Pennsylvania Amends Data Protection Requirements with Revised Breach Notification Act

Sheppard Mullin Richter & Hampton LLP

On June 28, Pennsylvania took a significant step to enhance its data protection framework by updating the Breach of Personal Information Notification Act through the enactment of SB 824. This new legislation revises the older 2005 law and places a stronger emphasis on the security of digital data. It also introduces more stringent guidelines for notifying consumers and relevant authorities following a data breach.

Under the new law, if a data breach affects more than 500 Pennsylvania residents, entities are required to notify both the impacted individuals and the Pennsylvania Attorney General, as well as consumer reporting agencies, without unreasonable delay. The information provided to the Pennsylvania AG must include the organization’s name and location, the date on which the breach occurred, a brief summary of the incident, and an estimate of the number of affected individuals, both within the state and beyond.

Additionally, the Act mandates that entities bear the expenses related to providing affected individuals with free credit reporting and monitoring services for one year following the breach notification.

The legislation specifies that these obligations are triggered when an entity identifies a security breach and reasonably believes that personal information, such as a person’s name in conjunction with Social Security numbers, bank account numbers, or driver’s license/state ID numbers, have been accessed without authorization.

The law is slated to take effect in 90 days.

Putting It Into Practice: Pennsylvania’s updates to its Breach of Personal Information Notification Act reflect a broader trend among states and federal agencies to address the evolving challenges of data security (see our previous posts on data breach legislation here and here). Businesses subject to the law are now tasked with adapting to these changes swiftly to ensure compliance. In addition, companies facing a breach that spans multiple states must be mindful of how this law, its triggers, and its notification requirements compare to other jurisdictions. 

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Sheppard Mullin Richter & Hampton LLP | Attorney Advertising

Written by:

Sheppard Mullin Richter & Hampton LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Sheppard Mullin Richter & Hampton LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide