{
 "jurisdiction_id": "US-PA",
 "jurisdiction": "United States – Pennsylvania",
 "url": "https://dataprotection.gi/jurisdictions/united-states-pennsylvania/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-06",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 28,
  "sub_modules": 57,
  "source_register": 13
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-pennsylvania/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "A named regulator and an in-force breach-notification statute exist, but there is no comprehensive material/territorial scope test or general registration regime, only sectoral fragments.",
   "claims": [
    {
     "statement": "Pennsylvania does not have a general/comprehensive privacy act; the Pennsylvania Attorney General is the state's regulator for consumer-protection and breach-notification matters.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/pennsylvania",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The Breach of Personal Information Notification Act of 2005, as amended by Senate Bill 696 (2022) and Senate Bill 824/825 (effective September 26, 2024), is Pennsylvania's primary state-level data-protection instrument and addresses breach notification only.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/pennsylvania",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The FTC enforces Section 5 of the FTC Act, prohibiting unfair or deceptive practices, providing a general federal privacy-adjacent baseline applicable to entities operating in Pennsylvania absent a state omnibus law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/business-guidance/resources/complying-ftcs-health-breach-notification-rule-0",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "BPINA's reporting obligations are triggered with respect to breaches impacting more than 500 Pennsylvania residents, defining the statute's practical territorial reach.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/pennsylvania-ag-launches-online-portal-data-breach",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The Pennsylvania AG launched an online portal to streamline breach reporting by companies for incidents impacting more than 500 Pennsylvania residents under amended BPINA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/pennsylvania-ag-launches-online-portal-data-breach",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "red",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-pennsylvania/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "No in-force general lawful-basis or consent regime; only pending bills identified via targeted search of PA legislative trackers.",
   "claims": [
    {
     "statement": "House Bill 78, the Consumer Data Privacy Act, would establish comprehensive data-controller obligations and consumer privacy rights in Pennsylvania but has passed the House and remains under Senate review, not yet enacted.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/pennsylvania-consumer-data-privacy-act-passes-third",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "House Bills 1530 and 2627 would impose express-consent and data-security obligations on direct-to-consumer genetic testing companies operating in Pennsylvania, but remain pending, not enacted.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/pennsylvania",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "red",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-pennsylvania/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "No in-force general data-subject-rights framework at state level; only a pending bill identified.",
   "claims": [
    {
     "statement": "House Bill 78 outlines data-privacy obligations for businesses and would grant consumer rights (access, correction, deletion, opt-out) in Pennsylvania, but as of the dispatch date it remains under Senate review following passage of its third reading in the House.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/pennsylvania-consumer-data-privacy-act-passes-third",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-pennsylvania/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Breach notification and an insurance-sector security-program duty are in force; general accountability/DPIA/DPO/ROPA obligations are absent.",
   "claims": [
    {
     "statement": "The Pennsylvania Insurance Data Security Act imposes strict cybersecurity measures, and compliance and notification requirements, on insurance entities licensed in the Commonwealth.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/pennsylvania",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Following the September 26, 2024 effective date of SB 824/825, BPINA requires notification of breaches impacting more than 500 Pennsylvania residents to the Attorney General via a dedicated online portal, alongside credit-monitoring and reporting provisions.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/pennsylvania-ag-launches-online-portal-data-breach",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "House Bill 1879 would mandate DPIAs and high default privacy settings for children's data and prohibit high-risk profiling and unauthorized data use, but remains pending, not enacted, as of the dispatch date.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/pennsylvania",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "red",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-pennsylvania/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "No comprehensive cross-border transfer regime exists in Pennsylvania law; this is a legitimate gap finding rather than an omission.",
   "claims": []
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-pennsylvania/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Insurance/financial sector overlays are in force; other sectors (employment, education, credit-scoring) remain at the pending-bill stage.",
   "claims": [
    {
     "statement": "Pennsylvania's financial privacy and safeguards laws are specifically targeted at insurers: consumer financial information privacy is governed by Chapter 146a and its safeguarding by Chapter 146c of Title 31 of the Pennsylvania Code.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/pennsylvania-data-protection-financial-sector",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "For most hospitals, doctors' offices, and insurance companies, HIPAA governs health-record privacy and security; the FTC's Health Breach Notification Rule fills the gap for health apps and connected devices not covered by HIPAA nationally, including in Pennsylvania.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/business-guidance/resources/complying-ftcs-health-breach-notification-rule-0",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Pennsylvania's Telemarketer Registration Act, amended in October 2019, removed the five-year limit on Do Not Call List enrollment, prohibited solicitation calls on legal holidays, and created procedures governing robocalls.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/pennsylvania",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "House Bill 1559 would require Pennsylvania employers to notify employees of electronic monitoring, with fines for violations, but remains pending, not enacted.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/pennsylvania",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Senate Bill 378 seeks to enhance student data privacy and protection in Pennsylvania but has not been enacted as of the dispatch date.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/pennsylvania",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The Pennsylvania Insurance Data Security Act enforces strict cybersecurity measures for licensed insurance entities, with compliance and notification requirements.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/pennsylvania-insurance-data-security-act",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-pennsylvania/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Only a narrow telemarketing/Do-Not-Call regime is in force; broader adtech/commercial-privacy protections are absent.",
   "claims": [
    {
     "statement": "Pennsylvania's Telemarketer Registration Act regulates telephone solicitation, Do Not Call List enrollment, and robocall practices as the state's principal direct-marketing-adjacent privacy instrument.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/pennsylvania",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "red",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-pennsylvania/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "A cluster of AI/biometric/genetic bills is in the legislative pipeline, but none are yet in force; PA has no enacted ADM-transparency, profiling, or biometric regime.",
   "claims": [
    {
     "statement": "Senate Bill 1090, aimed at protecting minors from AI chatbots, passed the Pennsylvania State Senate, imposing new disclosure and safeguard requirements on operators, but has not yet been enacted into law.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/pennsylvania",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "House Bill 95 would amend the Unfair Trade Practices and Consumer Protection Law to classify undisclosed AI-generated content as an unfair or deceptive practice, and was referred to the House Communications and Technology Committee on January 14, 2025, without further enactment identified.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/pennsylvania-unfair-trade-practices-and-consumer",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "House Bill 1530 and House Bill 2627 would impose express-consent and data-security obligations, and prohibit unauthorized disclosures, on direct-to-consumer genetic testing companies in Pennsylvania, but remain pending.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/pennsylvania",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "red",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-pennsylvania/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "All identified children's-data protections in Pennsylvania are at the pending-bill stage; none are in force.",
   "claims": [
    {
     "statement": "Pennsylvania Senate Bill 22 seeks to protect minors on social media by enforcing parental consent and penalizing harmful content exposure, but has not been enacted as of the dispatch date.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/pennsylvania",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "House Bill 1879 mandates DPIAs and high privacy settings for children's data and prohibits high-risk profiling and unauthorized data use, but remains pending, not enacted.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/pennsylvania",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Senate Bill 378 seeks to enhance student data privacy and protection in Pennsylvania but has not been enacted as of the dispatch date.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/pennsylvania",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-pennsylvania/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "AG enforcement power and a private right of action are in force under UTPCPL; there is no dedicated privacy regulator, no privacy-specific collective-redress statute, and enforcement activity is general-consumer-protection rather than privacy-specific.",
   "claims": [
    {
     "statement": "The Unfair Trade Practices and Consumer Protection Law provides the Pennsylvania Attorney General with the power to enforce actions against companies sustaining large data breaches due to inadequate cybersecurity practices.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/pennsylvania",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The Pennsylvania AG and GEICO agreed to improve consumer protections against unfair auto-insurance cancellations following an AI-related investigation.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/pennsylvania",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Pennsylvania's data-breach and consumer-protection statutes create a private cause of action with a fee-shifting component, enabling direct consumer litigation independent of AG enforcement.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/pennsylvania",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "On April 22, 2026, U.S. House Energy and Commerce Committee Vice Chairman John Joyce, R-Pa., introduced HR 8413, the SECURE Data Act, a comprehensive federal consumer-privacy bill representing an early-stage legislative proposal.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/secure-data-act-analysis-of-the-new-federal-privacy-bill",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  }
 ]
}