2-17-552. Collection of personally identifiable information -- requirements. (1) A government website operator may not collect personally identifiable information online from a website user unless the operator complies with the provisions of this section.
(2) A government website operator shall ensure that the website:
(a) identifies who operates the website;
(b) provides the address and telephone number at which the operator may be contacted as well as an electronic means for contacting the operator; and
(c) generally describes the operator's information practices, including policies to protect the privacy of the user and the steps taken to protect the security of the collected information.
(3) In addition to the requirements of subsection (2), if the personally identifiable information may be used for a purpose other than the express purpose of the website or may be given or sold to a third party, except as required by law, then the operator shall ensure that the website includes:
(a) a clear and conspicuous notice to the user that the information collected could be used for other than the purposes of the website;
(b) a general description of the types of third parties that may obtain the information; and
(c) a clear, conspicuous, and easily understood online procedure requiring an affirmative expression of the user's permission before the information is collected.