An Act amending the act of December 22, 2005 (P.L.474, No.94), known as the Breach of Personal Information Notification Act, further providing for definitions, for notification of the breach of the security of the system, for exceptions and for notice exemption; repealing provisions relating to civil relief; providing for protection of personal information, for civil relief, for information security and for applicability; and repealing provisions relating to applicability.
What changed between versions
Added sponsor Rivera to the list of bill sponsors.
Updated the legislative history to indicate the bill was amended on second consideration on September 30, 2025.
Changed the security requirement from a strict mandate to allow entities to act in 'good faith' to implement security measures.
Expanded the definition of 'Person' to include biometric data such as facial or video likeness.
Modified the breach notification rule to allow notification after 'determination' or 'notification' of the breach, rather than just discovery.
Added an option for financial institutions to be deemed compliant if they act in 'good faith' to follow federal regulator guidelines.
Changed the security mandate for personal information from 'implement and maintain' to 'implement and maintain or, in good faith, act to implement and maintain'.
Added a new provision creating a 'rebuttable presumption' that compliance with the act shields entities from civil liability.