SB0076 amends the Illinois Local Governmental and Governmental Employees Tort Immunity Act to add new provisions shielding public entities and public employees from liability for injuries caused by unauthorized access to government records, data, or electronic information systems. In practical terms, the bill creates a statutory immunity rule for local public entities and their employees when a third party hacks, accesses, or otherwise breaches government-held digital information.
The measure is narrowly focused on civil liability and does not create new duties, penalties, or remedies; instead, it limits lawsuits seeking damages for harms arising from data breaches or other unauthorized access incidents. The bill applies to government records and electronic systems, which suggests it is aimed at cybersecurity-related incidents affecting public-sector data infrastructure and information security.
Impact
If enacted, SB0076 would expand the Tort Immunity Act by adding Sections 2-107.5 and 2-210.5, expressly barring liability claims against local public entities and public employees for injuries caused by unauthorized access to government data or electronic systems. This would likely reduce exposure to tort claims following cyber incidents, identity theft, privacy breaches, or other harms tied to compromised government information, while leaving unaffected any liability that may arise under other statutes or legal theories not covered by the immunity language.
Sentiment
The available record shows little direct debate, as there are no committee transcripts or recorded votes included with the bill materials. Based on the bill’s caption and text, the proposal appears to be a government-liability and cybersecurity measure intended to protect public entities from litigation risk after data breaches. The absence of recorded opposition or amendments in the provided context suggests the bill had not yet generated a visible public controversy in the materials supplied.
Contention
The main point of contention likely would be whether the bill goes too far in insulating government from accountability when residents are harmed by a data breach. Supporters would likely argue that public entities should not be treated as insurers against criminal cyberattacks by third parties, especially where the breach is outside their direct control. Opponents, if any, would likely focus on the loss of legal recourse for individuals whose personal information is exposed or misused, and on whether immunity could reduce incentives for strong cybersecurity practices.