Providing for duties of covered entities to protect the best interests of children that use online services, products or features and for data protection impact assessments; prohibiting certain actions by covered entities; and imposing penalties.
HB2108, titled the Online Safety Protection Act, would impose new duties on businesses and organizations that knowingly process children’s personal information and provide online services, products, or features likely to be accessed by children. The bill requires covered entities to conduct and maintain data protection impact assessments for new or significantly changed products, review those assessments as needed, and provide them to the Attorney General upon request. It also requires default privacy settings for children to be set to a high level of privacy unless the processing is necessary to enhance the child’s experience and the child is given controls over that use of data.
The bill further prohibits covered entities from using children’s personal information in high-risk ways identified in an assessment unless those risks are mitigated, from profiling children by default in certain high-risk circumstances, from using children’s data for purposes other than those for which it was collected absent a compelling best-interests justification, and from collecting or retaining precise geolocation data by default unless specific exceptions apply. It also bars the use of dark patterns to pressure children into sharing more data, giving up privacy protections, or taking actions not in their best interests. Enforcement authority is given to the Pennsylvania Office of Attorney General, which may seek injunctions and civil penalties, subject to a notice-and-cure process.
The bill would create a new state-level child online privacy and safety framework in Pennsylvania law, with detailed definitions for terms such as covered entity, child, profiling, dark pattern, precise geolocation information, and data protection impact assessment. It would not create a private right of action, and it includes carveouts for certain health information, clinical trials, and services already governed by HIPAA or federal human-subject rules. It also provides that compliance with federal COPPA requirements for children under 13 counts as compliance with this act for those users, and it is designed to yield to future federal law or regulation on the same subject.
Based on the bill text and available context, the overall sentiment appears supportive of stronger protections for children online, with the bill framed around prioritizing children’s privacy, safety, and well-being over commercial interests. There are no committee transcripts or recorded votes provided, so there is no documented opposition or recorded floor debate to assess. The structure of the bill suggests a policy approach that seeks to balance child protection with business compliance flexibility through assessments, exceptions, and a cure period before penalties.
The main points of potential contention are likely to involve the scope of covered entities, the burden and cost of required impact assessments, the limits on profiling and geolocation use, and whether the bill’s standards are too vague or too restrictive for online platforms. Businesses may also object to Attorney General access to assessments, even with trade-secret protections, while privacy advocates may favor the bill’s restrictions but could question whether the exceptions are broad enough. The bill’s reliance on a future federal preemption trigger also suggests concern about overlap with evolving federal children’s privacy law.
HB2108 would add a new chapter of state requirements governing online products and services likely to be accessed by children, creating affirmative duties to assess and mitigate privacy and safety risks, restrict certain data practices, and configure child-facing defaults toward privacy. It would authorize the Pennsylvania Attorney General to enforce these requirements through civil actions and penalties, while preserving confidentiality for impact assessments and avoiding a private right of action. The bill would also interact with existing federal and state privacy regimes by exempting HIPAA-covered information and clinical trials, and by treating COPPA compliance as sufficient for children under 13.
The bill is presented in strongly protective terms, emphasizing children’s privacy, safety, and best interests over commercial interests. With no committee transcript or vote record available, there is no direct evidence of opposition or amendment debate in the provided materials. The available text suggests a generally favorable policy posture toward child online safety, with enforcement and compliance mechanisms intended to make the proposal workable for regulated entities.
Likely areas of disagreement include whether the bill’s definition of “likely to be accessed by a child” is too broad, whether mandatory data protection impact assessments create significant compliance burdens, and whether restrictions on profiling, geolocation, and data reuse could interfere with product design or personalization. Another likely point of contention is the Attorney General’s access to assessments and the extent to which trade secrets remain protected. Privacy and child-safety advocates would likely support the restrictions, while technology and business stakeholders may argue for narrower coverage, clearer standards, or more flexibility in implementation.