DisclosureLens
ILlive

Illinois data breach notifications

Notice to the Illinois Attorney General is required when a single breach requires notification to more than 500 Illinois residents, in the most expedient time possible and no later than 45 days after notice to residents. The AG publishes the entity name, the categories of personal information involved and the breach date range — the statute does not require it to publish the number of residents affected.

Browse Illinois records

How DisclosureLens indexes Illinois filings

DisclosureLens polls the Illinois AG portal on a regular schedule, fetches each new notice, extracts a structured BreachDisclosure v1 record, resolves the affected entity to its LEI/CIK when possible, and publishes via the REST API and webhooks (STIX/TAXII delivery is planned).

Extraction provenance

Extracted records carry per-field source citations into the Illinois AG notice they came from, plus a per-record confidence score and a full extraction audit trail. Illinois filings inherit the same BreachDisclosure v1 schema as SEC 8-Ks, HHS OCR notices, and EU DPA registers — same fields, same provenance metadata, deduped against same-incident filings in other jurisdictions. Full pipeline details: Sources & Methodology.

Statute

815 ILCS 530/10

Authoritative source

https://illinoisattorneygeneral.gov/consumer-protection/identity-theft/data-breach-notifications/

Corrections

Email corrections@disclosurelens.com — 48-hour SLA from receipt.