🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
US-PA v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing13 sources retrieved model claude-sonnet-5 · 2026-08-06

Pennsylvania, USA

US-PA schema gdpri-v2 trajectory: not yet assessedregulated (sectoral)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 27 claims · 23 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
27Claimsbaseline..claims[]
4Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Pennsylvania's comprehensive consumer privacy legislation, House Bill 78 (the Consumer Data Privacy Act), advanced to Senate second consideration on June 25, 2026, after a Senate committee amendment on June 24, 2026 raised the bill's applicability threshold from 50,000 to 100,000 consumers, households, or devices. HB78 passed the House 127-76 on October 1, 2025 and remains pending in the Senate, meaning Pennsylvania still has no comprehensive consumer data privacy law in force as of this cycle, but the bill's advancement and the threshold amendment together mark a live legislative escalation on the state's core privacy framework.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A named regulator and an in-force breach-notification statute exist, but there is no comprehensive material/territorial scope test or general registration regime, only sectoral fragments.

Primary frameworkBreach of Personal Information Notification Act (BPINA), 73 P.S. §2301 et seq., as amended; Unfair Trade Practices and Consumer Protection Law, 73 P.S. §201-1 et seq.
Traffic-light rationale — AmberA named regulator and an in-force breach-notification statute exist, but there is no comprehensive material/territorial scope test or general registration regime, only sectoral fragments.

Sub-modules (5)

Regulator And AuthorityAmber

The Pennsylvania AG enforces consumer-protection and breach-notification law; no dedicated data-protection authority exists.

Claims (1):

  • Pennsylvania does not have a general/comprehensive privacy act; the Pennsylvania Attorney General is the state's regulator for consumer-protection and breach-notification matters.

Act And InstrumentsAmber

BPINA (2005) as amended by SB 696 (2022) and SB 824/825 (effective September 26, 2024) is the operative state DP instrument, addressing breach notification only.

Claims (1):

  • The Breach of Personal Information Notification Act of 2005, as amended by Senate Bill 696 (2022) and Senate Bill 824/825 (effective September 26, 2024), is Pennsylvania's primary state-level data-protection instrument and addresses breach notification only.

Material ScopeAmber

No PA-specific material scope test for 'personal data' processing generally; federal FTC Act Section 5 supplies a baseline unfair/deceptive-practices scope nationally.

Claims (1):

  • The FTC enforces Section 5 of the FTC Act, prohibiting unfair or deceptive practices, providing a general federal privacy-adjacent baseline applicable to entities operating in Pennsylvania absent a state omnibus law.

Territorial ScopeAmber

BPINA applies by reference to breaches affecting Pennsylvania residents (reporting trigger at 500+ residents), rather than an establishment/targeting test.

Claims (1):

  • BPINA's reporting obligations are triggered with respect to breaches impacting more than 500 Pennsylvania residents, defining the statute's practical territorial reach.

Regulator Registration And FilingAmber

No general controller registration regime exists; the only filing obligation is breach reporting to the AG via its online portal once the 500-resident threshold is met.

Claims (1):

  • The Pennsylvania AG launched an online portal to streamline breach reporting by companies for incidents impacting more than 500 Pennsylvania residents under amended BPINA.

Key findings (1)

  • — source on file
Category narrative78 words

Pennsylvania has no comprehensive consumer-privacy statute. The Pennsylvania Attorney General (Bureau of Consumer Protection) is the primary regulator, acting under the general Unfair Trade Practices and Consumer Protection Law (UTPCPL) and the state's dedicated Breach of Personal Information Notification Act (BPINA, 2005, as amended). Federal FTC Section 5 authority provides an additional, reactive national baseline. Material and territorial scope are defined narrowly (breach notification for computerized personal information of PA residents), not by a GDPR/CCPA-style omnibus scope test.

Periodic update · new data 2026-09-28

Regulator & Framework

Pennsylvania has no dedicated data-protection authority; the Pennsylvania Attorney General is the sole enforcement authority for the state's data-breach-notification law, the Breach of Personal Information Notification Act. This structural position remains unchanged this cycle. The active development is on the comprehensive-privacy-statute front: House Bill 78, the Consumer Data Privacy Act, passed the House 127-76 on October 1, 2025 and reached Senate second consideration on June 25, 2026. A Senate committee amendment dated June 24, 2026 raised the bill's applicability threshold from 50,000 to 100,000 consumers, households, or devices, narrowing the population of entities that would be covered were the bill enacted as amended.

HB78 would establish duties for controllers and processors of consumer data if enacted, but it has not yet passed the full Senate and Pennsylvania accordingly has no comprehensive consumer data privacy law in force as of this cycle. The threshold amendment is itself a material development: raising the applicability floor from 50,000 to 100,000 meaningfully narrows which businesses would be captured by the bill's controller/processor obligations, a scope-narrowing move typical of late-stage legislative negotiation on comprehensive privacy statutes.

Outlook

Whether HB78 clears the full Senate and is signed into law before the end of the 2025-2026 session, and whether the 100,000-threshold amendment survives to final passage or is further negotiated, remains the central open question for Pennsylvania's regulator-and-framework position.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. ConfirmedDataGuidance — Pennsylvania does not have a general/comprehensive privacy act; the Pennsylvania Attorney General is the state's regulator for consumer-protection and breach-notification matters.observed
  2. ConfirmedDataGuidance — The Breach of Personal Information Notification Act of 2005, as amended by Senate Bill 696 (2022) and Senate Bill 824/825 (effective September 26, 2024), is Pennsylvania's primary state-level data-protection instrument and addresses breach notification only.observed
  3. ConfirmedFederal Trade Commission — The FTC enforces Section 5 of the FTC Act, prohibiting unfair or deceptive practices, providing a general federal privacy-adjacent baseline applicable to entities operating in Pennsylvania absent a state omnibus law.observed
  4. ConfirmedDataGuidance — BPINA's reporting obligations are triggered with respect to breaches impacting more than 500 Pennsylvania residents, defining the statute's practical territorial reach.observed
  5. ConfirmedDataGuidance — The Pennsylvania AG launched an online portal to streamline breach reporting by companies for incidents impacting more than 500 Pennsylvania residents under amended BPINA.observed

#

No in-force general lawful-basis or consent regime; only pending bills identified via targeted search of PA legislative trackers.

Traffic-light rationale — RedNo in-force general lawful-basis or consent regime; only pending bills identified via targeted search of PA legislative trackers.

Sub-modules (4)

Lawful BasesRed

No enacted enumerated lawful bases; HB 78 (pending) would create controller obligations and consumer rights.

Claims (1):

  • House Bill 78, the Consumer Data Privacy Act, would establish comprehensive data-controller obligations and consumer privacy rights in Pennsylvania but has passed the House and remains under Senate review, not yet enacted.

Special CategoriesRed

No enacted special/sensitive-category regime; pending genetic-data bills are the closest analogue.

Claims (1):

  • House Bills 1530 and 2627 would impose express-consent and data-security obligations on direct-to-consumer genetic testing companies operating in Pennsylvania, but remain pending, not enacted.

Pseudonymisation And AnonymisationRed

No PA-specific statutory definition of pseudonymisation or anonymisation was identified.

Key findings (1)

  • — source on file
Category narrative58 words

Pennsylvania has no enacted lawful-basis, consent-threshold, or special-category regime analogous to GDPR Art 6/7/9. House Bill 78 (Consumer Data Privacy Act) would introduce such a framework but remains pending before the Senate as of the dispatch date. Sector bills (HB 1530/HB 2627) would impose consent requirements specifically on direct-to-consumer genetic testing companies but are likewise not yet enacted.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (2)
  1. ProbableDataGuidance — House Bill 78, the Consumer Data Privacy Act, would establish comprehensive data-controller obligations and consumer privacy rights in Pennsylvania but has passed the House and remains under Senate review, not yet enacted.observed
  2. ProbableDataGuidance — House Bills 1530 and 2627 would impose express-consent and data-security obligations on direct-to-consumer genetic testing companies operating in Pennsylvania, but remain pending, not enacted.observed

#

No in-force general data-subject-rights framework at state level; only a pending bill identified.

Traffic-light rationale — RedNo in-force general data-subject-rights framework at state level; only a pending bill identified.

Sub-modules (5)

Access RightRed

No enacted general access right; HB 78 (pending) would grant consumer rights typical of state comprehensive laws.

Claims (1):

  • House Bill 78 outlines data-privacy obligations for businesses and would grant consumer rights (access, correction, deletion, opt-out) in Pennsylvania, but as of the dispatch date it remains under Senate review following passage of its third reading in the House.

Rectification And ErasureRed

Not addressed by enacted state law; dependent on eventual passage of HB 78.

Restriction And ObjectionRed

No enacted restriction/objection right identified.

Data PortabilityRed

No enacted portability right identified.

Deadlines And Response WindowsRed

No statutory response-window requirement for consumer rights requests exists under current PA law.

Key findings (1)

  • — source on file
Category narrative63 words

No enacted PA statute grants a general set of subject-access, rectification, erasure, restriction, objection or portability rights. Federal sectoral rights (e.g., HIPAA access, GLBA opt-out) may apply to specific data categories but are treated as part of the US-federal JID rather than duplicated here. House Bill 78 would introduce comprehensive consumer rights modeled on other state omnibus laws but is not yet enacted.

Sources and claims (1)
  1. ProbableDataGuidance — House Bill 78 outlines data-privacy obligations for businesses and would grant consumer rights (access, correction, deletion, opt-out) in Pennsylvania, but as of the dispatch date it remains under Senate review following passage of its third reading in the House.observed

#

Breach notification and an insurance-sector security-program duty are in force; general accountability/DPIA/DPO/ROPA obligations are absent.

Primary frameworkBreach of Personal Information Notification Act; Pennsylvania Insurance Data Security Act
Traffic-light rationale — AmberBreach notification and an insurance-sector security-program duty are in force; general accountability/DPIA/DPO/ROPA obligations are absent.

Sub-modules (7)

Accountability And DpiaRed

No general accountability/DPIA duty in force; HB 1879 (pending) would mandate DPIAs for children's-data processing.

Claims (1):

  • House Bill 1879 would mandate DPIAs and high default privacy settings for children's data and prohibit high-risk profiling and unauthorized data use, but remains pending, not enacted, as of the dispatch date.

Dpo RequirementsRed

No DPO appointment threshold identified under PA law.

Ropa RequirementsRed

No records-of-processing obligation identified under PA law.

Joint Controller ArrangementsRed

No joint-controller regime identified under PA law.

Security MeasuresAmber

The Insurance Data Security Act imposes technical and organisational security-program requirements on licensed insurance entities in the Commonwealth.

Claims (1):

  • The Pennsylvania Insurance Data Security Act imposes strict cybersecurity measures, and compliance and notification requirements, on insurance entities licensed in the Commonwealth.

Breach NotificationAmber

BPINA (as amended) requires notification to the PA AG (via online portal) and affected residents once the 500-resident threshold is met, with credit-monitoring and reporting provisions added by SB 824/825.

Claims (1):

  • Following the September 26, 2024 effective date of SB 824/825, BPINA requires notification of breaches impacting more than 500 Pennsylvania residents to the Attorney General via a dedicated online portal, alongside credit-monitoring and reporting provisions.

Retention And DisposalRed

No general retention-limit or disposal-duty statute was identified for Pennsylvania.

Key findings (1)

  • — source on file
Category narrative65 words

General accountability, DPIA, DPO, ROPA and joint-controller obligations of the GDPR type are absent from Pennsylvania law. Two enforceable duties exist in sectoral form: (1) the Insurance Data Security Act imposes cybersecurity-program requirements on licensed insurance entities, and (2) BPINA imposes a breach-notification duty (regulator and consumer notice) once thresholds are met. House Bill 1879 would add DPIA-style obligations for children's data but is pending.

Periodic update · new data 2026-09-28

Controller/Processor Duties

Pennsylvania's standing, in-force controller/processor duty remains the breach-notification regime under the Breach of Personal Information Notification Act as amended by Act 33 of 2024, effective September 26, 2024. That regime requires concurrent notification to the Office of Attorney General for breaches affecting more than 500 Pennsylvania residents, alongside mandatory credit-monitoring offers for most breaches. This binding requirement is unchanged this cycle beyond its already-established position; no new controller/processor duty took effect this cycle.

The forward-looking development on this front is House Bill 78, the Consumer Data Privacy Act, which would create a broader set of controller and processor duties beyond breach notification if enacted, but which remains pending in the Senate following its October 1, 2025 House passage and June 25, 2026 second-consideration vote. Because HB78 has not been enacted, it imposes no current controller/processor obligation, and the breach-notification regime under Act 33 of 2024 remains the sole binding controller/processor duty in Pennsylvania as of this cycle.

Outlook

Enactment of HB78 would introduce a substantially broader controller/processor duty framework than the current breach-notification-only regime; until then, the Act 33 breach-notification requirements remain the operative standard against which controllers and processors handling Pennsylvania residents' data must measure their compliance.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (3)
  1. ConfirmedDataGuidance — The Pennsylvania Insurance Data Security Act imposes strict cybersecurity measures, and compliance and notification requirements, on insurance entities licensed in the Commonwealth.observed
  2. ConfirmedDataGuidance — Following the September 26, 2024 effective date of SB 824/825, BPINA requires notification of breaches impacting more than 500 Pennsylvania residents to the Attorney General via a dedicated online portal, alongside credit-monitoring and reporting provisions.observed
  3. ProbableDataGuidance — House Bill 1879 would mandate DPIAs and high default privacy settings for children's data and prohibit high-risk profiling and unauthorized data use, but remains pending, not enacted, as of the dispatch date.observed

#

No comprehensive cross-border transfer regime exists in Pennsylvania law; this is a legitimate gap finding rather than an omission.

Traffic-light rationale — Not assessedNo comprehensive cross-border transfer regime exists in Pennsylvania law; this is a legitimate gap finding rather than an omission.

Sub-modules (6)

Transfer MechanismsRed

No state transfer-mechanism regime identified.

Adequacy ReceivedRed

Not applicable; Pennsylvania is not a party to adequacy-style determinations.

Adequacy GrantedRed

Not applicable; Pennsylvania does not grant adequacy decisions.

Sccs And BcrsRed

No state-mandated SCC/BCR uptake requirement identified.

Transfer Impact AssessmentRed

No TIA requirement identified under PA law.

Data LocalisationRed

No data-localisation mandate identified under PA law.

Key findings (1)

  • — source on file
Category narrative54 words

No PA-specific transfer mechanism, adequacy-recognition process, SCC/BCR uptake requirement, transfer-impact-assessment duty, or data-localisation mandate was identified. Because Pennsylvania has no omnibus privacy statute, cross-border transfer restrictions of the GDPR type simply do not exist at the state level; any constraints derive from federal sectoral law (out of scope for this JID) or contractual practice.

#

Insurance/financial sector overlays are in force; other sectors (employment, education, credit-scoring) remain at the pending-bill stage.

Primary frameworkPennsylvania Insurance Data Security Act; Privacy of Consumer Financial Information Law (31 Pa. Code Ch. 146a); Standards for Safeguarding Law (31 Pa. Code Ch. 146c)
Traffic-light rationale — AmberInsurance/financial sector overlays are in force; other sectors (employment, education, credit-scoring) remain at the pending-bill stage.

Sub-modules (7)

Financial Sector OverlayAmber

Insurers' handling of consumer financial information is governed by dedicated privacy and safeguarding chapters of the Pennsylvania Code.

Claims (1):

  • Pennsylvania's financial privacy and safeguards laws are specifically targeted at insurers: consumer financial information privacy is governed by Chapter 146a and its safeguarding by Chapter 146c of Title 31 of the Pennsylvania Code.

Health Sector OverlayAmber

Health data protection in Pennsylvania relies on federal HIPAA and, for non-HIPAA-covered health apps, the FTC Health Breach Notification Rule; no PA-specific health-privacy statute was identified.

Claims (1):

  • For most hospitals, doctors' offices, and insurance companies, HIPAA governs health-record privacy and security; the FTC's Health Breach Notification Rule fills the gap for health apps and connected devices not covered by HIPAA nationally, including in Pennsylvania.

Telecoms And EprivacyAmber

The Telemarketer Registration Act governs Do-Not-Call enrollment, robocalls, and telephone solicitation timing.

Claims (1):

  • Pennsylvania's Telemarketer Registration Act, amended in October 2019, removed the five-year limit on Do Not Call List enrollment, prohibited solicitation calls on legal holidays, and created procedures governing robocalls.

Employment DataRed

House Bill 1559 would require PA employers to notify employees of electronic monitoring, with fines for violations, but remains pending.

Claims (1):

  • House Bill 1559 would require Pennsylvania employers to notify employees of electronic monitoring, with fines for violations, but remains pending, not enacted.

Credit And ScoringRed

No PA-specific credit-scoring privacy statute identified beyond federal FCRA (out of scope for this JID).

EducationRed

Senate Bill 378 seeks to enhance student data privacy and protection in Pennsylvania but is pending.

Claims (1):

  • Senate Bill 378 seeks to enhance student data privacy and protection in Pennsylvania but has not been enacted as of the dispatch date.

InsuranceAmber

The Insurance Data Security Act imposes cybersecurity-program, investigation, and notification requirements on licensed insurance entities.

Claims (1):

  • The Pennsylvania Insurance Data Security Act enforces strict cybersecurity measures for licensed insurance entities, with compliance and notification requirements.

Key findings (1)

  • — source on file
Category narrative80 words

Sectoral overlays exist for insurance/financial data and telemarketing, with employment and education-sector bills pending. The Privacy of Consumer Financial Information Law and Standards for Safeguarding Law (31 Pa. Code Ch. 146a/146c) govern insurers' handling of consumer financial information; the Insurance Data Security Act adds cybersecurity duties. The Telemarketer Registration Act governs the Do-Not-Call regime. Health data is governed principally by federal HIPAA and, for non-HIPAA health apps, the FTC's Health Breach Notification Rule (both federal, noted here as overlay context).

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (6)
  1. ConfirmedDataGuidance — Pennsylvania's financial privacy and safeguards laws are specifically targeted at insurers: consumer financial information privacy is governed by Chapter 146a and its safeguarding by Chapter 146c of Title 31 of the Pennsylvania Code.observed
  2. ConfirmedFederal Trade Commission — For most hospitals, doctors' offices, and insurance companies, HIPAA governs health-record privacy and security; the FTC's Health Breach Notification Rule fills the gap for health apps and connected devices not covered by HIPAA nationally, including in Pennsylvania.observed
  3. ConfirmedDataGuidance — Pennsylvania's Telemarketer Registration Act, amended in October 2019, removed the five-year limit on Do Not Call List enrollment, prohibited solicitation calls on legal holidays, and created procedures governing robocalls.observed
  4. ProbableDataGuidance — House Bill 1559 would require Pennsylvania employers to notify employees of electronic monitoring, with fines for violations, but remains pending, not enacted.observed
  5. ProbableDataGuidance — Senate Bill 378 seeks to enhance student data privacy and protection in Pennsylvania but has not been enacted as of the dispatch date.observed
  6. ConfirmedDataGuidance — The Pennsylvania Insurance Data Security Act enforces strict cybersecurity measures for licensed insurance entities, with compliance and notification requirements.observed

#

Only a narrow telemarketing/Do-Not-Call regime is in force; broader adtech/commercial-privacy protections are absent.

Primary frameworkTelemarketer Registration Act
Traffic-light rationale — RedOnly a narrow telemarketing/Do-Not-Call regime is in force; broader adtech/commercial-privacy protections are absent.

Sub-modules (6)

Cookies And TrackersRed

No cookie/tracker consent statute identified.

Dark PatternsRed

No dark-pattern prohibition identified under PA law.

Opt Out SignalsRed

No recognized universal opt-out signal (e.g., GPC) obligation identified under PA law.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rules identified.

Cross Context AdvertisingRed

No 'sale'/'share' cross-context-advertising concept exists under PA law.

Direct MarketingAmber

The Telemarketer Registration Act governs telephone-based direct marketing, Do-Not-Call enrollment, and robocall procedures.

Claims (1):

  • Pennsylvania's Telemarketer Registration Act regulates telephone solicitation, Do Not Call List enrollment, and robocall practices as the state's principal direct-marketing-adjacent privacy instrument.

Key findings (1)

  • — source on file
Category narrative41 words

Pennsylvania has no cookie/tracker consent law, dark-pattern prohibition, recognized opt-out signal regime, clean-room framework, or cross-context-advertising 'sale/share' concept of the CPRA type. The only adjacent commercial-privacy instrument identified is the Telemarketer Registration Act, which governs direct telephone marketing and Do-Not-Call compliance.

Sources and claims (1)
  1. ConfirmedDataGuidance — Pennsylvania's Telemarketer Registration Act regulates telephone solicitation, Do Not Call List enrollment, and robocall practices as the state's principal direct-marketing-adjacent privacy instrument.observed

#

A cluster of AI/biometric/genetic bills is in the legislative pipeline, but none are yet in force; PA has no enacted ADM-transparency, profiling, or biometric regime.

Traffic-light rationale — RedA cluster of AI/biometric/genetic bills is in the legislative pipeline, but none are yet in force; PA has no enacted ADM-transparency, profiling, or biometric regime.

Sub-modules (6)

Profiling RestrictionsRed

No enacted profiling-restriction analogous to GDPR Art 22; HB 1879 (children's-data profiling ban) is pending, tracked under children_and_vulnerable_groups.

Automated Decision Making TransparencyRed

No enacted ADM-transparency right identified in Pennsylvania.

Ai Risk AssessmentsRed

No enacted AI-risk-assessment mandate; several disclosure/liability bills (HB 95, HB 1533, HB 317, HB 2660) are pending.

Claims (1):

  • House Bill 95 would amend the Unfair Trade Practices and Consumer Protection Law to classify undisclosed AI-generated content as an unfair or deceptive practice, and was referred to the House Communications and Technology Committee on January 14, 2025, without further enactment identified.

Biometric RegimeRed

No Pennsylvania-specific biometric-data statute (facial recognition, fingerprint, gait) was identified.

Genetic DataRed

House Bills 1530 and 2627 would regulate direct-to-consumer genetic testing companies' consent, security, and disclosure practices, but remain pending.

Claims (1):

  • House Bill 1530 and House Bill 2627 would impose express-consent and data-security obligations, and prohibit unauthorized disclosures, on direct-to-consumer genetic testing companies in Pennsylvania, but remain pending.

State Surveillance CarveoutsRed

No PA-specific state-surveillance carveout was identified; this domain is predominantly federal.

Key findings (1)

  • — source on file
Category narrative77 words

Pennsylvania has no enacted profiling-restriction, ADM-transparency, AI-risk-assessment, biometric, or genetic-data statute. Several bills are pending: SB 1090 (AI chatbot protections for minors, passed the Senate as of mid-2026), HB 95 (UTPCPL amendment requiring AI-content disclosure, referred to committee), HB 1533 (AI system deployment liability), HB 317/HB 2660 (AI-content watermarking), and HB 1530/HB 2627 (genetic-testing consent/security). None have been signed into law as of the dispatch date. No PA-specific biometric-privacy statute (of the Illinois BIPA type) was identified.

Sources and claims (3)
  1. ProbableDataGuidance — Senate Bill 1090, aimed at protecting minors from AI chatbots, passed the Pennsylvania State Senate, imposing new disclosure and safeguard requirements on operators, but has not yet been enacted into law.observed
  2. ProbableDataGuidance — House Bill 95 would amend the Unfair Trade Practices and Consumer Protection Law to classify undisclosed AI-generated content as an unfair or deceptive practice, and was referred to the House Communications and Technology Committee on January 14, 2025, without further enactment identified.observed
  3. ProbableDataGuidance — House Bill 1530 and House Bill 2627 would impose express-consent and data-security obligations, and prohibit unauthorized disclosures, on direct-to-consumer genetic testing companies in Pennsylvania, but remain pending.observed

#

All identified children's-data protections in Pennsylvania are at the pending-bill stage; none are in force.

Traffic-light rationale — RedAll identified children's-data protections in Pennsylvania are at the pending-bill stage; none are in force.

Sub-modules (5)

Age VerificationRed

Senate Bill 22 would require parental consent and age-related safeguards for minors on social media, but is pending.

Claims (1):

  • Pennsylvania Senate Bill 22 seeks to protect minors on social media by enforcing parental consent and penalizing harmful content exposure, but has not been enacted as of the dispatch date.

Minor Profiling BansRed

House Bill 1879 would prohibit high-risk profiling of children's data and mandate high default privacy settings, but remains pending.

Claims (1):

  • House Bill 1879 mandates DPIAs and high privacy settings for children's data and prohibits high-risk profiling and unauthorized data use, but remains pending, not enacted.

Education SettingsRed

Senate Bill 378 would enhance student data privacy protections but has not been enacted.

Claims (1):

  • Senate Bill 378 seeks to enhance student data privacy and protection in Pennsylvania but has not been enacted as of the dispatch date.

Dependent AdultsRed

No Pennsylvania-specific statute addressing data protections for dependent or incapacitated adults was identified.

Key findings (1)

  • — source on file
Category narrative59 words

No enacted PA statute sets an age of consent for data processing, mandates parental consent for minors' data, bans minor profiling, imposes education-setting-specific data rules, or protects dependent adults' data specifically. Pending bills include SB 22 (parental consent for minors on social media), HB 1879 (DPIA mandate and profiling ban for children's data), and SB 378 (student data privacy).

Sources and claims (3)
  1. ProbableDataGuidance — Pennsylvania Senate Bill 22 seeks to protect minors on social media by enforcing parental consent and penalizing harmful content exposure, but has not been enacted as of the dispatch date.observed
  2. ProbableDataGuidance — House Bill 1879 mandates DPIAs and high privacy settings for children's data and prohibits high-risk profiling and unauthorized data use, but remains pending, not enacted.observed
  3. ProbableDataGuidance — Senate Bill 378 seeks to enhance student data privacy and protection in Pennsylvania but has not been enacted as of the dispatch date.observed

#

AG enforcement power and a private right of action are in force under UTPCPL; there is no dedicated privacy regulator, no privacy-specific collective-redress statute, and enforcement activity is general-consumer-protection rather than privacy-specific.

Primary frameworkUnfair Trade Practices and Consumer Protection Law, 73 P.S. §201-1 et seq.
Traffic-light rationale — AmberAG enforcement power and a private right of action are in force under UTPCPL; there is no dedicated privacy regulator, no privacy-specific collective-redress statute, and enforcement activity is general-consumer-protection rather than privacy-specific.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

UTPCPL empowers the AG to pursue restitution and other equitable relief against companies for data-breach-related unfair/deceptive practices.

Claims (1):

  • The Unfair Trade Practices and Consumer Protection Law provides the Pennsylvania Attorney General with the power to enforce actions against companies sustaining large data breaches due to inadequate cybersecurity practices.

Enforcement Activity IndexAmber

The AG/GEICO settlement over unfair auto-insurance cancellations, arising from an AI-related investigation, is a recent example of general consumer-protection enforcement with data/AI dimensions.

Claims (1):

  • The Pennsylvania AG and GEICO agreed to improve consumer protections against unfair auto-insurance cancellations following an AI-related investigation.

Regulator Funding And CapacityRed

No specific funding or headcount data for the PA AG's Bureau of Consumer Protection was located in this research pass.

Collective Redress And Class ActionsRed

No PA-specific privacy class-action statute was identified beyond general UTPCPL private-action mechanics.

Private Right Of ActionAmber

UTPCPL creates a private cause of action with a fee-shifting component, allowing consumers to sue directly for breach-related unfair/deceptive practices.

Claims (1):

  • Pennsylvania's data-breach and consumer-protection statutes create a private cause of action with a fee-shifting component, enabling direct consumer litigation independent of AG enforcement.

Recent Developments 180DAmber

A federal comprehensive consumer-privacy bill, the SECURE Data Act (HR 8413), was introduced April 22, 2026 by a Pennsylvania member of Congress; it is a federal, not state, development and remains at an early legislative stage.

Claims (1):

  • On April 22, 2026, U.S. House Energy and Commerce Committee Vice Chairman John Joyce, R-Pa., introduced HR 8413, the SECURE Data Act, a comprehensive federal consumer-privacy bill representing an early-stage legislative proposal.

Key findings (1)

  • — source on file
Category narrative106 words

The UTPCPL gives the Pennsylvania AG power to bring enforcement actions against companies for large data breaches attributable to inadequate cybersecurity practices, and creates a private cause of action with fee-shifting, giving Pennsylvania consumers a route to court independent of AG action. Recent enforcement activity includes the PA AG/GEICO agreement improving consumer protections against unfair auto-insurance cancellations following an AI-related investigation. At the federal level, a comprehensive consumer-privacy bill (the SECURE Data Act, HR 8413) was introduced in Congress on April 22, 2026 by a Pennsylvania member of the House Energy and Commerce Committee, though this is federal, not state, legislation and remains in early-stage negotiation.

Periodic update · new data 2026-09-28

Enforcement & Redress

Pennsylvania's enforcement and redress landscape is escalating on two separate legislative tracks this cycle. First, the Pennsylvania Attorney General currently holds exclusive enforcement authority for the Breach of Personal Information Notification Act under the statute's Section 8 civil-relief provision, and no private right of action exists under current law. Second, House Bill 997 would change that position directly: it would introduce a private right of action allowing individuals to sue companies for damages arising from a data breach. HB997 passed the House 112-91 and cleared the Senate Consumer Protection Committee by a 14-0 vote in February 2026, and is now pending before the Senate Communications and Technology Committee.

Separately, House Bill 78's continued advancement, reaching Senate second consideration on June 25, 2026, is itself relevant to the enforcement-and-redress picture: a comprehensive privacy statute typically carries its own enforcement mechanism, and HB78's progress alongside HB997's private-right-of-action proposal together represent the most significant potential expansion of Pennsylvania's privacy enforcement and redress architecture since the Attorney-General-only breach-notification model was established. Neither bill has been enacted, so the Attorney-General-only enforcement posture remains the current, binding position.

Outlook

Whether HB997 advances out of the Senate Communications and Technology Committee following its unanimous Senate Consumer Protection Committee approval in February 2026 is the key near-term marker for whether Pennsylvania moves toward a private-right-of-action model for data-breach redress, materially changing accountability dynamics beyond the current Attorney-General-exclusive framework.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (4)
  1. ConfirmedDataGuidance — The Unfair Trade Practices and Consumer Protection Law provides the Pennsylvania Attorney General with the power to enforce actions against companies sustaining large data breaches due to inadequate cybersecurity practices.observed
  2. ConfirmedDataGuidance — The Pennsylvania AG and GEICO agreed to improve consumer protections against unfair auto-insurance cancellations following an AI-related investigation.observed
  3. ConfirmedDataGuidance — Pennsylvania's data-breach and consumer-protection statutes create a private cause of action with a fee-shifting component, enabling direct consumer litigation independent of AG enforcement.observed
  4. ConfirmedIAPP — On April 22, 2026, U.S. House Energy and Commerce Committee Vice Chairman John Joyce, R-Pa., introduced HR 8413, the SECURE Data Act, a comprehensive federal consumer-privacy bill representing an early-stage legislative proposal.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct16.67
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Pennsylvania, USA
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 27 claim(s) (28 category placement(s)), 23 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacyadequacy granted
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacysccs and bcrs
Art. 49Cross-Border & Adequacytransfer impact assessment
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, controller_processor_duties (breach_notification/security_measures), sectoral_watch (financial/insurance/telecoms), and enforcement_and_redress (UTPCPL powers/private right of action) rest on T1/T2 anchors (FTC.gov, NAAG.org, DataGuidance primary-instrument summaries) and are Confirmed. lawful_processing_and_special_data, data_subject_rights, algorithmic_biometric_and_surveillance_governance, and children_and_vulnerable_groups rely on T2/T3 legislative-tracker sources describing pending (not-yet-enacted) bills, rated Probable/Uncertain. cross_border_and_adequacy carries no claims and is supported only by absent_field_provenance, reflecting a genuine regulatory gap given Pennsylvania's lack of an omnibus statute. adtech_and_commercial_privacy is populated only for the narrow telemarketing/Do-Not-Call sub-module, all other sub-modules are gap findings.

Unresolved questions (4):

  • Whether House Bill 78 (Consumer Data Privacy Act) will pass the PA Senate and be signed into law, and on what timeline.
  • Whether Senate Bill 1090 (AI chatbot protections for minors) will pass the PA House and be enacted.
  • Current headcount/funding data for the PA AG's Bureau of Consumer Protection privacy-enforcement capacity (not located in this pass).
  • Whether any Pennsylvania court has certified a privacy-related class action under UTPCPL's private-action provisions in the last 12 months.

Escalate to primary-source review: yes