Loading chat...
PA SB112
Bill
Status
3/21/2025
Primary Sponsor
Maria Collett
Click for details
AI Summary
-
Grants Pennsylvania consumers rights to access, correct, delete, and obtain portable copies of their personal data, as well as opt out of targeted advertising, data sales, and automated profiling decisions
-
Applies to for-profit businesses operating in Pennsylvania with annual gross revenues exceeding $10,000,000, or that process personal data of at least 50,000 consumers, or derive 50% or more of revenue from selling personal data
-
Requires controllers to obtain consent before processing sensitive data (including racial/ethnic origin, health information, biometric data, precise geolocation, and data from children), limit data collection to what is reasonably necessary, and provide clear privacy notices
-
Mandates data protection assessments for high-risk processing activities like targeted advertising and profiling, with enforcement authority granted exclusively to the Attorney General and violations treated as unfair trade practices
-
Exempts government entities, nonprofits, higher education institutions, HIPAA-covered entities, financial institutions under Gramm-Leach-Bliley, and provides a 60-day cure period for violations through December 31, 2026
Legislative Description
Providing for consumer data privacy, for duties of controllers and for duties of processors; and imposing penalties.
Last Action
Referred to Communications & Technology
3/21/2025