Issue · Technology

Technology (Consumer Data Protection)

Every technology bill, vote, and legislator stance in Illinois, automatically classified by Maddy, our AI policy reader.

Total bills
47
104th Regular Session
Top supporter
Curtis Tarver
100% support rate
Top opponent
Tom Weber
0% support rate
Ranked legislators
10
5 support · 5 oppose
Key legislators

Who's moving consumer data protection in Illinois

Legislators moving consumer data protection in Illinois
Legislator Party Stance Support rate Votes
Curtis Tarver
Curtis Tarver House · District 25
D
Strong +
100% 4
Theresa Mah
Theresa Mah House · District 24
D
Strong +
100% 4
Debbie Meyers-Martin
Debbie Meyers-Martin House · District 38
D
Strong +
100% 3
Jay Hoffman
Jay Hoffman House · District 113
D
Strong +
100% 3
Kevin Olickal
Kevin Olickal House · District 16
D
Strong +
100% 3
Tom Weber
Tom Weber House · District 64
R
Strong −
0% 5
David Friess
David Friess House · District 115
R
Strong −
0% 3
Marty McLaughlin
Marty McLaughlin House · District 52
R
Strong −
0% 3
Travis Weaver
Travis Weaver House · District 93
R
Strong −
0% 3
Norine Hammond
Norine Hammond House · District 94
R
Oppose
25% 4
Showing 31–40 of 47 bills

All technology bills

in committee · Illinois · House Mar 27, 2026

HB 2838: BIPA-SECURITY PURPOSES

Amends the Biometric Information Privacy Act. Changes the definition of "biometric identifier". Defines "biometric lock", "biometric time clock", "person", and "security purpose". Waives certain requirements for collecting, capturing, or otherwise obtaining a person's or a customer's biometric identifier or biometric information under certain circumstances relating to security purposes. Provides that nothing in the Act shall be construed to apply to information captured by a biometric time clock or biometric lock that converts a person's biometric identifier or biometric information to a mathematical representation. Provides that any person aggrieved by a violation of this Act has a right of action in State court or federal court within one year from its occurrence. Requires the aggrieved person to provide the private entity 30 days a written entity alleging the specific provisions of the Act that have been violated. Provides the private entity 30 days to cure the noticed violation. Exempts a private entity if its employees are covered by a collective bargaining agreement that provides for different policies regarding the retention, collection, disclosure, and destruction of biometric information. Effective immediately.
in committee · Illinois · House Apr 11, 2025

HB 3375: PERSONAL INFO PROTECTION-SSN

Amends the Personal Information Protection Act. Provides that no data collector shall routinely collect the social security number of an Illinois resident without a specific and immediate need. Defines "specific and immediate need".
in committee · Illinois · Senate Apr 11, 2025

SB 52: PRIVACY RIGHTS ACT

Creates the Privacy Rights Act. Sets forth duties and obligations of businesses that collected consumers' personal information and sensitive personal information to keep such information private. Sets forth consumer rights in relation to the collected personal information and sensitive personal information, including the right to: delete personal information; correct inaccurate personal information; know what personal information is sold or shared and to whom; opt out of the sale or sharing of personal information; limit use and disclosure of sensitive personal information; and no retaliation for exercising any rights. Sets forth enforcement provisions. Creates the Consumer Privacy Fund. Allows the Attorney General to create rules to implement the Act. Establishes the Privacy Protection Agency. Includes provisions regarding remedies and fines for violations of the Act. Makes a conforming change in the State Finance Act.
in committee · Illinois · House Mar 21, 2025

HB 2913: DATA BROKER REGISTER/DELETION

Creates the Data Broker Registration and Accessible Deletion Mechanism Act. Provides that, annually, on or before January 31, a data broker operating in the State shall register with the Attorney General. Provides that, in registering with the Attorney General, a data broker shall pay a registration fee in an amount determined by the Attorney General and shall also provide specified information. Provides that the Attorney General shall create a page on its website where the registration information shall be made accessible to the public. Provides for civil penalties. Provides that all moneys received by the Attorney General under the provisions shall be deposited into the Data Broker Registry Fund. Provides that, no later than January 1, 2027, the Attorney General shall establish an accessible deletion mechanism that allows a consumer, through a single verifiable consumer request, to request that every data broker that maintains any personal information delete any personal information related to that consumer held by the data broker. Amends the State Finance Act and the Consumer Fraud and Deceptive Business Practices Act to make conforming changes.
in committee · Illinois · Senate May 22, 2026

SB 2273: HEALTH DATA PRIVACY ACT

Creates the Protect Health Data Privacy Act. Provides that a regulated entity shall disclose and maintain a health data privacy policy that clearly and conspicuously discloses specified information. Sets forth provisions concerning health data privacy policies. Provides that a regulated entity shall not collect, share, or store health data, except in specified circumstances. Provides that it is unlawful for any person to sell or offer to sell health data concerning an individual without first obtaining valid authorization from the individual. Provides that a valid authorization to sell individual health data must contain specified information; a copy of the signed valid authorization must be provided to the individual; and the seller and purchaser of health data must retain a copy of all valid authorizations for sale of health data for 6 years after the date of its signature or the date when it was last in effect, whichever is later. Sets forth provisions concerning the consent required for collection, sharing, and storage of health data. Provides that an individual has the right to withdraw consent from the processing of the individual's health data. Provides that it is unlawful for a regulated entity to engage in discriminatory practices against individuals solely because they have not provided consent to the processing of their health data or have exercised any other rights provided by the provisions or guaranteed by law. Sets forth provisions concerning an individual's right to confirm whether a regulated entity is collecting, selling, sharing, or storing any of the individual's health data; an individual's right to have the individual's health data that is collected by a regulated entity deleted; prohibitions regarding geofencing; and individual health data security. Provides that any person aggrieved by a violation of the provisions shall have a right of action in a State circuit court or as a supplemental claim in federal district court against an offending party. Provides that the Attorney General may enforce a violation of the provisions as an unlawful practice under the Consumer Fraud and Deceptive Business Practices Act. Defines terms. Makes a conforming change in the Consumer Fraud and Deceptive Business Practices Act.
in committee · Illinois · House Mar 21, 2025

HB 2866: BIPA-ACTION APPLICABILITY

Amends the Biometric Information Privacy Act. Provides that the changes made by Public Act 103-769 apply to pending actions as of August 2, 2024, and any actions commenced and complaints filed on or after August 2, 2024. Effective immediately.
in committee · Illinois · House May 30, 2026

HB 3494: HEALTH DATA PRIVACY ACT

Creates the Protect Health Data Privacy Act. Provides that a regulated entity shall disclose and maintain a health data privacy policy that clearly and conspicuously discloses specified information. Sets forth provisions concerning health data privacy policies. Provides that a regulated entity shall not collect, share, or store health data, except in specified circumstances. Provides that it is unlawful for any person to sell or offer to sell health data concerning an individual without first obtaining valid authorization from the individual. Provides that a valid authorization to sell individual health data must contain specified information; a copy of the signed valid authorization must be provided to the individual; and the seller and purchaser of health data must retain a copy of all valid authorizations for sale of health data for 6 years after the date of its signature or the date when it was last in effect, whichever is later. Sets forth provisions concerning the consent required for collection, sharing, and storage of health data. Provides that an individual has the right to withdraw consent from the processing of the individual's health data. Provides that it is unlawful for a regulated entity to engage in discriminatory practices against individuals solely because they have not provided consent to the processing of their health data or have exercised any other rights provided by the provisions or guaranteed by law. Sets forth provisions concerning an individual's right to confirm whether a regulated entity is collecting, selling, sharing, or storing any of the individual's health data; an individual's right to have the individual's health data that is collected by a regulated entity deleted; prohibitions regarding geofencing; and individual health data security. Provides that any person aggrieved by a violation of the provisions shall have a right of action in a State circuit court or as a supplemental claim in federal district court against an offending party. Provides that the Attorney General may enforce a violation of the provisions as an unlawful practice under the Consumer Fraud and Deceptive Business Practices Act. Defines terms. Makes a conforming change in the Consumer Fraud and Deceptive Business Practices Act.
in committee · Illinois · House Mar 27, 2026

HB 2984: BIPA-NEURAL DATA

Amends the Biometric Information Privacy Act. Defines "biometric identifier" to include neural data. Defines "neural data" as information that is generated by the measurement of activity of an individual's central or peripheral nervous system, and that is not inferred from non-neural information.
in committee · Illinois · House Mar 27, 2026

HB 3041: DATA PRIVACY AND PROTECTION

Creates the Illinois Data Privacy and Protection Act. Provides that a covered entity (any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data) may not collect, process, or transfer covered data unless the collection, processing, or transfer is limited to what is reasonably necessary and proportionate. Provides that a covered entity and a service provider shall establish, implement, and maintain reasonable policies, practices, and procedures concerning the collection, processing, and transferring of covered data. Contains provisions concerning retaliation; transparency; individual data rights; consent; data protection for children and minors; civil rights; data security; small business protections; executive responsibility; service providers and third parties; enforcement; severability; and rulemaking. Effective 180 days after becoming law.
in committee · Illinois · Senate Jun 2, 2025

SB 2478: UTILITY DATA ACCESS ACT

Creates the Utility Data Access Act. Requires the Illinois Commerce Commission to enact the following procedures: (1) a utility shall retain all consumption data for a period of not less than 2 years; (2) a qualified utility shall retain monthly consumption data used for billing for a period of not less than 15 years; (3) a utility shall honor an account holder's request to transmit the account holder's covered usage data held by the utility to any entity designated by the account holder; (4) a qualified data recipient with respect to a qualified building or qualified property may request that a qualified utility provide aggregated usage data for the qualified building or qualified property; (5) a utility shall deliver requested data on a schedule set by the Commission; and (6) the account holder request process and utility delivery of requested data shall be convenient and secure. Establishes requirements for: the Commission's participation in a stakeholder process; the form and timeline in which covered usage data is provided to the data recipient; entry of data into the benchmarking tool; and the provision of covered usage data to recipients upon account holder authorization. Provides that, except in cases where the utility has not followed processes established by the Act or the utility is grossly negligent, the utility shall be held harmless for third-party misuse of data shared under the Act and no cause of action may be initiated against the utility for such subsequent misuse. Provides that prior to filing for cost recovery, a qualified utility must first demonstrate good faith efforts to secure federal, State, or other relevant funding options. Sets forth provisions regarding funding for the Commission to carry out its responsibilities under the Act and the Commission selecting and engaging outside consultants with experience in benchmarking and utility data access. States findings. Defines terms.
Showing 31 to 40 of 47 bills
Previous 1 3 4 5 Next