CCTV privacy laws in Illinois: what we map and name
What CCTV Privacy Law Mapper maps for a camera at a site in Illinois, what it names without mapping, and what it leaves out. This is not every law that applies there.
- Jurisdiction
- Illinois, United States
- Laws placed
- Illinois Biometric Information Privacy Act (BIPA), on face matching cameras, which collect biometric identifiers
- Date last read
- Held and read 29 Sep 2026
- Named, not quoted
- Illinois Eavesdropping Act, 720 ILCS 5/14
- Read from a list as
il,il us,il usa,illinois,us il
Coverage here
Laws mapped and checked- Mapped
- Illinois Biometric Information Privacy Act (BIPA)
- Named, not mapped
- Illinois Eavesdropping Act, 720 ILCS 5/14
- The national or state layer
- State biometric, eavesdropping, wiretap and consumer privacy laws sit here; only those named on this page are named, and only BIPA and the CCPA are mapped anywhere in the United States.
Findings a camera here can raise
6 of the 18 can arise here- 1 Face matching or face recognition: biometric identification
- 5 No retention period set, or retention above the maximum you set
- 6 No signage or notice recorded
- 8 A third party can view or manage the footage, and no agreement is recorded
- 10 Audio recorded
- 14 Disclosures to police or insurers not logged
Named, not quoted
- Illinois Eavesdropping Act, 720 ILCS 5/14: recording a private conversation without the consent of all parties (Illinois; named, not quoted)
These are named so you know to open them. We do not hold their text in full and the page does not state what they require beyond the one line above.
The clauses cited here
7 clausesBIPA s. 15(a)Written, public retention schedule and destruction guidelines, appliedWritten, public retention schedule and destruction guidelines, applied. A private entity in possession of biometric identifiers or biometric information must develop a written policy, made available to the public, that establishes a retention schedule and guidelines for permanently destroying the identifiers and information when the initial purpose for collecting or obtaining them has been satisfied or within three years of the individual's last interaction with the entity, whichever comes first. Absent a valid warrant or subpoena issued by a court of competent jurisdiction, the entity must comply with its own established schedule and guidelines. The duty attaches on possession, so an entity that holds biometric data collected by a vendor on its behalf must publish the policy as well.
BIPA s. 15(b)(1)Written notice that a biometric identifier or information is being collected or storedWritten notice that a biometric identifier or information is being collected or stored. Before collecting, capturing, purchasing, receiving through trade or otherwise obtaining a person's or customer's biometric identifier or biometric information, the private entity must inform the subject, or the subject's legally authorized representative, in writing that a biometric identifier or biometric information is being collected or stored. The notice must precede the first collection; a notice given after enrolment does not cure the collection already made.
BIPA s. 15(b)(2)Written notice of the specific purpose and length of term of collection, storage and useWritten notice of the specific purpose and length of term of collection, storage and use. Before obtaining a biometric identifier or biometric information, the private entity must inform the subject or the subject's legally authorized representative in writing of the specific purpose for which, and the length of term for which, the identifier or information is being collected, stored and used. The purpose must be specific to the use (timekeeping, facility access, identity verification for a transaction) and the term must be stated, which in practice ties the notice to the retention schedule of 15(a).
BIPA s. 15(b)(3)Written release executed by the subject or representative before collectionWritten release executed by the subject or representative before collection. Before obtaining a biometric identifier or biometric information, the private entity must receive a written release executed by the subject of the identifier or information or by the subject's legally authorized representative. A written release is informed written consent, an electronic signature (a checkbox, click-through or other electronic process executed with intent to sign, confirmed by the 2024 amendment) or, in employment, a release executed by an employee as a condition of employment. For a minor the release comes from the parent or guardian.
BIPA s. 15(c)No sale, lease, trade or other profit from biometric identifiers or informationNo sale, lease, trade or other profit from biometric identifiers or information. No private entity in possession of a biometric identifier or biometric information may sell, lease, trade or otherwise profit from a person's or a customer's biometric identifier or biometric information. The prohibition is absolute; consent does not authorise it. Courts have distinguished profiting from the data itself, which is banned, from charging for a product or service that uses biometrics, which is not.
BIPA s. 15(d)No disclosure, redisclosure or dissemination except on four groundsNo disclosure, redisclosure or dissemination except on four grounds. No private entity in possession of a biometric identifier or biometric information may disclose, redisclose or otherwise disseminate a person's or customer's biometric identifier or biometric information unless the subject or the subject's legally authorized representative consents to the disclosure or redisclosure; or the disclosure completes a financial transaction requested or authorized by the subject or representative; or the disclosure is required by State or federal law or municipal ordinance; or the disclosure is required by a valid warrant or subpoena issued by a court of competent jurisdiction. Transfer to a vendor or cloud provider is a disclosure that needs consent. Under section 20(c) as amended in 2024, repeated disclosure of the same identifier from the same person to the same recipient by the same method is a single violation with at most one recovery.
BIPA s. 15(e)(1)Reasonable standard of care within the entity's industryReasonable standard of care within the entity's industry. A private entity in possession of biometric identifiers or biometric information shall store, transmit and protect from disclosure all biometric identifiers and biometric information using the reasonable standard of care within the private entity's industry. The measure is what a reasonable entity in the same industry does for such data, which makes industry security standards and practice the yardstick.