See other bills
under the
same topic
PRINTER'S NO. 382
THE GENERAL ASSEMBLY OF PENNSYLVANIA
HOUSE BILL
No.
414
Session of
2023
INTRODUCED BY GALLOWAY, SCHLOSSBERG, CIRESI, SANCHEZ, MADDEN,
BURGOS, NEILSON AND N. NELSON, MARCH 14, 2023
REFERRED TO COMMITTEE ON COMMERCE, MARCH 14, 2023
AN ACT
Amending the act of December 22, 2005 (P.L.474, No.94), entitled
"An act providing for the notification of residents whose
personal information data was or may have been disclosed due
to a security system breach; and imposing penalties," further
providing for definitions.
The General Assembly of the Commonwealth of Pennsylvania
hereby enacts as follows:
Section 1. The definition of "personal information" in
section 2 of the act of December 22, 2005 (P.L.474, No.94),
known as the Breach of Personal Information Notification Act,
amended November 3, 2022 (P.L.2139, No.151), is amended and the
section is amended by adding a definition to read:
Section 2. Definitions.
The following words and phrases when used in this act shall
have the meanings given to them in this section unless the
context clearly indicates otherwise:
* * *
"Digital wallet." An electronic payment system that allows
an individual to store funds and make electronic transactions.
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
* * *
"Personal information."
(1) An individual's first name or first initial and last
name in combination with and linked to any one or more of the
following data elements when the data elements are not
encrypted or redacted:
(i) Social Security number.
(ii) Driver's license number or a State
identification card number issued in lieu of a driver's
license.
(iii) Financial account number, credit or debit card
number, in combination with any required security code,
access code or password that would permit access to an
individual's financial account.
(iv) Medical information.
(v) Health insurance information.
(vi) A user name or e-mail address, in combination
with a password or security question and answer that
would permit access to an online account.
(vii) Digital wallet.
(2) The term does not include publicly available
information that is lawfully made available to the general
public from Federal, State or local government records or
widely distributed media.
* * *
Section 2. This act shall take effect in 60 days.
20230HB0414PN0382 - 2 -
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26