Illinois data privacy rights and data broker removal (2026)

Updated Corrections

July 7, 2026

How to exercise your data privacy rights in Illinois, opt out of data brokers, and file a complaint — updated for 2026.

At a glance

  • Comprehensive privacy law? No. Your rights come from the statutes below.
  • In effect since BIPA effective 2008; SB 2979 (Public Act 103-0769) amendment effective August 2, 2024. No comprehensive law as of 2026.
  • Honors Global Privacy Control? Not required
  • Data-broker registry? No
  • Enforced by Illinois Attorney General for most sectoral statutes (PIPA, SOPPA)

What Delist can do for you in Illinois

Illinois has no comprehensive privacy law in effect. We submit your requests through each broker's own opt-out channel, on your behalf. Many national brokers honor these requests wherever you live, but none is required to by Illinois law, so we follow up and re-file rather than assume.

How the three groups work: our authorized-agent framework.

What still protects you

Illinois has no comprehensive consumer privacy law, but it offers the nation's strongest biometric protection (BIPA, 740 ILCS 14, with a private right of action) plus breach notification (815 ILCS 530), student-data (SOPPA), and genetic-data statutes. For general (non-biometric) personal data, residents cannot compel access/deletion/opt-out from most businesses under state law and must rely on opt-outs to CCPA-covered and other-state-registered data brokers and on GPC.

How to exercise your rights

For biometric data, residents can sue private entities directly under BIPA (one of the only private rights of action in U.S. privacy law). For general personal data, residents rely on breach notification (815 ILCS 530), submit opt-out/deletion requests to CCPA-covered and other-state-registered data brokers, and enable the Global Privacy Control. There is no Illinois mechanism to compel access/deletion of general (non-biometric) personal data from businesses not covered by another state's law.

Ready to see who's selling your information? Browse our data broker removal guides for step-by-step opt-out instructions.

California DROP

None for general consumers; Illinois's address-protection provisions (see special_protections) provide targeted takedown for covered officials.

Sensitive information

BIPA requires written, informed opt-in consent before a private entity may collect/capture/obtain biometric identifiers or information, plus a public retention/destruction schedule and a ban on selling/profiting from biometric data.

Special protections

Illinois enacted address-protection provisions for judges and certain officials (e.g., the Judicial Privacy Act, 705 ILCS 90, and related provisions) allowing requests to restrict disclosure of personal information — a Daniel's-Law-style protection; VERIFY exact citation/scope. Genetic Information Privacy Act (410 ILCS 513). SOPPA (student records). Right to Privacy in the Workplace Act and the AI Video Interview Act. Address Confidentiality Program for DV survivors administered by the Illinois Attorney General.

Biometric privacy

Illinois Biometric Information Privacy Act (BIPA), 740 ILCS 14 — the nation's strongest biometric law and the ONLY one with a PRIVATE RIGHT OF ACTION (§ 20). Statutory damages: $1,000 per negligent violation or $5,000 per intentional/reckless violation (or actual damages, whichever is greater), plus attorneys' fees, costs, and injunctive relief. The Illinois Supreme Court's Cothron v. White Castle (2023) held a claim accrues per scan/disclosure (creating massive exposure); the legislature responded with SB 2979 / Public Act 103-0769 (effective Aug 2, 2024), which limits a plaintiff to a single recovery per person per method of collection and permits electronic signatures for consent. The U.S. Court of Appeals for the 7th Circuit, in Clay v. Union Pacific Railroad Co. (consolidated with Gregg and Willis), No. 25-2185, 2026 WL 891902 (April 1, 2026), held the SB 2979 amendment is remedial and therefore applies RETROACTIVELY to cases pending when it was enacted — significantly curtailing per-scan damages exposure.

How to file a complaint

Illinois Attorney General, Consumer Protection — https://illinoisattorneygeneral.gov/protecting-consumers/

Recent updates (2025–2026)

The 7th Circuit held BIPA's 2024 damages amendment retroactive in Clay v. Union Pacific (April 1, 2026), capping recovery at one per person per collection method. A comprehensive consumer privacy bill remains in committee as of 2026.

Frequently asked questions

Does Illinois have a data privacy law?

Illinois has no comprehensive consumer privacy law, but federal rules and data-broker opt-out paths still apply.

How do I remove my information from data brokers in Illinois?

For biometric data, residents can sue private entities directly under BIPA (one of the only private rights of action in U.S. privacy law). For general personal data, residents rely on breach notification (815 ILCS 530), submit opt-out/deletion requests to CCPA-covered and other-state-registered data brokers, and enable the Global Privacy Control. There is no Illinois mechanism to compel access/deletion of general (non-biometric) personal data from businesses not covered by another state's law.

Who enforces privacy law in Illinois?

Illinois Attorney General for most sectoral statutes (PIPA, SOPPA). BIPA is enforced through a PRIVATE RIGHT OF ACTION (individuals sue directly).

Does Illinois have a data broker registry?

No. Illinois does not have a dedicated data-broker registry, but you can still opt out of brokers directly.

Sources

  1. ilga.gov
  2. caselaw.findlaw.com
  3. datamatters.sidley.com
  4. paulhastings.com

Also in this state

Find out what data brokers know about you

A free scan shows which sites are exposing your name, phone, address and email, and Delist files the removals for you.

Start your free scan No card required