Providing for consumer data privacy, for duties of controllers and for duties of processors; and imposing penalties.
SB 112 would create the Pennsylvania Consumer Data Privacy Act, establishing a comprehensive state privacy framework for businesses that collect and process personal data of Pennsylvania residents. The bill gives consumers rights to confirm whether their data is being processed, correct inaccuracies, delete data, obtain a portable copy of their data, and opt out of targeted advertising, the sale of personal data, and certain profiling that leads to significant decisions. It also requires controllers to provide clear privacy notices, honor opt-out mechanisms, and allow consumers to use authorized agents or, for children and protected adults, parents or guardians to exercise rights on their behalf.
The bill imposes duties on businesses acting as controllers and processors, including data minimization, security safeguards, limits on processing sensitive data, consent requirements for certain uses, and restrictions on discriminatory treatment of consumers who exercise privacy rights. It also requires data protection assessments for high-risk processing, sets rules for de-identified and pseudonymous data, and creates contractual and oversight obligations for processors and subcontractors. Enforcement would be handled exclusively by the Pennsylvania Attorney General, with a temporary right-to-cure period for violations and no private right of action.
SB 112 would add a new chapter of consumer privacy obligations to Pennsylvania law and would likely affect a broad range of for-profit businesses that meet the bill’s revenue or data-processing thresholds and do business in the Commonwealth. It would not apply to several categories already regulated elsewhere, including the Commonwealth and its subdivisions, nonprofits, higher education institutions, financial institutions subject to GLBA, HIPAA covered entities and business associates, and numerous health, research, credit-reporting, motor vehicle, education, and airline-related data categories. The bill would also require the Attorney General to promulgate implementing regulations and would make violations unfair or deceptive acts or practices enforceable under the Unfair Trade Practices and Consumer Protection Law.
No committee transcripts or recorded votes were provided, so there is no direct evidence of debate, amendments, or formal support/opposition in the available record. Based on the bill text alone, the measure appears to reflect a pro-consumer privacy approach similar to other state data privacy laws, with a structured compliance regime rather than a punitive enforcement model. The inclusion of a cure period, broad exemptions, and no private right of action suggests an effort to balance consumer protections with business compliance concerns.
The main likely points of contention are the scope of covered businesses, the breadth of exemptions, and the operational burden of compliance. Businesses may object to the thresholds, the requirement to honor opt-out preference signals, the need for data protection assessments, and the restrictions on targeted advertising, sale of data, and profiling. Consumer advocates may focus on whether the exemptions for nonprofits, higher education, financial institutions, health data, research, and certain employment-related data are too broad, and whether the absence of a private right of action weakens enforcement. The bill also leaves significant implementation details to the Attorney General, which may be another area of concern for regulated entities.