Preparing for Pennsylvania's Consumer Privacy Legislation
House Bill 1049, modeled after the CCPA, addresses consumer data privacy by setting forth the rights of consumers as well as the duties of companies relating to the collection of consumer personal information.
August 23, 2019 at 12:55 PM
7 minute read
In the wake of several massive data breaches, consumer privacy (or lack thereof) has become a growing concern. For some, more surprising than the breaches was learning how much personal information companies collect from consumers—everything from Social Security numbers and email addresses to location data and demographics—and how much personal information is being sold or otherwise disseminated. As a result, legislation is being enacted around the world requiring companies to inform consumers about the collection and use of their personal information. Most notably in 2018, the European Union's General Data Protection Regulation, commonly referred to as the GDPR, established groundbreaking consumer rights over the collection, retention and dissemination of personal information. In the United States, in the absence of federal consumer privacy law, states are enacting privacy legislation focusing upon: requiring transparency around the consumer personal information that companies are collecting and using; and providing consumers with control over the personal information. For example, California enacted the California Consumer Privacy Act (CCPA), which takes effect on Jan. 1, 2020.
Now, Pennsylvania is following suit. On April 5, Pennsylvania introduced House Bill 1049, which is currently pending before the Committee on Consumer Affairs. House Bill 1049, modeled after the CCPA, addresses consumer data privacy by setting forth the rights of consumers as well as the duties of companies relating to the collection of consumer personal information. Therefore, companies doing business in Pennsylvania should familiarize themselves with its key provisions and prepare for its enactment.
Important Provisions
Even though House Bill 1049 is in committee and will likely be amended prior to its enactment, the are several provisions of the current bill that are the cornerstones of recent consumer privacy legislation and are likely to remain in the final bill. These are:
- Narrow definition of "businesses" subject to compliance—House Bill 1049 applies to companies doing business in Pennsylvania satisfying one or more of the following requirements: companies with an annual gross revenue exceeding $10 million; companies that annually buy, receive, sell or share for commercial purposes the personal information of 50,000 or more consumers; or companies that derive 50% or more of their annual revenue from selling consumers' personal information.
- Comprehensive definition of "personal information"—Most of the information that consumers regularly give to companies in the regular course of business is deemed "personal information," such as:
- Identifiers like names, aliases, postal addresses, email addresses, account names, Social Security numbers, etc.;
- Protected characteristics under federal or state law;
- Commercial information like records of personal property or products or services purchased, obtained or considered;
- Biometric information;
- Internet or other electronics network activity like browser and search history;
- Geolocation data;
- Audio, electronic, visual, thermal, olfactory or similar information;
- Professional or employment-related information;
- Education information; and
- Inferences drawn from any of the information above to create a consumer profile reflecting a consumer's preferences, characteristics, psychological trends, predispositions, behaviors, attitudes, intelligence, and abilities and aptitudes.
House Bill 1049 explicitly excludes information that is publicly available, even if it fits into any of the above categories of protected personal information.
- Empowering consumer rights—Consistent with other consumer privacy legislation, House Bill 1049 provides consumer control over personal data. Such provisions will require companies to review policies and internal controls to determine whether current data collection and retention practices comply. These include:
- Notice and access—Consumers will have the right to know and access what personal information a company collects and whether that company sells or discloses personal information to another party. Companies must give consumers at least two methods of submitting requests for information, and the requested information must be provided to consumers within 45 days of receiving a request.
- Deletion—Consumers will have the right to request that a company delete personal information from their system entirely. A deletion request does not apply solely to the company that initially collected the information—if a consumer's personal information was sold or disseminated to another party, companies must direct that party to delete the information as well. Thus, companies must keep track of how it sells and disseminates personal information. Companies that receive deletion requests may retain the data under prescribed circumstances, such as to complete a transaction, detect security incidents, debug to repair errors, exercise free speech, engage in public of peer-reviewed research, comply with legal obligations, and enable solely internal uses that are reasonably aligned with the expectations of the consumer.
- Opt-out—Consumers will have the right to decline or opt-out of the sale of their personal information. Companies must provide notice of the possibility of sale before collecting consumer personal information. Additionally, companies must publicly offer a "Do Not Sell My Personal Information" form, which, if submitted, prohibits a company from selling the consumer's personal information. Once a consumer opts-out, a company must give the consumer at least 12 months before requesting that the consumer agree to a sale of his or her personal data.
- Private right of action—Consumers have the right to individually sue a company in the event their nonencrypted or nonredacted personal information is subject to a breach. Damages are capped at $100-$750 per consumer per incident or actual damages, whichever is greater. Additionally, injunctive or declaratory relief, and any other relief a court deems appropriate, is available. Companies must be given an opportunity to cure the violation within 30 days of receiving written notice before a consumer can sue.
- Protection for minors—Under House Bill 1049, companies cannot sell personal information of consumers under age 16 without affirmative authorization by a minor aged 13 to 16 or a parent for children under 13.
- Anti-discrimination provision—Companies cannot discriminate against consumers for exercising rights enumerated under House Bill 1049. Yet companies can offer a different price for goods or services based upon the value derived from a consumer's data.
- Civil penalties—If a company violates any provision under House Bill 1049, the attorney general can bring a civil action against the company, with potential liability capped at $7,500 per violation. Prior to initiating an action, however, companies must be given an opportunity to cure the violation within 30 days of notification.
The Takeaway
Data privacy legislation is coming to Pennsylvania. Companies doing business in Pennsylvania must begin to examine critically their data collection, retention and dissemination practices to ensure compliance. Companies should analyze: what personal information they collect; how the personal information is being collected; why the personal information is being collected; how are they using the personal information; how the personal information is protected; and who has access to the personal information. Companies should also examine what personal information is being sold or disseminated to third parties and whether the third parties have systems in place for privacy compliance. Additionally, companies should develop policies and procedures that comply with the law, and should ensure that all employees are trained properly regarding the privacy obligations.
Christopher A. Iacono is a partner in the government enforcement, compliance and white-collar litigation; health care; and litigation practice groups of Pietragallo Gordon Alfano Bosick & Raspanti. Iacono focuses his practice on commercial litigation, white-collar criminal defense, internal investigations, compliance, health care litigation and professional licensing litigation.
Gabrielle I. Weiss is an associate at the firm. She is a member of the employment and labor group where she focuses on a variety of issues including defending discrimination claims and conducting internal investigations. Weiss also works on white collar and general litigation matters.
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2025 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllSmaller Firms in 'Growth Mode' as Competition, Rates Heat Up
Trending Stories
- 1Is It Time for Large UK Law Firms to Begin Taking Private Equity Investment?
- 2Federal Judge Pauses Trump Funding Freeze as Democratic AGs Launch Defensive Measure
- 3Class Action Litigator Tapped to Lead Shook, Hardy & Bacon's Houston Office
- 4Arizona Supreme Court Presses Pause on KPMG's Bid to Deliver Legal Services
- 5Bill Would Consolidate Antitrust Enforcement Under DOJ
Who Got The Work
J. Brugh Lower of Gibbons has entered an appearance for industrial equipment supplier Devco Corporation in a pending trademark infringement lawsuit. The suit, accusing the defendant of selling knock-off Graco products, was filed Dec. 18 in New Jersey District Court by Rivkin Radler on behalf of Graco Inc. and Graco Minnesota. The case, assigned to U.S. District Judge Zahid N. Quraishi, is 3:24-cv-11294, Graco Inc. et al v. Devco Corporation.
Who Got The Work
Rebecca Maller-Stein and Kent A. Yalowitz of Arnold & Porter Kaye Scholer have entered their appearances for Hanaco Venture Capital and its executives, Lior Prosor and David Frankel, in a pending securities lawsuit. The action, filed on Dec. 24 in New York Southern District Court by Zell, Aron & Co. on behalf of Goldeneye Advisors, accuses the defendants of negligently and fraudulently managing the plaintiff's $1 million investment. The case, assigned to U.S. District Judge Vernon S. Broderick, is 1:24-cv-09918, Goldeneye Advisors, LLC v. Hanaco Venture Capital, Ltd. et al.
Who Got The Work
Attorneys from A&O Shearman has stepped in as defense counsel for Toronto-Dominion Bank and other defendants in a pending securities class action. The suit, filed Dec. 11 in New York Southern District Court by Bleichmar Fonti & Auld, accuses the defendants of concealing the bank's 'pervasive' deficiencies in regards to its compliance with the Bank Secrecy Act and the quality of its anti-money laundering controls. The case, assigned to U.S. District Judge Arun Subramanian, is 1:24-cv-09445, Gonzalez v. The Toronto-Dominion Bank et al.
Who Got The Work
Crown Castle International, a Pennsylvania company providing shared communications infrastructure, has turned to Luke D. Wolf of Gordon Rees Scully Mansukhani to fend off a pending breach-of-contract lawsuit. The court action, filed Nov. 25 in Michigan Eastern District Court by Hooper Hathaway PC on behalf of The Town Residences LLC, accuses Crown Castle of failing to transfer approximately $30,000 in utility payments from T-Mobile in breach of a roof-top lease and assignment agreement. The case, assigned to U.S. District Judge Susan K. Declercq, is 2:24-cv-13131, The Town Residences LLC v. T-Mobile US, Inc. et al.
Who Got The Work
Wilfred P. Coronato and Daniel M. Schwartz of McCarter & English have stepped in as defense counsel to Electrolux Home Products Inc. in a pending product liability lawsuit. The court action, filed Nov. 26 in New York Eastern District Court by Poulos Lopiccolo PC and Nagel Rice LLP on behalf of David Stern, alleges that the defendant's refrigerators’ drawers and shelving repeatedly break and fall apart within months after purchase. The case, assigned to U.S. District Judge Joan M. Azrack, is 2:24-cv-08204, Stern v. Electrolux Home Products, Inc.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250