On June 28, Pennsylvania took a significant step to enhance its data protection framework by updating the Breach of Personal Information Notification Act through the enactment of SB 824. This new legislation revises the older 2005 law and places a stronger emphasis on the security of digital data. It also introduces more stringent guidelines for notifying consumers and relevant authorities following a data breach.
Under the new law, if a data breach affects more than 500 Pennsylvania residents, entities are required to notify both the impacted individuals and the Pennsylvania Attorney General, as well as consumer reporting agencies, without unreasonable delay. The information provided to the Pennsylvania AG must include the organization’s name and location, the date on which the breach occurred, a brief summary of the incident, and an estimate of the number of affected individuals, both within the state and beyond.
Additionally, the Act mandates that entities bear the expenses related to providing affected individuals with free credit reporting and monitoring services for one year following the breach notification.
The legislation specifies that these obligations are triggered when an entity identifies a security breach and reasonably believes that personal information, such as a person’s name in conjunction with Social Security numbers, bank account numbers, or driver’s license/state ID numbers, have been accessed without authorization.
The law is slated to take effect in 90 days.
Putting It Into Practice: Pennsylvania’s updates to its Breach of Personal Information Notification Act reflect a broader trend among states and federal agencies to address the evolving challenges of data security (see our previous posts on data breach legislation here and here). Businesses subject to the law are now tasked with adapting to these changes swiftly to ensure compliance. In addition, companies facing a breach that spans multiple states must be mindful of how this law, its triggers, and its notification requirements compare to other jurisdictions.