Loading chat...
IL HB3200
Bill
Status
2/15/2019
Primary Sponsor
Diane Pappas
Click for details
AI Summary
-
Amends the Personal Information Protection Act to require data collectors to notify the Illinois Attorney General in addition to affected Illinois residents of security breaches.
-
Establishes a strict 5-day deadline for breach notification, replacing the previous "expedient time possible" standard and removing language that allowed delays for investigation purposes.
-
Requires notification to include toll-free numbers and addresses for consumer reporting agencies and the Federal Trade Commission, along with information about fraud alerts and security freezes.
-
Allows data collectors maintaining their own notification procedures as part of an information security policy to comply if consistent with the 5-day timing requirement.
-
Permits delayed notification only if a law enforcement agency provides written notice that notification would interfere with a criminal investigation, requiring notification as soon as the interference ends.
Legislative Description
PERSONAL INFO-NOTICE OF BREACH
Last Action
House Committee Amendment No. 1 Rule 19(c) / Re-referred to Rules Committee
3/29/2019