1 | 1 | | 103RD GENERAL ASSEMBLY State of Illinois 2023 and 2024 SB1511 Introduced 2/7/2023, by Sen. Bill Cunningham SYNOPSIS AS INTRODUCED: 740 ILCS 14/10740 ILCS 14/15 Amends the Biometric Privacy Information Act. Defines "security purpose" as the purpose of preventing retail theft, fraud, or any other misappropriation or theft of a thing of value, including protecting property from trespass, controlling access to property, protecting any person from harm, including stalking, violence, or harassment, and assisting a law enforcement investigation. Allows a private entity to collect, capture, or otherwise obtain a person's or customer's biometric identifier or biometric information without satisfying other specified requirements if: (1) the private entity collects, captures, or otherwise obtains a person's or customer's biometric identifier or biometric information for a security purpose; (2) the private entity uses the biometric identifier or biometric information only for a security purpose; (3) the private entity retains the biometric identifier or biometric information no longer than is reasonably necessary to satisfy a security purpose; and (4) the private entity documents a process and time frame to delete any biometric identifier or biometric information. LRB103 25583 LNS 51932 b A BILL FOR 103RD GENERAL ASSEMBLY State of Illinois 2023 and 2024 SB1511 Introduced 2/7/2023, by Sen. Bill Cunningham SYNOPSIS AS INTRODUCED: 740 ILCS 14/10740 ILCS 14/15 740 ILCS 14/10 740 ILCS 14/15 Amends the Biometric Privacy Information Act. Defines "security purpose" as the purpose of preventing retail theft, fraud, or any other misappropriation or theft of a thing of value, including protecting property from trespass, controlling access to property, protecting any person from harm, including stalking, violence, or harassment, and assisting a law enforcement investigation. Allows a private entity to collect, capture, or otherwise obtain a person's or customer's biometric identifier or biometric information without satisfying other specified requirements if: (1) the private entity collects, captures, or otherwise obtains a person's or customer's biometric identifier or biometric information for a security purpose; (2) the private entity uses the biometric identifier or biometric information only for a security purpose; (3) the private entity retains the biometric identifier or biometric information no longer than is reasonably necessary to satisfy a security purpose; and (4) the private entity documents a process and time frame to delete any biometric identifier or biometric information. LRB103 25583 LNS 51932 b LRB103 25583 LNS 51932 b A BILL FOR |
---|
2 | 2 | | 103RD GENERAL ASSEMBLY State of Illinois 2023 and 2024 SB1511 Introduced 2/7/2023, by Sen. Bill Cunningham SYNOPSIS AS INTRODUCED: |
---|
3 | 3 | | 740 ILCS 14/10740 ILCS 14/15 740 ILCS 14/10 740 ILCS 14/15 |
---|
4 | 4 | | 740 ILCS 14/10 |
---|
5 | 5 | | 740 ILCS 14/15 |
---|
6 | 6 | | Amends the Biometric Privacy Information Act. Defines "security purpose" as the purpose of preventing retail theft, fraud, or any other misappropriation or theft of a thing of value, including protecting property from trespass, controlling access to property, protecting any person from harm, including stalking, violence, or harassment, and assisting a law enforcement investigation. Allows a private entity to collect, capture, or otherwise obtain a person's or customer's biometric identifier or biometric information without satisfying other specified requirements if: (1) the private entity collects, captures, or otherwise obtains a person's or customer's biometric identifier or biometric information for a security purpose; (2) the private entity uses the biometric identifier or biometric information only for a security purpose; (3) the private entity retains the biometric identifier or biometric information no longer than is reasonably necessary to satisfy a security purpose; and (4) the private entity documents a process and time frame to delete any biometric identifier or biometric information. |
---|
7 | 7 | | LRB103 25583 LNS 51932 b LRB103 25583 LNS 51932 b |
---|
8 | 8 | | LRB103 25583 LNS 51932 b |
---|
9 | 9 | | A BILL FOR |
---|
10 | 10 | | SB1511LRB103 25583 LNS 51932 b SB1511 LRB103 25583 LNS 51932 b |
---|
11 | 11 | | SB1511 LRB103 25583 LNS 51932 b |
---|
12 | 12 | | 1 AN ACT concerning civil law. |
---|
13 | 13 | | 2 Be it enacted by the People of the State of Illinois, |
---|
14 | 14 | | 3 represented in the General Assembly: |
---|
15 | 15 | | 4 Section 5. The Biometric Information Privacy Act is |
---|
16 | 16 | | 5 amended by changing Sections 10 and 15 as follows: |
---|
17 | 17 | | 6 (740 ILCS 14/10) |
---|
18 | 18 | | 7 Sec. 10. Definitions. In this Act: |
---|
19 | 19 | | 8 "Biometric identifier" means a retina or iris scan, |
---|
20 | 20 | | 9 fingerprint, voiceprint, or scan of hand or face geometry. |
---|
21 | 21 | | 10 Biometric identifiers do not include writing samples, written |
---|
22 | 22 | | 11 signatures, photographs, human biological samples used for |
---|
23 | 23 | | 12 valid scientific testing or screening, demographic data, |
---|
24 | 24 | | 13 tattoo descriptions, or physical descriptions such as height, |
---|
25 | 25 | | 14 weight, hair color, or eye color. Biometric identifiers do not |
---|
26 | 26 | | 15 include donated organs, tissues, or parts as defined in the |
---|
27 | 27 | | 16 Illinois Anatomical Gift Act or blood or serum stored on |
---|
28 | 28 | | 17 behalf of recipients or potential recipients of living or |
---|
29 | 29 | | 18 cadaveric transplants and obtained or stored by a federally |
---|
30 | 30 | | 19 designated organ procurement agency. Biometric identifiers do |
---|
31 | 31 | | 20 not include biological materials regulated under the Genetic |
---|
32 | 32 | | 21 Information Privacy Act. Biometric identifiers do not include |
---|
33 | 33 | | 22 information captured from a patient in a health care setting |
---|
34 | 34 | | 23 or information collected, used, or stored for health care |
---|
35 | 35 | | |
---|
36 | 36 | | |
---|
37 | 37 | | |
---|
38 | 38 | | 103RD GENERAL ASSEMBLY State of Illinois 2023 and 2024 SB1511 Introduced 2/7/2023, by Sen. Bill Cunningham SYNOPSIS AS INTRODUCED: |
---|
39 | 39 | | 740 ILCS 14/10740 ILCS 14/15 740 ILCS 14/10 740 ILCS 14/15 |
---|
40 | 40 | | 740 ILCS 14/10 |
---|
41 | 41 | | 740 ILCS 14/15 |
---|
42 | 42 | | Amends the Biometric Privacy Information Act. Defines "security purpose" as the purpose of preventing retail theft, fraud, or any other misappropriation or theft of a thing of value, including protecting property from trespass, controlling access to property, protecting any person from harm, including stalking, violence, or harassment, and assisting a law enforcement investigation. Allows a private entity to collect, capture, or otherwise obtain a person's or customer's biometric identifier or biometric information without satisfying other specified requirements if: (1) the private entity collects, captures, or otherwise obtains a person's or customer's biometric identifier or biometric information for a security purpose; (2) the private entity uses the biometric identifier or biometric information only for a security purpose; (3) the private entity retains the biometric identifier or biometric information no longer than is reasonably necessary to satisfy a security purpose; and (4) the private entity documents a process and time frame to delete any biometric identifier or biometric information. |
---|
43 | 43 | | LRB103 25583 LNS 51932 b LRB103 25583 LNS 51932 b |
---|
44 | 44 | | LRB103 25583 LNS 51932 b |
---|
45 | 45 | | A BILL FOR |
---|
46 | 46 | | |
---|
47 | 47 | | |
---|
48 | 48 | | |
---|
49 | 49 | | |
---|
50 | 50 | | |
---|
51 | 51 | | 740 ILCS 14/10 |
---|
52 | 52 | | 740 ILCS 14/15 |
---|
53 | 53 | | |
---|
54 | 54 | | |
---|
55 | 55 | | |
---|
56 | 56 | | LRB103 25583 LNS 51932 b |
---|
57 | 57 | | |
---|
58 | 58 | | |
---|
59 | 59 | | |
---|
60 | 60 | | |
---|
61 | 61 | | |
---|
62 | 62 | | |
---|
63 | 63 | | |
---|
64 | 64 | | |
---|
65 | 65 | | |
---|
66 | 66 | | SB1511 LRB103 25583 LNS 51932 b |
---|
67 | 67 | | |
---|
68 | 68 | | |
---|
69 | 69 | | SB1511- 2 -LRB103 25583 LNS 51932 b SB1511 - 2 - LRB103 25583 LNS 51932 b |
---|
70 | 70 | | SB1511 - 2 - LRB103 25583 LNS 51932 b |
---|
71 | 71 | | 1 treatment, payment, or operations under the federal Health |
---|
72 | 72 | | 2 Insurance Portability and Accountability Act of 1996. |
---|
73 | 73 | | 3 Biometric identifiers do not include an X-ray, roentgen |
---|
74 | 74 | | 4 process, computed tomography, MRI, PET scan, mammography, or |
---|
75 | 75 | | 5 other image or film of the human anatomy used to diagnose, |
---|
76 | 76 | | 6 prognose, or treat an illness or other medical condition or to |
---|
77 | 77 | | 7 further validate scientific testing or screening. |
---|
78 | 78 | | 8 "Biometric information" means any information, regardless |
---|
79 | 79 | | 9 of how it is captured, converted, stored, or shared, based on |
---|
80 | 80 | | 10 an individual's biometric identifier used to identify an |
---|
81 | 81 | | 11 individual. Biometric information does not include information |
---|
82 | 82 | | 12 derived from items or procedures excluded under the definition |
---|
83 | 83 | | 13 of biometric identifiers. |
---|
84 | 84 | | 14 "Confidential and sensitive information" means personal |
---|
85 | 85 | | 15 information that can be used to uniquely identify an |
---|
86 | 86 | | 16 individual or an individual's account or property. Examples of |
---|
87 | 87 | | 17 confidential and sensitive information include, but are not |
---|
88 | 88 | | 18 limited to, a genetic marker, genetic testing information, a |
---|
89 | 89 | | 19 unique identifier number to locate an account or property, an |
---|
90 | 90 | | 20 account number, a PIN number, a pass code, a driver's license |
---|
91 | 91 | | 21 number, or a social security number. |
---|
92 | 92 | | 22 "Private entity" means any individual, partnership, |
---|
93 | 93 | | 23 corporation, limited liability company, association, or other |
---|
94 | 94 | | 24 group, however organized. A private entity does not include a |
---|
95 | 95 | | 25 State or local government agency. A private entity does not |
---|
96 | 96 | | 26 include any court of Illinois, a clerk of the court, or a judge |
---|
97 | 97 | | |
---|
98 | 98 | | |
---|
99 | 99 | | |
---|
100 | 100 | | |
---|
101 | 101 | | |
---|
102 | 102 | | SB1511 - 2 - LRB103 25583 LNS 51932 b |
---|
103 | 103 | | |
---|
104 | 104 | | |
---|
105 | 105 | | SB1511- 3 -LRB103 25583 LNS 51932 b SB1511 - 3 - LRB103 25583 LNS 51932 b |
---|
106 | 106 | | SB1511 - 3 - LRB103 25583 LNS 51932 b |
---|
107 | 107 | | 1 or justice thereof. |
---|
108 | 108 | | 2 "Security purpose" means the purpose of preventing or |
---|
109 | 109 | | 3 investigating retail theft, fraud, or any other |
---|
110 | 110 | | 4 misappropriation or theft of a thing of value, including |
---|
111 | 111 | | 5 protecting property from trespass, controlling access to |
---|
112 | 112 | | 6 property, protecting any person from harm including stalking, |
---|
113 | 113 | | 7 violence, or harassment, and assisting a law enforcement |
---|
114 | 114 | | 8 investigation. |
---|
115 | 115 | | 9 "Written release" means informed written consent or, in |
---|
116 | 116 | | 10 the context of employment, a release executed by an employee |
---|
117 | 117 | | 11 as a condition of employment. |
---|
118 | 118 | | 12 (Source: P.A. 95-994, eff. 10-3-08.) |
---|
119 | 119 | | 13 (740 ILCS 14/15) |
---|
120 | 120 | | 14 Sec. 15. Retention; collection; disclosure; destruction. |
---|
121 | 121 | | 15 (a) A private entity in possession of biometric |
---|
122 | 122 | | 16 identifiers or biometric information must develop a written |
---|
123 | 123 | | 17 policy, made available to the public, establishing a retention |
---|
124 | 124 | | 18 schedule and guidelines for permanently destroying biometric |
---|
125 | 125 | | 19 identifiers and biometric information when the initial purpose |
---|
126 | 126 | | 20 for collecting or obtaining such identifiers or information |
---|
127 | 127 | | 21 has been satisfied or within 3 years of the individual's last |
---|
128 | 128 | | 22 interaction with the private entity, whichever occurs first. |
---|
129 | 129 | | 23 Absent a valid warrant or subpoena issued by a court of |
---|
130 | 130 | | 24 competent jurisdiction, a private entity in possession of |
---|
131 | 131 | | 25 biometric identifiers or biometric information must comply |
---|
132 | 132 | | |
---|
133 | 133 | | |
---|
134 | 134 | | |
---|
135 | 135 | | |
---|
136 | 136 | | |
---|
137 | 137 | | SB1511 - 3 - LRB103 25583 LNS 51932 b |
---|
138 | 138 | | |
---|
139 | 139 | | |
---|
140 | 140 | | SB1511- 4 -LRB103 25583 LNS 51932 b SB1511 - 4 - LRB103 25583 LNS 51932 b |
---|
141 | 141 | | SB1511 - 4 - LRB103 25583 LNS 51932 b |
---|
142 | 142 | | 1 with its established retention schedule and destruction |
---|
143 | 143 | | 2 guidelines. |
---|
144 | 144 | | 3 (b) No private entity may collect, capture, purchase, |
---|
145 | 145 | | 4 receive through trade, or otherwise obtain a person's or a |
---|
146 | 146 | | 5 customer's biometric identifier or biometric information, |
---|
147 | 147 | | 6 unless it first: |
---|
148 | 148 | | 7 (1) informs the subject or the subject's legally |
---|
149 | 149 | | 8 authorized representative in writing that a biometric |
---|
150 | 150 | | 9 identifier or biometric information is being collected or |
---|
151 | 151 | | 10 stored; |
---|
152 | 152 | | 11 (2) informs the subject or the subject's legally |
---|
153 | 153 | | 12 authorized representative in writing of the specific |
---|
154 | 154 | | 13 purpose and length of term for which a biometric |
---|
155 | 155 | | 14 identifier or biometric information is being collected, |
---|
156 | 156 | | 15 stored, and used; and |
---|
157 | 157 | | 16 (3) receives a written release executed by the subject |
---|
158 | 158 | | 17 of the biometric identifier or biometric information or |
---|
159 | 159 | | 18 the subject's legally authorized representative. |
---|
160 | 160 | | 19 (b-5) A private entity may collect, capture, or otherwise |
---|
161 | 161 | | 20 obtain a person's or customer's biometric identifier or |
---|
162 | 162 | | 21 biometric information without satisfying the requirements of |
---|
163 | 163 | | 22 subsection (b) if: |
---|
164 | 164 | | 23 (1) the private entity collects, captures, or |
---|
165 | 165 | | 24 otherwise obtains a person's or customer's biometric |
---|
166 | 166 | | 25 identifier or biometric information for a security |
---|
167 | 167 | | 26 purpose; |
---|
168 | 168 | | |
---|
169 | 169 | | |
---|
170 | 170 | | |
---|
171 | 171 | | |
---|
172 | 172 | | |
---|
173 | 173 | | SB1511 - 4 - LRB103 25583 LNS 51932 b |
---|
174 | 174 | | |
---|
175 | 175 | | |
---|
176 | 176 | | SB1511- 5 -LRB103 25583 LNS 51932 b SB1511 - 5 - LRB103 25583 LNS 51932 b |
---|
177 | 177 | | SB1511 - 5 - LRB103 25583 LNS 51932 b |
---|
178 | 178 | | 1 (2) the private entity uses the biometric identifier |
---|
179 | 179 | | 2 or biometric information only for a security purpose; |
---|
180 | 180 | | 3 (3) the private entity retains the biometric |
---|
181 | 181 | | 4 identifier or biometric information no longer than is |
---|
182 | 182 | | 5 reasonably necessary to satisfy a security purpose; and |
---|
183 | 183 | | 6 (4) the private entity documents a process and time |
---|
184 | 184 | | 7 frame to delete any biometric identifier or biometric |
---|
185 | 185 | | 8 information used for the purposes identified in this |
---|
186 | 186 | | 9 subsection. |
---|
187 | 187 | | 10 (c) No private entity in possession of a biometric |
---|
188 | 188 | | 11 identifier or biometric information may sell, lease, trade, or |
---|
189 | 189 | | 12 otherwise profit from a person's or a customer's biometric |
---|
190 | 190 | | 13 identifier or biometric information. |
---|
191 | 191 | | 14 (d) No private entity in possession of a biometric |
---|
192 | 192 | | 15 identifier or biometric information may disclose, redisclose, |
---|
193 | 193 | | 16 or otherwise disseminate a person's or a customer's biometric |
---|
194 | 194 | | 17 identifier or biometric information unless: |
---|
195 | 195 | | 18 (1) the subject of the biometric identifier or |
---|
196 | 196 | | 19 biometric information or the subject's legally authorized |
---|
197 | 197 | | 20 representative consents to the disclosure or redisclosure; |
---|
198 | 198 | | 21 (2) the disclosure or redisclosure completes a |
---|
199 | 199 | | 22 financial transaction requested or authorized by the |
---|
200 | 200 | | 23 subject of the biometric identifier or the biometric |
---|
201 | 201 | | 24 information or the subject's legally authorized |
---|
202 | 202 | | 25 representative; |
---|
203 | 203 | | 26 (3) the disclosure or redisclosure is required by |
---|
204 | 204 | | |
---|
205 | 205 | | |
---|
206 | 206 | | |
---|
207 | 207 | | |
---|
208 | 208 | | |
---|
209 | 209 | | SB1511 - 5 - LRB103 25583 LNS 51932 b |
---|
210 | 210 | | |
---|
211 | 211 | | |
---|
212 | 212 | | SB1511- 6 -LRB103 25583 LNS 51932 b SB1511 - 6 - LRB103 25583 LNS 51932 b |
---|
213 | 213 | | SB1511 - 6 - LRB103 25583 LNS 51932 b |
---|
214 | 214 | | 1 State or federal law or municipal ordinance; or |
---|
215 | 215 | | 2 (4) the disclosure is required pursuant to a valid |
---|
216 | 216 | | 3 warrant or subpoena issued by a court of competent |
---|
217 | 217 | | 4 jurisdiction. |
---|
218 | 218 | | 5 (e) A private entity in possession of a biometric |
---|
219 | 219 | | 6 identifier or biometric information shall: |
---|
220 | 220 | | 7 (1) store, transmit, and protect from disclosure all |
---|
221 | 221 | | 8 biometric identifiers and biometric information using the |
---|
222 | 222 | | 9 reasonable standard of care within the private entity's |
---|
223 | 223 | | 10 industry; and |
---|
224 | 224 | | 11 (2) store, transmit, and protect from disclosure all |
---|
225 | 225 | | 12 biometric identifiers and biometric information in a |
---|
226 | 226 | | 13 manner that is the same as or more protective than the |
---|
227 | 227 | | 14 manner in which the private entity stores, transmits, and |
---|
228 | 228 | | 15 protects other confidential and sensitive information. |
---|
229 | 229 | | 16 (Source: P.A. 95-994, eff. 10-3-08.) |
---|
230 | 230 | | |
---|
231 | 231 | | |
---|
232 | 232 | | |
---|
233 | 233 | | |
---|
234 | 234 | | |
---|
235 | 235 | | SB1511 - 6 - LRB103 25583 LNS 51932 b |
---|