← All jurisdictions
IL · data breach notification

Illinois

med

815 ILCS 530/5 et seq. (PIPA)

Individual deadline
No fixed limit
Trigger standard
Any breach
AG / regulator
Required
Notice to individualsin the most expedient time possible and without unreasonable delay
Risk-of-harm standardNone, notice required on any qualifying breach of covered personal information.
Encryption safe harborYes, encrypted data (key not compromised) generally exempt.
Regulator noticeIllinois Attorney General, required above 500 residents; within 45 days
Written notice to AG
Or when individual notice is given, whichever is sooner
Credit reporting agenciesNo CRA-notice requirement.
Substitute noticeTypically available above $250,000 cost / 500,000 affected (verify).
Private right of actionNo, enforcement by the state.
Notable PI definitionsIncludes biometric, medical, health insurance, credentials.
Notes
State agencies: 72-hour notice rule (>250)

Rule last verified July 10, 2026 · confidence med. This is a reference summary, not legal advice; verify against the current statute. How we compile this →

Is a Illinois breach part of a multi-state incident?

See every jurisdiction at once, with letters and filing packets generated.

Run the calculator →