SB0340 creates the Illinois Consumer Data Privacy Act, a comprehensive consumer privacy framework governing how covered businesses collect, use, share, sell, and retain personal data of Illinois residents. The bill applies to entities doing business in Illinois or targeting Illinois residents that meet specified size or revenue thresholds, and it defines key terms such as personal data, sensitive data, targeted advertising, profiling, sale, controller, processor, deidentified data, and pseudonymous data. It gives consumers rights to confirm processing, access data, correct inaccuracies, delete data, obtain portable copies, and opt out of targeted advertising, sale of personal data, and certain profiling. It also requires privacy notices, data minimization, security safeguards, consent for sensitive data, and internal appeal procedures when a request is denied.
The bill also imposes operational duties on controllers and processors, including written contracts, assistance with consumer requests, data protection assessments for higher-risk processing, and limits on retention and discriminatory processing. It contains numerous exemptions for data already regulated by other laws, including health information, financial data, education records, employment records, public records, law enforcement records, firearms-related records, and several other specialized statutory categories. Enforcement is placed primarily with the Attorney General and State's Attorneys, with violations treated as unlawful practices under the Consumer Fraud and Deceptive Business Practices Act; beginning in 2028, individuals suffering actual damages may also bring private actions under that Act. The bill also amends the Freedom of Information Act to exempt privacy assessments shared with the Attorney General and includes a home-rule preemption provision barring local governments from regulating consumer data privacy.
The overall sentiment reflected by the bill text is strongly pro-consumer and privacy-protective, with a structure modeled on modern state privacy laws. Although no committee transcripts or recorded votes were provided, the bill's detailed compliance obligations, broad consumer rights, and extensive exemptions suggest an effort to balance privacy protections with existing sector-specific regulatory regimes and business concerns. The delayed effective date and staged enforcement provisions also indicate an attempt to give covered entities time to prepare.
Notable points of contention likely center on the scope of coverage, the compliance burden on businesses, and the breadth of exemptions. Businesses may be concerned about notice, opt-out, assessment, recordkeeping, and contract requirements, while consumer advocates may focus on whether the many carve-outs weaken the law. The bill also raises issues around universal opt-out mechanisms, profiling and targeted advertising restrictions, private rights of action beginning in 2028, and the preemption of local regulation, all of which are common flashpoints in data privacy legislation.
The bill would add a new Illinois Consumer Data Privacy Act to state law and amend the Consumer Fraud and Deceptive Business Practices Act to make violations of the new privacy act an unlawful practice. It would also amend the Freedom of Information Act to exempt certain privacy assessments from disclosure when provided to the Attorney General. The measure would preempt local consumer-data-privacy regulation, preserve enforcement under the Biometric Information Privacy Act and Genetic Information Privacy Act, and create new duties and rights for controllers, processors, consumers, and enforcement officials.
The bill appears generally favorable toward consumer privacy and data protection, with a policy design that mirrors broader national privacy-law trends. Because no committee transcript or vote record was provided, there is no direct evidence of formal support or opposition in the legislative record here. Based on the text alone, the bill seems intended as a comprehensive but compromise-oriented privacy measure, combining strong consumer rights with substantial exemptions and delayed implementation.
The main areas of likely contention are the compliance costs and operational burdens on covered businesses, especially around privacy notices, opt-out systems, data privacy assessments, retention limits, and processor contracts. Another likely point of debate is the bill's many exemptions for regulated sectors and special categories of data, which may be seen either as necessary harmonization or as loopholes that weaken consumer protections. The private right of action beginning in 2028, the Attorney General's enforcement role, and the home-rule preemption of local privacy regulation are also likely to be contested by business groups, local governments, and consumer advocates with differing views on enforcement and regulatory scope.