← All jurisdictions
IL · data breach notification
medIllinois
815 ILCS 530/5 et seq. (PIPA)
Individual deadline
No fixed limit
Trigger standard
Any breach
AG / regulator
Required
| Notice to individuals | in the most expedient time possible and without unreasonable delay |
| Risk-of-harm standard | None, notice required on any qualifying breach of covered personal information. |
| Encryption safe harbor | Yes, encrypted data (key not compromised) generally exempt. |
| Regulator notice | Illinois Attorney General, required above 500 residents; within 45 days Written notice to AG Or when individual notice is given, whichever is sooner |
| Credit reporting agencies | No CRA-notice requirement. |
| Substitute notice | Typically available above $250,000 cost / 500,000 affected (verify). |
| Private right of action | No, enforcement by the state. |
| Notable PI definitions | Includes biometric, medical, health insurance, credentials. |
Notes
※ State agencies: 72-hour notice rule (>250)
Rule last verified July 10, 2026 · confidence med. This is a reference summary, not legal advice; verify against the current statute. How we compile this →
Is a Illinois breach part of a multi-state incident?
See every jurisdiction at once, with letters and filing packets generated.
Run the calculator →