Law note · Pennsylvania
House Bill 78, Consumer Data Privacy Act, general applicability and controller and processor duties
House Bill 78, as amended by the Senate Communications and Technology Committee (Printer's No. 3688), would apply to a for-profit controller doing business in Pennsylvania that meets a revenue threshold of more than $10,000,000, or that alone or in combination buys, receives, sells, or shares for commercial purposes the personal information of at least 100,000 consumers, households, or devices (raised from 50,000 in the original bill), or that derives at least 50% of annual revenue from selling personal information.
Controllers must limit processing to purposes disclosed to the consumer and conduct data protection assessments for high-risk processing; processors act only on a controller's documented instructions. The bill establishes no lawful-basis regime distinct from this disclosed-purpose limitation; consent is required specifically for sensitive-data processing, not for processing generally.
This bill has not been enacted and binds nothing today; it passed the House 127-76 on 2025-10-01 and had second consideration in the Senate on 2026-06-25, with no Senate third-consideration vote or gubernatorial action as of 2026-08-28.
What it asks of an app
- This bill has not been enacted. It passed the House on 2025-10-01 and remained at second consideration in the Senate as of 2026-08-28; do not treat it as binding.
- Watch for further Senate action. If enacted as currently amended, it would apply to a for-profit business meeting a revenue or data-volume threshold and would require data protection assessments before high-risk processing.
When LexLint raises it
Declared activities: automated_outreach, crawls_web, deploys_chatbot, processes_biometrics, processes_voice, trains_models
Primary source: official Pennsylvania bill text, House Bill 78, Senate Printer's No. 3688, Pennsylvania General Assembly website