Law note · Pennsylvania

Breach of Personal Information Notification Act

cite 73 P.S. secs. 2302, 2303, 2305, 2308 (Act 94 of 2005) stage IN FORCE in force since 2006-06-20 reviewed 2026-08-28

An entity that maintains, stores, or manages computerized data including personal information must provide notice of a breach of the security of the system, without unreasonable delay, to any Pennsylvania resident whose unencrypted and unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person.

Personal information is name plus a Social Security number, driver's license or state ID number, a financial account number with access credential, medical information held by a state agency or contractor, health insurance information, or a username or email with a password or security question, and excludes publicly available information lawfully available from government records or widely distributed media (added by the June 28, 2024 amendment); it does not reach biometric identifiers as such.

An entity that notifies more than 500 persons at one time (lowered from 1,000 by the 2024 amendment) must also notify nationwide consumer reporting agencies; a state agency's own breach separately requires Attorney General notice within seven business days, but no parallel duty requires a private entity's breach to notify the Attorney General directly.

A violation is deemed an unfair or deceptive practice under the Unfair Trade Practices and Consumer Protection Law, 73 P.S. secs. 201-1 to 201-9.3, but the Office of Attorney General has exclusive authority to bring that action, so the Act creates no private right of action even though its deeming clause would otherwise open a UDAP route the way Connecticut's breach statute does.

What it asks of an app

  • Notify each affected Pennsylvania resident of a breach of system security involving personal information without unreasonable delay.
  • Notify each nationwide consumer reporting agency if you notify more than 500 persons of a breach at one time.
  • Do not rely on this statute to cover a breach of biometric data alone. It does not fold biometric identifiers into personal information.
  • Expect this Act's notice duty to be enforced exclusively by the Pennsylvania Attorney General, never by a private plaintiff, even though a violation is deemed an unfair trade practice.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach

Primary source: official Pennsylvania session-law text of the Act of Dec. 22
2005, P.L. 474, No. 94, as amended by Act 151 of 2022. The state publishes this act by its own section numbers, not the Purdon's numbering: 73 P.S. sec. 2302 is section 2 (definitions), 2303 is section 3 (notification), 2305 is section 5 (consumer reporting agencies), and 2308 is section 8 (civil relief). The Purdon's section numbers themselves cannot be verified against this source: Pennsylvania publishes the act by its own section numbers and the codified 73 P.S. numbering is West's, appearing nowhere on the state's site. The act number anchors the citation to the right law the section correspondence above was established by matching the act's own section headings and is not machine-checkable.

← Back to the example  ·  Lint your app →