Law / United States / Pennsylvania

House Bill 78, Consumer Data Privacy Act, general applicability and controller and processor duties

Pa. H.B. 78, secs. 2, 5, 6, 7 (PN 3688)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

Proposed: draft date not recorded.

Before the second chamber, dated 25 June 2026, as of 12 September 2026.

A comprehensive regime rule binding private bodies.

As of 28 August 2026.

Where it has got to

The text described here is Printer's Number 3688, as amended by the Senate Communications and Technology Committee. That print is PN 3688, published 24 June 2026.

Locally, this stage is second consideration in the Senate.

The stage above is recorded at www.palegis.us.

More on this stage

House passed HB 78 (PN 1476) 127-76 on 2025-10-01. Senate Consumer Protection and Professional Licensure Committee reported it as committed 14-0 on 2026-02-04 and re-referred it to Communications and Technology same day; that committee re-reported it as amended (PN 3688) 11-0 on 2026-06-24. Senate gave it first consideration 2026-06-24 and second consideration 2026-06-25; no action recorded since. The 2025-2026 session runs through 2026-11-30.

What it requires

  • This bill has not been enacted. It passed the House on 2025-10-01 and remained at second consideration in the Senate as of 2026-08-28; do not treat it as binding.
  • Watch for further Senate action. If enacted as currently amended, it would apply to a for-profit business meeting a revenue or data-volume threshold and would require data protection assessments before high-risk processing.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

House Bill 78, as amended by the Senate Communications and Technology Committee (Printer's No. 3688), would apply to a for-profit controller doing business in Pennsylvania that meets a revenue threshold of more than $10,000,000, or that alone or in combination buys, receives, sells, or shares for commercial purposes the personal information of at least 100,000 consumers, households, or devices (raised from 50,000 in the original bill), or that derives at least 50% of annual revenue from selling personal information.

Controllers must limit processing to purposes disclosed to the consumer and conduct data protection assessments for high-risk processing; processors act only on a controller's documented instructions. The bill establishes no lawful-basis regime distinct from this disclosed-purpose limitation; consent is required specifically for sensitive-data processing, not for processing generally.

This bill has not been enacted and binds nothing today; it passed the House 127-76 on 1 October 2025 and had second consideration in the Senate on 25 June 2026, with no Senate third-consideration vote or gubernatorial action as of 28 August 2026.

When LexLint raises it

  • automated_outreach
  • crawls_web
  • deploys_chatbot
  • processes_biometrics
  • processes_voice
  • trains_models

Read the law

official Pennsylvania bill text, House Bill 78, Senate Printer's No. 3688, Pennsylvania General Assembly website

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app