Mandated Timeframe
Without unreasonable delay
Violations
$100 up to $50,000
![]() |
![]() |
---|---|
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
---|
Breach Reporting Requirements
Consumer Notification Requirements
Vendor Notification of Breach
Vendor Specific Obligations
Vendor Mandated Contracts
Protection/Security
Employee Training
Vendor Protection/Security Program
Personal Information Protection
Data Disposal of Personal Information
Mandated Timeframe
Without unreasonable delay
Violations
$100 up to $50,000
![]() Reporting |
![]() Notifications |
---|---|
![]() Management |
![]() Contract Required |
![]() |
![]() |
![]() |
![]() |
---|
Breach Reporting Requirements
Consumer Notification Requirements
Vendor Notification of Breach
Vendor Specific Obligations
Vendor Mandated Contracts
Protection/Security
Employee Training
Vendor Protection/Security Program
Personal Information Protection
Data Disposal of Personal Information
Mandated Timeframe
Without unreasonable delay
Violations
$100 up to $50,000
![]() Reporting |
![]() Notifications |
---|---|
![]() Management |
![]() Contract Required |
![]() |
![]() |
![]() |
![]() |
---|
Breach Reporting Requirements
Consumer Notification Requirements
Vendor Notification of Breach
Vendor Specific Obligations
Vendor Mandated Contracts
Protection/Security
Employee Training
Vendor Protection/Security Program
Personal Information Protection
Data Disposal of Personal Information
Organizations must contract with Vendors if they disclose personal information including data disposal vendors. Organizations and their contracted vendors must implement and maintain reasonable security measures to protect personal information from unauthorized access, acquisition, destruction, use, modification, or disclosure and must have measures in place for the secure disposal of personal information making so it cannot be read or reconstructed. Organizations in possession of biometric identifiers must ensure measures are in place for the storage, disclosure and protection of biometric identifiers. In addition, they must have a publicly available written policy that states their retention schedule and disposal guidelines.
Sector-specific regulations provide for an individual’s right to access their personal information. A private right of action can be brought with fines up to $5,000 or actual damages for violations of the Biometric Information Privacy Act.
Organizations that experience a breach, internally or through a third party, are responsible for all regulatory reporting and consumer notification for breaches of personal information involving more than 500 Illinois residents. Reporting must be submitted to the Attorney General without delay, but no later than when the breach notification is provided to affected consumers. Reporting must include the nature of the breach, the number of affected residents and any mitigation actions. Vendors must notify Organizations upon discovery of a breach or suspected breach. Vendors must cooperate with Organizations and provide all necessary information relative to the breach or suspected breach.
If your breach affects residents in other jurisdictions, those individuals must be notified based on the breach notification laws of the jurisdiction where they reside.
Vendors contracted to dispose of an Organization’s records containing personal information must maintain policies and procedures for the protection of the records from unauthorized access, acquisition, or use while in the Vendor’s possession and during disposal.
Violations of the Personal Information Protection regulations constitute an unlawful practice under the Illinois Consumer Fraud and Deceptive Business Practices Act. Violations of the disposal regulations may result in a civil penalty of up to $100 for each affected individual, up to $50,000 for each instance of improper disposal. The Attorney General may publish the names of organizations who experience a data breach, type of information involved, including data range. Organizations may be fined or penalized for Vendor violations.
Illinois
Entities subject to the federal Health Insurance Portability and Accountability Act of 1996
Cookie | Duration | Description |
---|---|---|
cookielawinfo-checbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
cookielawinfo-checbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
cookielawinfo-checbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |