|Public Act 094-0036
||LRB094 07564 RXD 37732 b
AN ACT concerning business.
Be it enacted by the People of the State of Illinois,
represented in the General Assembly:
This Act may be cited as the
Personal Information Protection Act.
In this Act:
"Data Collector" may include, but is not limited to,
government agencies, public and private universities,
privately and publicly held corporations, financial
institutions, retail operators, and any other entity that, for
any purpose, handles, collects, disseminates, or otherwise
deals with nonpublic personal information.
"Breach of the security of the system data" means
unauthorized acquisition of computerized data that compromises
the security, confidentiality, or integrity of personal
information maintained by the data collector. "Breach of the
security of the system data" does not include good faith
acquisition of personal information by an employee or agent of
the data collector for a legitimate purpose of the data
collector, provided that the personal information is not used
for a purpose unrelated to the data collector's business or
subject to further unauthorized disclosure.
"Personal information" means an individual's first name or
first initial and last name in combination with any one or more
of the following data elements, when either the name or the
data elements are not encrypted or redacted:
(1) Social Security number.
(2) Driver's license number or State identification
(3) Account number or credit or debit card number, or
account number or credit card number in combination with
any required security code, access code, or password that