Creates the Identity Verification for Consumer Services Act. Requires an entity that provides specified services to use identity verification to verify a person's identity before initiating or modifying an agreement to provide the service. Provides that an entity that provides a specified service that becomes aware of an attempted or confirmed identity theft through its compliance with the Act shall report the attempted or confirmed identity theft to the Attorney General. Provides that a violation of the Act constitutes an unlawful practice under the Consumer Fraud and Deceptive Business Practices Act. Limits home rule. Amends the Consumer Fraud and Deceptive Business Practices Act to make a conforming change. Effective January 1, 2027.
Creates the Automated License Plate Recognition System Act. Sets forth provisions regarding authorized uses of an automated license plate recognition system, data retention, prohibited uses of an automated license plate recognition system, restrictions, requirements for use, preservation and disclosure, required data collection, reporting requirements, admissibility, privacy, penalties, and a private right of action. Makes a conforming change in the Freedom of Information Act. Effective immediately.
Amends the Illinois Controlled Substances Act concerning the Prescription Monitoring Program. Provides that interstate data sharing agreements shall be mutual. Provides that the Department of Human Services shall only share data if the reciprocal state provides equal access to data of the reciprocating state to all authorized users, licensed health care entities, and application vendors regardless of their method of connection to the Prescription Monitoring Program for interstate data sharing. Effective immediately.
Creates the Protection of Neural Data Act. Requires any nonmedical person or organization using or facilitating neural devices to access individuals' neural data to publicly post all user agreements and privacy terms on their website and clearly disclose to individuals the health and safety risks associated with the device. Prohibits a covered entity from storing, retaining, or transferring an individual's neural data unless the individual consents. Requires that covered entities must delete all neural data in their possession and instruct all third party recipients to do the same within 30 days of an individual's retracting of consent. Authorizes the Attorney General and State's Attorneys to enforce the Act. Makes violation of this Act a Class 1 misdemeanor Creates a civil cause of action for violation and a presumption of at least $10,000 in damages for unauthorized transfer of neural data.
Amends the Right to Privacy in the Workplace Act. Provides that an employer enrolled in an Employment Eligibility Verification System, including the E-Verify program, shall not impose work authorization verification or re-verification requirements greater than those required by the Employment Eligibility Verification System. Provides that, if an employer receives notification from any federal agency or other outside third party not responsible for the enforcement of immigration law of a discrepancy as it relates to an employee's individual taxpayer identification number or other identifying documents, guarantees specified rights and protections to the employee. Makes changes in provisions concerning the administration and enforcement of the Act by the Department of Labor. Sets forth provisions concerning action for civil penalties brought by an interested party; private right of action; penalties; and review under the Administrative Review Law.
Creates the Digital Assets and Consumer Protection Act. Provides that the Department of Financial and Professional Regulation shall regulate digital asset business activity in the State. Sets forth provisions concerning: applicability; the powers and duties of the Department; funds; customer protections; custody and protection of customer assets; covered exchanges; compliance; registration; supervision; records; additional procedural provisions; confidentiality; violations; enforcement; rulemaking authority; and severability. Creates the Special Purpose Trust Company Article in the Corporate Fiduciary Act. Sets forth provisions concerning certificates of authority; rulemaking and organization; certificates of authority for foreign corporate fiduciaries; eligibility; fees; and certificates of reciprocity. Makes other changes to various Acts. Effective immediately.
Creates the Virtual Currency Kiosk Consumer Protection Act. Provides that specified information reported to the Department of Financial and Professional Regulation by virtual currency kiosk shall be confidential, except as otherwise provided in the Act. Establishes warning and general terms and conditions disclosure requirements for a virtual currency kiosk operator opening an account for a new customer and prior to entering into an initial transaction for, on behalf of, or with the customer. Requires a receipt to be provided to each customer following a transaction. Requires all virtual currency kiosk operators to have live customer service, as specified; create anti-fraud, enhanced due diligence, and federal and State law compliance policies; designate a compliance officer and a consumer protection officer; and use blockchain analytics software to assist in the prevention of sending purchased virtual currency from a virtual currency kiosk operator to a digital wallet known to be affiliated with fraudulent activity at the time of a transaction; and report the location of each virtual currency kiosk located within this State within 45 days after the end of the calendar quarter. Requires a virtual currency kiosk operator to receive a money transmitter license. Sets forth supervision duties for the Department and the Secretary of Financial and Professional Regulation.
Amends the Illinois Century Network Act. Provides that the connection of anchor institutions to the Illinois Century Network shall be prioritized according to the type of anchor institution, starting with schools and libraries.
Creates the Behavioral Health Workforce Data Collection Act. Requires The Department of Financial and Professional Regulation to collect data, as specified, from behavioral health professionals at the time of initial application for licensure and renewal of an active license. Requires the Department to ensure the data collection process is secure and adheres to State and federal privacy laws, including de-identification of personal data. Provides that the Department shall make the collected data publicly available in an aggregated, de-identified format. Requires the data to be published in a format that allows policy groups, advocates, and other stakeholders to monitor the diversity, linguistic capacity, and availability of the behavioral health workforce; identify regions and specialties with severe shortages; and forecast future workforce needs. Requires the Department to publish the aggregated data annually by January 31 on its website and through other accessible formats. Grants the Department rulemaking authority to implement the Act. Requires the Department to comply with applicable data privacy and confidentiality laws. Provides that, for a period of 2 years following the effective date of the Act, the Department shall submit to the Illinois Behavioral Health Workforce Center a list of email addresses or email communications, subject to data privacy and confidentiality laws, of all licensed behavioral health professionals exclusively for purposes of collecting data related to the behavioral health workforce in Illinois. Effective immediately.
Amends the Emergency Medical Services (EMS) Systems Act. In provisions concerning opioid overdose reporting, provides that overdose information reported by a covered vehicle service provider shall not be used in an opioid use-related criminal investigation, prosecution, welfare checks, or warrant checks of the individual who was treated by the covered vehicle service provider personnel for experiencing the suspected or actual overdose. Provides that any misuse of the information reported by a covered vehicle service provider shall result in, but is not limited to, the Department of Transportation reporting misuse to the Washington/Baltimore High Intensity Drug Trafficking Area Overdose Detection Mapping Application or similar technology platform. Permits the Department of Health to adopt rules to set forth standards under which misuse of access may be reported to the Washington/Baltimore High Intensity Drug Trafficking Area Overdose Detection Map or similar platform based on misuse or misconduct by a covered vehicle service provider or other individual or entity at the discretion of the Department. Provides that no data that allows for or creates a risk of identification of an individual or individuals experiencing a suspected or actual overdose treated by the covered vehicle service provider personnel shall be submitted to the Washington/Baltimore High Intensity Drug Trafficking Area Overdose Detection Mapping Application or Similar technology platform. Provides that covered vehicle service provider personnel may report overdose surveillance through an identified technology platform for the use of overdose surveillance under exceptions to HIPAA and the reported data shall only be used to support public safety and public health efforts. Sets forth additional provisions concerning requirements for the Department concerning opioid overdose reporting.