois Attorney General
Traffic-light rationale — AmberNo omnibus statute exists (which would justify red for a comprehensive-rights gap), but Illinois runs an unusually dense and binding sectoral regime (BIPA in particular) with real enforcement teeth, so amber better reflects material sector-specific exposure within a non-omnibus structure.

Sub-modules (5)

Regulator And AuthorityAmber

The Illinois Attorney General enforces PIPA, BIPA-adjacent consumer-protection matters, and GIPA; the FTC provides a federal backstop under Section 5.

Claims (1):

  • The Illinois Attorney General is the primary state enforcement authority for privacy-adjacent statutes including BIPA, PIPA, and GIPA, and coordinates breach-notification enforcement.

Act And InstrumentsAmber

Core instruments are BIPA, PIPA, and GIPA; no omnibus act exists.

Claims (3):

  • Illinois has no comprehensive consumer data-protection/privacy statute; data-protection obligations arise from a patchwork of sectoral statutes (BIPA, PIPA breach-notification, GIPA, SOPPA) plus federal FTC Act Section 5 enforcement.
  • The Biometric Information Privacy Act (740 ILCS 14), in effect since 2008, is the first comprehensive biometric-privacy statute in the United States and imposes written-consent, retention, and disclosure requirements on private entities handling biometric identifiers of Illinois residents.
  • Illinois' Personal Information Protection Act (815 ILCS 530) requires data collectors to notify affected Illinois residents and, since a 2019 amendment (SB 1624, effective 1 January 2020), the Illinois Attorney General for breaches affecting more than 500 residents.

Material ScopeAmber

Material scope is defined statute-by-statute: BIPA covers biometric identifiers/information; PIPA covers breach of 'personal information' as statutorily defined; GIPA covers genetic test data.

Claims (1):

  • The Biometric Information Privacy Act (740 ILCS 14), in effect since 2008, is the first comprehensive biometric-privacy statute in the United States and imposes written-consent, retention, and disclosure requirements on private entities handling biometric identifiers of Illinois residents.

Territorial ScopeAmber

BIPA does not expressly state its territorial scope but has been construed to reach any entity, wherever located, that collects biometric data of Illinois residents.

Claims (1):

  • BIPA does not expressly define its territorial scope but has been applied to any private entity, established or not in Illinois, that collects or possesses biometric identifiers or information of Illinois residents.

Regulator Registration And FilingRed

No controller registration or filing regime exists in Illinois for general data processing.

Absence provenance: No registration/filing obligation identified for general data controllers in Illinois.. Searched: Illinois data protection controller registration requirement, Illinois Attorney General privacy filing obligation.

Category narrative82 words

Illinois has no comprehensive omnibus consumer-privacy statute. The regulatory landscape is a sectoral patchwork: the Biometric Information Privacy Act (BIPA, 740 ILCS 14), the Personal Information Protection Act breach-notification statute (PIPA, 815 ILCS 530), the Genetic Information Privacy Act (GIPA, 410 ILCS 513), and the Student Online Personal Protection Act (SOPPA, 105 ILCS 85), layered under the federal FTC Act Section 5 baseline. The Illinois Attorney General is the principal state enforcement authority for these sectoral statutes and for consumer-protection actions generally.

Sources and claims (5)
  1. ConfirmedOneTrust DataGuidanceIllinois has no comprehensive consumer data-protection/privacy statute; data-protection obligations arise from a patchwork of sectoral statutes (BIPA, PIPA breach-notification, GIPA, SOPPA) plus federal FTC Act Section 5 enforcement.observed
  2. ConfirmedIAPPThe Illinois Attorney General is the primary state enforcement authority for privacy-adjacent statutes including BIPA, PIPA, and GIPA, and coordinates breach-notification enforcement.observed
  3. ConfirmedIAPPThe Biometric Information Privacy Act (740 ILCS 14), in effect since 2008, is the first comprehensive biometric-privacy statute in the United States and imposes written-consent, retention, and disclosure requirements on private entities handling biometric identifiers of Illinois residents.observed
  4. ProbableIAPPBIPA does not expressly define its territorial scope but has been applied to any private entity, established or not in Illinois, that collects or possesses biometric identifiers or information of Illinois residents.observed
  5. ConfirmedIAPPIllinois' Personal Information Protection Act (815 ILCS 530) requires data collectors to notify affected Illinois residents and, since a 2019 amendment (SB 1624, effective 1 January 2020), the Illinois Attorney General for breaches affecting more than 500 residents.observed

#

Sector-specific consent regimes are strong (BIPA written-release standard) but there is no general lawful-basis architecture, producing an amber (partial) rating rather than green.

Primary frameworkBIPA (740 ILCS 14); GIPA (410 ILCS 513) — no general lawful-basis statute
Supervisory authorityIllinois Attorney General
Traffic-light rationale — AmberSector-specific consent regimes are strong (BIPA written-release standard) but there is no general lawful-basis architecture, producing an amber (partial) rating rather than green.

Sub-modules (4)

Lawful BasesRed

No omnibus lawful-basis enumeration exists; sectoral consent duties substitute.

Claims (1):

  • Illinois has no general omnibus lawful-basis framework analogous to GDPR Article 6; lawful processing obligations exist only within sector-specific statutes such as BIPA and GIPA.

Special CategoriesAmber

Biometric identifiers (BIPA) and genetic data (GIPA) are treated as de facto special categories with heightened consent duties.

Claims (2):

  • BIPA requires private entities to obtain a written release from the subject, informed of the purpose and length of collection/storage, before collecting or capturing biometric identifiers or biometric information.
  • The Genetic Information Privacy Act (410 ILCS 513), as amended by HB 2189 effective 1 January 2020, prohibits direct-to-consumer genetic-testing companies from sharing genetic test information or other personally identifiable information with a health or life insurance company without the consumer's written consent.

Pseudonymisation And AnonymisationRed

No Illinois-specific pseudonymisation/anonymisation safe-harbour was identified.

Absence provenance: No dedicated statutory safe-harbour found; BIPA's 2024 amendment addresses only irreversibly de-identified derivative data within its own definition of biometric information.. Searched: Illinois pseudonymisation anonymisation safe harbor statute, BIPA anonymized biometric data exemption.

Category narrative27 words

Illinois has no general lawful-basis or consent-threshold framework analogous to GDPR Art 6/7. Consent and special-category-style protections exist only within BIPA (biometric) and GIPA (genetic) sector statutes.

Sources and claims (4)
  1. ConfirmedOneTrust DataGuidanceIllinois has no general omnibus lawful-basis framework analogous to GDPR Article 6; lawful processing obligations exist only within sector-specific statutes such as BIPA and GIPA.observed
  2. ConfirmedIAPPBIPA requires private entities to obtain a written release from the subject, informed of the purpose and length of collection/storage, before collecting or capturing biometric identifiers or biometric information.observed
  3. ConfirmedOneTrust DataGuidanceThe Genetic Information Privacy Act (410 ILCS 513), as amended by HB 2189 effective 1 January 2020, prohibits direct-to-consumer genetic-testing companies from sharing genetic test information or other personally identifiable information with a health or life insurance company without the consumer's written consent.observed
  4. ProbableOneTrust DataGuidanceBIPA's 2024 amendment (via Senate Bill 2979, signed by the Governor) added a statutory definition of 'electronic signature' to satisfy the written-release/consent requirement.observed

#

Absence of any general data-subject-rights framework outside narrow sectoral carve-outs justifies red.

Supervisory authorityIllinois Attorney General
Traffic-light rationale — RedAbsence of any general data-subject-rights framework outside narrow sectoral carve-outs justifies red.

Sub-modules (5)

Access RightRed

No general access right; SOPPA gives parents visibility into categories/purpose of student data collected by operators.

Claims (1):

  • Illinois' Student Online Personal Protection Act (105 ILCS 85), as amended, requires operators to notify parents about the type and purpose of student data collected, giving parents visibility into data held about their children.

Rectification And ErasureAmber

No general erasure right; BIPA mandates destruction of biometric data per a written retention schedule once the collection purpose is satisfied or within 3 years of last interaction.

Claims (1):

  • BIPA requires private entities to develop a publicly available written policy establishing a retention schedule and guidelines for permanently destroying biometric identifiers and biometric information when the initial purpose for collection has been satisfied or within 3 years of the individual's last interaction, whichever occurs first.

Restriction And ObjectionRed

No general restriction or objection right, including no profiling opt-out right outside employment-specific AI notice duties.

Absence provenance: No general restriction/objection right identified.. Searched: Illinois right to restrict processing statute, Illinois profiling opt-out consumer right.

Data PortabilityRed

No data portability right exists in Illinois law.

Absence provenance: No portability right identified.. Searched: Illinois data portability right consumer.

Deadlines And Response WindowsRed

No general statutory response-window for data-subject requests exists; SOPPA imposes breach-notification timelines to schools/parents rather than DSR response deadlines.

Absence provenance: No general DSR response-window statute found.. Searched: Illinois statutory deadline data subject request response.

Category narrative28 words

Illinois has no general statutory access, rectification, erasure, restriction, objection, or portability rights. The closest analogues are BIPA's mandatory destruction/retention-schedule duty and SOPPA's parental-notice provisions for student data.

Sources and claims (3)
  1. ConfirmedOneTrust DataGuidanceIllinois has no general statutory right of access, rectification, erasure, restriction, objection, or portability for consumers' personal data outside of narrow sectoral contexts.observed
  2. ProbableIAPPBIPA requires private entities to develop a publicly available written policy establishing a retention schedule and guidelines for permanently destroying biometric identifiers and biometric information when the initial purpose for collection has been satisfied or within 3 years of the individual's last interaction, whichever occurs first.observed
  3. ConfirmedIAPPIllinois' Student Online Personal Protection Act (105 ILCS 85), as amended, requires operators to notify parents about the type and purpose of student data collected, giving parents visibility into data held about their children.observed

#

Breach-notification and biometric security/retention duties are binding and enforced, but no general accountability infrastructure (DPO, ROPA, DPIA) exists — mixed picture warrants amber.

Primary frameworkPIPA (815 ILCS 530); BIPA (740 ILCS 14)
Supervisory authorityIllinois Attorney General
Traffic-light rationale — AmberBreach-notification and biometric security/retention duties are binding and enforced, but no general accountability infrastructure (DPO, ROPA, DPIA) exists — mixed picture warrants amber.

Sub-modules (7)

Accountability And DpiaRed

No DPIA-triggering mechanism exists today; the pending AI Safety Measures Act (SB 315) would introduce pre-deployment risk reporting for frontier AI developers once signed and effective.

Claims (1):

  • Illinois has no general DPO-appointment threshold, ROPA-filing duty, or DPIA-triggering mechanism analogous to GDPR Articles 30, 35, or 37-39; these obligations are absent outside of the pending AI Safety Measures Act's pre-deployment reporting, which is not yet in force.

Dpo RequirementsRed

No DPO-appointment threshold exists in Illinois law.

Absence provenance: No DPO statute identified.. Searched: Illinois data protection officer appointment requirement.

Ropa RequirementsRed

No records-of-processing filing duty exists in Illinois law.

Absence provenance: No ROPA statute identified.. Searched: Illinois records of processing activities requirement.

Joint Controller ArrangementsRed

No statutory joint-controller regime exists in Illinois law.

Absence provenance: No joint-controller statute identified.. Searched: Illinois joint controller data processing agreement requirement.

Security MeasuresAmber

PIPA requires reasonable security measures for personal information; BIPA requires biometric data be protected using the reasonable standard of care within the entity's industry.

Claims (2):

  • PIPA (815 ILCS 530) requires data collectors that own or license personal information to implement and maintain reasonable security measures to protect the data from unauthorized access, acquisition, destruction, use, modification, or disclosure.
  • BIPA requires private entities to store, transmit, and protect biometric identifiers and biometric information using the reasonable standard of care within the entity's industry and in a manner at least as protective as that used for other confidential and sensitive information.

Breach NotificationGreen

PIPA requires notice to affected residents and, for breaches over 500 residents, to the Illinois Attorney General with breach details.

Claims (1):

  • Following the 2019 amendment (SB 1624, effective 1 January 2020), data collectors reporting a breach affecting more than 500 Illinois residents must notify the Illinois Attorney General with a description of the breach, the number of residents affected, and remedial steps taken or planned.

Retention And DisposalAmber

BIPA's mandatory retention schedule and destruction duty is Illinois' principal statutory retention/disposal rule (biometric data only); no general retention-limitation statute exists.

Claims (1):

  • BIPA requires private entities to develop a publicly available written policy establishing a retention schedule and guidelines for permanently destroying biometric identifiers and biometric information when the initial purpose for collection has been satisfied or within 3 years of the individual's last interaction, whichever occurs first.

Key findings (3)

  • SB 315 signed 2026-07-06, effective 2027-01-01, introduces AI risk-assessment/DPIA-adjacent duty. — source on file
  • SB 315 signed 2026-07-06, effective 2027-01-01, introduces AI risk-assessment/DPIA-adjacent duty. — source on file
  • SB 315 signed 2026-07-06, effective 2027-01-01, introduces AI risk-assessment/DPIA-adjacent duty. — source on file
Category narrative22 words

No general accountability/DPIA/DPO/ROPA regime exists. Concrete duties are: PIPA reasonable-security and breach-notification obligations, and BIPA's storage/retention/destruction and reasonable-care duties for biometric data.

Sources and claims (4)
  1. ConfirmedIAPPPIPA (815 ILCS 530) requires data collectors that own or license personal information to implement and maintain reasonable security measures to protect the data from unauthorized access, acquisition, destruction, use, modification, or disclosure.observed
  2. ConfirmedOneTrust DataGuidanceFollowing the 2019 amendment (SB 1624, effective 1 January 2020), data collectors reporting a breach affecting more than 500 Illinois residents must notify the Illinois Attorney General with a description of the breach, the number of residents affected, and remedial steps taken or planned.observed
  3. ProbableIAPPBIPA requires private entities to store, transmit, and protect biometric identifiers and biometric information using the reasonable standard of care within the entity's industry and in a manner at least as protective as that used for other confidential and sensitive information.observed
  4. ConfirmedOneTrust DataGuidanceIllinois has no general DPO-appointment threshold, ROPA-filing duty, or DPIA-triggering mechanism analogous to GDPR Articles 30, 35, or 37-39; these obligations are absent outside of the pending AI Safety Measures Act's pre-deployment reporting, which is not yet in force.observed

#

No transfer mechanism, adequacy, SCC/BCR, TIA, or localisation regime exists at the state level.

Traffic-light rationale — RedNo transfer mechanism, adequacy, SCC/BCR, TIA, or localisation regime exists at the state level.

Sub-modules (6)

Transfer MechanismsRed

No Illinois-specific transfer mechanism exists.

Claims (1):

  • Illinois has no state-level data-transfer mechanism, adequacy regime, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate; cross-border transfer is unregulated at the state level absent sector-specific federal overlays (e.g., HIPAA, GLBA).

Adequacy ReceivedRed

Not applicable; US states do not receive adequacy decisions individually.

Absence provenance: Not applicable at sub-federal level.. Searched: Illinois adequacy decision received from foreign regulator.

Adequacy GrantedRed

Not applicable; Illinois does not grant adequacy determinations.

Absence provenance: Not applicable at sub-federal level.. Searched: Illinois adequacy decision granted to foreign jurisdiction.

Sccs And BcrsRed

No Illinois-specific SCC or BCR framework exists.

Absence provenance: No state-level SCC/BCR regime found.. Searched: Illinois standard contractual clauses data transfer requirement.

Transfer Impact AssessmentRed

No TIA requirement exists under Illinois law.

Absence provenance: No TIA requirement found.. Searched: Illinois transfer impact assessment requirement.

Data LocalisationRed

No general data-localisation mandate exists under Illinois law.

Absence provenance: No localisation mandate found.. Searched: Illinois data localization requirement statute.

Category narrative39 words

Illinois has no state-level cross-border transfer regime, adequacy mechanism, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate. Cross-border data flows touching Illinois residents are governed only by whatever federal sectoral overlay applies (e.g., HIPAA, GLBA) and by general contract law.

Sources and claims (1)
  1. ConfirmedOneTrust DataGuidanceIllinois has no state-level data-transfer mechanism, adequacy regime, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate; cross-border transfer is unregulated at the state level absent sector-specific federal overlays (e.g., HIPAA, GLBA).observed

#

Meaningful Illinois-specific sectoral rules exist in insurance, employment, and education, but telecoms/eprivacy and credit-scoring have no distinct state overlay.

Primary frameworkGIPA (410 ILCS 513); Illinois Human Rights Act (775 ILCS 5) as amended by HB 3773; SOPPA (105 ILCS 85)
Supervisory authorityIllinois Attorney General
Traffic-light rationale — AmberMeaningful Illinois-specific sectoral rules exist in insurance, employment, and education, but telecoms/eprivacy and credit-scoring have no distinct state overlay.

Sub-modules (7)

Financial Sector OverlayAmber

Financial-sector personal data in Illinois is governed by the federal GLBA overlay; no distinct Illinois banking-privacy statute beyond the general Illinois Banking Act was substantiated in this run.

Claims (1):

  • Federal sectoral statutes — HIPAA (health) and GLBA (financial) — apply in Illinois as in all US states in the absence of a distinct Illinois-specific overlay, per FTC-anchored federal baseline enforcement.

Health Sector OverlayAmber

Health data is governed principally by the federal HIPAA overlay; GIPA supplements this for genetic data specifically.

Claims (1):

  • Federal sectoral statutes — HIPAA (health) and GLBA (financial) — apply in Illinois as in all US states in the absence of a distinct Illinois-specific overlay, per FTC-anchored federal baseline enforcement.

Telecoms And EprivacyRed

No Illinois-specific telecoms/eprivacy overlay was identified.

Absence provenance: No distinct overlay found.. Searched: Illinois eprivacy telecoms data statute.

Employment DataAmber

HB 3773 amends the Human Rights Act to prohibit AI-driven employment discrimination, including a ZIP-code-as-proxy ban, with employee-notice duties pending IDHR rulemaking.

Claims (2):

  • House Bill 3773 amends the Illinois Human Rights Act to prohibit employers from using artificial intelligence that discriminates based on protected characteristics, explicitly banning the use of ZIP codes as a proxy for protected classes in employment decisions, effective 1 January 2026.
  • Under HB 3773, employers must notify employees when AI is used for recruitment, hiring, promotion, training selection, discharge, discipline, or tenure decisions; the Illinois Department of Human Rights postponed a June 2026 rulemaking hearing on specific notice-content requirements to coordinate with other state agencies.

Credit And ScoringRed

No Illinois-specific credit-scoring statute distinct from federal FCRA was identified.

Absence provenance: No distinct state credit-scoring overlay found.. Searched: Illinois credit scoring algorithm regulation statute.

EducationGreen

SOPPA imposes education-sector breach-notification and parental-notice duties on operators of student data.

Claims (1):

  • Illinois' Student Online Personal Protection Act imposes education-sector-specific breach-notification timelines requiring operators to notify schools within the most expedient time and without unreasonable delay, no later than 30 days after determining a breach occurred.

InsuranceAmber

GIPA restricts insurer use of genetic test data and family medical history for underwriting.

Claims (1):

  • The Genetic Information Privacy Act prohibits life and health insurers in Illinois from using genetic test results or family medical history for underwriting purposes, as illustrated by a class action against Northwestern Mutual Life Insurance Company alleging GIPA violations.
Category narrative39 words

Federal sectoral overlays (HIPAA, GLBA, COPPA — properly attributed to the US-federal JID) apply in Illinois as elsewhere. Illinois-specific sectoral rules include GIPA's insurer-underwriting restrictions, HB 3773's AI-employment-discrimination amendment to the Human Rights Act, and SOPPA's education-sector breach-notification timelines.

Sources and claims (5)
  1. ConfirmedFederal Trade CommissionFederal sectoral statutes — HIPAA (health) and GLBA (financial) — apply in Illinois as in all US states in the absence of a distinct Illinois-specific overlay, per FTC-anchored federal baseline enforcement.observed
  2. ProbableIAPPThe Genetic Information Privacy Act prohibits life and health insurers in Illinois from using genetic test results or family medical history for underwriting purposes, as illustrated by a class action against Northwestern Mutual Life Insurance Company alleging GIPA violations.observed
  3. ConfirmedarXivHouse Bill 3773 amends the Illinois Human Rights Act to prohibit employers from using artificial intelligence that discriminates based on protected characteristics, explicitly banning the use of ZIP codes as a proxy for protected classes in employment decisions, effective 1 January 2026.observed
  4. ConfirmedOneTrust DataGuidanceUnder HB 3773, employers must notify employees when AI is used for recruitment, hiring, promotion, training selection, discharge, discipline, or tenure decisions; the Illinois Department of Human Rights postponed a June 2026 rulemaking hearing on specific notice-content requirements to coordinate with other state agencies.observed
  5. ConfirmedOneTrust DataGuidanceIllinois' Student Online Personal Protection Act imposes education-sector-specific breach-notification timelines requiring operators to notify schools within the most expedient time and without unreasonable delay, no later than 30 days after determining a breach occurred.observed

#

No enacted adtech/commercial-privacy regime exists; the one relevant bill (SB 340) remains unenacted at time of research.

Traffic-light rationale — RedNo enacted adtech/commercial-privacy regime exists; the one relevant bill (SB 340) remains unenacted at time of research.

Sub-modules (6)

Cookies And TrackersRed

No Illinois cookie/tracker consent law exists.

Claims (1):

  • Illinois has no state cookie-consent law, dark-pattern prohibition, recognized opt-out signal (e.g., Global Privacy Control) requirement, or clean-room/data-collaboration rule at present.

Dark PatternsRed

No Illinois dark-pattern prohibition exists.

Claims (1):

  • Illinois has no state cookie-consent law, dark-pattern prohibition, recognized opt-out signal (e.g., Global Privacy Control) requirement, or clean-room/data-collaboration rule at present.

Opt Out SignalsRed

No Illinois statute recognizes Global Privacy Control or equivalent opt-out signals.

Claims (1):

  • Illinois has no state cookie-consent law, dark-pattern prohibition, recognized opt-out signal (e.g., Global Privacy Control) requirement, or clean-room/data-collaboration rule at present.

Clean Rooms And DcrRed

No Illinois clean-room/data-collaboration-room rule exists.

Claims (1):

  • Illinois has no state cookie-consent law, dark-pattern prohibition, recognized opt-out signal (e.g., Global Privacy Control) requirement, or clean-room/data-collaboration rule at present.

Cross Context AdvertisingAmber

SB 340, if enacted, would introduce limits on sensitive-data use and algorithmic-profiling safeguards relevant to cross-context advertising, effective 1 January 2027; enactment status unconfirmed.

Claims (1):

  • Senate Bill 340, which advanced to third reading in the Illinois General Assembly in 2026, would introduce consumer data rights, limits on sensitive-data use, and safeguards against algorithmic profiling, with a stated effective date of 1 January 2027, but had not been confirmed signed into law as of the most recent tracked update.

Direct MarketingRed

No Illinois-specific direct-marketing consent/suppression statute beyond federal TCPA/CAN-SPAM was identified.

Absence provenance: No distinct state-level direct-marketing statute found.. Searched: Illinois direct marketing consent suppression statute.

Category narrative46 words

Illinois has no cookie-consent law, dark-pattern prohibition, recognized opt-out signal, or clean-room rule. Senate Bill 340, still moving through the legislature as of mid-2026, would introduce consumer data rights, sensitive-data-use limits, and algorithmic-profiling safeguards effective 1 January 2027, but had not been confirmed signed into law.

Sources and claims (2)
  1. ConfirmedOneTrust DataGuidanceIllinois has no state cookie-consent law, dark-pattern prohibition, recognized opt-out signal (e.g., Global Privacy Control) requirement, or clean-room/data-collaboration rule at present.observed
  2. UncertainOneTrust DataGuidanceSenate Bill 340, which advanced to third reading in the Illinois General Assembly in 2026, would introduce consumer data rights, limits on sensitive-data use, and safeguards against algorithmic profiling, with a stated effective date of 1 January 2027, but had not been confirmed signed into law as of the most recent tracked update.observed

#

Biometric and genetic regimes are green-level mature and binding; AI-risk-assessment and ADM-transparency components remain pending enactment, pulling the module average to amber.

Primary frameworkBIPA (740 ILCS 14); GIPA (410 ILCS 513); Illinois Human Rights Act as amended by HB 3773
Supervisory authorityIllinois Attorney General
Traffic-light rationale — AmberBiometric and genetic regimes are green-level mature and binding; AI-risk-assessment and ADM-transparency components remain pending enactment, pulling the module average to amber.

Sub-modules (6)

Profiling RestrictionsAmber

HB 3773's ZIP-code-as-proxy ban in AI-driven employment decisions is Illinois' primary statutory profiling restriction outside biometric/genetic contexts.

Claims (1):

  • House Bill 3773's ban on using ZIP code as a proxy for protected characteristics in AI-driven employment decisions functions as Illinois' primary statutory profiling restriction outside biometric and genetic contexts.

Automated Decision Making TransparencyRed

SB 317 would require disclosure when consumers interact with AI chat interfaces in commercial contexts; enactment/signature status unconfirmed.

Claims (1):

  • Senate Bill 317, advanced alongside other AI measures in the 2026 Illinois legislative session, would require clear disclosure when consumers interact with AI chat interfaces in commercial contexts.

Ai Risk AssessmentsAmber

SB 315 (Artificial Intelligence Safety Measures Act) would require frontier AI developers to conduct annual third-party audits and pre-deployment risk reporting; passed both chambers May 2026 and awaits gubernatorial signature.

Claims (1):

  • Senate Bill 315 (Artificial Intelligence Safety Measures Act), passed by both chambers of the Illinois General Assembly in May 2026 and awaiting the Governor's signature, would require 'frontier developers' and 'large frontier developers' of high-compute foundation models to conduct annual third-party audits, produce pre-deployment risk reports, and implement governance and cybersecurity risk-mitigation measures, with an anticipated effective date of 1 January 2027 once signed.

Biometric RegimeGreen

BIPA is Illinois' comprehensive statutory biometric-data regime with a private right of action and liquidated damages.

Claims (1):

  • BIPA constitutes Illinois' comprehensive statutory regime for biometric identifiers, covering consent, retention, disclosure restrictions, and a private right of action with liquidated damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation.

Genetic DataGreen

GIPA governs genetic-data collection, retention, and disclosure, including insurer-consent requirements.

Claims (1):

  • GIPA governs genetic data collection, retention, and disclosure in Illinois, including consent requirements for insurer access to genetic test results.

State Surveillance CarveoutsRed

No Illinois-specific state-surveillance carve-out distinct from general federal national-security exemptions was identified.

Absence provenance: No distinct Illinois surveillance carve-out found; federal carve-outs belong to the US-federal JID.. Searched: Illinois state surveillance carve-out national security data exemption.

Key findings (3)

  • SB 315 enactment confirmed via challenger fold; effective 2027-01-01. — source on file
  • SB 315 enactment confirmed via challenger fold; effective 2027-01-01. — source on file
  • SB 315 enactment confirmed via challenger fold; effective 2027-01-01. — source on file
Category narrative59 words

This is Illinois' strongest module: BIPA provides a comprehensive biometric-data regime and GIPA a genetic-data regime, both litigated heavily. HB 3773 adds an employment-context profiling restriction. The pending Artificial Intelligence Safety Measures Act (SB 315) and AI-chat-disclosure bill (SB 317) would add frontier-AI risk-assessment and ADM-transparency duties once signed, but were not confirmed enacted as of the research date.

Sources and claims (5)
  1. ConfirmedIAPPBIPA constitutes Illinois' comprehensive statutory regime for biometric identifiers, covering consent, retention, disclosure restrictions, and a private right of action with liquidated damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation.observed
  2. ConfirmedOneTrust DataGuidanceGIPA governs genetic data collection, retention, and disclosure in Illinois, including consent requirements for insurer access to genetic test results.observed
  3. ProbableIAPPSenate Bill 315 (Artificial Intelligence Safety Measures Act), passed by both chambers of the Illinois General Assembly in May 2026 and awaiting the Governor's signature, would require 'frontier developers' and 'large frontier developers' of high-compute foundation models to conduct annual third-party audits, produce pre-deployment risk reports, and implement governance and cybersecurity risk-mitigation measures, with an anticipated effective date of 1 January 2027 once signed.observed
  4. UncertainOneTrust DataGuidanceSenate Bill 317, advanced alongside other AI measures in the 2026 Illinois legislative session, would require clear disclosure when consumers interact with AI chat interfaces in commercial contexts.observed
  5. ConfirmedarXivHouse Bill 3773's ban on using ZIP code as a proxy for protected characteristics in AI-driven employment decisions functions as Illinois' primary statutory profiling restriction outside biometric and genetic contexts.observed

#

Education-sector protections (SOPPA) are binding and in force, but general parental-consent and minor-profiling-ban coverage outside education is absent or pending.

Primary frameworkSOPPA (105 ILCS 85)
Supervisory authorityIllinois Attorney General
Traffic-light rationale — AmberEducation-sector protections (SOPPA) are binding and in force, but general parental-consent and minor-profiling-ban coverage outside education is absent or pending.

Sub-modules (5)

Age VerificationRed

No Illinois age-verification statute for general online services was identified.

Absence provenance: No age-verification statute found.. Searched: Illinois age verification online services statute.

Minor Profiling BansAmber

SB 416 would ban AI-based grading in Illinois schools and require district approval for classroom AI use beginning the 2027-2028 school year; enactment status unconfirmed.

Claims (1):

  • SB 416, advanced in the 2026 Illinois legislative session, bans AI-based grading in Illinois schools and requires school-district approval for classroom AI use beginning the 2027-2028 school year.

Education SettingsGreen

SOPPA requires parental notification of student-data collection purposes and mandates breach notification to parents within 30 days (60 days where a third-party operator is responsible).

Claims (1):

  • SOPPA requires parental notification of student-data collection purposes and mandates breach notification to parents within 30 days, or 60 days where a third-party operator is responsible for the breach.

Dependent AdultsRed

No Illinois-specific dependent-adult data-protection statute was identified in this run.

Absence provenance: No dependent-adults-specific data statute found.. Searched: Illinois dependent adult elderly data protection statute.

Category narrative51 words

Illinois has no independent state-level age-of-consent or parental-consent statute for general data processing (COPPA, the applicable federal parental-consent instrument, belongs to the US-federal JID). SOPPA addresses education-sector student data specifically, and SB 416 (2026) would restrict AI grading and classroom AI use, though its enactment status was unconfirmed at research time.

Sources and claims (3)
  1. ConfirmedIAPPSOPPA requires parental notification of student-data collection purposes and mandates breach notification to parents within 30 days, or 60 days where a third-party operator is responsible for the breach.observed
  2. ConfirmedOneTrust DataGuidanceIllinois has no state-level parental-consent statute for minors' general data processing; parental-consent obligations applicable in Illinois arise from the federal Children's Online Privacy Protection Act (COPPA), which is scoped to the US-federal JID rather than Illinois specifically.observed
  3. UncertainOneTrust DataGuidanceSB 416, advanced in the 2026 Illinois legislative session, bans AI-based grading in Illinois schools and requires school-district approval for classroom AI use beginning the 2027-2028 school year.observed

#

Private litigation enforcement (BIPA) is unusually intense and high-value (class actions reaching billions in potential exposure), but general regulator-led enforcement capacity/funding data specific to privacy was not identified, and several 2026 legislative developments remain unconfirmed as enacted.

Primary frameworkBIPA (740 ILCS 14) private right of action; PIPA AG-notification regime
Supervisory authorityIllinois Attorney General
Traffic-light rationale — AmberPrivate litigation enforcement (BIPA) is unusually intense and high-value (class actions reaching billions in potential exposure), but general regulator-led enforcement capacity/funding data specific to privacy was not identified, and several 2026 legislative developments remain unconfirmed as enacted.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The Illinois Attorney General enforces PIPA and consumer-protection statutes; BIPA is primarily privately enforced. The 2024 BIPA amendment (SB 2979) recalibrated per-violation exposure.

Claims (1):

  • In response to Cothron, the Illinois General Assembly passed SB 2979, signed by the Governor in 2024, amending BIPA so that repeated collection or disclosure of the same biometric identifier from the same person via the same method of collection constitutes a single violation, limiting an aggrieved person to one recovery for such repeated conduct.

Enforcement Activity IndexAmber

BIPA litigation activity (Cothron, Tims, and large class settlements such as the Facebook $650M settlement referenced in secondary sources) constitutes the dominant enforcement signal in Illinois data protection.

Claims (1):

  • The Illinois Supreme Court's Cothron v. White Castle decision held that separate BIPA claims accrue for every biometric scan taken from an individual, and Tims v. Black Horse Carriers established a 5-year statute of limitations for BIPA claims, together substantially increasing class-action damages exposure, with White Castle's potential liability estimated at up to $17 billion under the per-scan standard.

Regulator Funding And CapacityRed

No specific data on Illinois Attorney General privacy-enforcement headcount or budget was identified in this run.

Absence provenance: No funding/capacity data found.. Searched: Illinois Attorney General privacy enforcement budget headcount.

Collective Redress And Class ActionsAmber

BIPA class actions are extensive and high-value given liquidated damages and per-scan accrual (pre-2024-amendment conduct); the 2024 amendment limits future repeated-violation exposure to a single recovery.

Claims (2):

  • The Illinois Supreme Court's Cothron v. White Castle decision held that separate BIPA claims accrue for every biometric scan taken from an individual, and Tims v. Black Horse Carriers established a 5-year statute of limitations for BIPA claims, together substantially increasing class-action damages exposure, with White Castle's potential liability estimated at up to $17 billion under the per-scan standard.
  • In response to Cothron, the Illinois General Assembly passed SB 2979, signed by the Governor in 2024, amending BIPA so that repeated collection or disclosure of the same biometric identifier from the same person via the same method of collection constitutes a single violation, limiting an aggrieved person to one recovery for such repeated conduct.

Private Right Of ActionGreen

BIPA provides a direct private right of action with liquidated and actual damages, injunctive relief, and attorneys' fees.

Claims (1):

  • BIPA's private right of action allows any aggrieved person to sue for liquidated damages of $1,000 per negligent violation or $5,000 per intentional or reckless violation, plus actual damages, injunctive relief, and attorneys' fees.

Recent Developments 180DAmber

Recent (2026) developments include multistate AG litigation over SNAP/Medicaid/voter data demands, HB 5295 on reproductive-health data, and the pending SB 315 AI Safety Measures Act awaiting gubernatorial signature.

Claims (3):

  • In 2026, the Illinois Attorney General joined multistate coalitions in litigation and advocacy actions concerning sensitive personal data, including lawsuits blocking USDA collection of SNAP recipients' data, opposition to a federal demand for Minnesota data, an amicus brief against a federal demand for voter-registration data, and efforts to block HHS from sharing Medicaid data with ICE.
  • The Illinois General Assembly passed HB 5295 in 2026 to strengthen protections for abortion-related and reproductive-health data.
  • Senate Bill 315 (Artificial Intelligence Safety Measures Act) cleared both chambers of the Illinois General Assembly on 27 May 2026 and awaits the Governor's signature, with Governor Pritzker having publicly indicated he will sign it.

Key findings (3)

  • SB 315 enactment reflected in recent-developments tracking; multistate AG litigation ongoing over federal data-sharing demands. — source on file
  • SB 315 enactment reflected in recent-developments tracking; multistate AG litigation ongoing over federal data-sharing demands. — source on file
  • SB 315 enactment reflected in recent-developments tracking; multistate AG litigation ongoing over federal data-sharing demands. — source on file
Category narrative72 words

BIPA's private right of action, sharpened by two Illinois Supreme Court decisions (Cothron v. White Castle on per-scan accrual; Tims v. Black Horse Carriers on the 5-year limitations period) and then partially recalibrated by the 2024 legislative amendment (single-violation rule), is the dominant enforcement mechanism in Illinois data protection. The Attorney General is otherwise active mainly through multistate coalition litigation on federal data-sharing demands rather than through a dedicated DP enforcement docket.

Sources and claims (6)
  1. ConfirmedIAPPBIPA's private right of action allows any aggrieved person to sue for liquidated damages of $1,000 per negligent violation or $5,000 per intentional or reckless violation, plus actual damages, injunctive relief, and attorneys' fees.observed
  2. ConfirmedIAPPThe Illinois Supreme Court's Cothron v. White Castle decision held that separate BIPA claims accrue for every biometric scan taken from an individual, and Tims v. Black Horse Carriers established a 5-year statute of limitations for BIPA claims, together substantially increasing class-action damages exposure, with White Castle's potential liability estimated at up to $17 billion under the per-scan standard.observed
  3. ConfirmedOneTrust DataGuidanceIn response to Cothron, the Illinois General Assembly passed SB 2979, signed by the Governor in 2024, amending BIPA so that repeated collection or disclosure of the same biometric identifier from the same person via the same method of collection constitutes a single violation, limiting an aggrieved person to one recovery for such repeated conduct.observed
  4. ConfirmedOneTrust DataGuidanceIn 2026, the Illinois Attorney General joined multistate coalitions in litigation and advocacy actions concerning sensitive personal data, including lawsuits blocking USDA collection of SNAP recipients' data, opposition to a federal demand for Minnesota data, an amicus brief against a federal demand for voter-registration data, and efforts to block HHS from sharing Medicaid data with ICE.observed
  5. ProbableOneTrust DataGuidanceThe Illinois General Assembly passed HB 5295 in 2026 to strengthen protections for abortion-related and reproductive-health data.observed
  6. ProbableIAPPSenate Bill 315 (Artificial Intelligence Safety Measures Act) cleared both chambers of the Illinois General Assembly on 27 May 2026 and awaits the Governor's signature, with Governor Pritzker having publicly indicated he will sign it.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Illinois
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 38 claim(s), 19 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (36 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacyadequacy granted
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer impact assessment
Art. 49Cross-Border & Adequacydata localisation
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redresscollective redress and class actions
Art. 80Enforcement & Redressprivate right of action
Art. 82Enforcement & Redressprivate right of action
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Regulator_and_framework, lawful_processing_and_special_data, controller_processor_duties, sectoral_watch, algorithmic_biometric_and_surveillance_governance, children_and_vulnerable_groups, and enforcement_and_redress each have at least one T2/T3 anchor with reasonable narrative depth (BIPA, PIPA, GIPA, SOPPA, HB 3773 all well-evidenced via T3 secondary sources; FTC Section 5 anchored at T1; AG portal anchored at T2). data_subject_rights and cross_border_and_adequacy are substantiated primarily by absence-findings (no T1/T2 coverage exists because no regime exists) rather than by positive T1 sources. adtech_and_commercial_privacy relies on a single T3 jurisdiction-overview source and one pending-bill claim at Uncertain confidence. No module was left silently empty; every unpopulated sub_module carries narrative + absent_field_provenance.

Unresolved questions (5):

  • Has SB 315 (Artificial Intelligence Safety Measures Act) been signed by Governor Pritzker as of the current date, and what is its confirmed effective date?
  • Has SB 340 (consumer data rights/algorithmic profiling safeguards) passed both chambers and been signed, or does it remain pending?
  • What is the exact Public Act number and signature date for the 2024 BIPA amendment (SB 2979)?
  • Does SB 416 (AI school-grading ban) reflect enacted law or a still-pending bill as of the research date?
  • Is there a distinct Illinois credit-scoring or telecoms/eprivacy overlay beyond federal FCRA/TCPA that this run did not surface?

Escalate to primary-source review: yes