Illinois Compiled Statutes

815 ILCS 530/5 (2026)

Definitions

✓ current as of May 2026
Find cases: SyfertCases citing this section IL-ILGAilga.gov JustiaChapter on Justia CornellLII Search CasesGoogle Scholar
(815 ILCS 530/5)
    Sec. 5. Definitions. In this Act:
    "Data collector" may include, but is not limited to, government agencies, public and private universities, privately and publicly held corporations, financial institutions, retail operators, and any other entity that, for any purpose, handles, collects, disseminates, or otherwise deals with nonpublic personal information.
    "Breach of the security of the system data" or "breach" means unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by the data collector. "Breach of the security of the system data" does not include good faith acquisition of personal information by an employee or agent of the data collector for a legitimate purpose of the data collector, provided that the personal information is not used for a purpose unrelated to the data collector's business or subject to further unauthorized disclosure.
    "Health insurance information" means an individual's health insurance policy number or subscriber identification number, any unique identifier used by a health insurer to identify the individual, or any medical information in an individual's health insurance application and claims history, including any appeals records.
    "Medical information" means any information regarding an individual's medical history, mental or physical condition, or medical treatment or diagnosis by a healthcare professional, including such information provided to a website or mobile application.
    "Personal information" means either of the following:
        (1) An individual's first name or first initial and
    
last name in combination with any one or more of the following data elements, when either the name or the data elements are not encrypted or redacted or are encrypted or redacted but the keys to unencrypt or unredact or otherwise read the name or data elements have been acquired without authorization through the breach of security:
            (A) Social Security number.
            (B) Driver's license number or State
        
identification card number.
            (C) Account number or credit or debit card
        
number, or an account number or credit card number in combination with any required security code, access code, or password that would permit access to an individual's financial account.
            (D) Medical information.
            (E) Health insurance information.
            (F) Unique biometric data generated from
        
measurements or technical analysis of human body characteristics used by the owner or licensee to authenticate an individual, such as a fingerprint, retina or iris image, or other unique physical representation or digital representation of biometric data.
        (2) User name or email address, in combination with a
    
password or security question and answer that would permit access to an online account, when either the user name or email address or password or security question and answer are not encrypted or redacted or are encrypted or redacted but the keys to unencrypt or unredact or otherwise read the data elements have been obtained through the breach of security.
    "Personal information" does not include publicly available information that is lawfully made available to the general public from federal, State, or local government records.
(Source: P.A. 99-503, eff. 1-1-17.)

    
Notes of Decisions
Cited in 6 cases (2 in the last 5 years), 2010–2025 · leading case: Cooney v. Chicago Pub. Schs., 943 N.E.2d 23 (Ill. App. Ct. 2010).
Cooney v. Chicago Pub. Schs., 943 N.E.2d 23 (Ill. App. Ct. 2010). · cites it 6× “” 815 ILCS 530/5 (West 2006). Plaintiffs claim that the Board, as a data collector, violated the Act because a “breach of the security of the system data” occurred.”
Maglio v. Advocate Health & Hospitals Corp., 2015 IL App (2d) 140782 (Ill. App. Ct. 2015). “¶7 In their Protection Act counts, plaintiffs alleged that Advocate was a “data collector” (815 ILCS 530/5 (West 2014) (defined as an “entity that, for any purpose, handles, collects, disseminates, or otherwise deals with nonpublic personal information”)) and did not timely…”
Doctors Direct Ins., Inc. v. Bochenek, 2015 IL App (1st) 142919 (Ill. App. Ct. 2015). · cites it 2× “815 ILCS 530/5, 10 (West 2012). The statute defines “personal information” as someone’s first name or first initial and last name in combination with any one or more of the - 10 - following: (1) social security number; (2) driver’s license number or state identification card…”
Doctors Direct Ins., Inc. v. Bochenek, 2015 IL App (1st) 142919 (Ill. App. Ct. 2015). “815 ILCS 530/5 (West 2012). ¶ 38 Despite the definition of "personal information" above, and that a violation of the Personal Information Protection Act is a violation of the Consumer Fraud Act under section 2Z (815 ILCS 505/2Z (West 2012)), the Consumer Fraud Act is not…”
Padma Rao v. J.P. Morgan Chase Bank, N.A. (7th Cir. 2025). · cites it 2× “815 ILCS 530/5 (“Breach of the security of the system data does not include good faith acquisition of personal infor- mation by an employee or agent of the data collector for a le- gitimate purpose of the data collector, provided that the per- sonal information is not used for a…”
Cole v. McLeod, 2025 IL App (1st) 241414-U (Ill. App. Ct. 2025). “§ 2511 ) (2018)) (ECPA), and the Illinois Personal Information Protection Act (815 ILCS 530/5 (West 2018)) (PIPA). After allowing Mr.”
— 815 ILCS 530/5(1) — 1 case
Padma Rao v. J.P. Morgan Chase Bank, N.A. (7th Cir. 2025). “815 ILCS 530/5 (“Breach of the security of the system data does not include good faith acquisition of personal infor- mation by an employee or agent of the data collector for a le- gitimate purpose of the data collector, provided that the per- sonal information is not used for a…”
Annotations are extracted automatically from the opinions in the Syfert caselaw corpus and ranked by authority, recency, and treatment. Dots show Syfertize treatment of the citing case itself.