Rep. John A. Fritchey

Filed: 4/7/2005

 

 


 

 


 
09400HB1633ham003 LRB094 07564 RXD 44491 a

1
AMENDMENT TO HOUSE BILL 1633

2     AMENDMENT NO. ______. Amend House Bill 1633, AS AMENDED, by
3 replacing everything after the enacting clause with the
4 following:
 
5     "Section 1. Short title. This Act may be cited as the
6 Personal Information Protection Act.
 
7     Section 5. Definitions. In this Act:
8     "Data Collector" may include, but is not limited to,
9 government agencies, public and private universities,
10 privately and publicly held corporations, financial
11 institutions, retail operators, and any other entity that, for
12 any purpose, handles, collects, disseminates, or otherwise
13 deals with nonpublic personal information.
14     "Breach of the security of the system data" means
15 unauthorized acquisition of computerized data that compromises
16 the security, confidentiality, or integrity of personal
17 information maintained by the data collector. "Breach of the
18 security of the system data" does not include good faith
19 acquisition of personal information by an employee or agent of
20 the data collector for a legitimate purpose of the data
21 collector, provided that the personal information is not used
22 for a purpose unrelated to the data collector's business or
23 subject to further unauthorized disclosure.
24     "Personal information" means an individual's first name or

 

 

09400HB1633ham003 - 2 - LRB094 07564 RXD 44491 a

1 first initial and last name in combination with any one or more
2 of the following data elements, when either the name or the
3 data elements are not encrypted or redacted:
4         (1) Social Security number.
5         (2) Driver's license number or State identification
6     card number.
7         (3) Account number or credit or debit card number, or
8     an account number or credit card number in combination with
9     any required security code, access code, or password that
10     would permit access to an individual's financial account.
11 "Personal information" does not include publicly available
12 information that is lawfully made available to the general
13 public from federal, State, or local government records.
 
14     Section 10. Notice of Breach.
15     (a) Any data collector that owns or licenses personal
16 information concerning an Illinois resident shall notify the
17 resident that there has been a breach of the security of the
18 system data following discovery or notification of the breach.
19 The disclosure notification shall be made in the most expedient
20 time possible and without unreasonable delay or with any
21 measures necessary to determine the scope of the breach and
22 restore the reasonable integrity, security, and
23 confidentiality of the data system.
24     (b) Any data collector that maintains computerized data
25 that includes personal information that the data collector does
26 not own or license shall notify the owner or licensee of the
27 information of any breach of the security of the data
28 immediately following discovery, if the personal information
29 was, or is reasonably believed to have been, acquired by an
30 unauthorized person.
31     (c) For purposes of this Section, notice to consumers may
32 be provided by one of the following methods:
33         (1) written notice;

 

 

09400HB1633ham003 - 3 - LRB094 07564 RXD 44491 a

1         (2) electronic notice, if the notice provided is
2     consistent with the provisions regarding electronic
3     records and signatures for notices legally required to be
4     in writing as set forth in Section 7001 of Title 15 of the
5     United States Code; or
6         (3) substitute notice, if the data collector
7     demonstrates that the cost of providing notice would exceed
8     $250,000 or that the affected class of subject persons to
9     be notified exceeds 500,000, or the data collector does not
10     have sufficient contact information. Substitute notice
11     shall consist of all of the following: (i) e mail notice if
12     the data collector has an email address for the subject
13     persons; (ii) conspicuous posting of the notice on the data
14     collector's web site page if the data collector maintains
15     one; and (iii) notification to major statewide media.
 
16     Section 15. Waiver. Any waiver of the provisions of this
17 Act is contrary to public policy and is void and unenforceable.
 
18     Section 20. Violation. A violation of this Act constitutes
19 an unlawful practice under the Consumer Fraud and Deceptive
20 Business Practices Act.
 
21     Section 900. The Consumer Fraud and Deceptive Business
22 Practices Act is amended by changing Section 2Z as follows:
 
23     (815 ILCS 505/2Z)  (from Ch. 121 1/2, par. 262Z)
24     Sec. 2Z. Violations of other Acts. Any person who knowingly
25 violates the Automotive Repair Act, the Home Repair and
26 Remodeling Act, the Dance Studio Act, the Physical Fitness
27 Services Act, the Hearing Instrument Consumer Protection Act,
28 the Illinois Union Label Act, the Job Referral and Job Listing
29 Services Consumer Protection Act, the Travel Promotion
30 Consumer Protection Act, the Credit Services Organizations

 

 

09400HB1633ham003 - 4 - LRB094 07564 RXD 44491 a

1 Act, the Automatic Telephone Dialers Act, the Pay-Per-Call
2 Services Consumer Protection Act, the Telephone Solicitations
3 Act, the Illinois Funeral or Burial Funds Act, the Cemetery
4 Care Act, the Safe and Hygienic Bed Act, the Pre-Need Cemetery
5 Sales Act, the High Risk Home Loan Act, subsection (a) or (b)
6 of Section 3-10 of the Cigarette Tax Act, subsection (a) or (b)
7 of Section 3-10 of the Cigarette Use Tax Act, the Electronic
8 Mail Act, paragraph (6) of subsection (k) of Section 6-305 of
9 the Illinois Vehicle Code, or the Automatic Contract Renewal
10 Act, or the Personal Information Protection Act commits an
11 unlawful practice within the meaning of this Act.
12 (Source: P.A. 92-426, eff. 1-1-02; 93-561, eff. 1-1-04; 93-950,
13 eff. 1-1-05.)".