101ST GENERAL ASSEMBLY
State of Illinois
2019 and 2020
HB2736

 

Introduced , by Rep. Kambium Buckner

 

SYNOPSIS AS INTRODUCED:
 
New Act

    Creates the Right to Know Act. Provides that an operator of a commercial website or online service that collects personally identifiable information through the Internet about individual customers residing in Illinois who use or visit its commercial website or online service shall notify those customers of certain specified information pertaining to its personal information sharing practices. Requires an operator to make available certain specified information upon disclosing a customer's personal information to a third party, and to provide an e-mail address or toll-free telephone number whereby customers may request or obtain that information. Provides for a data protection safety plan. Provides for a right of action to customers whose rights are violated under the Act. Provides that any waiver of the provisions of the Act or any agreement that does not comply with the applicable provisions of the Act shall be void and unenforceable. Provides that no provision of the Act shall be construed to conflict with or apply to certain specified provisions of federal law or certain interactions with State or local government. Provides findings and purpose. Defines terms.


LRB101 09976 RJF 55078 b

 

 

A BILL FOR

 

HB2736LRB101 09976 RJF 55078 b

1    AN ACT concerning regulation.
 
2    Be it enacted by the People of the State of Illinois,
3represented in the General Assembly:
 
4    Section 1. Short title. This Act may be cited as the Right
5to Know Act.
 
6    Section 5. Findings and purpose.
7    The General Assembly hereby finds and declares that the
8right to privacy is a personal and fundamental right protected
9by the United States Constitution. As such, all individuals
10have a right to privacy in information pertaining to them. This
11State recognizes the importance of providing consumers with
12transparency about how their personal information, especially
13information relating to their children, is shared by
14businesses. This transparency is crucial for Illinois citizens
15to protect themselves and their families from cyber-crimes and
16identity thieves. Furthermore, for free market forces to have a
17role in shaping the privacy practices and for "opt-in" and
18"opt-out" remedies to be effective, consumers must be more than
19vaguely informed that a business might share personal
20information with third parties. Consumers must be better
21informed about what kinds of personal information are shared
22with other businesses. With these specifics, consumers can
23knowledgeably choose to opt-in, opt-out, or choose among

 

 

HB2736- 2 -LRB101 09976 RJF 55078 b

1businesses that disclose information to third parties on the
2basis of how protective the business is of consumers' privacy.
3    Businesses are now collecting personal information and
4sharing and selling it in ways not contemplated or properly
5covered by the current law. Some websites are installing
6tracking tools that record when consumers visit web pages, and
7sending very personal information, such as age, gender, race,
8income, health concerns, religion, and recent purchases to
9third party marketers and data brokers. Third party data broker
10companies are buying, selling, and trading personal
11information obtained from mobile phones, financial
12institutions, social media sites, and other online and brick
13and mortar companies. Some mobile applications are sharing
14personal information, such as location information, unique
15phone identification numbers, and age, gender, and other
16personal details with third party companies. As such, consumers
17need to know the ways that their personal information is being
18collected by companies and then shared or sold to third parties
19in order to properly protect their privacy, personal safety,
20and financial security.
 
21    Section 10. Definitions. As used in this Act:
22    "Categories of personal information" includes, but is not
23limited to, the following:
24        (a) Identity information including, but not limited
25    to, real name, alias, nickname, and user name.

 

 

HB2736- 3 -LRB101 09976 RJF 55078 b

1        (b) Address information, including, but not limited
2    to, postal or e-mail.
3        (c) Telephone number.
4        (d) Account name.
5        (e) Social security number or other government-issued
6    identification number, including, but not limited to,
7    social security number, driver's license number,
8    identification card number, and passport number.
9        (f) Birthdate or age.
10        (g) Physical characteristic information, including,
11    but not limited to, height and weight.
12        (h) Sexual information, including, but not limited to,
13    sexual orientation, sex, gender status, gender identity,
14    and gender expression.
15        (i) Race or ethnicity.
16        (j) Religious affiliation or activity.
17        (k) Political affiliation or activity.
18        (l) Professional or employment-related information.
19        (m) Educational information.
20        (n) Medical information, including, but not limited
21    to, medical conditions or drugs, therapies, mental health,
22    or medical products or equipment used.
23        (o) Financial information, including, but not limited
24    to, credit, debit, or account numbers, account balances,
25    payment history, or information related to assets,
26    liabilities, or general creditworthiness.

 

 

HB2736- 4 -LRB101 09976 RJF 55078 b

1        (p) Commercial information, including, but not limited
2    to, records of property, products or services provided,
3    obtained, or considered, or other purchasing or consumer
4    histories or tendencies.
5        (q) Location information.
6        (r) Internet or mobile activity information,
7    including, but not limited to, Internet protocol addresses
8    or information concerning the access or use of any Internet
9    or mobile-based site or service.
10        (s) Content, including text, photographs, audio or
11    video recordings, or other material generated by or
12    provided by the customer.
13        (t) Any of the above categories of information as they
14    pertain to the children of the customer.
15    "Customer" means an individual residing in Illinois who
16provides, either knowingly or unknowingly, personal
17information to a private entity, with or without an exchange of
18consideration, in the course of purchasing, viewing,
19accessing, renting, leasing, or otherwise using real or
20personal property, or any interest therein, or obtaining a
21product or service from the private entity, including
22advertising or any other content.
23    "Designated request address" means an e-mail address or
24toll-free telephone number whereby customers may request or
25obtain the information required to be provided under Section 15
26of this Act.

 

 

HB2736- 5 -LRB101 09976 RJF 55078 b

1    "Disclose" means to disclose, release, transfer, share,
2disseminate, make available, or otherwise communicate orally,
3in writing, or by electronic or any other means to any third
4party. "Disclose" does not include the following:
5        (a) Disclosure of personal information by a private
6    entity to a third party under a written contract
7    authorizing the third party to utilize the personal
8    information to perform services on behalf of the private
9    entity, including maintaining or servicing accounts,
10    providing customer service, processing or fulfilling
11    orders and transactions, verifying customer information,
12    processing payments, providing financing, or similar
13    services, but only if (i) the contract prohibits the third
14    party from using the personal information for any reason
15    other than performing the specified service or services on
16    behalf of the private entity and from disclosing any such
17    personal information to additional third parties; and (ii)
18    the private entity effectively enforces these
19    prohibitions.
20        (b) Disclosure of personal information by a business to
21    a third party based on a good-faith belief that disclosure
22    is required to comply with applicable law, regulation,
23    legal process, or court order.
24        (c) Disclosure of personal information by a private
25    entity to a third party that is reasonably necessary to
26    address fraud, security, or technical issues; to protect

 

 

HB2736- 6 -LRB101 09976 RJF 55078 b

1    the disclosing private entity's rights or property; or to
2    protect customers or the public from illegal activities as
3    required or permitted by law.
4    "Operator" means any person or entity that owns a website
5located on the Internet or an online service that collects and
6maintains personally identifiable information from a customer
7residing in Illinois who uses or visits the website or online
8service if the website or online service is operated for
9commercial purposes. It does not include any third party that
10operates, hosts, or manages, but does not own, a website or
11online service on the owner's behalf or by processing
12information on behalf of the owner.
13    "Personal information" means any information that
14identifies, relates to, describes, or is capable of being
15associated with, a particular individual, including, but not
16limited to, his or her name, signature, physical
17characteristics or description, address, telephone number,
18passport number, driver's license or State identification card
19number, insurance policy number, education, employment,
20employment history, bank account number, credit card number,
21debit card number, or any other financial information.
22"Personal information" also means any data or information
23pertaining to an individual's income, assets, liabilities,
24purchases, leases, or rentals of goods, services, or real
25property, if that information is disclosed, or is intended to
26be disclosed, with any identifying information, such as the

 

 

HB2736- 7 -LRB101 09976 RJF 55078 b

1individual's name, address, telephone number, or social
2security number.
3    "Third party" or "third parties" means (i) a private entity
4that is a separate legal entity from the private entity that
5has disclosed personal information; (ii) a private entity that
6does not share common ownership or common corporate control
7with the private entity that has disclosed personal
8information; or (iii) a private entity that does not share a
9brand name or common branding with the private entity that has
10disclosed personal information such that the affiliate
11relationship is clear to the customer.
 
12    Section 15. Notification of information sharing practices.
13An operator of a commercial website or online service that
14collects personally identifiable information through the
15Internet about individual customers residing in Illinois who
16use or visit its commercial website or online service shall, in
17its customer agreement or incorporated addendum: (i) identify
18all categories of personal information that the operator
19collects through the website or online service about individual
20customers who use or visit its commercial website or online
21service; (ii) identify all categories of third party persons or
22entities with whom the operator may disclose that personally
23identifiable information; and (iii) provide a description of a
24customer's rights, as required under Section 25 of this Act,
25accompanied by one or more designated request addresses.
 

 

 

HB2736- 8 -LRB101 09976 RJF 55078 b

1    Section 20. Disclosure of a customer's personal
2information to a third party.
3    (a) An operator that discloses a customer's personal
4information to a third party shall make the following
5information available to the customer free of charge:
6        (1) all categories of personal information that were
7    disclosed; and
8        (2) the names of all third parties that received the
9    customer's personal information.
10    (b) This Section applies only to personal information
11disclosed after the effective date of this Act.
 
12    Section 25. Information availability service.
13    (a) An operator required to comply with Section 20 shall
14make the required information available by providing a
15designated request address in its customer agreement or
16incorporated addendum, and, upon receipt of a request under
17this Section, shall provide the customer with the information
18required under Section 20 for all disclosures occurring in the
19prior 12 months.
20    (b) An operator that receives a request from a customer
21under this Section at one of the designated addresses shall
22provide a response to the customer within 30 days.
 
23    Section 30. Data protection safety plan. Each manufacturer

 

 

HB2736- 9 -LRB101 09976 RJF 55078 b

1or company doing business in this State, or which collects
2personal information from customers who are residents of this
3State, shall develop a safety plan for the protection of
4customer data.
 
5    Section 35. Right of action. Any person whose rights under
6this Act are violated shall have a right of action against an
7offending party, and shall recover: (i) liquidated damages of
8$10 or actual damages, whichever is greater; (ii) injunctive
9relief, if appropriate; and (iii) reasonable attorneys' fees,
10costs, and expenses.
 
11    Section 40. Waivers; contracts. Any waiver of the
12provisions of this Act shall be void and unenforceable. Any
13agreement that does not comply with the applicable provisions
14of this Act shall be void and unenforceable.
 
15    Section 45. Construction.
16    (a) Nothing in this Act shall be construed to conflict with
17the federal Health Insurance Portability and Accountability
18Act of 1996 and the rules promulgated under that Act.
19    (b) Nothing in this Act shall be deemed to apply in any
20manner to a financial institution or an affiliate of a
21financial institution that is subject to Title V of the federal
22Gramm-Leach-Bliley Act of 1999 and the rules promulgated under
23that Act.

 

 

HB2736- 10 -LRB101 09976 RJF 55078 b

1    (c) Nothing in this Act shall be deemed to apply to the
2activities of an individual or entity to the extent that those
3activities are subject to Section 222 or 631 of the federal
4Communications Act of 1934.
5    (d) Nothing in this Act shall be construed to apply to a
6contractor, subcontractor, or agent of a State agency or local
7unit of government when working for that State agency or local
8unit of government.