Back to all lessons
Awareness Lessons
2 months ago

Illinois Prosecutors Shared Defendant Data with ICE Without Warrants or Oversight

County prosecutors in Illinois shared personal data of defendants with ICE without criminal warrants, public disclosure, or legislative oversight, effectively bypassing the state's TRUST Act protections. The root cause is a failure of data governance and regulatory compliance — staff at multiple levels had the ability and willingness to share sensitive personal data without proper authorization frameworks in place. This matters because individuals' immigration status, personal records, and legal proceedings constitute highly sensitive data that carries life-altering consequences when mishandled. The lack of logging, oversight, and clear data-sharing policies meant this practice went undetected and unchallenged for an extended period, demonstrating that compliance laws alone are insufficient without enforcement mechanisms.

Tactical Insight

Immediate actions

  • Audit all existing data-sharing agreements and informal communications channels to identify unauthorized disclosures of defendant personal data.
  • Revoke or restrict staff permissions to share sensitive case data with external federal agencies without documented, supervisor-approved authorization.
  • Issue formal guidance to all prosecutorial staff clarifying what data may and may not be shared under the TRUST Act and applicable state law.

Long-term improvements

  • Implement a formal Data Sharing Agreement (DSA) policy requiring legal review and public disclosure before any defendant data is shared with federal agencies.
  • Establish role-based access controls (RBAC) on case management systems to limit who can export or transmit defendant personal data externally.
  • Embed privacy-by-design principles into prosecutorial workflows so that data minimization is the default practice.

Detection & Oversight measures

  • Enable comprehensive audit logging on all case management and email systems to create a tamper-evident record of data disclosures to external parties.
  • Appoint a dedicated Data Protection Officer (DPO) or Privacy Compliance Officer within each county prosecutor's office to monitor and enforce data-sharing policies.
  • Conduct periodic third-party compliance audits to assess adherence to the TRUST Act and flag unauthorized data-sharing patterns.