#
A named regulator and an in-force breach-notification statute exist, but there is no comprehensive material/territorial scope test or general registration regime, only sectoral fragments.
Sub-modules (5)
Regulator And AuthorityAmber
The Pennsylvania AG enforces consumer-protection and breach-notification law; no dedicated data-protection authority exists.
Claims (1):
- Pennsylvania does not have a general/comprehensive privacy act; the Pennsylvania Attorney General is the state's regulator for consumer-protection and breach-notification matters.
Act And InstrumentsAmber
BPINA (2005) as amended by SB 696 (2022) and SB 824/825 (effective September 26, 2024) is the operative state DP instrument, addressing breach notification only.
Claims (1):
- The Breach of Personal Information Notification Act of 2005, as amended by Senate Bill 696 (2022) and Senate Bill 824/825 (effective September 26, 2024), is Pennsylvania's primary state-level data-protection instrument and addresses breach notification only.
Material ScopeAmber
No PA-specific material scope test for 'personal data' processing generally; federal FTC Act Section 5 supplies a baseline unfair/deceptive-practices scope nationally.
Claims (1):
- The FTC enforces Section 5 of the FTC Act, prohibiting unfair or deceptive practices, providing a general federal privacy-adjacent baseline applicable to entities operating in Pennsylvania absent a state omnibus law.
Territorial ScopeAmber
BPINA applies by reference to breaches affecting Pennsylvania residents (reporting trigger at 500+ residents), rather than an establishment/targeting test.
Claims (1):
- BPINA's reporting obligations are triggered with respect to breaches impacting more than 500 Pennsylvania residents, defining the statute's practical territorial reach.
Regulator Registration And FilingAmber
No general controller registration regime exists; the only filing obligation is breach reporting to the AG via its online portal once the 500-resident threshold is met.
Claims (1):
- The Pennsylvania AG launched an online portal to streamline breach reporting by companies for incidents impacting more than 500 Pennsylvania residents under amended BPINA.
Key findings (1)
- — source on file
Regulator & Framework
Pennsylvania has no dedicated data-protection authority; the Pennsylvania Attorney General is the sole enforcement authority for the state's data-breach-notification law, the Breach of Personal Information Notification Act. This structural position remains unchanged this cycle. The active development is on the comprehensive-privacy-statute front: House Bill 78, the Consumer Data Privacy Act, passed the House 127-76 on October 1, 2025 and reached Senate second consideration on June 25, 2026. A Senate committee amendment dated June 24, 2026 raised the bill's applicability threshold from 50,000 to 100,000 consumers, households, or devices, narrowing the population of entities that would be covered were the bill enacted as amended.
HB78 would establish duties for controllers and processors of consumer data if enacted, but it has not yet passed the full Senate and Pennsylvania accordingly has no comprehensive consumer data privacy law in force as of this cycle. The threshold amendment is itself a material development: raising the applicability floor from 50,000 to 100,000 meaningfully narrows which businesses would be captured by the bill's controller/processor obligations, a scope-narrowing move typical of late-stage legislative negotiation on comprehensive privacy statutes.
Outlook
Whether HB78 clears the full Senate and is signed into law before the end of the 2025-2026 session, and whether the 100,000-threshold amendment survives to final passage or is further negotiated, remains the central open question for Pennsylvania's regulator-and-framework position.
1 further periodic run re-emitted the standing brief unchanged and is not shown.
Sources and claims (5)
- ConfirmedDataGuidance — Pennsylvania does not have a general/comprehensive privacy act; the Pennsylvania Attorney General is the state's regulator for consumer-protection and breach-notification matters.observed
- ConfirmedDataGuidance — The Breach of Personal Information Notification Act of 2005, as amended by Senate Bill 696 (2022) and Senate Bill 824/825 (effective September 26, 2024), is Pennsylvania's primary state-level data-protection instrument and addresses breach notification only.observed
- ConfirmedFederal Trade Commission — The FTC enforces Section 5 of the FTC Act, prohibiting unfair or deceptive practices, providing a general federal privacy-adjacent baseline applicable to entities operating in Pennsylvania absent a state omnibus law.observed
- ConfirmedDataGuidance — BPINA's reporting obligations are triggered with respect to breaches impacting more than 500 Pennsylvania residents, defining the statute's practical territorial reach.observed
- ConfirmedDataGuidance — The Pennsylvania AG launched an online portal to streamline breach reporting by companies for incidents impacting more than 500 Pennsylvania residents under amended BPINA.observed