CRANDALL CONSULTING
HomePrivacy Laws Risk Scanner › Illinois

Illinois Website Tracking, Privacy & Wiretap Litigation

Published by Crandall Consulting · Informational litigation intelligence · Last intelligence update: August 31, 2026

41/100
Risk Guideline
Moderate
Risk Level
90%
Evidence Confidence
stable
Trend
1
Tracked Lawsuits
0
Tracked Matters
0
Tracked Demand Letters
0
Reported Claims
Limited data
GPC Opt-Out Signal Status

Lawsuits, demand letters, tracked matters, and reported claims are counted separately and are not interchangeable. Last intelligence update: August 31, 2026.

Risk scores, classifications, statistics, and technical findings are informational guidelines based on observed website behavior and publicly available litigation activity, statutes, court decisions, legal commentary, and other public sources. They are not legal advice, legal opinions, or determinations of liability.

Current Landscape

In Illinois the tracked litigation activity is currently modest: one tracked putative class action is pending. Relevant state and federal statutes that appear in tracked matters include the Illinois Eavesdropping Act (720 ILCS 5/14-1 et seq.) and the Illinois Biometric Information Privacy Act (BIPA) (740 ILCS 14/1 et seq.), and courts are also being asked to apply federal statutes in related privacy claims. The technologies appearing across tracked matters include third-party tracking pixels and scripts (e.g., Meta/Facebook Pixel and Facebook Conversions API), cookies (including example c_user cookies and first-party cookies), Google Analytics and other Google tracking tools, browser fingerprinting, IP and device identifiers, session replay and form-field capture, SDKs, URL/form field capture, appointment forms, patient portals, and a range of third-party vendors (Meta/Facebook, Google, LinkedIn, TikTok, Microsoft, Amazon).

Current Litigation Activity

Current litigation component: 3/100.

August 31, 2024 – August 31, 2026
Research Window
stable
Current Filing Trend
0
Filing Velocity
1
Filed Cases (est.)
0
Tracked Matters

Current Filing & Litigation Trends

Filing activity tracked in Illinois is currently limited to one filed case, but the matters focus on a consistent set of technologies and factual patterns: use of tracking pixels and analytics (including server-side conversion tools), cookie-based identifiers, form-field and URL capture, session replay, and cross-vendor data transfers. Courts in the tracked matter are parsing statutory theories under the Illinois Eavesdropping Act, VPPA-related allegations, and federal privacy statutes at the pleading stage.

Precedent Landscape: What Courts Have Decided

Precedent component: 50/100. Litigation activity (volume) and precedential risk (authority of decisions) are measured separately — a high number of filings does not by itself indicate strong plaintiff-favorable binding precedent.

No decided precedent with a clear substantive direction is currently tracked.

0
Plaintiff-Favorable
0
Defense-Favorable
0
Mixed / Neutral
0
Binding Decisions
0
Persuasive Decisions

A settlement is not a binding precedent, and a procedural dismissal (for example, for lack of standing) is not a holding that the underlying technology is lawful. Where courts disagree, that disagreement is reflected rather than resolved.

Current Laws & Relevant Statutes

Regulatory Enforcement

Regulatory enforcement component: 0/100. Regulatory enforcement (agency investigations, sweeps, settlements, guidance, rulemaking) is tracked separately from private litigation and is never counted as a lawsuit.

No specific enforcement actions are itemized for this jurisdiction.

Agency Guidance

Regulatory trend: insufficient data.

Global Privacy Control / Opt-Out Signals

Limited data

GPC / universal opt-out exposure component: limited data — this component is excluded from the overall risk guideline for this jurisdiction until researched (remaining components are reweighted accordingly).

GPC / universal opt-out privacy rights are a different legal theory from wiretap / interception litigation, though both affect third-party website data flows.

GPC evidence confidence: 50%.

Learn more about Global Privacy Control → · How GPC posture is weighted in the risk guideline →

Changes Coming in the Next 24 Months

Forward-looking (24-month) component: 0/100. Enacted changes with future effective dates may affect a jurisdiction's forward-looking risk, but are not presented as currently enforceable.

Coming Into Effect (Enacted)

No enacted future-effective laws identified in our latest research cycle.

Legislation to Watch (Pending)

No pending website-privacy legislation identified for this jurisdiction in our latest research cycle.

Important Cases & Tracked Matters

Dawson v. The University of Phoenix, Inc.

United States District Court for the Northern District of Illinois, Eastern Division · 2026-01-13 · lawsuit · Outcome: Mixed · Status: LITIGATION PENDING

What the court decided: The district court granted in part and denied in part Defendant University of Phoenix’s motion to dismiss. The court found Plaintiff plausibly pleaded that the University is a video tape service provider and that plaintiff is a consumer, and rejected the defendant’s arguments that the VPPA is unconstitutional and that statutory damages require proof of actual damages. The court dismissed VPPA claims to the extent premised on disclosures to Google, LinkedIn, TikTok, Microsoft, and Amazon, allowed other claims to proceed (Counts II and III) as to Facebook, Google, LinkedIn, TikTok, Microsoft, and Amazon, and dismissed certain allegations that the University directed third-parties to illegally intercept communications.

What the court did not decide: The court did not resolve the factual merits of whether the University actually disclosed protected information to third-parties, did not adjudicate liability or damages on the merits, and did not resolve at summary judgment or trial whether any particular vendor unlawfully intercepted communications. It likewise did not enter final judgment on any claim.

Technologies Appearing in Claims

Historical Risk Guideline

August 8, 2026: 20/100August 10, 2026: 40/100August 11, 2026: 40/100August 12, 2026: 40/100August 14, 2026: 41/100August 16, 2026: 41/100August 17, 2026: 41/100August 18, 2026: 41/100August 20, 2026: 41/100August 21, 2026: 41/100August 22, 2026: 41/100August 23, 2026: 41/100August 26, 2026: 41/100August 31, 2026: 41/100
DateRisk GuidelineLevelConfidenceTracked Lawsuits
August 11, 202640Moderate20%0
August 12, 202640Moderate42%0
August 14, 202641Moderate63%1
August 16, 202641Moderate78%1
August 17, 202641Moderate84%1
August 18, 202641Moderate84%1
August 20, 202641Moderate84%1
August 21, 202641Moderate84%1
August 22, 202641Moderate84%1
August 23, 202641Moderate87%1
August 26, 202641Moderate90%1
August 31, 202641Moderate90%1

What Businesses Should Review

Technical review suggestions for businesses operating in this landscape: perform an audit of all third-party scripts, pixels, SDKs and server-side trackers; map data flows from client pages (especially video players, appointment/patient portals, and form pages) to vendor endpoints; minimize collection and transmission of identifiable or sensitive fields, and disable or reconfigure tools that capture form fields or session replay on sensitive pages; implement or review consent-management and cookie controls; ensure logging, access controls, retention limits, encryption in transit and at rest, and up-to-date vendor DPAs that address data handling and deletion requests; and document decisions and settings so that technical configurations and contractual terms can be correlated if litigation or regulatory inquiries arise.

Data Quality

8
Primary Sources
22
Total Tracked Sources
fresh
Evidence Freshness
August 30, 2026
Last Research Run
August 12, 2026
Most Recent Source

22 source(s), 8 primary; evidence is fresh.

Methodology & Limitations

Statistics on this page are generated by the Crandall Consulting litigation intelligence engine. Publicly available sources (court and government materials, recognized legal press, professional analysis, and industry reports) are discovered through automated web research, classified into a tiered source hierarchy, and reduced to structured facts with full source provenance. Risk guidelines and evidence-confidence scores are computed by a deterministic formula from those stored facts — never by an AI model directly (AI explains findings; it never assigns a score). Counts labeled "tracked" reflect matters identified in our source set and are not official court statistics.

The overall risk guideline is composed of six deterministically weighted components: statutory structure (25%), current litigation activity (25%), prior precedent (18%), GPC / universal opt-out posture (15%), regulatory enforcement (9%), and the forward-looking 24-month horizon (8%). When a state's GPC status is limited data, that component is excluded and the remaining weights are renormalized — limited data never reads as lower exposure. Current litigation activity is measured over recent windows (velocity), not lifetime volume, so a jurisdiction with high historical activity but declining current filings reflects that decline. Litigation activity (volume) and precedential risk (authority of decisions) are measured separately. Full details are on the methodology page.

Sources

Risk scores, classifications, statistics, and technical findings are informational guidelines based on observed website behavior and publicly available litigation activity, statutes, court decisions, legal commentary, and other public sources. They are not legal advice, legal opinions, or determinations of liability.

All State Pages

Is Your Website Creating Hidden Tracking Risk?

Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.

Scan My Website