EnglishEspañol
Illinois flag

Illinois

Illinois Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 7 primary sources cited on this page. How we verify our legal content

Illinois Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must an Illinois business report a data breach?

Illinois law requires notification in the most expedient time possible and without unreasonable delay after discovering a breach. There is no fixed day count like some states impose. The data collector may delay briefly to determine the breach scope and restore system integrity, or if law enforcement requests a delay in writing for a criminal investigation.

When must a business notify the Illinois Attorney General of a breach?

Private data collectors must notify the Illinois Attorney General when a breach affects more than 500 Illinois residents. State agencies have a lower threshold, needing to notify when more than 250 residents are affected. The notification should be submitted through the OAG Data Breach Notice System or by emailing Datasecurity@ilag.gov.

Does Illinois have an encryption safe harbor for data breaches?

Yes. If the compromised data was encrypted and the encryption key was not also acquired by the unauthorized party, the data collector does not need to send breach notifications. However, if both the encrypted data and the decryption key were compromised, the full notification requirements apply.

Can individuals sue over a data breach in Illinois?

The Personal Information Protection Act does not provide a direct private right of action. However, individuals can bring claims under the Consumer Fraud and Deceptive Business Practices Act if they demonstrate actual damages. If biometric data was involved, a separate private right of action exists under BIPA with statutory damages of $1,000 to $5,000 per violation.

How does Illinois's breach notification law interact with BIPA?

A breach involving biometric data triggers dual obligations. The Personal Information Protection Act requires standard breach notification. If the biometric data was collected without proper consent under BIPA, the affected individual may also pursue a private lawsuit with statutory damages. The 2024 SB 2979 amendment to BIPA limits per-person exposure by treating multiple violations involving the same person as a single violation.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the definition of financial data that triggers notification, re-attributed the state-agency General Assembly and annual reporting duties to 815 ILCS 530/25, and restated the Consumer Fraud Act civil penalty so the $50,000 per-violation figure is shown as applying only on a finding of intent to defraud.

Corrected the Gramm-Leach-Bliley Act carve-out, which only excuses compliant financial institutions from PIPA's data-security duty, not from Illinois breach-notification duties; fixed four Attorney General/credit-reporting-agency notification thresholds from inclusive wording ("500 or more", "250 or more", "1,000 or more") to the statute's exact exclusive wording ("more than 500", "more than 250", "more than 1,000"); re-pointed a threshold citation to the statute; and clarified the separate, unthresholded state-agency threat-actor reporting duty under 815 ILCS 530/12(f).

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Personal Information Protection Act(ilga.gov).gov
  2. Illinois Attorney General Data Breach Reporting(illinoisattorneygeneral.gov).gov
  3. Consumer Fraud and Deceptive Business Practices Act(ilga.gov).gov
  4. Consumer Fraud Act Section 7 - Penalties(ilga.gov).gov
  5. Biometric Information Privacy Act (740 ILCS 14)(ilga.gov).gov
  6. SB 2979 - BIPA Amendment(ilga.gov).gov
  7. Marriott Data Breach Settlement(illinoisattorneygeneral.gov).gov
  8. 815 ILCS 530/25 - Annual reporting (State agency breach reports to the General Assembly)(ilga.gov)
  9. 815 ILCS 530/12 - Notice of breach by State agencies(ilga.gov)
  10. 815 ILCS 530/5 - Definitions, including personal information(ilga.gov)
Share: