Pennsylvania Amends Data Protection Requirements With Revised Breach Notification Act

SM
Sheppard Mullin Richter & Hampton

Contributor

Sheppard Mullin is a full service Global 100 firm with over 1,000 attorneys in 16 offices located in the United States, Europe and Asia. Since 1927, companies have turned to Sheppard Mullin to handle corporate and technology matters, high stakes litigation and complex financial transactions. In the US, the firm’s clients include more than half of the Fortune 100.
On June 28, Pennsylvania took a significant step to enhance its data protection framework by updating the Breach of Personal Information Notification Act through the enactment of SB 824.
United States Technology
To print this article, all you need is to be registered or login on Mondaq.com.

Listen to this post

On June 28, Pennsylvania took a significant step to enhance its data protection framework by updating the Breach of Personal Information Notification Act through the enactment of SB 824. This new legislation revises the older 2005 law and places a stronger emphasis on the security of digital data. It also introduces more stringent guidelines for notifying consumers and relevant authorities following a data breach.

Under the new law, if a data breach affects more than 500 Pennsylvania residents, entities are required to notify both the impacted individuals and the Pennsylvania Attorney General, as well as consumer reporting agencies, without unreasonable delay. The information provided to the Pennsylvania AG must include the organization's name and location, the date on which the breach occurred, a brief summary of the incident, and an estimate of the number of affected individuals, both within the state and beyond.

Additionally, the Act mandates that entities bear the expenses related to providing affected individuals with free credit reporting and monitoring services for one year following the breach notification.

The legislation specifies that these obligations are triggered when an entity identifies a security breach and reasonably believes that personal information, such as a person's name in conjunction with Social Security numbers, bank account numbers, or driver's license/state ID numbers, have been accessed without authorization.

The law is slated to take effect in 90 days.

Putting It Into Practice: Pennsylvania's updates to its Breach of Personal Information Notification Act reflect a broader trend among states and federal agencies to address the evolving challenges of data security (see our previous posts on data breach legislation here and here). Businesses subject to the law are now tasked with adapting to these changes swiftly to ensure compliance. In addition, companies facing a breach that spans multiple states must be mindful of how this law, its triggers, and its notification requirements compare to other jurisdictions.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More