Law / Pennsylvania

Pennsylvania

age

Pennsylvania has not enacted an age gating law in any of the four tracked families and has no comprehensive consumer privacy law of its own yet. Bipartisan bills requiring age verification for pornography websites (HB 1513 and SB 603) and a bill requiring parental consent verification for minors on social media (HB 1430) were introduced in 2025 and remain in committee without passing either chamber. Pennsylvania has no app store age verification bill of note.

Its most advanced privacy related bill is the Consumer Data Privacy Act (HB 78), which would require opt in consent before processing a known child's data under 13 or a known minor's data under 16 for targeted advertising, sale, or profiling.

It passed the House 127 to 76 on October 1, 2025, was reported out of the Senate Consumer Protection and Professional Licensure Committee on February 4, 2026 and re-referred to the Senate Communications and Technology Committee, which re-reported it as amended on June 24, 2026; it received second consideration on the Senate floor on June 25, 2026 and awaits final Senate passage.

privacy

Pennsylvania has no enacted comprehensive personal-data statute.

House Bill 78, the Consumer Data Privacy Act, passed the House 127-76 on 2025-10-01 and remained at second consideration in the Senate as of 2026-08-28 after a Senate committee amendment (Printer's No. 3688); as currently amended it would classify biometric or genetic data processed to identify a person as sensitive data, would exclude a photograph, video, or audio recording, or any data generated from one, from the biometric data definition with no clawback for identification purpose, and would foreclose a private right of action twice over, by an express bar and by making its unfair-trade-practice deeming clause enforceable only by the Attorney General.

Pennsylvania's only enacted personal-data statute of general application is the Breach of Personal Information Notification Act, 73 P.S. secs. 2301 et seq. (Act of Dec. 22, 2005, P.L.474, No.94), which took effect 180 days after its December 22, 2005 enactment (June 20, 2006), was most recently amended June 28, 2024 to lower its consumer-reporting-agency notice threshold to 500 persons and to exclude publicly available government-records information, and does not reach biometric data at all.

That breach statute deems a notice violation an unfair trade practice under the Unfair Trade Practices and Consumer Protection Law but gives the Attorney General exclusive authority to sue on it, closing the indirect private-action route the deeming clause would otherwise open.

14 instruments named 5 researched in detail As of 2026-08-28

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Age-appropriate design code

HB 78, Pennsylvania Consumer Data Privacy Act

cite Pennsylvania House Bill No. 78 (2025-2026 Reg. Sess.), pending stage PROPOSED draft date not recorded source official Pennsylvania General Assembly bill information page

Would require a controller to obtain opt in consent before processing the personal data of a known child under 13, and before processing a known minor's data under 16 for targeted advertising, sale, or profiling producing legal or similarly significant effects.

Passed the House 127 to 76 on October 1, 2025, was reported by the Senate Consumer Protection and Professional Licensure Committee on February 4, 2026 and re-referred to the Senate Communications and Technology Committee, which re-reported it as amended on June 24, 2026; it received second consideration on June 25, 2026 but has not passed the full Senate.

Note and primary source

Breach notification

Breach of Personal Information Notification Act

cite 73 P.S. secs. 2302, 2303, 2305, 2308 (Act 94 of 2005) stage IN FORCE in force since 2006-06-20 source official Pennsylvania session-law text of the Act of Dec. 22

An entity that maintains, stores, or manages computerized data including personal information must provide notice of a breach of the security of the system, without unreasonable delay, to any Pennsylvania resident whose unencrypted and unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person.

Personal information is name plus a Social Security number, driver's license or state ID number, a financial account number with access credential, medical information held by a state agency or contractor, health insurance information, or a username or email with a password or security question, and excludes publicly available information lawfully available from government records or widely distributed media (added by the June 28, 2024 amendment); it does not reach biometric identifiers as such.

An entity that notifies more than 500 persons at one time (lowered from 1,000 by the 2024 amendment) must also notify nationwide consumer reporting agencies; a state agency's own breach separately requires Attorney General notice within seven business days, but no parallel duty requires a private entity's breach to notify the Attorney General directly.

A violation is deemed an unfair or deceptive practice under the Unfair Trade Practices and Consumer Protection Law, 73 P.S. secs. 201-1 to 201-9.3, but the Office of Attorney General has exclusive authority to bring that action, so the Act creates no private right of action even though its deeming clause would otherwise open a UDAP route the way Connecticut's breach statute does.

What it asks of an app

Comprehensive regime

House Bill 78, Consumer Data Privacy Act, general applicability and controller and processor duties

cite Pa. H.B. 78, secs. 2, 5, 6, 7 (PN 3688) stage PROPOSED draft date not recorded source official Pennsylvania bill text, House Bill 78, Senate Printer's No. 3688, Pennsylvania General Assembly website

House Bill 78, as amended by the Senate Communications and Technology Committee (Printer's No. 3688), would apply to a for-profit controller doing business in Pennsylvania that meets a revenue threshold of more than $10,000,000, or that alone or in combination buys, receives, sells, or shares for commercial purposes the personal information of at least 100,000 consumers, households, or devices (raised from 50,000 in the original bill), or that derives at least 50% of annual revenue from selling personal information.

Controllers must limit processing to purposes disclosed to the consumer and conduct data protection assessments for high-risk processing; processors act only on a controller's documented instructions. The bill establishes no lawful-basis regime distinct from this disclosed-purpose limitation; consent is required specifically for sensitive-data processing, not for processing generally.

This bill has not been enacted and binds nothing today; it passed the House 127-76 on 2025-10-01 and had second consideration in the Senate on 2026-06-25, with no Senate third-consideration vote or gubernatorial action as of 2026-08-28.

What it asks of an app

Enforcement supervision

House Bill 78, Attorney General enforcement and private right of action

cite Pa. H.B. 78, sec. 10 (PN 3688) stage PROPOSED draft date not recorded source official Pennsylvania bill text, House Bill 78, Senate Printer's No. 3688, Pennsylvania General Assembly website

As amended (PN 3688), HB 78 would give the Attorney General exclusive authority to enforce the Act and would foreclose a private right of action twice over: subsection (b), strengthened by the 2026-06-24 Senate amendment, provides that nothing in the Act creates, is used as the basis or predicate for, or otherwise gives rise to a private right of action; and subsection (c) deems a violation an unfair or deceptive practice under the Unfair Trade Practices and Consumer Protection Law but makes that deeming enforceable exclusively by the Attorney General, closing the UDAP route the deeming clause would otherwise open, the same double-foreclosure shape as the enacted breach statute below.

This bill has not been enacted and binds nothing today.

What it asks of an app

Sensitive categories

House Bill 78, sensitive data and biometric data definitions

cite Pa. H.B. 78, sec. 2 (PN 3688) stage PROPOSED draft date not recorded source official Pennsylvania bill text, House Bill 78, Senate Printer's No. 3688, Pennsylvania General Assembly website

As amended (PN 3688), HB 78 would define biometric data as data generated by automatic measurements of an individual's biological characteristics, including fingerprints, voiceprints, eye retinas, irises, or other unique biological patterns or characteristics used to identify a specific individual, but the definition excludes a digital or physical photograph, an audio or video recording, or any data generated from either, with no exception for data generated to identify a specific person, unconditionally, unlike Kentucky's, Maryland's, Minnesota's, or New Jersey's clawback-shaped equivalents.

A separate clause also excludes an irreversible mathematical representation (a template or hash that cannot be used to recreate the underlying capture), and 'personal data' itself separately excludes biometric data converted to such a representation.

Sensitive data, requiring opt-in consent, includes the processing of genetic or biometric data to uniquely identify an individual, alongside race or ethnicity, religion, health, sexuality, citizenship or immigration status, child data, precise geolocation, and, added by the 2026-06-24 amendment, Social Security number, driver's license number, and financial account number with access credentials. This bill has not been enacted and binds nothing today.

Pennsylvania has no enacted, freestanding biometric-privacy statute; a 2023-2024 session bill of that kind, HB 926, never advanced past introduction and has no confirmed 2025-2026 successor.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.