Do Illinois Dispensaries Share Information With the Government?

Yes. Illinois dispensaries share a great deal of information with the government, and the sharing runs in several directions at once. Every sale, inventory movement, and financial record flows to state regulators through mandatory tracking and reporting systems, and banking activity generates parallel federal reports. At the same time, Illinois law shields specific categories of information — customer identities, medical patient records, dispensary security plans, and criminal history data — from public disclosure and imposes real penalties when a dispensary mishandles personal data it collects from you.

What Dispensaries Report to State Regulators

The Cannabis Regulation and Tax Act (CRTA) requires dispensaries to keep and produce a wide range of records. Under Section 15-65, every dispensary must maintain business records covering assets, liabilities, monetary transactions, invoices, receipts, and supporting documents for five years.1Justia. Illinois Code 410 ILCS 705 – Article 15, License and Regulation of Dispensing Organizations

Section 15-75 layers a real-time reporting obligation on top of that. Every dispensary must run a web-based point-of-sale system that logs the date of each sale, the amount sold, the price, and the currency used. The Illinois Department of Financial and Professional Regulation (IDFPR) can access that system at any time. Documentation from the system must also be stored in a locked location at the dispensary for five years, and bank account records carry the same five-year retention.1Justia. Illinois Code 410 ILCS 705 – Article 15, License and Regulation of Dispensing Organizations

Section 15-110 requires dispensaries to keep operating procedures, inventory logs, and financial accounts electronically for at least three years and make them available to IDFPR on request.2Illinois General Assembly. Illinois Code 410 ILCS 705 – Cannabis Regulation and Tax Act

On top of the daily reporting, every licensed cannabis business must use the state’s designated seed-to-sale tracking platform, which follows products from cultivation to final sale. Illinois moved to Metrc in 2025.3Cannabis Regulation Oversight Office. Seed-to-Sale FAQs The CRTA requires each dispensary’s agent-in-charge to reconcile inventory daily so the state’s tracking system, the dispensary’s point-of-sale records, and the physical product on the shelf all match. Dispensaries also file an annual compilation report — reviewed and certified by a licensed CPA — that includes income statements, balance sheets, profit-and-loss statements, cash flow, wholesale costs, and sales data, due within 60 days after the end of the calendar year.1Justia. Illinois Code 410 ILCS 705 – Article 15, License and Regulation of Dispensing Organizations

Employees who make sales or adjust inventory are individually identified in the tracking system and hold unique API keys, so the record links specific staff to specific transactions.3Cannabis Regulation Oversight Office. Seed-to-Sale FAQs

Who Can Walk In and Inspect

IDFPR’s inspection authority is broad. Under Section 15-135, the department and its authorized representatives can enter any place where cannabis is held, stored, sold, or transported and inspect equipment, containers, labeling, records, financial data, sales data, pricing data, personnel data, and inventory. They can also take samples of cannabis products.2Illinois General Assembly. Illinois Code 410 ILCS 705 – Cannabis Regulation and Tax Act

The administrative code authorizes random, unannounced inspections and cannabis testing. IDFPR can investigate any applicant, dispensing organization, principal officer, agent, or third-party vendor for alleged violations, and failing to produce requested documents is itself grounds for discipline.4Illinois Department of Financial and Professional Regulation. DFPR Administrative Code 1290 The Illinois Department of Revenue also uses this record access to audit cannabis excise tax compliance.5Illinois Department of Revenue. Cannabis Taxes

The Federal Layer Through Banking

State legalization did not switch off federal financial reporting. The Financial Crimes Enforcement Network (FinCEN) has stated that the obligation to file Suspicious Activity Reports under the Bank Secrecy Act is “unaffected by any state law that legalizes marijuana-related activity.”6FinCEN.gov. BSA Expectations Regarding Marijuana-Related Businesses Banks that serve dispensaries file SARs on cannabis-related transactions, which means dispensary financial activity produces a federal paper trail alongside the state one.

What the State Keeps Confidential

The CRTA also restricts what happens to information once the state has it. Section 55-30 makes most dispensary application materials, security plans, and supporting documents confidential and exempt from disclosure under the Illinois Freedom of Information Act. That information can only be shared among IDFPR, the Department of Agriculture, the Department of Public Health, the Department of Revenue, Illinois State Police, and the Attorney General when they are performing official duties.7Illinois General Assembly. Illinois Code 410 ILCS 705 – Cannabis Regulation and Tax Act, Confidentiality

Criminal history records submitted during licensing get stronger protection: IDFPR and the Department of Agriculture cannot disclose them to anyone except the Attorney General when enforcement requires it.7Illinois General Assembly. Illinois Code 410 ILCS 705 – Cannabis Regulation and Tax Act, Confidentiality Information collected during examinations, inspections, and investigations is also treated as confidential, so the public generally cannot use FOIA to obtain a dispensary’s security procedures, financial details, or licensing file.

Medical Cannabis Patient Privacy

Medical dispensaries face additional protections under the Compassionate Use of Medical Cannabis Program Act. Section 145 makes patient applications, registry information, designated caregiver details, and medical records submitted to the Department of Public Health confidential and exempt from FOIA. These records can be shared among the Departments of Public Health, Financial and Professional Regulation, Agriculture, and Illinois State Police only to administer the program.8Illinois General Assembly. Illinois Code 410 ILCS 130 – Compassionate Use of Medical Cannabis Program Act

One provision matters especially for patients: dispensing records required under the medical program must identify cardholders and cultivation centers by registry identification numbers only, not by name or other personally identifying information.8Illinois General Assembly. Illinois Code 410 ILCS 130 – Compassionate Use of Medical Cannabis Program Act That anonymization layer does not exist for adult-use customers.

A federal rule known as Part 2 (42 CFR Part 2) protects records of anyone receiving substance use disorder diagnosis, treatment, or referral through a federally assisted program, and generally prohibits sharing identifying information without written consent, an emergency, or a court order. A 2024 final rule aligned Part 2 more closely with HIPAA, with a compliance deadline of February 16, 2026.9U.S. Department of Health and Human Services. Understanding Confidentiality of Substance Use Disorder Patient Records or Part 2 Whether Part 2 covers a particular Illinois medical dispensary depends on whether it qualifies as a federally assisted program providing substance use disorder services, which is a fact-specific question.

How Your Personal Data Is Protected Under PIPA

The Illinois Personal Information Protection Act (PIPA) applies to any entity that handles nonpublic personal information about Illinois residents, dispensaries included. It creates duties around breach notification and disposal.10Illinois General Assembly. Illinois Code 815 ILCS 530 – Personal Information Protection Act

Breach Notification

If a dispensary suffers a data breach involving personal information, it must notify affected Illinois residents at no charge, in the most expedient time possible and without unreasonable delay. The notice must include contact information for consumer reporting agencies, the FTC’s address and website, and a statement that consumers can place fraud alerts and security freezes on their credit files. For breaches involving login credentials rather than financial data, the notice can instead direct consumers to change their passwords.11Illinois General Assembly. Illinois Code 815 ILCS 530/10 – Notice of Breach

Breaches affecting more than 500 Illinois residents also require notice to the Attorney General, who may publicly disclose the dispensary’s name, the types of personal information compromised, and the date range of the breach.12Illinois General Assembly. Illinois Code 815 ILCS 530 – Personal Information Protection Act

Disposal

When a dispensary throws out materials containing personal information, PIPA requires destruction thorough enough that the information cannot practically be read or reconstructed. Paper records must be shredded, burned, or pulverized; electronic media must be erased or destroyed. A dispensary that outsources disposal remains responsible for the contractor’s practices. Improper disposal carries civil penalties of up to $100 per affected individual, capped at $50,000 per incident, enforceable by the Attorney General.12Illinois General Assembly. Illinois Code 815 ILCS 530 – Personal Information Protection Act

Biometric Scans at the Door

If a dispensary collects a biometric identifier — a fingerprint at a secure entry, a face scan at a check-in kiosk, a palm scan for age verification — the Illinois Biometric Information Privacy Act (BIPA) applies. Before collecting the identifier, the dispensary must inform the person in writing that biometric data is being collected, explain the specific purpose and how long it will be stored, and obtain a signed written release.13Justia. Illinois Code 740 ILCS 14 – Biometric Information Privacy Act

BIPA gives individuals a private right to sue. Liquidated damages are $1,000 per violation for negligent conduct and $5,000 per violation for intentional or reckless conduct, plus attorney’s fees and costs. Courts can also grant injunctions.13Justia. Illinois Code 740 ILCS 14 – Biometric Information Privacy Act A 2024 amendment treats collecting the same biometric from the same person using the same method as a single violation, rather than a separate violation each time.

What You Can Do If a Dispensary Mishandles Your Information

Illinois consumers have several routes to relief. Any person who suffers actual damage from a violation of the Consumer Fraud and Deceptive Business Practices Act can sue, and courts can award actual economic damages, reasonable attorney’s fees, and injunctive relief.14Illinois General Assembly. Illinois Code 815 ILCS 505/10a PIPA violations are classified as Consumer Fraud Act violations, so a data breach caused by a dispensary’s negligent security can expose the business to private litigation from affected customers.12Illinois General Assembly. Illinois Code 815 ILCS 530 – Personal Information Protection Act

BIPA is a separate and often more powerful remedy. It awards liquidated damages of $1,000 to $5,000 per violation regardless of whether the plaintiff suffered any financial harm.13Justia. Illinois Code 740 ILCS 14 – Biometric Information Privacy Act

On the regulatory side, IDFPR can revoke or suspend a dispensary’s license, place it on probation, issue cease-and-desist orders, refuse to renew, or impose fines of up to $20,000 per violation.15Justia. Illinois Code 410 ILCS 705 – Article 45, Enforcement and Immunities Section 45-5(d) of the CRTA also lets the Attorney General pursue violations of the act’s social equity, advertising, and predatory practice provisions as unlawful practices under the Consumer Fraud Act.16Illinois General Assembly. Illinois Code 410 ILCS 705/45-5 – License Suspension, Revocation, Other Penalties If you think a dispensary has mishandled your information, a complaint to IDFPR or the Attorney General’s office can trigger enforcement even where a private lawsuit is not the right fit.