HB 997 Pennsylvania House · 2025-2026 Regular Session

An Act amending the act of December 22, 2005 (P.L.474, No.94), known as the Breach of Personal Information Notification Act, further providing for definitions, for notification of the breach of the security of the system, for exceptions and for notice exemption; repealing provisions relating to civil relief; providing for protection of personal information, for civil relief, for information security and for applicability; and repealing provisions relating to applicability.

HB 997 updates Pennsylvania's data breach notification law, requiring businesses to notify affected individuals more clearly and promptly after a security breach involving personal information. It directly affects businesses that collect or store personal data, such as healthcare providers, retailers, and financial institutions. Key changes include modernizing definitions of personal information, clarifying when notification is required, adding new security protections, and repealing outdated civil relief provisions. The bill also removes certain exemptions that previously allowed businesses to delay or avoid notifying individuals about breaches.
Bill status passed 3 of 5 stages cleared
Introduction
Mar 2025
Committee Review
Oct 2025
House Passage
Oct 2025
Senate Passage
Governor
Introduced Mar 24, 2025 Last action Oct 3, 2025
Maddy AI version diff · 2 comparisons

What changed between versions

Printer's No. PN1621 Printer's No. PN2381 · 8 edits
MODERATE
This bill update adds a new sponsor, Rivera, and changes the committee reporting status to reflect a second consideration amendment. It significantly weakens the security requirements for entities by allowing them to act in 'good faith' rather than mandating strict compliance, and it introduces a 'rebuttable presumption' that compliance with the act protects entities from civil liability claims.
Scope change
The bill's scope of applicability remains the same, but the enforcement mechanisms and liability standards have been altered to provide broader exemptions for entities.
ELIGIBILITY

Added sponsor Rivera to the list of bill sponsors.

TIMELINE

Updated the legislative history to indicate the bill was amended on second consideration on September 30, 2025.

REQUIREMENT

Changed the security requirement from a strict mandate to allow entities to act in 'good faith' to implement security measures.

Expanded the definition of 'Person' to include biometric data such as facial or video likeness.

Modified the breach notification rule to allow notification after 'determination' or 'notification' of the breach, rather than just discovery.

Added an option for financial institutions to be deemed compliant if they act in 'good faith' to follow federal regulator guidelines.

Changed the security mandate for personal information from 'implement and maintain' to 'implement and maintain or, in good faith, act to implement and maintain'.

ENFORCEMENT

Added a new provision creating a 'rebuttable presumption' that compliance with the act shields entities from civil liability.

Floor votes · House Sep 30, 2025

How they voted

2030
Passed
Total votes 203
Sep 30, 2025
D Democratic102
102 Yea
100% Yea
R Republican101
101 Yea
100% Yea
Vote distribution
All Yea All Nay Mixed No data
Full legislative history

Actions timeline

Total actions
11
Key actions
4
Committee
4
Amendments
1
Oct 3, 2025
Committee
Referred to Communications & Technology
upper
Oct 1, 2025
Lower · Passed
Third consideration and final passage
lower
Oct 1, 2025
Lower · Passed
Re-reported as committed
lower
Sep 30, 2025
House · Passed
House Vote: pass (203-0)
house
Sep 30, 2025
Committee
Re-committed to Appropriations
lower
May 6, 2025
Lower · Passed
Reported as amended
lower
Mar 24, 2025
Committee
Referred to Commerce
lower
1 primary · 24 co-sponsors

Sponsors