Illinois
Illinois Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 7 primary sources cited on this page. How we verify our legal content

Under the Illinois Personal Information Protection Act, 815 ILCS 530/10, any data collector that suffers a security breach must notify affected Illinois residents in the most expedient time possible and without unreasonable delay. No fixed day count applies; the standard is reasonableness.
If your business handles personal data belonging to Illinois residents, a security breach triggers mandatory notification obligations under state law. The Personal Information Protection Act (815 ILCS 530), often called PIPA, requires prompt notice to affected individuals and, in many cases, to the Illinois Attorney General. Illinois stands out among states because its broad definition of personal information includes biometric data, and a separate law, the Biometric Information Privacy Act (BIPA), adds additional obligations for biometric-related incidents.
This guide explains who must comply, what triggers notification, how to report, and what penalties apply under current Illinois data privacy law.
Who Must Comply With Illinois Breach Notification Law
The law applies to any "data collector" that owns or licenses computerized data containing personal information of Illinois residents. Section 5 of 815 ILCS 530 defines data collector broadly. It includes state and local government agencies, universities, corporations, financial institutions, retail operators, and any other entity that handles, collects, disseminates, or otherwise deals with nonpublic personal information.
Third-party service providers that maintain data on behalf of another entity must notify the data owner or licensee immediately after discovering a breach. The data owner then carries the direct obligation to notify affected residents.
Entities With Separate Compliance Frameworks
Section 50 of 815 ILCS 530 provides that entities subject to the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health Act (HITECH) are deemed in compliance with the Act if they follow their federal breach notification procedures. These entities must still notify the Illinois Attorney General within five business days of notifying the U.S. Secretary of Health and Human Services.
Financial institutions subject to and in compliance with the data-security standards under Section 501(b) of the Gramm-Leach-Bliley Act are deemed compliant only with Section 45 of 815 ILCS 530, the reasonable-security-measures requirement. That carve-out does not extend to the Section 10 and Section 12 breach-notification duties. A GLBA-regulated financial institution that experiences a breach must still notify affected Illinois residents, and the Attorney General where the applicable threshold is met, the same as any other data collector.
What Qualifies as a Breach of Security
Under Section 5 of 815 ILCS 530, a "breach of the security of the system data" means the unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by the data collector.
The statute focuses on unauthorized acquisition rather than mere unauthorized access. An employee who encounters personal information during normal job duties has not triggered a breach, provided the information is not used for an unauthorized purpose or shared without authorization.
The Encryption Safe Harbor
Illinois provides an encryption safe harbor. If the compromised personal information was encrypted and the encryption key was not acquired by the unauthorized party, the data collector is not required to send breach notifications.
This means organizations that encrypt personal data both at rest and in transit can avoid notification obligations, but only if the encryption keys remain secure. If an attacker obtains both the encrypted data and the decryption key, the full notification requirements apply.
Personal Information That Triggers Notification
Illinois defines personal information in two categories under Section 5 of 815 ILCS 530.
Category 1 requires the individual's first name or first initial and last name combined with any one or more of the following data elements:
- Social Security number
- Driver's license number or state identification card number
- Financial account number, credit card number, or debit card number, either alone or in combination with any required security code, access code, or password that would permit access to a financial account
- Medical information, including any data regarding an individual's medical history, mental or physical condition, or diagnosis or treatment by a healthcare professional
- Health insurance information, including policy or subscriber numbers, unique identifiers, and any medical information in applications, claims histories, or appeals records
- Unique biometric data generated from measurements or analysis of human body characteristics used for authentication, including fingerprints, retina or iris images, and other unique physical or digital representations of biometric data

Category 2 covers a resident's username or email address combined with a password or security question and answer that would permit access to an online account. This category does not require the individual's name.
Personal information does not include publicly available data lawfully obtained from federal, state, or local government records.
Biometric Data and BIPA Overlap
Illinois is one of only a few states that includes biometric data in its breach notification trigger. This creates dual obligations when biometric information is compromised. A breach involving fingerprints, facial scans, or iris images triggers notification under 815 ILCS 530, and may also expose the organization to a private right of action under BIPA (740 ILCS 14) if the data was collected without proper consent.
In August 2024, Governor Pritzker signed SB 2979 amending BIPA to clarify that multiple violations involving the same person's biometric data constitute a single violation, limiting per-person damages. This narrowed exposure under BIPA but did not change the breach notification requirements under 815 ILCS 530.
Notification Timeline and Requirements
When to Notify
Section 10 of 815 ILCS 530 requires notification "in the most expedient time possible and without unreasonable delay." Unlike many states that set a specific day count (such as 30 or 60 days), Illinois uses a reasonableness standard.
The clock starts after the data collector discovers or is notified of the breach. The statute permits delay only to determine the scope of the breach and restore system integrity, or when law enforcement provides a written request that notification would interfere with a criminal investigation.
Who Receives Notification

Affected residents must receive individual notice at no charge. Notification must include:
- A description of the breach
- Toll-free numbers for consumer reporting agencies
- FTC contact information
- Guidance on placing fraud alerts and security freezes
For breaches involving usernames and passwords, the notice may direct residents to change their credentials promptly and take steps to protect linked accounts.

Illinois Attorney General: Private data collectors must notify the AG when a breach affects more than 500 Illinois residents. State agencies must notify the AG when more than 250 residents are affected. The AG notification must include the nature of the breach, the number of Illinois residents affected, and the steps taken or planned in response.
Credit reporting agencies: State agencies must notify all nationwide consumer reporting agencies when more than 1,000 individuals are affected.
How to Notify
The law permits three methods of individual notice under Section 10(c):
- Written notice sent to the resident's last known address
- Electronic notice that complies with the federal Electronic Signatures in Global and National Commerce Act (E-SIGN)
- Substitute notice when the cost of direct notification exceeds $250,000, more than 500,000 Illinois residents are affected, or the data collector lacks sufficient contact information. Substitute notice requires email (if available), conspicuous posting on the data collector's website, and notification to statewide media
To report a breach to the Attorney General, businesses use the OAG Data Breach Notice System or email Datasecurity@ilag.gov.
State Agency Requirements
Illinois state agencies carry additional obligations beyond the lower AG notification threshold of more than 250 residents:
- Report the breach to the General Assembly within 5 business days of discovering or being notified of it, under Section 25 of 815 ILCS 530
- Submit an annual report listing all breaches and the corrective measures taken to prevent future breaches, also under Section 25
- Notify the AG within 45 days of discovering the breach, under Section 12(e) of 815 ILCS 530
Separately, if a state agency determines the identity of the actor responsible for a breach, Section 12(f) of 815 ILCS 530 requires the agency to report that identity to the General Assembly within 5 days of making the determination, in addition to the routine breach report above. These additional reporting layers reflect the heightened accountability expected of government data custodians.
Enforcement and Penalties

Consumer Fraud Act Enforcement
Section 20 of 815 ILCS 530 declares that any violation of the Personal Information Protection Act constitutes an unlawful practice under the Consumer Fraud and Deceptive Business Practices Act (815 ILCS 505). This gives the Illinois Attorney General broad enforcement authority.
Under Section 7 of 815 ILCS 505, the AG can seek:
- Injunctive relief to stop ongoing violations
- A civil penalty of up to $50,000 for engaging in an unlawful practice, with no per-violation multiplier
- A civil penalty of up to $50,000 per violation in place of that baseline, but only where the court finds the practice was entered into with intent to defraud
- An additional penalty of up to $10,000 for each violation committed against a person 65 years of age or older
- Restitution for affected consumers, which takes priority over civil penalties
Private Right of Action
The Personal Information Protection Act does not create a direct private right of action. Individuals cannot sue a data collector solely for failing to notify them of a breach. However, consumers can bring claims under the Consumer Fraud and Deceptive Business Practices Act if they can demonstrate actual damages resulting from the violation.
When a breach involves biometric data, affected individuals may have a separate cause of action under BIPA (740 ILCS 14), which does provide a private right of action with statutory damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation.
Data Disposal Penalties
Section 40 of 815 ILCS 530 requires that personal information be rendered unreadable and undecipherable when disposed of, through shredding, burning, pulverizing, or electronic destruction. Violations carry civil penalties of up to $100 per individual affected, capped at $50,000 per disposal instance.
Notable Illinois Breach Enforcement Actions
The Illinois Attorney General's office has actively enforced data breach requirements through multistate and state-level actions.
In a notable settlement, Attorney General Kwame Raoul joined a 50-state coalition that reached a $52 million agreement with Marriott International over the Starwood reservation database breach. From 2014 to 2018, intruders accessed approximately 131.5 million guest records. Illinois received $2.1 million from the settlement. Marriott agreed to implement a comprehensive information security program with zero-trust principles, mandatory third-party audits every two years for 20 years, and consumer protections including data deletion options.
Data Security Requirements
Beyond breach notification, Section 45 of 815 ILCS 530 requires all data collectors to implement and maintain reasonable security measures to protect personal information from unauthorized access, acquisition, destruction, use, modification, or disclosure. While the statute does not prescribe specific technical standards, failing to maintain reasonable security and subsequently suffering a breach strengthens the AG's enforcement position.
This article provides general legal information about Illinois data breach notification requirements. It does not constitute legal advice. Consult a qualified attorney licensed in Illinois for guidance on specific situations.
More Illinois Laws
Frequently Asked Questions
How quickly must an Illinois business report a data breach?
Illinois law requires notification in the most expedient time possible and without unreasonable delay after discovering a breach. There is no fixed day count like some states impose. The data collector may delay briefly to determine the breach scope and restore system integrity, or if law enforcement requests a delay in writing for a criminal investigation.
When must a business notify the Illinois Attorney General of a breach?
Private data collectors must notify the Illinois Attorney General when a breach affects more than 500 Illinois residents. State agencies have a lower threshold, needing to notify when more than 250 residents are affected. The notification should be submitted through the OAG Data Breach Notice System or by emailing Datasecurity@ilag.gov.
Does Illinois have an encryption safe harbor for data breaches?
Yes. If the compromised data was encrypted and the encryption key was not also acquired by the unauthorized party, the data collector does not need to send breach notifications. However, if both the encrypted data and the decryption key were compromised, the full notification requirements apply.
Can individuals sue over a data breach in Illinois?
The Personal Information Protection Act does not provide a direct private right of action. However, individuals can bring claims under the Consumer Fraud and Deceptive Business Practices Act if they demonstrate actual damages. If biometric data was involved, a separate private right of action exists under BIPA with statutory damages of $1,000 to $5,000 per violation.
How does Illinois's breach notification law interact with BIPA?
A breach involving biometric data triggers dual obligations. The Personal Information Protection Act requires standard breach notification. If the biometric data was collected without proper consent under BIPA, the affected individual may also pursue a private lawsuit with statutory damages. The 2024 SB 2979 amendment to BIPA limits per-person exposure by treating multiple violations involving the same person as a single violation.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the definition of financial data that triggers notification, re-attributed the state-agency General Assembly and annual reporting duties to 815 ILCS 530/25, and restated the Consumer Fraud Act civil penalty so the $50,000 per-violation figure is shown as applying only on a finding of intent to defraud.
Corrected the Gramm-Leach-Bliley Act carve-out, which only excuses compliant financial institutions from PIPA's data-security duty, not from Illinois breach-notification duties; fixed four Attorney General/credit-reporting-agency notification thresholds from inclusive wording ("500 or more", "250 or more", "1,000 or more") to the statute's exact exclusive wording ("more than 500", "more than 250", "more than 1,000"); re-pointed a threshold citation to the statute; and clarified the separate, unthresholded state-agency threat-actor reporting duty under 815 ILCS 530/12(f).
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Illinois Compiled Statutes Chapter 815, Act 530 (Personal Information Protection Act)
§ 10Notice of breach; notice to Attorney GeneralIn force
(a) Any data collector that owns or licenses personal information concerning an Illinois resident shall notify the resident at no charge that there has been a breach of the security of the system data following discovery or notification of the breach. The disclosure notification shall be made in the most expedient time possible and without unreasonable delay, consistent with any measures necessary to determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system. The disclosure notification to an Illinois resident shall include, but need not be limited to, information as follows: (1) With respect to personal information as defined in Section 5 in paragraph (1) of the definition of "personal information": (A) the toll-free numbers and addresses for consumer reporting agencies; (B) the toll-free number, address, and website address for the Federal Trade Commission; and (C) a statement that the individual can obtain information from these sources about fraud alerts and security freezes.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at ilga.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Personal Information Protection Act(ilga.gov).gov
- Illinois Attorney General Data Breach Reporting(illinoisattorneygeneral.gov).gov
- Consumer Fraud and Deceptive Business Practices Act(ilga.gov).gov
- Consumer Fraud Act Section 7 - Penalties(ilga.gov).gov
- Biometric Information Privacy Act (740 ILCS 14)(ilga.gov).gov
- SB 2979 - BIPA Amendment(ilga.gov).gov
- Marriott Data Breach Settlement(illinoisattorneygeneral.gov).gov
- 815 ILCS 530/25 - Annual reporting (State agency breach reports to the General Assembly)(ilga.gov)
- 815 ILCS 530/12 - Notice of breach by State agencies(ilga.gov)
- 815 ILCS 530/5 - Definitions, including personal information(ilga.gov)