Skip to main content
Menu Icon
Close

InfoBytes Blog

Financial Services Law Insights and Observations

Illinois requires companies to report data breaches to attorney general

State Issues State Legislation Privacy/Cyber Risk & Data Security Data Breach State Attorney General

State Issues

On August 9, the Illinois governor signed SB 1624, which requires that a single data breach involving the personal information of more than 500 Illinois residents must be reported to the state attorney general. The notice must include: (i) a description of the nature of the breach of security or unauthorized acquisition or use; (ii) the number of Illinois residents affected by such incident at the time of notification; and (iii) any steps the data collector has taken or plans to take relating to the incident. Notification is required to be made “in the most expedient time possible and without unreasonable delay,” but no later than when the data collector informs consumers of the breach under current law. The bill is effective January 1, 2020.