DATA PRIVACY AND PROTECTION
HB3041 creates the Illinois Data Privacy and Protection Act, a comprehensive consumer privacy law governing how covered entities and service providers collect, process, and transfer personal data. The bill establishes a broad framework of definitions for covered data, sensitive covered data, data brokers, large data holders, minors, targeted advertising, and service providers, and it generally limits data practices to what is reasonably necessary and proportionate for specified purposes. It also requires privacy-by-design policies, data security safeguards, transparency notices, and written contracts governing transfers to service providers and third parties.
The bill gives individuals new rights to access, correct, delete, and port their covered data, and it requires covered entities to provide a clear means to withdraw consent. It also imposes special protections for children and minors, including limits on targeted advertising and transfers of minors’ data, and it prohibits discriminatory data practices and retaliation against individuals who exercise their rights. Enforcement authority is given to the Attorney General, State’s Attorneys, municipal attorneys, and private persons, with civil penalties, damages, injunctive relief, and attorneys’ fees available in some cases. The act would take effect 180 days after becoming law.
If enacted, HB3041 would create a new state privacy statute and impose significant compliance obligations on businesses and other covered entities operating in Illinois, while exempting government entities and certain nonprofit child-safety organizations. It would require privacy policies, consent mechanisms, data minimization practices, security programs, retention limits, executive certifications for large data holders, privacy impact assessments, and contractual controls over service providers and third parties. It would also affect advertising practices, data brokerage, biometric and genetic data handling, and the treatment of minors’ data, with smaller businesses receiving limited exemptions and alternative compliance options.
No committee transcripts or recorded votes were provided, so there is no direct evidence of debate or formal support/opposition in the available context. Based on the bill text, the measure is framed as a strong consumer privacy and data security proposal, suggesting a generally privacy-protective policy orientation. The absence of voting history or hearing testimony means the overall sentiment cannot be measured from the record provided, but the bill’s structure indicates an intent to impose substantial obligations on data-intensive businesses while preserving consumer rights.
The most likely points of contention are the bill’s breadth and compliance burden, especially for large data holders, data brokers, online platforms, and businesses that rely on targeted advertising or extensive data sharing. Businesses may object to the affirmative express consent requirements, limits on sensitive data transfers, private right of action, executive certification, and the extensive transparency and audit obligations. Supporters would likely emphasize consumer control, child protections, anti-discrimination safeguards, and stronger security standards. The bill also includes carve-outs and exemptions for small businesses, loyalty programs, research, and certain operational uses, which suggests an attempt to balance privacy protections with business and operational concerns.