#
A named regulator and an in-force breach-notification statute exist, but there is no comprehensive material/territorial scope test or general registration regime, only sectoral fragments.
Sub-modules (5)
Regulator And AuthorityAmber
The Pennsylvania AG enforces consumer-protection and breach-notification law; no dedicated data-protection authority exists.
Claims (1):
- Pennsylvania does not have a general/comprehensive privacy act; the Pennsylvania Attorney General is the state's regulator for consumer-protection and breach-notification matters.
Act And InstrumentsAmber
BPINA (2005) as amended by SB 696 (2022) and SB 824/825 (effective September 26, 2024) is the operative state DP instrument, addressing breach notification only.
Claims (1):
- The Breach of Personal Information Notification Act of 2005, as amended by Senate Bill 696 (2022) and Senate Bill 824/825 (effective September 26, 2024), is Pennsylvania's primary state-level data-protection instrument and addresses breach notification only.
Material ScopeAmber
No PA-specific material scope test for 'personal data' processing generally; federal FTC Act Section 5 supplies a baseline unfair/deceptive-practices scope nationally.
Claims (1):
- The FTC enforces Section 5 of the FTC Act, prohibiting unfair or deceptive practices, providing a general federal privacy-adjacent baseline applicable to entities operating in Pennsylvania absent a state omnibus law.
Territorial ScopeAmber
BPINA applies by reference to breaches affecting Pennsylvania residents (reporting trigger at 500+ residents), rather than an establishment/targeting test.
Claims (1):
- BPINA's reporting obligations are triggered with respect to breaches impacting more than 500 Pennsylvania residents, defining the statute's practical territorial reach.
Regulator Registration And FilingAmber
No general controller registration regime exists; the only filing obligation is breach reporting to the AG via its online portal once the 500-resident threshold is met.
Claims (1):
- The Pennsylvania AG launched an online portal to streamline breach reporting by companies for incidents impacting more than 500 Pennsylvania residents under amended BPINA.
Key findings (3)
- — source on file
- — source on file
- — source on file
Sources and claims (5)
- ConfirmedDataGuidance — Pennsylvania does not have a general/comprehensive privacy act; the Pennsylvania Attorney General is the state's regulator for consumer-protection and breach-notification matters.observed
- ConfirmedDataGuidance — The Breach of Personal Information Notification Act of 2005, as amended by Senate Bill 696 (2022) and Senate Bill 824/825 (effective September 26, 2024), is Pennsylvania's primary state-level data-protection instrument and addresses breach notification only.observed
- ConfirmedFederal Trade Commission — The FTC enforces Section 5 of the FTC Act, prohibiting unfair or deceptive practices, providing a general federal privacy-adjacent baseline applicable to entities operating in Pennsylvania absent a state omnibus law.observed
- ConfirmedDataGuidance — BPINA's reporting obligations are triggered with respect to breaches impacting more than 500 Pennsylvania residents, defining the statute's practical territorial reach.observed
- ConfirmedDataGuidance — The Pennsylvania AG launched an online portal to streamline breach reporting by companies for incidents impacting more than 500 Pennsylvania residents under amended BPINA.observed