Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Age-appropriate design code
Would require a controller to obtain opt in consent before processing the personal data of a known child under 13, and before processing a known minor's data under 16 for targeted advertising, sale, or profiling producing legal or similarly significant effects.
Passed the House 127 to 76 on October 1, 2025, was reported by the Senate Consumer Protection and Professional Licensure Committee on February 4, 2026 and re-referred to the Senate Communications and Technology Committee, which re-reported it as amended on June 24, 2026; it received second consideration on June 25, 2026 but has not passed the full Senate.
Note and primary source →
Breach notification
An entity that maintains, stores, or manages computerized data including personal information must provide notice of a breach of the security of the system, without unreasonable delay, to any Pennsylvania resident whose unencrypted and unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person.
Personal information is name plus a Social Security number, driver's license or state ID number, a financial account number with access credential, medical information held by a state agency or contractor, health insurance information, or a username or email with a password or security question, and excludes publicly available information lawfully available from government records or widely distributed media (added by the June 28, 2024 amendment); it does not reach biometric identifiers as such.
An entity that notifies more than 500 persons at one time (lowered from 1,000 by the 2024 amendment) must also notify nationwide consumer reporting agencies; a state agency's own breach separately requires Attorney General notice within seven business days, but no parallel duty requires a private entity's breach to notify the Attorney General directly.
A violation is deemed an unfair or deceptive practice under the Unfair Trade Practices and Consumer Protection Law, 73 P.S. secs. 201-1 to 201-9.3, but the Office of Attorney General has exclusive authority to bring that action, so the Act creates no private right of action even though its deeming clause would otherwise open a UDAP route the way Connecticut's breach statute does.
What it asks of an app →
Comprehensive regime
cite Pa. H.B. 78, secs. 2, 5, 6, 7 (PN 3688)
stage PROPOSED draft date not recorded
source official Pennsylvania bill text, House Bill 78, Senate Printer's No. 3688, Pennsylvania General Assembly website
House Bill 78, as amended by the Senate Communications and Technology Committee (Printer's No. 3688), would apply to a for-profit controller doing business in Pennsylvania that meets a revenue threshold of more than $10,000,000, or that alone or in combination buys, receives, sells, or shares for commercial purposes the personal information of at least 100,000 consumers, households, or devices (raised from 50,000 in the original bill), or that derives at least 50% of annual revenue from selling personal information.
Controllers must limit processing to purposes disclosed to the consumer and conduct data protection assessments for high-risk processing; processors act only on a controller's documented instructions. The bill establishes no lawful-basis regime distinct from this disclosed-purpose limitation; consent is required specifically for sensitive-data processing, not for processing generally.
This bill has not been enacted and binds nothing today; it passed the House 127-76 on 2025-10-01 and had second consideration in the Senate on 2026-06-25, with no Senate third-consideration vote or gubernatorial action as of 2026-08-28.
What it asks of an app →
Enforcement supervision
cite Pa. H.B. 78, sec. 10 (PN 3688)
stage PROPOSED draft date not recorded
source official Pennsylvania bill text, House Bill 78, Senate Printer's No. 3688, Pennsylvania General Assembly website
As amended (PN 3688), HB 78 would give the Attorney General exclusive authority to enforce the Act and would foreclose a private right of action twice over: subsection (b), strengthened by the 2026-06-24 Senate amendment, provides that nothing in the Act creates, is used as the basis or predicate for, or otherwise gives rise to a private right of action; and subsection (c) deems a violation an unfair or deceptive practice under the Unfair Trade Practices and Consumer Protection Law but makes that deeming enforceable exclusively by the Attorney General, closing the UDAP route the deeming clause would otherwise open, the same double-foreclosure shape as the enacted breach statute below.
This bill has not been enacted and binds nothing today.
What it asks of an app →
Sensitive categories
cite Pa. H.B. 78, sec. 2 (PN 3688)
stage PROPOSED draft date not recorded
source official Pennsylvania bill text, House Bill 78, Senate Printer's No. 3688, Pennsylvania General Assembly website
As amended (PN 3688), HB 78 would define biometric data as data generated by automatic measurements of an individual's biological characteristics, including fingerprints, voiceprints, eye retinas, irises, or other unique biological patterns or characteristics used to identify a specific individual, but the definition excludes a digital or physical photograph, an audio or video recording, or any data generated from either, with no exception for data generated to identify a specific person, unconditionally, unlike Kentucky's, Maryland's, Minnesota's, or New Jersey's clawback-shaped equivalents.
A separate clause also excludes an irreversible mathematical representation (a template or hash that cannot be used to recreate the underlying capture), and 'personal data' itself separately excludes biometric data converted to such a representation.
Sensitive data, requiring opt-in consent, includes the processing of genetic or biometric data to uniquely identify an individual, alongside race or ethnicity, religion, health, sexuality, citizenship or immigration status, child data, precise geolocation, and, added by the 2026-06-24 amendment, Social Security number, driver's license number, and financial account number with access credentials. This bill has not been enacted and binds nothing today.
Pennsylvania has no enacted, freestanding biometric-privacy statute; a 2023-2024 session bill of that kind, HB 926, never advanced past introduction and has no confirmed 2025-2026 successor.
What it asks of an app →