#
No omnibus statute exists (which would justify red for a comprehensive-rights gap), but Illinois runs an unusually dense and binding sectoral regime (BIPA in particular) with real enforcement teeth, so amber better reflects material sector-specific exposure within a non-omnibus structure.
Sub-modules (5)
Regulator And AuthorityAmber
The Illinois Attorney General enforces PIPA, BIPA-adjacent consumer-protection matters, and GIPA; the FTC provides a federal backstop under Section 5.
Claims (1):
- The Illinois Attorney General is the primary state enforcement authority for privacy-adjacent statutes including BIPA, PIPA, and GIPA, and coordinates breach-notification enforcement.
Act And InstrumentsAmber
Core instruments are BIPA, PIPA, and GIPA; no omnibus act exists.
Claims (3):
- Illinois has no comprehensive consumer data-protection/privacy statute; data-protection obligations arise from a patchwork of sectoral statutes (BIPA, PIPA breach-notification, GIPA, SOPPA) plus federal FTC Act Section 5 enforcement.
- The Biometric Information Privacy Act (740 ILCS 14), in effect since 2008, is the first comprehensive biometric-privacy statute in the United States and imposes written-consent, retention, and disclosure requirements on private entities handling biometric identifiers of Illinois residents.
- Illinois' Personal Information Protection Act (815 ILCS 530) requires data collectors to notify affected Illinois residents and, since a 2019 amendment (SB 1624, effective 1 January 2020), the Illinois Attorney General for breaches affecting more than 500 residents.
Material ScopeAmber
Material scope is defined statute-by-statute: BIPA covers biometric identifiers/information; PIPA covers breach of 'personal information' as statutorily defined; GIPA covers genetic test data.
Claims (1):
- The Biometric Information Privacy Act (740 ILCS 14), in effect since 2008, is the first comprehensive biometric-privacy statute in the United States and imposes written-consent, retention, and disclosure requirements on private entities handling biometric identifiers of Illinois residents.
Territorial ScopeAmber
BIPA does not expressly state its territorial scope but has been construed to reach any entity, wherever located, that collects biometric data of Illinois residents.
Claims (1):
- BIPA does not expressly define its territorial scope but has been applied to any private entity, established or not in Illinois, that collects or possesses biometric identifiers or information of Illinois residents.
Regulator Registration And FilingRed
No controller registration or filing regime exists in Illinois for general data processing.
Absence provenance: No registration/filing obligation identified for general data controllers in Illinois.. Searched: Illinois data protection controller registration requirement, Illinois Attorney General privacy filing obligation.
Sources and claims (5)
- ConfirmedOneTrust DataGuidance — Illinois has no comprehensive consumer data-protection/privacy statute; data-protection obligations arise from a patchwork of sectoral statutes (BIPA, PIPA breach-notification, GIPA, SOPPA) plus federal FTC Act Section 5 enforcement.observed
- ConfirmedIAPP — The Illinois Attorney General is the primary state enforcement authority for privacy-adjacent statutes including BIPA, PIPA, and GIPA, and coordinates breach-notification enforcement.observed
- ConfirmedIAPP — The Biometric Information Privacy Act (740 ILCS 14), in effect since 2008, is the first comprehensive biometric-privacy statute in the United States and imposes written-consent, retention, and disclosure requirements on private entities handling biometric identifiers of Illinois residents.observed
- ProbableIAPP — BIPA does not expressly define its territorial scope but has been applied to any private entity, established or not in Illinois, that collects or possesses biometric identifiers or information of Illinois residents.observed
- ConfirmedIAPP — Illinois' Personal Information Protection Act (815 ILCS 530) requires data collectors to notify affected Illinois residents and, since a 2019 amendment (SB 1624, effective 1 January 2020), the Illinois Attorney General for breaches affecting more than 500 residents.observed