🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-PA · run data-protection-2026-08-06 v13-gdpri-1.0.0
content: ai_generated 13 sources retrieved model claude-sonnet-5 ·

United States – Pennsylvania

US-PA schema gdpri-v2 trajectory: not recordedregulated (sectoral)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 28 claims · 13 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
28Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A named regulator and an in-force breach-notification statute exist, but there is no comprehensive material/territorial scope test or general registration regime, only sectoral fragments.

Primary frameworkBreach of Personal Information Notification Act (BPINA), 73 P.S. §2301 et seq., as amended; Unfair Trade Practices and Consumer Protection Law, 73 P.S. §201-1 et seq.
Traffic-light rationale — AmberA named regulator and an in-force breach-notification statute exist, but there is no comprehensive material/territorial scope test or general registration regime, only sectoral fragments.

Sub-modules (5)

Regulator And AuthorityAmber

The Pennsylvania AG enforces consumer-protection and breach-notification law; no dedicated data-protection authority exists.

Claims (1):

  • Pennsylvania does not have a general/comprehensive privacy act; the Pennsylvania Attorney General is the state's regulator for consumer-protection and breach-notification matters.

Act And InstrumentsAmber

BPINA (2005) as amended by SB 696 (2022) and SB 824/825 (effective September 26, 2024) is the operative state DP instrument, addressing breach notification only.

Claims (1):

  • The Breach of Personal Information Notification Act of 2005, as amended by Senate Bill 696 (2022) and Senate Bill 824/825 (effective September 26, 2024), is Pennsylvania's primary state-level data-protection instrument and addresses breach notification only.

Material ScopeAmber

No PA-specific material scope test for 'personal data' processing generally; federal FTC Act Section 5 supplies a baseline unfair/deceptive-practices scope nationally.

Claims (1):

  • The FTC enforces Section 5 of the FTC Act, prohibiting unfair or deceptive practices, providing a general federal privacy-adjacent baseline applicable to entities operating in Pennsylvania absent a state omnibus law.

Territorial ScopeAmber

BPINA applies by reference to breaches affecting Pennsylvania residents (reporting trigger at 500+ residents), rather than an establishment/targeting test.

Claims (1):

  • BPINA's reporting obligations are triggered with respect to breaches impacting more than 500 Pennsylvania residents, defining the statute's practical territorial reach.

Regulator Registration And FilingAmber

No general controller registration regime exists; the only filing obligation is breach reporting to the AG via its online portal once the 500-resident threshold is met.

Claims (1):

  • The Pennsylvania AG launched an online portal to streamline breach reporting by companies for incidents impacting more than 500 Pennsylvania residents under amended BPINA.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative78 words

Pennsylvania has no comprehensive consumer-privacy statute. The Pennsylvania Attorney General (Bureau of Consumer Protection) is the primary regulator, acting under the general Unfair Trade Practices and Consumer Protection Law (UTPCPL) and the state's dedicated Breach of Personal Information Notification Act (BPINA, 2005, as amended). Federal FTC Section 5 authority provides an additional, reactive national baseline. Material and territorial scope are defined narrowly (breach notification for computerized personal information of PA residents), not by a GDPR/CCPA-style omnibus scope test.

Sources and claims (5)
  1. ConfirmedDataGuidancePennsylvania does not have a general/comprehensive privacy act; the Pennsylvania Attorney General is the state's regulator for consumer-protection and breach-notification matters.observed
  2. ConfirmedDataGuidanceThe Breach of Personal Information Notification Act of 2005, as amended by Senate Bill 696 (2022) and Senate Bill 824/825 (effective September 26, 2024), is Pennsylvania's primary state-level data-protection instrument and addresses breach notification only.observed
  3. ConfirmedFederal Trade CommissionThe FTC enforces Section 5 of the FTC Act, prohibiting unfair or deceptive practices, providing a general federal privacy-adjacent baseline applicable to entities operating in Pennsylvania absent a state omnibus law.observed
  4. ConfirmedDataGuidanceBPINA's reporting obligations are triggered with respect to breaches impacting more than 500 Pennsylvania residents, defining the statute's practical territorial reach.observed
  5. ConfirmedDataGuidanceThe Pennsylvania AG launched an online portal to streamline breach reporting by companies for incidents impacting more than 500 Pennsylvania residents under amended BPINA.observed

#

No in-force general lawful-basis or consent regime; only pending bills identified via targeted search of PA legislative trackers.

Traffic-light rationale — RedNo in-force general lawful-basis or consent regime; only pending bills identified via targeted search of PA legislative trackers.

Sub-modules (4)

Lawful BasesRed

No enacted enumerated lawful bases; HB 78 (pending) would create controller obligations and consumer rights.

Claims (1):

  • House Bill 78, the Consumer Data Privacy Act, would establish comprehensive data-controller obligations and consumer privacy rights in Pennsylvania but has passed the House and remains under Senate review, not yet enacted.

Special CategoriesRed

No enacted special/sensitive-category regime; pending genetic-data bills are the closest analogue.

Claims (1):

  • House Bills 1530 and 2627 would impose express-consent and data-security obligations on direct-to-consumer genetic testing companies operating in Pennsylvania, but remain pending, not enacted.

Pseudonymisation And AnonymisationRed

No PA-specific statutory definition of pseudonymisation or anonymisation was identified.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative58 words

Pennsylvania has no enacted lawful-basis, consent-threshold, or special-category regime analogous to GDPR Art 6/7/9. House Bill 78 (Consumer Data Privacy Act) would introduce such a framework but remains pending before the Senate as of the dispatch date. Sector bills (HB 1530/HB 2627) would impose consent requirements specifically on direct-to-consumer genetic testing companies but are likewise not yet enacted.

Sources and claims (2)
  1. ProbableDataGuidanceHouse Bill 78, the Consumer Data Privacy Act, would establish comprehensive data-controller obligations and consumer privacy rights in Pennsylvania but has passed the House and remains under Senate review, not yet enacted.observed
  2. ProbableDataGuidanceHouse Bills 1530 and 2627 would impose express-consent and data-security obligations on direct-to-consumer genetic testing companies operating in Pennsylvania, but remain pending, not enacted.observed

#

No in-force general data-subject-rights framework at state level; only a pending bill identified.

Traffic-light rationale — RedNo in-force general data-subject-rights framework at state level; only a pending bill identified.

Sub-modules (5)

Access RightRed

No enacted general access right; HB 78 (pending) would grant consumer rights typical of state comprehensive laws.

Claims (1):

  • House Bill 78 outlines data-privacy obligations for businesses and would grant consumer rights (access, correction, deletion, opt-out) in Pennsylvania, but as of the dispatch date it remains under Senate review following passage of its third reading in the House.

Rectification And ErasureRed

Not addressed by enacted state law; dependent on eventual passage of HB 78.

Restriction And ObjectionRed

No enacted restriction/objection right identified.

Data PortabilityRed

No enacted portability right identified.

Deadlines And Response WindowsRed

No statutory response-window requirement for consumer rights requests exists under current PA law.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative63 words

No enacted PA statute grants a general set of subject-access, rectification, erasure, restriction, objection or portability rights. Federal sectoral rights (e.g., HIPAA access, GLBA opt-out) may apply to specific data categories but are treated as part of the US-federal JID rather than duplicated here. House Bill 78 would introduce comprehensive consumer rights modeled on other state omnibus laws but is not yet enacted.

Sources and claims (1)
  1. ProbableDataGuidanceHouse Bill 78 outlines data-privacy obligations for businesses and would grant consumer rights (access, correction, deletion, opt-out) in Pennsylvania, but as of the dispatch date it remains under Senate review following passage of its third reading in the House.observed

#

Breach notification and an insurance-sector security-program duty are in force; general accountability/DPIA/DPO/ROPA obligations are absent.

Primary frameworkBreach of Personal Information Notification Act; Pennsylvania Insurance Data Security Act
Traffic-light rationale — AmberBreach notification and an insurance-sector security-program duty are in force; general accountability/DPIA/DPO/ROPA obligations are absent.

Sub-modules (7)

Accountability And DpiaRed

No general accountability/DPIA duty in force; HB 1879 (pending) would mandate DPIAs for children's-data processing.

Claims (1):

  • House Bill 1879 would mandate DPIAs and high default privacy settings for children's data and prohibit high-risk profiling and unauthorized data use, but remains pending, not enacted, as of the dispatch date.

Dpo RequirementsRed

No DPO appointment threshold identified under PA law.

Ropa RequirementsRed

No records-of-processing obligation identified under PA law.

Joint Controller ArrangementsRed

No joint-controller regime identified under PA law.

Security MeasuresAmber

The Insurance Data Security Act imposes technical and organisational security-program requirements on licensed insurance entities in the Commonwealth.

Claims (1):

  • The Pennsylvania Insurance Data Security Act imposes strict cybersecurity measures, and compliance and notification requirements, on insurance entities licensed in the Commonwealth.

Breach NotificationAmber

BPINA (as amended) requires notification to the PA AG (via online portal) and affected residents once the 500-resident threshold is met, with credit-monitoring and reporting provisions added by SB 824/825.

Claims (1):

  • Following the September 26, 2024 effective date of SB 824/825, BPINA requires notification of breaches impacting more than 500 Pennsylvania residents to the Attorney General via a dedicated online portal, alongside credit-monitoring and reporting provisions.

Retention And DisposalRed

No general retention-limit or disposal-duty statute was identified for Pennsylvania.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative65 words

General accountability, DPIA, DPO, ROPA and joint-controller obligations of the GDPR type are absent from Pennsylvania law. Two enforceable duties exist in sectoral form: (1) the Insurance Data Security Act imposes cybersecurity-program requirements on licensed insurance entities, and (2) BPINA imposes a breach-notification duty (regulator and consumer notice) once thresholds are met. House Bill 1879 would add DPIA-style obligations for children's data but is pending.

Sources and claims (3)
  1. ConfirmedDataGuidanceThe Pennsylvania Insurance Data Security Act imposes strict cybersecurity measures, and compliance and notification requirements, on insurance entities licensed in the Commonwealth.observed
  2. ConfirmedDataGuidanceFollowing the September 26, 2024 effective date of SB 824/825, BPINA requires notification of breaches impacting more than 500 Pennsylvania residents to the Attorney General via a dedicated online portal, alongside credit-monitoring and reporting provisions.observed
  3. ProbableDataGuidanceHouse Bill 1879 would mandate DPIAs and high default privacy settings for children's data and prohibit high-risk profiling and unauthorized data use, but remains pending, not enacted, as of the dispatch date.observed

#

No comprehensive cross-border transfer regime exists in Pennsylvania law; this is a legitimate gap finding rather than an omission.

Traffic-light rationale — RedNo comprehensive cross-border transfer regime exists in Pennsylvania law; this is a legitimate gap finding rather than an omission.

Sub-modules (6)

Transfer MechanismsRed

No state transfer-mechanism regime identified.

Adequacy ReceivedRed

Not applicable; Pennsylvania is not a party to adequacy-style determinations.

Adequacy GrantedRed

Not applicable; Pennsylvania does not grant adequacy decisions.

Sccs And BcrsRed

No state-mandated SCC/BCR uptake requirement identified.

Transfer Impact AssessmentRed

No TIA requirement identified under PA law.

Data LocalisationRed

No data-localisation mandate identified under PA law.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative54 words

No PA-specific transfer mechanism, adequacy-recognition process, SCC/BCR uptake requirement, transfer-impact-assessment duty, or data-localisation mandate was identified. Because Pennsylvania has no omnibus privacy statute, cross-border transfer restrictions of the GDPR type simply do not exist at the state level; any constraints derive from federal sectoral law (out of scope for this JID) or contractual practice.

#

Insurance/financial sector overlays are in force; other sectors (employment, education, credit-scoring) remain at the pending-bill stage.

Primary frameworkPennsylvania Insurance Data Security Act; Privacy of Consumer Financial Information Law (31 Pa. Code Ch. 146a); Standards for Safeguarding Law (31 Pa. Code Ch. 146c)
Traffic-light rationale — AmberInsurance/financial sector overlays are in force; other sectors (employment, education, credit-scoring) remain at the pending-bill stage.

Sub-modules (7)

Financial Sector OverlayAmber

Insurers' handling of consumer financial information is governed by dedicated privacy and safeguarding chapters of the Pennsylvania Code.

Claims (1):

  • Pennsylvania's financial privacy and safeguards laws are specifically targeted at insurers: consumer financial information privacy is governed by Chapter 146a and its safeguarding by Chapter 146c of Title 31 of the Pennsylvania Code.

Health Sector OverlayAmber

Health data protection in Pennsylvania relies on federal HIPAA and, for non-HIPAA-covered health apps, the FTC Health Breach Notification Rule; no PA-specific health-privacy statute was identified.

Claims (1):

  • For most hospitals, doctors' offices, and insurance companies, HIPAA governs health-record privacy and security; the FTC's Health Breach Notification Rule fills the gap for health apps and connected devices not covered by HIPAA nationally, including in Pennsylvania.

Telecoms And EprivacyAmber

The Telemarketer Registration Act governs Do-Not-Call enrollment, robocalls, and telephone solicitation timing.

Claims (1):

  • Pennsylvania's Telemarketer Registration Act, amended in October 2019, removed the five-year limit on Do Not Call List enrollment, prohibited solicitation calls on legal holidays, and created procedures governing robocalls.

Employment DataRed

House Bill 1559 would require PA employers to notify employees of electronic monitoring, with fines for violations, but remains pending.

Claims (1):

  • House Bill 1559 would require Pennsylvania employers to notify employees of electronic monitoring, with fines for violations, but remains pending, not enacted.

Credit And ScoringRed

No PA-specific credit-scoring privacy statute identified beyond federal FCRA (out of scope for this JID).

EducationRed

Senate Bill 378 seeks to enhance student data privacy and protection in Pennsylvania but is pending.

Claims (1):

  • Senate Bill 378 seeks to enhance student data privacy and protection in Pennsylvania but has not been enacted as of the dispatch date.

InsuranceAmber

The Insurance Data Security Act imposes cybersecurity-program, investigation, and notification requirements on licensed insurance entities.

Claims (1):

  • The Pennsylvania Insurance Data Security Act enforces strict cybersecurity measures for licensed insurance entities, with compliance and notification requirements.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative80 words

Sectoral overlays exist for insurance/financial data and telemarketing, with employment and education-sector bills pending. The Privacy of Consumer Financial Information Law and Standards for Safeguarding Law (31 Pa. Code Ch. 146a/146c) govern insurers' handling of consumer financial information; the Insurance Data Security Act adds cybersecurity duties. The Telemarketer Registration Act governs the Do-Not-Call regime. Health data is governed principally by federal HIPAA and, for non-HIPAA health apps, the FTC's Health Breach Notification Rule (both federal, noted here as overlay context).

Sources and claims (6)
  1. ConfirmedDataGuidancePennsylvania's financial privacy and safeguards laws are specifically targeted at insurers: consumer financial information privacy is governed by Chapter 146a and its safeguarding by Chapter 146c of Title 31 of the Pennsylvania Code.observed
  2. ConfirmedFederal Trade CommissionFor most hospitals, doctors' offices, and insurance companies, HIPAA governs health-record privacy and security; the FTC's Health Breach Notification Rule fills the gap for health apps and connected devices not covered by HIPAA nationally, including in Pennsylvania.observed
  3. ConfirmedDataGuidancePennsylvania's Telemarketer Registration Act, amended in October 2019, removed the five-year limit on Do Not Call List enrollment, prohibited solicitation calls on legal holidays, and created procedures governing robocalls.observed
  4. ProbableDataGuidanceHouse Bill 1559 would require Pennsylvania employers to notify employees of electronic monitoring, with fines for violations, but remains pending, not enacted.observed
  5. ProbableDataGuidanceSenate Bill 378 seeks to enhance student data privacy and protection in Pennsylvania but has not been enacted as of the dispatch date.observed
  6. ConfirmedDataGuidanceThe Pennsylvania Insurance Data Security Act enforces strict cybersecurity measures for licensed insurance entities, with compliance and notification requirements.observed

#

Only a narrow telemarketing/Do-Not-Call regime is in force; broader adtech/commercial-privacy protections are absent.

Primary frameworkTelemarketer Registration Act
Traffic-light rationale — RedOnly a narrow telemarketing/Do-Not-Call regime is in force; broader adtech/commercial-privacy protections are absent.

Sub-modules (6)

Cookies And TrackersRed

No cookie/tracker consent statute identified.

Dark PatternsRed

No dark-pattern prohibition identified under PA law.

Opt Out SignalsRed

No recognized universal opt-out signal (e.g., GPC) obligation identified under PA law.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rules identified.

Cross Context AdvertisingRed

No 'sale'/'share' cross-context-advertising concept exists under PA law.

Direct MarketingAmber

The Telemarketer Registration Act governs telephone-based direct marketing, Do-Not-Call enrollment, and robocall procedures.

Claims (1):

  • Pennsylvania's Telemarketer Registration Act regulates telephone solicitation, Do Not Call List enrollment, and robocall practices as the state's principal direct-marketing-adjacent privacy instrument.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative41 words

Pennsylvania has no cookie/tracker consent law, dark-pattern prohibition, recognized opt-out signal regime, clean-room framework, or cross-context-advertising 'sale/share' concept of the CPRA type. The only adjacent commercial-privacy instrument identified is the Telemarketer Registration Act, which governs direct telephone marketing and Do-Not-Call compliance.

Sources and claims (1)
  1. ConfirmedDataGuidancePennsylvania's Telemarketer Registration Act regulates telephone solicitation, Do Not Call List enrollment, and robocall practices as the state's principal direct-marketing-adjacent privacy instrument.observed

#

A cluster of AI/biometric/genetic bills is in the legislative pipeline, but none are yet in force; PA has no enacted ADM-transparency, profiling, or biometric regime.

Traffic-light rationale — RedA cluster of AI/biometric/genetic bills is in the legislative pipeline, but none are yet in force; PA has no enacted ADM-transparency, profiling, or biometric regime.

Sub-modules (6)

Profiling RestrictionsRed

No enacted profiling-restriction analogous to GDPR Art 22; HB 1879 (children's-data profiling ban) is pending, tracked under children_and_vulnerable_groups.

Automated Decision Making TransparencyRed

No enacted ADM-transparency right identified in Pennsylvania.

Ai Risk AssessmentsRed

No enacted AI-risk-assessment mandate; several disclosure/liability bills (HB 95, HB 1533, HB 317, HB 2660) are pending.

Claims (1):

  • House Bill 95 would amend the Unfair Trade Practices and Consumer Protection Law to classify undisclosed AI-generated content as an unfair or deceptive practice, and was referred to the House Communications and Technology Committee on January 14, 2025, without further enactment identified.

Biometric RegimeRed

No Pennsylvania-specific biometric-data statute (facial recognition, fingerprint, gait) was identified.

Genetic DataRed

House Bills 1530 and 2627 would regulate direct-to-consumer genetic testing companies' consent, security, and disclosure practices, but remain pending.

Claims (1):

  • House Bill 1530 and House Bill 2627 would impose express-consent and data-security obligations, and prohibit unauthorized disclosures, on direct-to-consumer genetic testing companies in Pennsylvania, but remain pending.

State Surveillance CarveoutsRed

No PA-specific state-surveillance carveout was identified; this domain is predominantly federal.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative77 words

Pennsylvania has no enacted profiling-restriction, ADM-transparency, AI-risk-assessment, biometric, or genetic-data statute. Several bills are pending: SB 1090 (AI chatbot protections for minors, passed the Senate as of mid-2026), HB 95 (UTPCPL amendment requiring AI-content disclosure, referred to committee), HB 1533 (AI system deployment liability), HB 317/HB 2660 (AI-content watermarking), and HB 1530/HB 2627 (genetic-testing consent/security). None have been signed into law as of the dispatch date. No PA-specific biometric-privacy statute (of the Illinois BIPA type) was identified.

Sources and claims (3)
  1. ProbableDataGuidanceSenate Bill 1090, aimed at protecting minors from AI chatbots, passed the Pennsylvania State Senate, imposing new disclosure and safeguard requirements on operators, but has not yet been enacted into law.observed
  2. ProbableDataGuidanceHouse Bill 95 would amend the Unfair Trade Practices and Consumer Protection Law to classify undisclosed AI-generated content as an unfair or deceptive practice, and was referred to the House Communications and Technology Committee on January 14, 2025, without further enactment identified.observed
  3. ProbableDataGuidanceHouse Bill 1530 and House Bill 2627 would impose express-consent and data-security obligations, and prohibit unauthorized disclosures, on direct-to-consumer genetic testing companies in Pennsylvania, but remain pending.observed

#

All identified children's-data protections in Pennsylvania are at the pending-bill stage; none are in force.

Traffic-light rationale — RedAll identified children's-data protections in Pennsylvania are at the pending-bill stage; none are in force.

Sub-modules (5)

Age VerificationRed

Senate Bill 22 would require parental consent and age-related safeguards for minors on social media, but is pending.

Claims (1):

  • Pennsylvania Senate Bill 22 seeks to protect minors on social media by enforcing parental consent and penalizing harmful content exposure, but has not been enacted as of the dispatch date.

Minor Profiling BansRed

House Bill 1879 would prohibit high-risk profiling of children's data and mandate high default privacy settings, but remains pending.

Claims (1):

  • House Bill 1879 mandates DPIAs and high privacy settings for children's data and prohibits high-risk profiling and unauthorized data use, but remains pending, not enacted.

Education SettingsRed

Senate Bill 378 would enhance student data privacy protections but has not been enacted.

Claims (1):

  • Senate Bill 378 seeks to enhance student data privacy and protection in Pennsylvania but has not been enacted as of the dispatch date.

Dependent AdultsRed

No Pennsylvania-specific statute addressing data protections for dependent or incapacitated adults was identified.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative59 words

No enacted PA statute sets an age of consent for data processing, mandates parental consent for minors' data, bans minor profiling, imposes education-setting-specific data rules, or protects dependent adults' data specifically. Pending bills include SB 22 (parental consent for minors on social media), HB 1879 (DPIA mandate and profiling ban for children's data), and SB 378 (student data privacy).

Sources and claims (3)
  1. ProbableDataGuidancePennsylvania Senate Bill 22 seeks to protect minors on social media by enforcing parental consent and penalizing harmful content exposure, but has not been enacted as of the dispatch date.observed
  2. ProbableDataGuidanceHouse Bill 1879 mandates DPIAs and high privacy settings for children's data and prohibits high-risk profiling and unauthorized data use, but remains pending, not enacted.observed
  3. ProbableDataGuidanceSenate Bill 378 seeks to enhance student data privacy and protection in Pennsylvania but has not been enacted as of the dispatch date.observed

#

AG enforcement power and a private right of action are in force under UTPCPL; there is no dedicated privacy regulator, no privacy-specific collective-redress statute, and enforcement activity is general-consumer-protection rather than privacy-specific.

Primary frameworkUnfair Trade Practices and Consumer Protection Law, 73 P.S. §201-1 et seq.
Traffic-light rationale — AmberAG enforcement power and a private right of action are in force under UTPCPL; there is no dedicated privacy regulator, no privacy-specific collective-redress statute, and enforcement activity is general-consumer-protection rather than privacy-specific.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

UTPCPL empowers the AG to pursue restitution and other equitable relief against companies for data-breach-related unfair/deceptive practices.

Claims (1):

  • The Unfair Trade Practices and Consumer Protection Law provides the Pennsylvania Attorney General with the power to enforce actions against companies sustaining large data breaches due to inadequate cybersecurity practices.

Enforcement Activity IndexAmber

The AG/GEICO settlement over unfair auto-insurance cancellations, arising from an AI-related investigation, is a recent example of general consumer-protection enforcement with data/AI dimensions.

Claims (1):

  • The Pennsylvania AG and GEICO agreed to improve consumer protections against unfair auto-insurance cancellations following an AI-related investigation.

Regulator Funding And CapacityRed

No specific funding or headcount data for the PA AG's Bureau of Consumer Protection was located in this research pass.

Collective Redress And Class ActionsRed

No PA-specific privacy class-action statute was identified beyond general UTPCPL private-action mechanics.

Private Right Of ActionAmber

UTPCPL creates a private cause of action with a fee-shifting component, allowing consumers to sue directly for breach-related unfair/deceptive practices.

Claims (1):

  • Pennsylvania's data-breach and consumer-protection statutes create a private cause of action with a fee-shifting component, enabling direct consumer litigation independent of AG enforcement.

Recent Developments 180DAmber

A federal comprehensive consumer-privacy bill, the SECURE Data Act (HR 8413), was introduced April 22, 2026 by a Pennsylvania member of Congress; it is a federal, not state, development and remains at an early legislative stage.

Claims (1):

  • On April 22, 2026, U.S. House Energy and Commerce Committee Vice Chairman John Joyce, R-Pa., introduced HR 8413, the SECURE Data Act, a comprehensive federal consumer-privacy bill representing an early-stage legislative proposal.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative106 words

The UTPCPL gives the Pennsylvania AG power to bring enforcement actions against companies for large data breaches attributable to inadequate cybersecurity practices, and creates a private cause of action with fee-shifting, giving Pennsylvania consumers a route to court independent of AG action. Recent enforcement activity includes the PA AG/GEICO agreement improving consumer protections against unfair auto-insurance cancellations following an AI-related investigation. At the federal level, a comprehensive consumer-privacy bill (the SECURE Data Act, HR 8413) was introduced in Congress on April 22, 2026 by a Pennsylvania member of the House Energy and Commerce Committee, though this is federal, not state, legislation and remains in early-stage negotiation.

Sources and claims (4)
  1. ConfirmedDataGuidanceThe Unfair Trade Practices and Consumer Protection Law provides the Pennsylvania Attorney General with the power to enforce actions against companies sustaining large data breaches due to inadequate cybersecurity practices.observed
  2. ConfirmedDataGuidanceThe Pennsylvania AG and GEICO agreed to improve consumer protections against unfair auto-insurance cancellations following an AI-related investigation.observed
  3. ConfirmedDataGuidancePennsylvania's data-breach and consumer-protection statutes create a private cause of action with a fee-shifting component, enabling direct consumer litigation independent of AG enforcement.observed
  4. ConfirmedIAPPOn April 22, 2026, U.S. House Energy and Commerce Committee Vice Chairman John Joyce, R-Pa., introduced HR 8413, the SECURE Data Act, a comprehensive federal consumer-privacy bill representing an early-stage legislative proposal.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Pennsylvania
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 28 claim(s), 13 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacyadequacy granted
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacysccs and bcrs
Art. 49Cross-Border & Adequacytransfer impact assessment
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, controller_processor_duties (breach_notification/security_measures), sectoral_watch (financial/insurance/telecoms), and enforcement_and_redress (UTPCPL powers/private right of action) rest on T1/T2 anchors (FTC.gov, NAAG.org, DataGuidance primary-instrument summaries) and are Confirmed. lawful_processing_and_special_data, data_subject_rights, algorithmic_biometric_and_surveillance_governance, and children_and_vulnerable_groups rely on T2/T3 legislative-tracker sources describing pending (not-yet-enacted) bills, rated Probable/Uncertain. cross_border_and_adequacy carries no claims and is supported only by absent_field_provenance, reflecting a genuine regulatory gap given Pennsylvania's lack of an omnibus statute. adtech_and_commercial_privacy is populated only for the narrow telemarketing/Do-Not-Call sub-module, all other sub-modules are gap findings.

Unresolved questions (4):

  • Whether House Bill 78 (Consumer Data Privacy Act) will pass the PA Senate and be signed into law, and on what timeline.
  • Whether Senate Bill 1090 (AI chatbot protections for minors) will pass the PA House and be enacted.
  • Current headcount/funding data for the PA AG's Bureau of Consumer Protection privacy-enforcement capacity (not located in this pass).
  • Whether any Pennsylvania court has certified a privacy-related class action under UTPCPL's private-action provisions in the last 12 months.

Escalate to primary-source review: yes