Pennsylvania
Pennsylvania Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 8 primary sources cited on this page. How we verify our legal content

Pennsylvania has no standalone biometric privacy law. The Breach of Personal Information Notification Act (BPINA) does not explicitly list biometric identifiers in its definition of personal information, so protections are indirect: the Unfair Trade Practices and Consumer Protection Law gives the Attorney General exclusive authority to enforce breach-notification failures, with no private right of action. Two bills that would change this remain pending in the legislature.
Pennsylvania does not have a dedicated biometric privacy statute. Unlike Illinois, which enacted the Biometric Information Privacy Act (BIPA) in 2008, and Texas, which passed its Capture or Use of Biometric Identifier Act (CUBI), Pennsylvania has yet to enact a law that specifically regulates the collection, storage, or use of biometric identifiers like fingerprints, facial geometry, or iris scans.
That does not mean biometric data goes unregulated in the state. Pennsylvania's existing breach notification law provides some coverage, and its consumer protection statute creates enforcement pathways. The state legislature has also introduced several bills that would directly address biometric privacy if passed.
For an overview of the broader privacy framework in the state, see the parent guide to Pennsylvania Data Privacy Laws.

How BPINA Applies to Biometric Data
The Breach of Personal Information Notification Act (BPINA), originally enacted as Act 94 of 2005, is Pennsylvania's primary data breach notification law. It requires businesses and government agencies to notify Pennsylvania residents when their personal information is compromised in a data breach.
BPINA defines "personal information" as an individual's first name or first initial and last name combined with one or more of these unencrypted data elements:
- Social Security number
- Driver's license or state identification card number
- Financial account number with any required security code, access code, or password
- Medical information held by a state agency
- Health insurance information
- A username or email address combined with a password or security question answer
Biometric identifiers like fingerprints, voiceprints, and facial geometry are not explicitly listed in the BPINA definition. This is a significant gap. If a company collects employee fingerprints for timekeeping and those fingerprints are stolen in a data breach, BPINA does not clearly require the company to notify affected individuals.
However, the law's broad language around "unauthorized access and acquisition of computerized data that materially compromises the security or confidentiality of personal information" could potentially apply in situations where biometric data is linked to other covered elements like names and Social Security numbers.
The 2024 BPINA Amendment (Act 33 of 2024)
Governor Josh Shapiro signed Act 33 of 2024 on June 28, 2024, with an effective date of September 26, 2024. This amendment strengthened BPINA in several ways, though it still did not add biometric data to the definition of personal information.
Key changes include:
- New Attorney General notice. Act 33 added Section 3(c.1), which requires an entity to notify the Pennsylvania Attorney General concurrently whenever breach notice must be given to more than 500 affected individuals in Pennsylvania. Before Act 33, BPINA imposed no Attorney General notification duty on private entities at any threshold.
- Lowered consumer reporting agency threshold. Act 33 also amended Section 5 to lower the threshold for notifying the nationwide consumer reporting agencies from more than 1,000 persons to more than 500.
- Free credit monitoring. Breached entities must provide affected individuals with 12 months of free credit monitoring when the breach involves Social Security numbers, driver's license numbers, state IDs, or financial account numbers.
- Faster timelines for government. State agencies must notify affected individuals and the Attorney General within seven business days of discovering a breach. Local government entities must notify individuals within seven business days and district attorneys within three business days.
The 2024 amendment was a step forward for breach response, but the absence of biometric identifiers in the covered data types means BPINA alone does not provide comprehensive protection for fingerprint scans, facial recognition templates, or other biometric data.
For more on breach notification requirements, see Pennsylvania Data Breach Notification Laws.
Consumer Protection Law and Attorney General Enforcement
BPINA designates any violation of its requirements as an "unfair or deceptive act or practice" under the Pennsylvania Unfair Trade Practices and Consumer Protection Law (UTPCPL), codified at 73 Pa. Stat. Sections 201-1 through 201-9.2.
This connection does not create a path for private lawsuits. BPINA's own civil relief section, 73 P.S. Section 2308, gives the Pennsylvania Attorney General exclusive authority to bring a UTPCPL action for a BPINA violation. The statute states that "the Office of Attorney General shall have exclusive authority to bring an action under the Unfair Trade Practices and Consumer Protection Law for a violation of this act."
Attorney General enforcement. The AG can bring civil actions against businesses that violate BPINA, seeking injunctive relief, restitution, and civil penalties of up to $1,000 per violation (up to $3,000 per violation when the victim is 60 or older).
No private right of action for BPINA violations. The UTPCPL's general private-lawsuit provision, Section 201-9.2, lets a consumer who suffers a loss from an unfair or deceptive practice sue for actual damages (or a minimum of $100), attorney's fees, and up to treble damages. But Section 2308's exclusive-authority grant to the Attorney General means that provision does not reach BPINA breach-notification failures. A consumer cannot sue under the UTPCPL over a company's failure to send a required BPINA breach notice; only the Attorney General can bring that claim.
Consumers whose personal information is exposed in a breach covered by BPINA have no BPINA-based private right of action against the company that failed to notify them. They may still have other legal theories available, such as a negligence claim, but those exist independently of BPINA and the UTPCPL and depend on the facts of the case.

Pending Legislation: HB 78 (Consumer Data Privacy Act)
The most significant biometric privacy bill in Pennsylvania's pipeline is House Bill 78, the Pennsylvania Consumer Data Privacy Act. The House passed HB 78 on October 1, 2025, with a vote of 127 to 76.
HB 78 follows the model of comprehensive state privacy laws already enacted in Virginia, Connecticut, and other states. Key biometric provisions include:
- Biometric data definition. The bill defines biometric data as data generated by automatic measurements of an individual's biological characteristics, including fingerprints, voiceprints, eye retinas, irises, or other unique biological patterns used to identify a specific individual. Photographs, video recordings, and audio recordings are excluded unless used for identification.
- Sensitive data classification. Biometric data is classified as "sensitive data" when processed to uniquely identify an individual. This triggers heightened protections.
- Opt-in consent required. Controllers must obtain affirmative opt-in consent from consumers before processing biometric data for identification purposes. Consent must be freely given, specific, informed, and unambiguous.
- Consumer rights. Individuals can request access to, correction of, deletion of, and portable copies of their biometric data. They can also opt out of the sale of their biometric data or its use for targeted advertising.
- AG-only enforcement. The Attorney General has exclusive enforcement authority. The bill does not include a private right of action. There is a 30-day cure period before the AG can initiate enforcement.
HB 78 was re-referred to the Senate Communications and Technology Committee on February 4, 2026. As of August 2026, the committee has since approved the bill as amended and reported it to the full Senate, where it passed second consideration on June 25, 2026. It remains pending a final Senate vote. Its companion bill, Senate Bill 112, sponsored by Senator Maria Collett, contains similar provisions and is also in the Senate Communications and Technology Committee.
Pending Legislation: HB 596 (Biometric Identifier Signage Act)
House Bill 596, introduced by Representative Ed Neilson on February 12, 2025, takes a narrower approach focused specifically on commercial disclosure of biometric data collection.
Key provisions:
- Scope. Applies to commercial establishments such as retail stores, restaurants, hotels, and entertainment venues that collect, retain, store, or share customers' biometric identifier information.
- Signage requirement. Covered establishments must place clear and conspicuous signs near customer entrances that notify customers in plain language about biometric data collection.
- Biometric identifier definition. Covers physiological or biological characteristics used to identify individuals, including retinal scans, fingerprints, voiceprints, and facial geometry.
- Private right of action. Customers can file civil lawsuits for violations. Damages range from $500 to $5,000 per violation, plus attorney's fees. There is a 30-day written notice and cure period before filing for signage-only violations.
- Exemptions. Government entities and financial institutions are excluded. Video recordings not used for identification purposes are also exempt.
HB 596 was referred to the House Commerce Committee on February 12, 2025, and has not advanced further as of August 2026. A nearly identical bill, HB 926, was introduced in the 2023-2024 session by the same sponsor but died in committee without receiving a vote.

Employer Use of Biometric Data in Pennsylvania
Pennsylvania employers that collect fingerprints, facial scans, or other biometric identifiers for timekeeping, access control, or security purposes currently operate without a state-specific biometric privacy law governing those activities.
There are several practical considerations:
No state-level mandate. Pennsylvania does not require employers to provide written notice, obtain consent, or establish retention schedules before collecting employee biometric data.
Multi-state exposure. Employers operating across state lines must consider the biometric laws of other states where they have employees. An employer headquartered in Pennsylvania but with workers in Illinois must comply with Illinois BIPA for those employees. BIPA class action settlements have reached tens of millions of dollars, including a $51.75 million settlement with Clearview AI in 2025.
HB 78 impact if passed. If HB 78 becomes law, it would likely exempt employee data collected in an employment context from most consumer privacy provisions, following the approach taken by most comprehensive state privacy laws. However, employers should monitor the bill's progress as exemption language can change during the legislative process.
Best practices. Employment law professionals in Pennsylvania recommend that employers proactively implement notice and consent procedures, establish data retention and destruction policies, and evaluate third-party vendor compliance even before a state law requires it.
How Pennsylvania Compares to Other States
Pennsylvania sits in a middle tier among states on biometric privacy protection. It lacks the strong standalone protections of states like Illinois (BIPA, with its private right of action that has generated billions in settlements) or Texas (CUBI, with AG enforcement and $25,000 per violation penalties).
The BPINA/UTPCPL combination provides some enforcement tools, but the absence of biometric identifiers from the breach notification trigger limits practical impact. If HB 78 passes, Pennsylvania would join more than 20 states with comprehensive consumer privacy laws that classify biometric data as sensitive, but without a private right of action for biometric claims specifically.
HB 596 would bring Pennsylvania closer to the Illinois model by creating a private right of action for commercial biometric data collection, though its scope is limited to customer-facing commercial establishments and does not cover employer data collection.
Sources and Official Resources
For the most current information on Pennsylvania biometric privacy laws and pending legislation, consult these official government sources:
- BPINA Full Text (Act 94 of 2005) on the Pennsylvania General Assembly website
- Act 33 of 2024 (BPINA Amendment) on the Pennsylvania General Assembly website
- PA Attorney General - Report a Data Breach for breach reporting and consumer guidance
- HB 78 Bill Status on the Pennsylvania General Assembly website
- HB 596 Bill Status on the Pennsylvania General Assembly website
- SB 112 Bill Status on the Pennsylvania General Assembly website
This article provides general legal information about Pennsylvania biometric privacy laws. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official Pennsylvania government sources.
More Pennsylvania Laws
Frequently Asked Questions
Does Pennsylvania have a biometric privacy law?
Pennsylvania does not have a standalone biometric privacy law as of August 2026. Biometric data receives indirect protection through the Breach of Personal Information Notification Act (BPINA) and the Unfair Trade Practices and Consumer Protection Law (UTPCPL). However, BPINA does not explicitly list biometric identifiers in its definition of personal information.
Can I sue a company in Pennsylvania for collecting my biometric data without consent?
There is no Pennsylvania-specific statute that creates a direct private right of action for unauthorized biometric data collection. BPINA's own enforcement provision, 73 P.S. Section 2308, gives the Pennsylvania Attorney General exclusive authority to bring a UTPCPL claim for a BPINA violation, so consumers cannot sue under the UTPCPL for a BPINA breach-notification failure either. Pending legislation like HB 596 would create a direct private right of action with damages of $500 to $5,000 per violation.
Does my Pennsylvania employer need my consent to scan my fingerprints?
Under current Pennsylvania law, employers are not required to obtain consent before collecting fingerprints or other biometric data. No state statute mandates written notice, consent, or retention policies for employer biometric collection. However, if HB 78 passes, it would classify biometric data as sensitive data requiring opt-in consent, though employment context exemptions may apply.
What happens if a company loses my biometric data in a Pennsylvania data breach?
BPINA does not explicitly require breach notification when biometric data alone is compromised. If the breach also involves covered personal information like Social Security numbers or financial account numbers, the company must notify affected individuals without unreasonable delay. The 2024 amendment added requirements for 12-month free credit monitoring and, in a provision new to Pennsylvania law, concurrent notice to the Attorney General when breach notice must go to more than 500 residents of the Commonwealth.
Will Pennsylvania pass a biometric privacy law in 2026?
Two relevant bills are pending. HB 78 (Consumer Data Privacy Act) passed the House in October 2025, was reported favorably as amended by the Senate Communications and Technology Committee on June 24, 2026, and passed second consideration in the full Senate on June 25, 2026. It still needs a final Senate vote. HB 596 (Biometric Identifier Signage Act) is in the House Commerce Committee. Both face uncertain timelines. Previous biometric bills like HB 926 from the 2023-2024 session died without advancing.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Clarified that Act 33 of 2024 newly created the Attorney General breach-notification duty for breaches affecting more than 500 Pennsylvania residents, and separately lowered the consumer reporting agency notification threshold from 1,000 to 500.
Corrected an enforcement claim: Pennsylvania's breach-notification law (BPINA) gives the state Attorney General exclusive authority to sue over violations, so there is no private right of action for BPINA breach-notification failures as this article previously stated. Also replaced two dead Attorney General website links and updated HB 78's legislative status to reflect its June 25, 2026 second-consideration vote in the Senate.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
Sources and References
- BPINA Full Text (Act 94 of 2005)(legis.state.pa.us).gov
- Act 33 of 2024 (BPINA Amendment)(legis.state.pa.us).gov
- PA UTPCPL Full Text (73 Pa. Stat. 201-1 et seq.)(attorneygeneral.gov).gov
- HB 78 - Consumer Data Privacy Act (2025-2026)(palegis.us).gov
- HB 596 - Biometric Identifier Signage Act (2025-2026)(palegis.us).gov
- SB 112 - Consumer Data Privacy (2025-2026)(palegis.us).gov
- HB 926 - Biometric Disclosure (2023-2024, expired)(palegis.us).gov
- PA Attorney General - Report a Data Breach(attorneygeneral.gov).gov