HB3375 - 104th General Assembly

 


 
104TH GENERAL ASSEMBLY
State of Illinois
2025 and 2026
HB3375

 

Introduced 2/18/2025, by Rep. Joyce Mason

 

SYNOPSIS AS INTRODUCED:
 
815 ILCS 530/45

    Amends the Personal Information Protection Act. Provides that no data collector shall routinely collect the social security number of an Illinois resident without a specific and immediate need. Defines "specific and immediate need".


LRB104 09628 SPS 19693 b

 

 

A BILL FOR

 

HB3375LRB104 09628 SPS 19693 b

1    AN ACT concerning business.
 
2    Be it enacted by the People of the State of Illinois,
3represented in the General Assembly:
 
4    Section 5. The Personal Information Protection Act is
5amended by changing Section 45 as follows:
 
6    (815 ILCS 530/45)
7    Sec. 45. Data security.
8    (a) A data collector that owns or licenses, or maintains
9or stores but does not own or license, records that contain
10personal information concerning an Illinois resident shall
11implement and maintain reasonable security measures to protect
12those records from unauthorized access, acquisition,
13destruction, use, modification, or disclosure.
14    (b) A contract for the disclosure of personal information
15concerning an Illinois resident that is maintained by a data
16collector must include a provision requiring the person to
17whom the information is disclosed to implement and maintain
18reasonable security measures to protect those records from
19unauthorized access, acquisition, destruction, use,
20modification, or disclosure.
21    (c) If a state or federal law requires a data collector to
22provide greater protection to records that contain personal
23information concerning an Illinois resident that are

 

 

HB3375- 2 -LRB104 09628 SPS 19693 b

1maintained by the data collector and the data collector is in
2compliance with the provisions of that state or federal law,
3the data collector shall be deemed to be in compliance with the
4provisions of this Section.
5    (d) A data collector that is subject to and in compliance
6with the standards established pursuant to Section 501(b) of
7the Gramm-Leach-Bliley Act of 1999, 15 U.S.C. Section 6801,
8shall be deemed to be in compliance with the provisions of this
9Section.
10    (e) No data collector shall routinely collect the social
11security number of an Illinois resident without a specific and
12immediate need. As used in this subsection, "specific and
13immediate need" includes, but is not limited to, conducting a
14background check as part of an employee onboarding process and
15verifying eligibility to work through an I-9 Employment
16Eligibility Verification form. "Specific and immediate need"
17does not include patient intake paperwork at a health care
18facility, unless otherwise required by State or federal law.
19(Source: P.A. 99-503, eff. 1-1-17.)