GroundRules
← Search the law
Illinois · Through at least Public Act 104-790

20 ILCS 505/5g: Administrative safeguards for sensitive identity information.

Read at publisher ↗
Where this section sits in the code
  1. CHAPTER 20 EXECUTIVE BRANCH
  2. Children and Family Services Act.

(a) The Department shall protect a child from unnecessary and unapproved disclosure of the child's sensitive identity information. Before or at the time the Department requests, initiates, or engages in a conversation, assessment, or service interaction in which a child may disclose the child's sensitive identity information to the Department or its service providing entities, the Department shall inform the child of the circumstances under which the Department or its service providing entities are permitted or required to share the child's sensitive identity information without the child's knowledge and agreement. If a child discloses the child's sensitive identity information before the Department provides this notice, the Department shall inform the child of these disclosure circumstances at the earliest possible opportunity, but no later than 14 days after the disclosure occurs. The Department shall document this discussion with the child in the Department's records, in a manner consistent with Department policy regarding documentation of sensitive identity information.

As used in this Section, "service providing entity" means a person, governmental unit, agency, organization, or body providing services or care for a child on behalf of the Department in accordance with a contract, grant agreement, or purchase-of-service agreement or any other person, governmental unit, agency, organization, or body subcontracted or otherwise engaged in the furtherance of those services, including, but not limited to, academic and research institutions and any person, governmental unit, agency, organization, or body that collects, processes, analyzes, stores, shares, or otherwise uses Department data that includes personal data that is or can be reasonably linked to an identified or identifiable individual served by the Department. A service providing entity does not include a recipient of Department records who is an attorney representing a child.

(b) If the Department discloses a child's sensitive identity information to the federal government, as required under federal law or pursuant to an order of a court of competent jurisdiction, the Department shall:

(1) limit such disclosure to the scope, purpose, and receiving party, and information necessary to comply with the specific legal necessity of that disclosure;

(2) narrow, limit, or de-identify that information to the fullest extent legally permitted before such disclosure;

(3) notify the child of the scope of the disclosure and receiving party as soon as the Department is legally permitted to inform the child; and

(4) document the date the Department made the disclosure, the scope of disclosure, the recipient party of the disclosure, and the activities completed by the Department to fulfill the obligations of paragraphs (1), (2), and (3).

The Department shall ensure that its service providing entities are also contractually obligated to limit disclosure of a child's sensitive identity information to a manner consistent with the restrictions described under this subsection.

(c) De-identified sensitive information.

(1) Datasets and aggregated data, including data related to a child's sensitive identity information that cannot reasonably be used to infer information about, re-identify, or otherwise be linked to an identified or identifiable child, are not considered a child's sensitive identity information for the purposes of this Section if the Department:

(A) takes reasonable measures to ensure the data cannot be linked to a child even if combined with other datasets or sources; and

(B) contractually obligates any third party recipient to process such data only in a de-identified manner; and

(C) prohibits any attempts to re-identify de-identified data.

(2) The Department shall not aggregate children's sensitive identity information unless:

(A) the information is gathered and maintained as de-identified sensitive information, as provided under paragraph (1); or

(B) the Department has a legitimate service delivery need that cannot be accomplished without the specific children's sensitive identity information.

(3) The Department may grant a third party access to Department data systems subject to the terms of Section 5g. Any third party granted access to Department data systems or records that include a child's sensitive identity information shall be prohibited from aggregating children's sensitive identity information in any manner that is not de-identified as prescribed under paragraph (1).

(d) Child-specific documentation requirement. The Department shall:

(1) maintain child-specific narrative sections within service plans, integrated assessments, and court reports;

(2) ensure that sensitive identity information concerning one child is not included in generalized family summaries or a sibling's child-specific record unless materially relevant to the safety or placement of that child's sibling or siblings or the permanency goal; and

(3) ensure a child is aware that the child's sensitive identity information is necessary for court reporting if the sensitive identity information is materially relevant to advance the child's permanency goal or ensure the child's safety or appropriate service provision.

(e) Internal electronic access controls. No later than January 1, 2028, the Department shall implement internal safeguards within its electronic case management systems to:

(1) limit access to a child's sensitive identity information to personnel with a documented case-related need; and

(2) segregate sensitive identity information fields from general case summaries where technologically feasible.

(f) The provisions of this Section apply on and after January 1, 2028, except that the provisions of subsection (b) apply on and after September 1, 2026 if the effective date of this amendatory Act of the 104th General Assembly is on or before September 1, 2026; otherwise, the provisions of this Section apply on and after January 1, 2028, except that the provisions of subsection (b) apply on and after December 1, 2026.

Collected 2026-09-15T04:46:13Z. Source file · JSON

Browse this collection