EnglishEspañol
Pennsylvania flag

Pennsylvania

Pennsylvania Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 4 primary sources cited on this page. How we verify our legal content

Pennsylvania Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must a business notify Pennsylvania residents of a data breach?

Pennsylvania requires notification without unreasonable delay under BPINA. There is no specific number of days. Delays are permitted only for law enforcement needs or to determine the scope of the breach and restore system integrity.

When must the Pennsylvania Attorney General be notified of a data breach?

Under Act 33 of 2024, the Attorney General must be notified concurrently with the affected-resident notice when a breach affects more than 500 Pennsylvania residents. The AG launched an online reporting portal in September 2024 to receive these notifications.

Does Pennsylvania require businesses to provide credit monitoring after a data breach?

Yes. Under Act 33 of 2024, businesses must offer 12 months of credit monitoring when a breach involves Social Security numbers, driver's license numbers, state ID numbers, or bank account numbers. Pennsylvania is among the first states to extend this requirement beyond SSN breaches.

Can individuals sue a business in Pennsylvania for failing to provide breach notification?

BPINA violations are classified as unfair or deceptive practices under the Pennsylvania Consumer Protection Law, but the statute gives the Pennsylvania Office of Attorney General exclusive authority to bring an action for a BPINA violation. There is no private right of action under BPINA itself, so an individual cannot sue a business directly under this act for a notification failure.

Does Pennsylvania's breach notification law cover online account credentials?

Yes. BPINA covers username or email addresses in combination with passwords or security questions that would permit access to an online account. This trigger was added by Act 151 of 2022, effective May 2023, not by the 2024 amendment.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the date Governor Shapiro signed Act 33 of 2024 into law to June 28, 2024, per the Pennsylvania General Assembly bill record for SB 824.

Corrected several BPINA facts: notification failures are enforceable only by the Attorney General (BPINA gives no private right of action), the consumer-reporting-agency notice threshold is more than 500 residents (not 1,000, per Act 33 of 2024), the health-insurance-information and username/password breach triggers date to Act 151 of 2022 (not Act 33 of 2024), Attorney General notice is due concurrently with consumer notice, and dead Attorney General citation links were replaced with the live reporting page.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. BPINA - Act 94 of 2005 (Original Text)(legis.state.pa.us).gov
  2. Act 33 of 2024 - BPINA Amendments(legis.state.pa.us).gov
  3. Act 33 of 2024 Full Text(legis.state.pa.us).gov
  4. PA Attorney General - Report a Data Breach(attorneygeneral.gov).gov
  5. Pennsylvania General Assembly - Senate Bill 824 (2023-24), enacted as Act 33 of 2024(palegis.us)
Share: