{
  "type": "practice-guide",
  "canonical": "https://openagreements.org/practice-guides/privacy/us/pennsylvania",
  "links": [
    {
      "rel": "self",
      "href": "https://openagreements.org/practice-guides/privacy/us/pennsylvania.json",
      "type": "application/json"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/pennsylvania",
      "type": "text/html"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/pennsylvania/markdown",
      "type": "text/markdown"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/pennsylvania/json",
      "type": "application/json"
    }
  ],
  "data": {
    "topic": "privacy",
    "state": "pennsylvania",
    "frontmatter": {
      "title": "Pennsylvania Consumer Privacy Law",
      "description": "Pennsylvania has no comprehensive consumer-privacy statute. The operative state law is the Breach of Personal Information Notification Act (73 P.S. §§ 2301 et seq.), enforced exclusively by the Attorney General under the Unfair Trade Practices and Consumer Protection Law; the rest of a Pennsylvania privacy program rides the federal and sectoral overlay (FTC Act § 5, GLBA, HIPAA, COPPA).",
      "state": "Pennsylvania",
      "lastReviewed": "2026-06-07",
      "license": "CC BY 4.0",
      "authors": [
        "steven-obiajulu"
      ],
      "summary": {
        "keyLaw": "Pennsylvania Breach of Personal Information Notification Act, 73 P.S. §§ 2301 et seq. — Pennsylvania has no comprehensive consumer-privacy law; the Breach Act plus a federal and sectoral overlay is the operative framework",
        "appliesTo": "Any entity — a sole proprietorship, partnership, corporation, association, or other group, for profit or not — doing business in Pennsylvania that maintains, stores, or manages computerized personal information of Pennsylvania residents; no revenue or consumer-volume threshold",
        "privacyPolicyRequired": "No comprehensive Pennsylvania statute mandates a consumer privacy policy or fixes its contents; contents are driven by FTC Act § 5 (a policy that misstates practices is deceptive), the UTPCPL, and the GLBA, HIPAA, and COPPA rules where the business is in scope",
        "privateRightOfAction": "Not under the Breach Act — the Attorney General has exclusive UTPCPL enforcement authority; but Pennsylvania's all-party-consent wiretap law (WESCA, 18 Pa.C.S. § 5725) provides a private cause of action that drives website session-replay class actions",
        "regulator": "Pennsylvania Office of Attorney General",
        "bottomLine": "Pennsylvania has not enacted a comprehensive consumer-privacy law, so there are no general data-rights, notice-at-collection, consent, or processor-contract duties under state law. The operative state statute is the Breach of Personal Information Notification Act, which requires notice of a data breach without unreasonable delay and is enforced solely by the Attorney General. Everything else in a Pennsylvania-facing privacy program comes from the federal and sectoral overlay — FTC Act § 5, GLBA, HIPAA, and COPPA — so build to those and to the Breach Act, and the program auto-upgrades if Pennsylvania later enacts an omnibus law. One state-law exposure does demand attention now — Pennsylvania's all-party-consent wiretap statute (WESCA) has become the basis for website session-replay and tracking-pixel class actions, so obtain visitor consent before running third-party tracking.",
        "lawCoverage": "baseline",
        "policyMandate": "none",
        "consumersCanSue": "broad",
        "sensitiveDataConsent": "none",
        "universalOptOutSignal": "notRequired"
      },
      "about": [
        "Pennsylvania consumer privacy law",
        "Pennsylvania Breach of Personal Information Notification Act",
        "Pennsylvania data breach notification 73 P.S. 2301",
        "Pennsylvania no comprehensive privacy law",
        "Pennsylvania privacy policy requirements",
        "Pennsylvania vendor data processing contracts",
        "Pennsylvania Attorney General privacy enforcement",
        "Pennsylvania data breach private right of action",
        "Pennsylvania WESCA wiretapping session replay",
        "Pennsylvania website tracking pixel lawsuit",
        "Popa v Harriet Carter Gifts wiretap"
      ],
      "translations": [
        {
          "language": "中文",
          "status": "planned"
        },
        {
          "language": "Español",
          "status": "planned"
        },
        {
          "language": "Português",
          "status": "planned"
        },
        {
          "language": "Deutsch",
          "status": "planned"
        }
      ]
    },
    "questions": [
      {
        "slug": "which-privacy-laws-apply",
        "label": "Which privacy laws apply to your business in Pennsylvania?",
        "heading": "Which privacy laws apply to your business in Pennsylvania?",
        "answerText": "There is no comprehensive Pennsylvania consumer-privacy law. The operative state statute is the Breach of Personal Information Notification Act, which applies to any entity — defined as a State agency, a political subdivision, or an individual or a business doing business in the Commonwealth — that maintains, stores, or manages computerized personal information of Pennsylvania residents. It carries no revenue or consumer-volume threshold, and it governs breach response rather than day-to-day data handling.",
        "sources": [
          {
            "id": "stat-2302-entity",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "73 P.S. § 2302",
            "citation": "73 P.S. § 2302.",
            "url": "https://codes.findlaw.com/pa/title-73-ps-trade-and-commerce/pa-st-sect-73-2302/",
            "proposition": "The Breach Act applies to any entity — a State agency, a political subdivision, or an individual or business doing business in Pennsylvania.",
            "verbatimQuote": "“Entity.” A State agency, a political subdivision of the Commonwealth or an individual or a business doing business in this Commonwealth.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/pennsylvania#src-stat-2302-entity"
          },
          {
            "id": "stat-2329-apply",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "73 P.S. § 2329",
            "citation": "73 P.S. § 2329.",
            "url": "https://codes.findlaw.com/pa/title-73-ps-trade-and-commerce/pa-st-sect-73-2329/",
            "proposition": "The Breach Act applies to the determination or notification of a breach occurring on or after its effective date — it is a breach-response statute, not a general data-handling regime.",
            "verbatimQuote": "This act shall apply to the determination or notification of a breach of the security of the system that occurs on or after the effective date of this section.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/pennsylvania#src-stat-2329-apply"
          }
        ]
      },
      {
        "slug": "privacy-policy-contents",
        "label": "What must your Pennsylvania privacy policy contain?",
        "heading": "What must your Pennsylvania privacy policy contain?",
        "answerText": "No Pennsylvania statute requires a general consumer privacy policy or fixes what it must say. For most businesses, the privacy policy is governed not by a state checklist but by the rule that whatever you publish has to be true: under Section 5 of the FTC Act and Pennsylvania's Unfair Trade Practices and Consumer Protection Law, a policy that misstates how you collect, use, share, retain, or secure data is a deceptive practice. Where a sectoral regime applies, that regime supplies the contents instead — a HIPAA covered entity, for example, must give individuals a notice of the uses and disclosures of their protected health information and of their rights and the entity's duties.",
        "sources": [
          {
            "id": "fed-ftc5-deceptive",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "FTC Act § 5",
            "citation": "15 U.S.C. § 45(a)(1).",
            "url": "https://www.law.cornell.edu/uscode/text/15/45",
            "deepLink": "https://www.law.cornell.edu/uscode/text/15/45#:~:text=Unfair%20methods%20of%20competition%20in,commerce%2C%20are%20hereby%20declared%20unlawful.",
            "proposition": "Section 5 of the FTC Act declares unfair or deceptive acts or practices in or affecting commerce unlawful, which reaches a privacy policy that misstates a business's actual data practices.",
            "verbatimQuote": "Unfair methods of competition in or affecting commerce, and unfair or deceptive acts or practices in or affecting commerce, are hereby declared unlawful.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/pennsylvania#src-fed-ftc5-deceptive"
          },
          {
            "id": "fed-hipaa-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "HIPAA Notice of Privacy Practices",
            "citation": "45 C.F.R. § 164.520.",
            "url": "https://www.law.cornell.edu/cfr/text/45/164.520",
            "deepLink": "https://www.law.cornell.edu/cfr/text/45/164.520#:~:text=an%20individual%20has%20a%20right,respect%20to%20protected%20health%20information",
            "proposition": "A HIPAA covered entity must give individuals a notice describing the uses and disclosures of their protected health information and their rights and the entity's legal duties.",
            "verbatimQuote": "an individual has a right to adequate notice of the uses and disclosures of protected health information that may be made by the covered entity, and of the individual's rights and the covered entity's legal duties with respect to protected health information",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/pennsylvania#src-fed-hipaa-notice"
          }
        ]
      },
      {
        "slug": "vendor-contracts",
        "label": "What must your contracts with vendors say?",
        "heading": "What must your contracts with vendors say?",
        "answerText": "Pennsylvania has no omnibus data-processing-agreement requirement — no state statute prescribes controller-to-processor terms, audit rights, deletion clauses, or subprocessor flow-downs for general private-sector contracts. Vendor data terms are instead driven by the sectoral regimes that apply to your business and by contract best practice.",
        "sources": [
          {
            "id": "fed-glba-safeguards",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "GLBA Safeguards Rule",
            "citation": "16 C.F.R. § 314.4.",
            "url": "https://www.law.cornell.edu/cfr/text/16/314.4",
            "deepLink": "https://www.law.cornell.edu/cfr/text/16/314.4#:~:text=Requiring%20your%20service%20providers%20by,implement%20and%20maintain%20such%20safeguards",
            "proposition": "The GLBA Safeguards Rule requires a financial institution to oversee its service providers, including by requiring them by contract to implement and maintain appropriate safeguards for customer information.",
            "verbatimQuote": "Requiring your service providers by contract to implement and maintain such safeguards",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/pennsylvania#src-fed-glba-safeguards"
          },
          {
            "id": "fed-hipaa-baa",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "HIPAA Business Associate Contracts",
            "citation": "45 C.F.R. § 164.504.",
            "url": "https://www.law.cornell.edu/cfr/text/45/164.504",
            "deepLink": "https://www.law.cornell.edu/cfr/text/45/164.504#:~:text=A%20contract%20between%20the%20covered,and%20a%20business%20associate%20must",
            "proposition": "HIPAA requires a written business-associate contract that establishes the permitted uses and disclosures of protected health information and binds the business associate to safeguard it.",
            "verbatimQuote": "A contract between the covered entity and a business associate must",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/pennsylvania#src-fed-hipaa-baa"
          }
        ]
      },
      {
        "slug": "breach-notification",
        "label": "When must you notify people of a data breach in Pennsylvania?",
        "heading": "When must you notify people of a data breach in Pennsylvania?",
        "answerText": "An entity that maintains, stores, or manages computerized personal information must notify any Pennsylvania resident whose unencrypted and unredacted personal information was, or is reasonably believed to have been, accessed and acquired by an unauthorized person. The notice must be made without unreasonable delay. A reportable breach is the unauthorized access and acquisition of computerized data that materially compromises personal information and causes, or is reasonably believed to cause, loss or injury to a resident. When notice goes to more than 500 persons at one time, the entity must also notify the nationwide consumer reporting agencies without unreasonable delay.",
        "sources": [
          {
            "id": "stat-2303-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "73 P.S. § 2303",
            "citation": "73 P.S. § 2303(a).",
            "url": "https://codes.findlaw.com/pa/title-73-ps-trade-and-commerce/pa-st-sect-73-2303/",
            "proposition": "An entity holding computerized personal information must notify any Pennsylvania resident whose unencrypted, unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person, without unreasonable delay.",
            "verbatimQuote": "An entity that maintains, stores or manages computerized data that includes personal information shall provide notice of any breach of the security of the system following determination of the breach of the security of the system to any resident of this Commonwealth whose unencrypted and unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/pennsylvania#src-stat-2303-notice"
          },
          {
            "id": "stat-2302-breach",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "73 P.S. § 2302",
            "citation": "73 P.S. § 2302.",
            "url": "https://codes.findlaw.com/pa/title-73-ps-trade-and-commerce/pa-st-sect-73-2302/",
            "proposition": "A breach of the security of the system is the unauthorized access and acquisition of computerized data that materially compromises personal information and causes, or is reasonably believed to cause, loss or injury to a Pennsylvania resident.",
            "verbatimQuote": "The unauthorized access and acquisition of computerized data that materially compromises the security or confidentiality of personal information maintained by the entity as part of a database of personal information regarding multiple individuals and that causes or the entity reasonably believes has caused or will cause loss or injury to any resident of this Commonwealth.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/pennsylvania#src-stat-2302-breach"
          },
          {
            "id": "stat-2305-cra",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "73 P.S. § 2305",
            "citation": "73 P.S. § 2305.",
            "url": "https://codes.findlaw.com/pa/title-73-ps-trade-and-commerce/pa-st-sect-73-2305/",
            "proposition": "When an entity notifies more than 500 persons at one time, it must also notify the nationwide consumer reporting agencies, without unreasonable delay, of the timing, distribution, and number of notices.",
            "verbatimQuote": "When an entity provides notification under this act to more than 500 persons at one time, the entity shall also notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, as defined in section 603 of the Fair Credit Reporting Act (Public Law 91-508, 15 U.S.C. § 1681a), of the timing, distribution and number of notices.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/pennsylvania#src-stat-2305-cra"
          }
        ]
      },
      {
        "slug": "consumer-lawsuit",
        "label": "Can a consumer sue your business in Pennsylvania over privacy?",
        "heading": "Can a consumer sue your business in Pennsylvania over privacy?",
        "answerText": "Not under the Breach Act. A violation of the Act is deemed an unfair or deceptive practice under the Unfair Trade Practices and Consumer Protection Law, and the Office of Attorney General has exclusive authority to bring that action — so the Breach Act gives consumers no private right of action. Other Pennsylvania law is a different story. The Wiretapping and Electronic Surveillance Control Act (WESCA) makes it a third-degree felony to intentionally intercept any wire, electronic, or oral communication without all parties' consent, and it gives any person whose communication is intercepted a private civil cause of action — with liquidated and punitive damages and fees. The Third Circuit held in Popa v. Harriet Carter Gifts that this framework reaches ordinary website tracking, so third-party session-replay or pixel code can be an unlawful interception unless the visitor consented.",
        "sources": [
          {
            "id": "stat-2308-utpcpl",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "73 P.S. § 2308",
            "citation": "73 P.S. § 2308.",
            "url": "https://codes.findlaw.com/pa/title-73-ps-trade-and-commerce/pa-st-sect-73-2308/",
            "proposition": "A violation of the Breach Act is deemed an unfair or deceptive act or practice under the Unfair Trade Practices and Consumer Protection Law.",
            "verbatimQuote": "A violation of this act shall be deemed to be an unfair or deceptive act or practice in violation of the act of December 17, 1968 (P.L. 1224, No. 387),",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/pennsylvania#src-stat-2308-utpcpl"
          },
          {
            "id": "stat-2308-exclusive",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "73 P.S. § 2308",
            "citation": "73 P.S. § 2308.",
            "url": "https://codes.findlaw.com/pa/title-73-ps-trade-and-commerce/pa-st-sect-73-2308/",
            "proposition": "The Office of Attorney General has exclusive authority to bring a UTPCPL action for a Breach Act violation, so there is no private right of action under the Act.",
            "verbatimQuote": "The Office of Attorney General shall have exclusive authority to bring an action under the Unfair Trade Practices and Consumer Protection Law for a violation of this act.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/pennsylvania#src-stat-2308-exclusive"
          },
          {
            "id": "wesca-5703",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "18 Pa.C.S. § 5703",
            "citation": "18 Pa.C.S. § 5703.",
            "url": "https://codes.findlaw.com/pa/title-18-pacsa-crimes-and-offenses/pa-csa-sect-18-5703/",
            "proposition": "Pennsylvania's Wiretapping and Electronic Surveillance Control Act makes it a third-degree felony to intentionally intercept, or procure another to intercept, any wire, electronic, or oral communication, subject to the chapter's exceptions.",
            "verbatimQuote": "Except as otherwise provided in this chapter, a person is guilty of a felony of the third degree if he: (1) intentionally intercepts, endeavors to intercept, or procures any other person to intercept or endeavor to intercept any wire, electronic or oral communication;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/pennsylvania#src-wesca-5703"
          },
          {
            "id": "wesca-5725",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "18 Pa.C.S. § 5725",
            "citation": "18 Pa.C.S. § 5725(a).",
            "url": "https://codes.findlaw.com/pa/title-18-pacsa-crimes-and-offenses/pa-csa-sect-18-5725/",
            "proposition": "Any person whose communication is intercepted, disclosed, or used in violation of WESCA has a private civil cause of action against the violator and may recover actual or liquidated damages, punitive damages, and reasonable attorney's fees.",
            "verbatimQuote": "Any person whose wire, electronic or oral communication is intercepted, disclosed or used in violation of this chapter shall have a civil cause of action against any person who intercepts, discloses or uses or procures any other person to intercept, disclose or use, such communication;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/pennsylvania#src-wesca-5725"
          },
          {
            "id": "case-popa",
            "authorityType": "case-law",
            "tier": "primary-source-backed",
            "title": "Popa v. Harriet Carter Gifts, Inc., 52 F.4th 121 (3d Cir. 2022)",
            "citation": "Popa v. Harriet Carter Gifts, Inc., 52 F.4th 121 (3d Cir. 2022).",
            "url": "https://www.courtlistener.com/opinion/8403630/ashley-popa-v-harriet-carter-gifts-inc/",
            "deepLink": "https://www.courtlistener.com/opinion/8403630/ashley-popa-v-harriet-carter-gifts-inc/#:~:text=Thus%20if%20someone%20consents%20to,WESCA%20does%20not%20impose%20liability.",
            "proposition": "The Third Circuit held that WESCA reaches everyday website tracking — a third party's interception of a visitor's browser communications can violate the Act unless the visitor consented — reviving a session-replay wiretap claim.",
            "verbatimQuote": "Thus if someone consents to the interception of her communications with a website, the WESCA does not impose liability.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/pennsylvania#src-case-popa"
          }
        ]
      }
    ]
  }
}
