Pennsylvania, United StatesCleared Senate Education Committee (Mar 23, 2026); pending full Senate

Pennsylvania Student Data Privacy Act (PA SB 378)

Establishes rules for how Pennsylvania public schools and their third-party vendors collect, store, and share student data. Increases transparency for parents, creates accountability mechanisms for vendors, and requires verifiable parental consent for specified data-collection activities involving minors.

Key Provisions

What PA SB 378 requires

01

Requires schools and ed-tech vendors to disclose student data collection, storage, and sharing practices

02

Creates parental transparency obligations — parents must be able to review what data is collected on their child

03

Requires verifiable parental consent for specified data-collection activities

04

Holds third-party vendors accountable for student data handling

05

Restricts targeted advertising directed at students using school-collected data

06

Restricts direct-message and geolocation data collection for minor students without opt-in

07

Authored by Sen. Kristin Phillips-Hill (R-York), who also co-authored Pennsylvania's social-media parental-consent legislation

Rule Categories Covered

Phosra enforcement categories for PA SB 378

Age Gate

access control
age_gate

Enforces age verification requirements and restricts access to age-inappropriate content or features.

Parental Consent Gate

other
parental_consent_gate

Enforces parental consent gate rules across connected platforms.

Parental Event Notification

other
parental_event_notification

Enforces parental event notification rules across connected platforms.

Targeted Ad Block

advertising
targeted_ad_block

Blocks behavioral advertising, ad profiling, and retargeting for minor users across connected platforms.

DM Restriction

access control
dm_restriction

Restricts direct messaging to approved contacts or friends only, blocking messages from strangers.

Algorithm Feed Control

algorithmic
algo_feed_control

Disables personalized algorithmic feeds and switches to chronological or non-profiled content delivery.

Geolocation Opt-In

privacy
geolocation_opt_in

Ensures location tracking is disabled by default, requiring explicit parental authorization to enable.

Commercial Data Ban

other
commercial_data_ban

Enforces commercial data ban rules across connected platforms.

Platforms Affected

Platforms covered by PA SB 378

WebiOSAndroidEd-tech platforms
Age: All K-12 students

MCP Enforcement

Enforce PA SB 378 with a single API call

mcp-enforcement
// Enforce PA SB 378 compliance
tool: trigger_child_enforcement
input: {
  child_id: "ch_emma_01",
  law: "PA_SB_378",
  rules: [
          "age_gate",
          "parental_consent_gate",
          "parental_event_notification",
          "targeted_ad_block"]
}

→ Web          enforcement applied     ✓
→ iOS          enforcement applied     ✓
→ Android      enforcement applied     ✓
→ Ed-tech platforms enforcement applied     ✓

Start building PA SB 378-compliant features today

Phosra handles the complexity of multi-platform compliance so you can focus on building great products for families.

Related Parental Controls

production·d77d8a4·main·