Law / United States / Pennsylvania

Pennsylvania

United States law applies in Pennsylvania Pennsylvania is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Pennsylvania, described on this page below, applies here too.
Pennsylvania has 1 local jurisdiction That local jurisdiction has law of its own, on a page of its own, listed below.

11 of 16 named instruments researched to a stage, across four of the six areas of law we track: 5 in force and 6 proposed. As of 15 September 2026.

When they take effect5 of 11 carry a date, 6 do not. Earlier is before 2014.
Before 2014: 2 instruments (2 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 2 instruments (2 in force) 2025: 1 instrument (1 in force) 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 5
  2. Privacy law 4
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law 1
  6. News aggregation law none researched

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law5 instruments, 3 in force, 2 proposed

Research summary (159 words)

Pennsylvania diverges from the federal AI-transparency baseline through two enacted criminal prohibitions rather than a disclosure regime. Act 125 of 2024 extended the state's child sexual abuse material statute and its unlawful dissemination of intimate image statute to reach artificially generated depictions, and Act 35 of 2025 created a new digital forgery offense reaching an AI-generated deepfake distributed to defraud or injure.

Two disclosure bills, an election deepfake labeling requirement (H.B. 811) and a companion chatbot disclosure and safety act, the SAFECHAT Act (S.B. 1090), have each passed one chamber and remain pending in the other as of the date shown.

Executive Order 2023-19 governs only the Commonwealth's own agencies' use of generative AI and binds no private party; Pennsylvania's general Unfair Trade Practices and Consumer Protection Law, 73 P.S. §§ 201-1 to 201-9.3, is not AI-specific, though its deceptive-practices prohibition would reach an undisclosed commercial chatbot the same way the FTC Act reaches one at the federal level.

AI prohibited practices

Act 125 of 2024, artificially generated child sexual abuse material

18 Pa.C.S. § 6312(c), (d)official text, Pennsylvania General Assembly consolidated statutes (palegis.us)

In force since 28 December 2024. Binds public and private bodies.

What this law does

Any person who knowingly sells, distributes, disseminates, displays, or possesses for such a purpose, any artificially generated child sexual abuse material commits an offense, as does any person who intentionally views or knowingly possesses or controls it.

Artificially generated child sexual abuse material is defined as material that appears to authentically depict a child under 18 engaging in a prohibited sexual act that did not occur in reality, whose production was substantially dependent on technical means including artificial intelligence.

An artificial intelligence developer, or its authorized employee or contractor, who reports such material to the National Center for Missing and Exploited Children as soon as reasonably possible upon obtaining actual knowledge of it, in compliance with 18 U.S.C. §§ 2258A and 2258B, is excepted from the offense. Act 125 of 2024 added this material category to a statute that previously reached only genuine child sexual abuse material, effective 60 days after its October 29, 2024 signature.

What it requires

Act 125 of 2024, artificially generated sexual depictions in the unlawful dissemination of intimate image offense

18 Pa.C.S. § 3131official text, Pennsylvania General Assembly consolidated statutes (palegis.us)

In force since 28 December 2024. Binds public and private bodies.

What this law does

A person commits the offense of unlawful dissemination of intimate image if, with intent to harass, annoy or alarm another, the person disseminates an artificially generated sexual depiction of an individual, defined as a visual depiction that appears to authentically depict the individual in a state of nudity or engaged in sexual conduct that did not occur in reality, and whose production was substantially dependent on technical means including artificial intelligence or photo editing software.

Consent of the person depicted is a defense. Act 125 of 2024 added this depiction category and the supporting artificial intelligence definitions to a statute that previously reached only genuine visual depictions, effective 60 days after its October 29, 2024 signature.

What it requires

Act 35 of 2025, digital forgery

18 Pa.C.S. § 4101.1official text, Pennsylvania General Assembly consolidated statutes (palegis.us)

In force since 5 September 2025. Binds public and private bodies.

What this law does

A person is guilty of digital forgery if, with intent to defraud or injure anyone, the person generates or creates and distributes a forged digital likeness as genuine, knowing or reasonably knowing it to be a forged digital likeness.

A forged digital likeness is a computer-generated visual representation or audio recording of an actual, identifiable individual that has been created or modified to closely resemble a genuine representation, materially misrepresents the individual's appearance, speech, or behavior, is likely to deceive a reasonable person into believing it is genuine, and is created and distributed without the individual's consent.

It is an affirmative defense that the actor took reasonable action to notify viewers or listeners that the forged digital likeness was not genuine, and the section does not reach a constitutionally protected activity, a law enforcement officer's official duties, a provider or developer of the underlying technology, or an information service or access software provider. Act 35 of 2025, signed July 7, 2025, added this section, effective 60 days after signature.

What it requires

AI transparency

H.B. 811, civil liability for fraudulent misrepresentation of candidates by deepfake

Pa. H.B. 811, 2025-2026 Regular Sessionofficial bill text, Pennsylvania General Assembly (palegis.us)

Proposed: draft date not recorded. Before the second chamber, dated 24 June 2025, as of 12 September 2026. Binds public and private bodies.

What this law does

This measure passed the Pennsylvania House 203-0 on June 23, 2025 and was referred to the Senate Communications and Technology Committee on June 24, 2025; it has not been reported from that committee as of the date shown.

As passed by the House, a covered person is liable for fraudulent misrepresentation of a candidate if, within 90 days before an election and with willful or reckless disregard for the possibility of influencing its outcome, the person knowingly and intentionally disseminates a campaign advertisement containing an artificially generated impersonation of a candidate (a deepfake) intended to misrepresent the candidate's words, actions, or beliefs.

A covered person is not liable if the advertisement carries a clear and conspicuous disclosure in a prescribed form, in a size or manner readable or audible to the viewer or listener, and content bearing the disclosure must also carry embedded, tamper-evident digital content provenance identifying its creator and any subsequent editor.

An aggrieved candidate may seek an order for immediate removal of the advertisement, and a court may impose a civil penalty per day of dissemination of up to $15,000 for a municipal candidate, $50,000 for a state candidate, or $250,000 for a candidate for President, Vice President, the U.S. Senate, or the U.S. House, doubled for a political action committee that only makes independent expenditures.

What it requires

S.B. 1090, SAFECHAT Act

Pa. S.B. 1090, 2025-2026 Regular Sessionofficial bill text, Pennsylvania General Assembly (palegis.us)

Proposed: draft date not recorded. Before the second chamber, dated 18 March 2026, as of 12 September 2026. Binds private bodies.

What this law does

This measure passed the Pennsylvania Senate 49-1 on March 17, 2026 and was referred to the House Communications and Technology Committee on March 18, 2026; it has not been reported from that committee as of the date shown.

As passed by the Senate, an operator of an AI companion platform must issue a clear and conspicuous notification that the AI companion is artificially generated and not human whenever a reasonable person interacting with it could be misled into believing otherwise; must maintain and publish a protocol, to the extent technologically feasible, to prevent the AI companion from producing suicidal ideation, suicide, or self-harm content, including a notification referring a user who expresses such content to a crisis line; and, for a user the operator knows or should have known is a minor, must give additional disclosures and safeguards.

The bill exempts an underlying AI model not directly offered as a companion, and several narrow categories including business-internal tools and video-game bots limited to game topics. The Attorney General has exclusive enforcement authority, with a civil penalty of up to $10,000 per violation; the bill states no private right of action. If enacted, it would take effect 120 days after signature.

What it requires

Privacy law4 instruments, 1 in force, 3 proposed

Research summary (230 words)

Pennsylvania has no enacted comprehensive personal-data statute.

House Bill 78, the Consumer Data Privacy Act, passed the House 127-76 on 1 October 2025 and remained at second consideration in the Senate as of 28 August 2026 after a Senate committee amendment (Printer's No. 3688); as currently amended it would classify biometric or genetic data processed to identify a person as sensitive data, would exclude a photograph, video, or audio recording, or any data generated from one, from the biometric data definition with no clawback for identification purpose, and would foreclose a private right of action twice over, by an express bar and by making its unfair-trade-practice deeming clause enforceable only by the Attorney General.

Pennsylvania's only enacted personal-data statute of general application is the Breach of Personal Information Notification Act, 73 P.S. secs. 2301 et seq. (Act of Dec. 22, 2005, P.L.474, No.94), which took effect 180 days after its December 22, 2005 enactment (June 20, 2006), was most recently amended June 28, 2024 to lower its consumer-reporting-agency notice threshold to 500 persons and to exclude publicly available government-records information, and does not reach biometric data at all.

That breach statute deems a notice violation an unfair trade practice under the Unfair Trade Practices and Consumer Protection Law but gives the Attorney General exclusive authority to sue on it, closing the indirect private-action route the deeming clause would otherwise open.

Breach notification

Breach of Personal Information Notification Act

73 P.S. secs. 2302, 2303, 2305, 2308 (Act 94 of 2005)official Pennsylvania session-law text of the Act of Dec. 22

In force since 20 June 2006. Binds public and private bodies.

What this law does

An entity that maintains, stores, or manages computerized data including personal information must provide notice of a breach of the security of the system, without unreasonable delay, to any Pennsylvania resident whose unencrypted and unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person.

Personal information is name plus a Social Security number, driver's license or state ID number, a financial account number with access credential, medical information held by a state agency or contractor, health insurance information, or a username or email with a password or security question, and excludes publicly available information lawfully available from government records or widely distributed media (added by the June 28, 2024 amendment); it does not reach biometric identifiers as such.

An entity that notifies more than 500 persons at one time (lowered from 1,000 by the 2024 amendment) must also notify nationwide consumer reporting agencies; a state agency's own breach separately requires Attorney General notice within seven business days, but no parallel duty requires a private entity's breach to notify the Attorney General directly.

A violation is deemed an unfair or deceptive practice under the Unfair Trade Practices and Consumer Protection Law, 73 P.S. secs. 201-1 to 201-9.3, but the Office of Attorney General has exclusive authority to bring that action, so the Act creates no private right of action even though its deeming clause would otherwise open a UDAP route the way Connecticut's breach statute does.

What it requires

Comprehensive regime

House Bill 78, Consumer Data Privacy Act, general applicability and controller and processor duties

Pa. H.B. 78, secs. 2, 5, 6, 7 (PN 3688)official Pennsylvania bill text, House Bill 78, Senate Printer's No. 3688, Pennsylvania General Assembly website

Proposed: draft date not recorded. Before the second chamber, dated 25 June 2026, as of 12 September 2026. Binds private bodies.

What this law does

House Bill 78, as amended by the Senate Communications and Technology Committee (Printer's No. 3688), would apply to a for-profit controller doing business in Pennsylvania that meets a revenue threshold of more than $10,000,000, or that alone or in combination buys, receives, sells, or shares for commercial purposes the personal information of at least 100,000 consumers, households, or devices (raised from 50,000 in the original bill), or that derives at least 50% of annual revenue from selling personal information.

Controllers must limit processing to purposes disclosed to the consumer and conduct data protection assessments for high-risk processing; processors act only on a controller's documented instructions. The bill establishes no lawful-basis regime distinct from this disclosed-purpose limitation; consent is required specifically for sensitive-data processing, not for processing generally.

This bill has not been enacted and binds nothing today; it passed the House 127-76 on 1 October 2025 and had second consideration in the Senate on 25 June 2026, with no Senate third-consideration vote or gubernatorial action as of 28 August 2026.

What it requires

Enforcement supervision

House Bill 78, Attorney General enforcement and private right of action

Pa. H.B. 78, sec. 10 (PN 3688)official Pennsylvania bill text, House Bill 78, Senate Printer's No. 3688, Pennsylvania General Assembly website

Proposed: draft date not recorded. Before the second chamber, dated 25 June 2026, as of 12 September 2026. Binds private bodies.

What this law does

As amended (PN 3688), HB 78 would give the Attorney General exclusive authority to enforce the Act and would foreclose a private right of action twice over: subsection (b), strengthened by the 24 June 2026 Senate amendment, provides that nothing in the Act creates, is used as the basis or predicate for, or otherwise gives rise to a private right of action; and subsection (c) deems a violation an unfair or deceptive practice under the Unfair Trade Practices and Consumer Protection Law but makes that deeming enforceable exclusively by the Attorney General, closing the UDAP route the deeming clause would otherwise open, the same double-foreclosure shape as the enacted breach statute below.

This bill has not been enacted and binds nothing today.

What it requires

Sensitive categories

House Bill 78, sensitive data and biometric data definitions

Pa. H.B. 78, sec. 2 (PN 3688)official Pennsylvania bill text, House Bill 78, Senate Printer's No. 3688, Pennsylvania General Assembly website

Proposed: draft date not recorded. Before the second chamber, dated 25 June 2026, as of 12 September 2026. Binds private bodies.

What this law does

As amended (PN 3688), HB 78 would define biometric data as data generated by automatic measurements of an individual's biological characteristics, including fingerprints, voiceprints, eye retinas, irises, or other unique biological patterns or characteristics used to identify a specific individual, but the definition excludes a digital or physical photograph, an audio or video recording, or any data generated from either, with no exception for data generated to identify a specific person, unconditionally, unlike Kentucky's, Maryland's, Minnesota's, or New Jersey's clawback-shaped equivalents.

A separate clause also excludes an irreversible mathematical representation (a template or hash that cannot be used to recreate the underlying capture), and 'personal data' itself separately excludes biometric data converted to such a representation.

Sensitive data, requiring opt-in consent, includes the processing of genetic or biometric data to uniquely identify an individual, alongside race or ethnicity, religion, health, sexuality, citizenship or immigration status, child data, precise geolocation, and, added by the 24 June 2026 amendment, Social Security number, driver's license number, and financial account number with access credentials. This bill has not been enacted and binds nothing today.

Pennsylvania has no enacted, freestanding biometric-privacy statute; a 2023-2024 session bill of that kind, HB 926, never advanced past introduction and has no confirmed 2025-2026 successor.

What it requires

Scraping law1 instrument, 1 in force

Research summary (180 words)

Pennsylvania's computer crime statute, 18 Pa.C.S. Chapter 76 Subchapter B, tracks the federal Computer Fraud and Abuse Act's bare without-authorization test rather than narrowing it the way a neighboring state's malicious-intent-or-deceptive-means standard does: intentionally accessing or exceeding authorization to access a computer, computer network, or World Wide Web site without authorization is itself an offense, with no separate showing of malice or deception required.

The statute's own defense provision reads authorization to include express or implied consent, including by trade usage, course of dealing, course of performance, or commercial programming practices, and its construction clause expressly preserves ordinary contract and license terms as a separate track, so terms-of-service enforcement in Pennsylvania rests on ordinary Pennsylvania contract law; no reported Pennsylvania case addresses browsewrap or clickwrap enforceability for a scraping dispute specifically.

Copyright, text-and-data-mining, and database rights are federal only; Pennsylvania adds nothing there. robots.txt carries no independent legal weight under Pennsylvania statute. Comprehensive protection of personal data, including any duty attaching to scraped public personal information, is covered by the privacy topic for this jurisdiction and is not restated here.

Computer misuse

Unlawful use of computer and other computer crimes (hacking and similar offenses)

18 Pa.C.S. §§ 7611-7616official text, Pennsylvania General Assembly consolidated statutes (palegis.us)

In force since 14 February 2003. Binds public and private bodies.

What this law does

A person commits unlawful use of a computer if, intentionally and without authorization, the person accesses or exceeds authorization to access, alters, interferes with the operation of, damages, or destroys a computer, computer system, computer network, computer software, computer database, or World Wide Web site (18 Pa.C.S. § 7611(a)(2)); bare unauthorized access to such a resource is itself the offense, with no separate showing of malice, deception, or resulting harm required.

Neighboring sections separately criminalize disruption of service including denial-of-service attacks (§ 7612), computer theft of data taken with intent to deprive the owner of it (§ 7613), unlawful duplication of computer data or software (§ 7614), computer trespass carried out with intent to remove or alter data, cause a malfunction, or effect an unauthorized funds transfer (§ 7615), and distribution of a computer virus (§ 7616).

Section 7605 provides a defense where the actor reasonably believed the owner had authorized or would have authorized the conduct, and defines authorization to include express or implied consent, including by trade usage, course of dealing, course of performance, or commercial programming practices.

Section 7606 states that nothing in this subchapter interferes with or prohibits the terms or conditions of a contract or license governing a computer, computer network, or database, preserving ordinary contract-based terms-of-service enforcement as a separate track from this statute. The chapter was added December 16, 2002, effective 60 days later.

What it requires

Age gating law1 instrument, 1 proposed

Research summary (178 words)

Pennsylvania has not enacted an age gating law in any of the four tracked families and has no comprehensive consumer privacy law of its own yet. Bipartisan bills requiring age verification for pornography websites (HB 1513 and SB 603) and a bill requiring parental consent verification for minors on social media (HB 1430) were introduced in 2025 and remain in committee without passing either chamber. Pennsylvania has no app store age verification bill of note.

Its most advanced privacy related bill is the Consumer Data Privacy Act (HB 78), which would require opt in consent before processing a known child's data under 13 or a known minor's data under 16 for targeted advertising, sale, or profiling.

It passed the House 127 to 76 on October 1, 2025, was reported out of the Senate Consumer Protection and Professional Licensure Committee on February 4, 2026 and re-referred to the Senate Communications and Technology Committee, which re-reported it as amended on June 24, 2026; it received second consideration on the Senate floor on June 25, 2026 and awaits final Senate passage.

Age-appropriate design code

HB 78, Pennsylvania Consumer Data Privacy Act

Pennsylvania House Bill No. 78 (2025-2026 Reg. Sess.), pendingofficial Pennsylvania General Assembly bill information page

Proposed: draft date not recorded. Before the second chamber, dated 25 June 2026, as of 12 September 2026. Binds private bodies.

What this law does

Would require a controller to obtain opt in consent before processing the personal data of a known child under 13, and before processing a known minor's data under 16 for targeted advertising, sale, or profiling producing legal or similarly significant effects.

Passed the House 127 to 76 on October 1, 2025, was reported by the Senate Consumer Protection and Professional Licensure Committee on February 4, 2026 and re-referred to the Senate Communications and Technology Committee, which re-reported it as amended on June 24, 2026; it received second consideration on June 25, 2026 but has not passed the full Senate.

Note and primary source

Law in local jurisdictions1 with a page

Each has a page of its own; the number is how many of its instruments are researched to a stage.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.