Law / United States / Pennsylvania

Consumer Protection Against Computer Spyware Act

73 P.S. §§ 2330.1-2330.9 (Act 86 of 2010)

In force since .

A device storage and tracking consent rule binding public and private bodies.

Obligation class
Prohibition, Consent

As of .

What it requires

  • If you are not an authorized user of a computer (its owner, or a person its owner or lessee has authorized to use it), do not cause software to be copied onto the computer of an authorized user in Pennsylvania, or procure its copying, and use the software to do any of the acts listed below; sections 3 and 4 apply where you act with actual knowledge, with conscious avoidance of actual knowledge or willfully.
  • Do not use deceptive means to modify the page a browser opens on launch, the default provider or proxy used to access or search the Internet, or the user's list of bookmarks; deception includes an intentionally and materially false or fraudulent statement, an intentional omission or misrepresentation of material information in order to deceive the user, and an intentional and material failure to give the user any notice of the download or installation of software in order to deceive.
  • Do not use deceptive means to collect personally identifiable information gathered by a keystroke-logging function that records all of a user's keystrokes and transfers them to another person, or that includes all or substantially all of the websites the user visits (other than the software provider's own) where the software was installed in a manner designed to conceal the installation from every authorized user, or by extracting from the hard drive, for a purpose wholly unrelated to any purpose of the software or service you described to the user, a credit or debit card or other financial account number, a password or PIN for a financial account, a Social Security number, or account balances or overdraft history in a form that personally identifies the user.
  • Without the user's authorization and through deceptive means, do not prevent the user's reasonable efforts to block or disable software by causing software the user has properly removed or disabled to reinstall or reactivate itself; do not misrepresent, knowing it to be untrue, that software will be uninstalled or disabled by the user's action; and do not use deceptive means to remove, disable or render inoperative security, antispyware or antivirus software installed on the computer.
  • Do not use the software to take control of the computer by transmitting or relaying commercial electronic mail or a computer virus that a person other than the user initiated, without the user's authorization; by using the user's modem or Internet service for the purpose of damaging the computer or making the user incur charges for a service the user did not authorize; by using the computer as part of a group of computers for the purpose of damaging another computer, including a denial of service attack; or by opening a series of stand-alone messages without the user's authorization, knowing a reasonable user cannot close them without turning off the computer or closing the Internet application.
  • Do not modify a user's security or other settings that protect information about the user for the purpose of stealing personal information, or the computer's security settings for the purpose of damaging one or more computers.
  • Without the user's authorization, do not prevent the user's reasonable efforts to block the installation of software or to disable it by presenting an option to decline installation when you know the installation will nevertheless proceed, by falsely representing that software has been disabled, by requiring the user in a deceptive manner to access the Internet to remove the software when you know or recklessly disregard that it frequently operates in a manner that prevents the user from accessing the Internet, by changing the software's name, location or other designation information, using randomized or deceptive file names, directory folders, formats or registry entries, or placing it in a particular directory or memory, in each case for the purpose of preventing the user from locating it, avoiding detection and removal, or evading the user's attempts to remove it, or by requiring, without the authority of the computer's owner, that the user obtain a special code or download software from a third party to uninstall it.
  • Do not induce a user to install a software component by misrepresenting that installing software is necessary for security or privacy reasons or in order to open, view or play a particular type of content, and do not cause a software component to be copied onto and executed on the computer with the intent that the user use it in a way that violates section 5.
  • These duties leave out the following: section 6 lifts sections 4 and 5, but not section 3, for a cable operator, computer hardware or software provider, or provider of information service or interactive computer service monitoring or interacting with a user's connection or computer for network or computer security, diagnostics, technical support, repair, authorized software or firmware updates, network management or maintenance, authorized remote system management, or detecting or preventing unauthorized use or fraud; a text or data file, an Internet website, or a website data component not executable independently of the website is not computer software; and transmission, routing, caching, a hosting medium through which a third party distributed the software, or an information location tool through which the user located it is not causing software to be copied.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

A person that violates sections 3(2) and 4(1)(i), (ii) and (iii) and (2) commits a felony of the second degree and is sentenced on conviction to imprisonment for not more than ten years or to pay a fine of not more than $25,000, or both.

Penalty structure

The $25,000 figure is the criminal fine section 8 sets, alone or together with imprisonment of not more than ten years, for a violation of sections 3(2) and 4(1)(i), (ii) and (iii) and (2); it is not a civil penalty.

Rule
Fixed only
As of
Currency
USD
Fixed cap
25,000

Statutory damages

Available to the persons section 9 names: a provider of computer software, an Internet Service Provider or a trademark owner adversely affected by the violation, and, for a violation of section 4(1)(ii), a communications provider under section 9(e). Damages equal the greater of actual damages or up to $100,000 for each violation as the court considers just, so $100,000 is a ceiling on the per-violation award rather than a set sum; the court may increase actual damages to not more than three times where violations occur with a frequency, across a group of victims, that constitutes a pattern or practice; a prevailing plaintiff recovers reasonable attorney fees and court costs; and one act violating more than one paragraph counts as multiple violations, by the number of paragraphs violated.

As of
Currency
USD

Who enforces it

Enforcement body

Criminal proceedings brought by the district attorneys of the counties and by the Attorney General under section 7; a civil action limited to a provider of computer software, an Internet Service Provider or a trademark owner adversely affected by a violation, and to a communications provider for a violation of section 4(1)(ii), under section 9.

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Section 3 of the Consumer Protection Against Computer Spyware Act bars a person or entity that is not an authorized user, acting with actual knowledge, with conscious avoidance of actual knowledge or willfully, from causing computer software to be copied onto the computer of an authorized user in Pennsylvania, or procuring the copying, and using the software to do any of the acts it lists or any other acts deemed to be deceptive.

An authorized user is, with respect to a computer, a person who owns it or is authorized by the owner or lessee to use it. The Act was approved on and took effect 60 days later.

Computer software is a sequence of instructions written in any programming language that is executed on a computer, and the term does not include a text or data file, an Internet website or a data component of an Internet website that is not executable independently of the Internet website.

To cause software to be copied is to distribute, transfer or procure the copying of computer software or any component of it, and the term does not include transmission, routing, or the provision of intermediate temporary storage or caching of software, a storage or hosting medium through which a third party distributed the software, or an information location tool through which the user of the computer located the software.

Deception includes an intentionally and materially false or fraudulent statement, a statement or description that intentionally omits or misrepresents material information in order to deceive the authorized user, and an intentional and material failure to provide any notice to an authorized user regarding the download or installation of software in order to deceive the authorized user.

The section 3 acts include modifying through deceptive means the page that appears when a browser launches, the default provider or proxy used to access or search the Internet, or the authorized user's list of bookmarks.

They also include collecting through deceptive means personally identifiable information by a keystroke-logging function that records all keystrokes made by an authorized user and transfers them to another person, or that includes all or substantially all of the websites the user visits other than the software provider's own where the software was installed in a manner designed to conceal the installation from all authorized users.

Section 4 applies to the same class of person on the same knowledge standard and lists acts by which the software takes control of the authorized user's computer.

Section 5 bars a person or entity that is not an authorized user from inducing an authorized user to install a software component by misrepresenting that installing software is necessary for security or privacy reasons or in order to open, view or play a particular type of content, and from causing the copying and execution of a software component with the intent of causing an authorized user to use it in a way that violates that section.

Section 6 provides that nothing in section 4 or 5 applies to monitoring of or interaction with a user's Internet or other network connection or service, or a protected computer, by a cable operator, computer hardware or software provider or provider of information service or interactive computer service for network or computer security purposes, diagnostics, technical support, repair, authorized updates of software or system firmware, network management or maintenance, authorized remote system management, or detection or prevention of the unauthorized use of or fraudulent or other illegal activities in connection with a network, service or computer software, including scanning for and removing software the Act proscribes.

The district attorneys of the counties and the Attorney General each have authority to investigate and institute criminal proceedings for any violation of the Act. A person that violates sections 3(2) and 4(1)(i), (ii) and (iii) and (2) commits a felony of the second degree and is sentenced on conviction to imprisonment for not more than ten years or to pay a fine of not more than $25,000, or both.

The Act lets a provider of computer software adversely affected by a violation, an Internet Service Provider adversely affected by a violation, and a trademark owner whose trademark is used without authorization to deceive users in the course of the deceptive practices the Act prohibits bring a civil action against a person who violates it.

A permitted plaintiff may seek an injunction and damages equal to the greater of actual damages or up to $100,000 for each violation, as the court considers just.

When LexLint raises it

When your app profile says your app tracks devices or distributes a software product.

Back to the example  ·  Lint your app