104TH GENERAL ASSEMBLY
State of Illinois
2025 and 2026
SB1995

 

Introduced 2/6/2025, by Sen. Graciela Guzmán

 

SYNOPSIS AS INTRODUCED:
 
815 ILCS 530/5
815 ILCS 530/45

    Amends the Personal Information Protection Act. Provides that a data collector shall not own, maintain, license, store, or disclose records that contain immigration or citizenship status information concerning an Illinois resident. Provides that the provision shall not apply to government agencies, public and private universities, or financial institutions. Provides that the definition of "personal information" includes immigration or citizenship status information. Defines "immigration or citizenship status information".


LRB104 10883 SPS 20965 b

 

 

A BILL FOR

 

SB1995LRB104 10883 SPS 20965 b

1    AN ACT concerning business.
 
2    Be it enacted by the People of the State of Illinois,
3represented in the General Assembly:
 
4    Section 5. The Personal Information Protection Act is
5amended by changing Sections 5 and 45 as follows:
 
6    (815 ILCS 530/5)
7    Sec. 5. Definitions. In this Act:
8    "Data collector" may include, but is not limited to,
9government agencies, public and private universities,
10privately and publicly held corporations, financial
11institutions, retail operators, and any other entity that, for
12any purpose, handles, collects, disseminates, or otherwise
13deals with nonpublic personal information.
14    "Breach of the security of the system data" or "breach"
15means unauthorized acquisition of computerized data that
16compromises the security, confidentiality, or integrity of
17personal information maintained by the data collector. "Breach
18of the security of the system data" does not include good faith
19acquisition of personal information by an employee or agent of
20the data collector for a legitimate purpose of the data
21collector, provided that the personal information is not used
22for a purpose unrelated to the data collector's business or
23subject to further unauthorized disclosure.

 

 

SB1995- 2 -LRB104 10883 SPS 20965 b

1    "Health insurance information" means an individual's
2health insurance policy number or subscriber identification
3number, any unique identifier used by a health insurer to
4identify the individual, or any medical information in an
5individual's health insurance application and claims history,
6including any appeals records.
7    "Immigration or citizenship status information" means any
8information concerning: (i) the status of an individual's
9citizenship of the United States or any other country; or (ii)
10the legal right, or lack thereof, of an individual to reside in
11or otherwise to be present in the United States. "Immigration
12or citizenship status information" includes an individual's
13nationality and country of origin.
14    "Medical information" means any information regarding an
15individual's medical history, mental or physical condition, or
16medical treatment or diagnosis by a healthcare professional,
17including such information provided to a website or mobile
18application.
19    "Personal information" means either of the following:
20        (1) An individual's first name or first initial and
21    last name in combination with any one or more of the
22    following data elements, when either the name or the data
23    elements are not encrypted or redacted or are encrypted or
24    redacted but the keys to unencrypt or unredact or
25    otherwise read the name or data elements have been
26    acquired without authorization through the breach of

 

 

SB1995- 3 -LRB104 10883 SPS 20965 b

1    security:
2            (A) Social Security number.
3            (B) Driver's license number or State
4        identification card number.
5            (C) Account number or credit or debit card number,
6        or an account number or credit card number in
7        combination with any required security code, access
8        code, or password that would permit access to an
9        individual's financial account.
10            (D) Medical information.
11            (E) Health insurance information.
12            (F) Unique biometric data generated from
13        measurements or technical analysis of human body
14        characteristics used by the owner or licensee to
15        authenticate an individual, such as a fingerprint,
16        retina or iris image, or other unique physical
17        representation or digital representation of biometric
18        data.
19            (G) Immigration or citizenship status information.
20        (2) User name or email address, in combination with a
21    password or security question and answer that would permit
22    access to an online account, when either the user name or
23    email address or password or security question and answer
24    are not encrypted or redacted or are encrypted or redacted
25    but the keys to unencrypt or unredact or otherwise read
26    the data elements have been obtained through the breach of

 

 

SB1995- 4 -LRB104 10883 SPS 20965 b

1    security.
2    "Personal information" does not include publicly available
3information that is lawfully made available to the general
4public from federal, State, or local government records.
5(Source: P.A. 99-503, eff. 1-1-17.)
 
6    (815 ILCS 530/45)
7    Sec. 45. Data security.
8    (a) A data collector that owns or licenses, or maintains
9or stores but does not own or license, records that contain
10personal information concerning an Illinois resident shall
11implement and maintain reasonable security measures to protect
12those records from unauthorized access, acquisition,
13destruction, use, modification, or disclosure.
14    (a-5) A data collector shall not own, maintain, license,
15store, or disclose records that contain immigration or
16citizenship status information concerning an Illinois
17resident. This subsection shall not apply to government
18agencies, public and private universities, or financial
19institutions.
20    (b) A contract for the disclosure of personal information
21concerning an Illinois resident that is maintained by a data
22collector must include a provision requiring the person to
23whom the information is disclosed to implement and maintain
24reasonable security measures to protect those records from
25unauthorized access, acquisition, destruction, use,

 

 

SB1995- 5 -LRB104 10883 SPS 20965 b

1modification, or disclosure.
2    (c) If a state or federal law requires a data collector to
3provide greater protection to records that contain personal
4information concerning an Illinois resident that are
5maintained by the data collector and the data collector is in
6compliance with the provisions of that state or federal law,
7the data collector shall be deemed to be in compliance with the
8provisions of this Section.
9    (d) A data collector that is subject to and in compliance
10with the standards established pursuant to Section 501(b) of
11the Gramm-Leach-Bliley Act of 1999, 15 U.S.C. Section 6801,
12shall be deemed to be in compliance with the provisions of this
13Section.
14(Source: P.A. 99-503, eff. 1-1-17.)