Alabama Privacy Law
Alabama was the last state in the country to enact a data breach notification law, and the statute it eventually passed in 2018 counts more categories of information than most of the laws that preceded it — medical history, health insurance identifiers and account credentials all sit inside its definition of sensitive personally identifying information. Its comprehensive statute, enacted in the 2026 Regular Session as House Bill 351 and effective May 1, 2027, moves in the same direction: it sets no revenue floor, applies from 25,000 consumers, and reaches any business deriving more than a quarter of gross revenue from selling personal data regardless of how few people that data describes. It also omits something almost every comparable statute contains — a data protection assessment requirement.
The Alabama Personal Data Protection Act (Alabama PDPA)
House Bill 351, by Representative Shaw and first read on January 29, 2026, was enacted in the 2026 Regular Session and takes effect May 1, 2027 under section 12. Section 1 names it the Alabama Personal Data Protection Act. Section 11(a) gives the Attorney General enforcement authority; subsection (b)(1) requires a notice of violation before any action; subsection (b)(2) allows an injunction action if the controller fails to correct within forty-five days and permits a court, on finding a violation and a failure to correct, to assess a civil penalty of not more than $15,000 per violation; and subsection (b)(3) bars any action where the controller corrects within the forty-five-day period and gives the Attorney General an express written statement that the alleged violations have been corrected and that no further violations will occur. No expiry date is attached to that correction right. The Act contains no data protection assessment requirement, and it neither creates nor references a private right of action.
Status: Enacted but not yet in force — the law takes effect May 1, 2027.
| Effective date | May 1, 2027 |
|---|---|
| Citation | HB 351, 2026 Regular Session |
| Enforced by | Alabama Attorney General |
| Maximum penalty | Up to $15,000 per violation, assessed by a court after a failure to correct within 45 days |
| Private right of action | No, enforcement by the state only |
| Right to cure | 45 days after a notice of violation, with no expiry date |
Who Must Comply
The Alabama PDPA reaches a business that conducts business in Alabama or produces products or services targeted to Alabama residents, and controls or processes the personal data of more than 25,000 consumers, excluding data processed solely to complete a payment transaction, or derives more than 25% of gross revenue from the sale of personal data, regardless of the number of consumers whose data the person controls or processes.
Section 2(20) defines a sale of personal data as an exchange for monetary consideration, or for other valuable consideration where the controller receives a material benefit and the third party is not restricted in its subsequent uses of the data — a qualifier that appears in no other state definition. The portability right in section 5(a)(4) is limited to data the consumer previously provided to the controller rather than all data held. Section 4(a) exempts political subdivisions, boards, authorities, districts and public corporations organised under Title 11 or Chapter 7 of Title 39, two-year and four-year institutions of higher education and their affiliates, and principal campaign committees as defined in Section 17-5-2
Consumer Rights Under the Alabama PDPA
Residents of Alabama can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.
Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.
Sector-Specific Privacy Laws in Alabama
Insurance Data Security Law (Ala. Code §§ 27-62-1 et seq.)
Enacted as Act 2019-98, this chapter is declared by § 27-62-2(a) to establish the exclusive state standards applicable to licensees for data security, for the investigation of a cybersecurity event and for notification to the Commissioner of Insurance. Subsection (b) is explicit in both directions: the chapter may not be construed to create or imply a private cause of action for a violation, nor to curtail a private cause of action that would otherwise exist without it. Section 27-62-6(a) requires notice to the Commissioner as promptly as possible and in no event later than three business days from a determination that a cybersecurity event involving nonpublic information has occurred, on either of two triggers — Alabama domicile or home state combined with a reasonable likelihood of materially harming an Alabama consumer or the licensee’s normal operations, or a reasonable belief that 250 or more Alabama consumers are involved together with an existing reporting obligation to another body or that same likelihood of material harm. Subsection (d) layers the two regimes: the licensee also complies with the Alabama Data Breach Notification Act of 2018 as applicable and gives the Commissioner a copy of the consumer notice. The exemptions in § 27-62-9(a)(1) are set by size — fewer than 25 employees, less than $5 million in gross annual revenue, or less than $10 million in year-end total assets — and subsection (b) gives a licensee that ceases to qualify 180 days to comply.
Alabama Deceptive Trade Practices Act (Ala. Code §§ 8-19-1 et seq.)
The Deceptive Trade Practices Act is where breach-notification violations are prosecuted, and its remedial structure is distinctive on two points. Section 8-19-10(f) bars a consumer or other person bringing an action under the chapter from doing so on behalf of a class, and states that the limitation is a substantive one because allowing a class or representative action would abridge, enlarge or modify the substantive rights the chapter creates. Subsection (g) leaves representative actions to the Attorney General or a district attorney alone, and provides that in such an action the court awards neither minimum nor treble damages but limits recovery to actual damages plus reasonable attorney’s fees and costs. For individual claimants, § 8-19-10(a) provides actual damages or $100, whichever is greater, or up to three times actual damages in the court’s discretion, with subsection (e) requiring a written demand for relief at least fifteen days before filing. On the public side, § 8-19-11(b) sets a civil penalty of not more than $2,000 per knowing violation of § 8-19-5 and subsection (a) sets not more than $25,000 per violation of an injunction, while subsection (d) supplies a defence: the penalties do not apply to an offender who shows by a preponderance of the evidence that it had established reasonable procedures to comply with the chapter or with an injunction.
Data Breach Notification in Alabama
The Alabama Data Breach Notification Act of 2018, Act 2018-396, sits at Ala. Code §§ 8-38-1 through 8-38-12 and turns on a harm standard rather than on acquisition alone. Section 8-38-5(a) requires individual notice only where sensitive personally identifying information has been or is reasonably believed to have been acquired by an unauthorized person and is reasonably likely to cause substantial harm to the individuals concerned. What counts as sensitive personally identifying information under § 8-38-2(6)(a) is broader than the usual list: alongside a non-truncated Social Security or tax identification number and a non-truncated driver’s licence, state identification, passport, military identification or other government identification number, it reaches any information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional; a health insurance policy or subscriber identification number with any unique insurer identifier; and a user name or email address combined with a password or security question and answer permitting access to an affiliated online account. Section 8-38-2(1) also settles a question most statutes leave open, providing that acquisition occurring over a period of time committed by the same entity constitutes one breach. Section 8-38-5(d) lists five items the individual notice must contain, including the estimated date or date range of the breach and a general description of steps an affected individual can take against identity theft. Section 8-38-6(b) lists four items for the Attorney General notice, and subsection (d) protects information marked confidential from open-records disclosure. Section 8-38-11 exempts entities regulated under federal breach-notification regimes but still requires a copy of the federal notice to the Attorney General where more than 1,000 individuals were notified.
Residents must be notified as expeditiously as possible and without unreasonable delay, and within 45 days of the determination that a breach occurred and is reasonably likely to cause substantial harm, or of notice from a third-party agent. Written notice to the Attorney General is due where the number of individuals to be notified exceeds 1,000, on the same 45-day clock. Complaints are taken by the Alabama Attorney General, which enforces the statute.
How the Alabama PDPA Is Enforced
Breach violations are deceptive trade practices, but not crimes. Section 8-38-9(a) provides that a violation of the notification provisions of the chapter is an unlawful trade practice under the Alabama Deceptive Trade Practices Act, Chapter 19 of Title 8, but expressly does not constitute a criminal offense under § 8-19-12. The same subsection gives the Attorney General exclusive authority to bring an action for civil penalties. The routing has a ceiling written into it: civil penalties assessed under § 8-19-11 for these violations may not exceed $500,000 per breach, a figure that appears nowhere in the Deceptive Trade Practices Act itself.
No class actions, and a reasonable-procedures defence. Two features of the Deceptive Trade Practices Act shape what enforcement looks like in practice. Section 8-19-10(f) bars private class or representative actions in terms, describing the limitation as substantive rather than procedural, and subsection (g) reserves representative actions to the Attorney General or a district attorney while capping recovery in such actions at actual damages plus fees and costs. Section 8-19-11(d) then supplies a defence to civil penalties for any offender that shows by a preponderance of the evidence that it had established reasonable procedures to comply with the chapter or with an injunction issued under § 8-19-8.
Recent Enforcement in Alabama
23andMe — genetic data breach claims resolved in bankruptcy, July 2026. The Attorney General’s office announced on July 16, 2026 that Alabama had joined a coalition of 42 attorneys general settling with the bankruptcy trustee for 23andMe over a 2023 breach that compromised the genetic data of 6.9 million customers worldwide, including 69,950 in Alabama. The settlement includes $150 million in allowed claims for the states; because the bankruptcy estate is finite and other claims compete, recovery is limited to $18 million paid immediately from available funds, of which Alabama receives $260,817. The office states that the multistate investigation found unreasonable data security practices including a failure to guard against credential-stuffing attacks by comparing passwords against blocklists of known breached passwords or requiring multifactor authentication, a failure to implement rate limiting or intrusion prevention, a failure to implement logging and monitoring, a failure to investigate unusual login patterns including a massive spike in login attempts, a failure to remediate known vulnerabilities, and a failure to review and test design features. The office notes that the company’s consumer data was sold in the bankruptcy to TTAM Research Institute on terms including enhanced data security requirements, an advisory board, agreement to be bound by comprehensive privacy laws without exception, and continued consumer deletion rights.
Blackbaud — $49.5 million multistate settlement, $1.6 million to Alabama. The office announced on October 5, 2023 a 49-state settlement with the software company Blackbaud over its data security practices and its response to a 2020 breach, with $49.5 million paid to the states and $1.6 million to Alabama. The office states the settlement resolves allegations that the company violated state consumer protection laws, breach notification laws and HIPAA by failing to implement reasonable data security programs and to remediate known security gaps, and then failing to give its customers timely, complete or accurate information about the breach — with the result that notification to affected consumers was significantly delayed or never occurred, because the company downplayed the incident and led customers to believe notification was not required. The injunctive terms include total database encryption and dark web monitoring, network segmentation, patch management, intrusion detection, access controls, logging and monitoring, penetration testing, and third-party assessments of compliance for seven years. Alabama sat on the executive committee for the investigation, which was co-led by Indiana and Vermont.
Pending Privacy Legislation
House Bill 351 of the 2026 Regular Session carries the record status “Enacted” with a certain effective date of May 1, 2027, so the state’s comprehensive framework is settled rather than pending. What remains scheduled is administrative and reportorial. The Act grants no rulemaking authority to any agency, so its text rather than a regulation will supply its detail from the effective date. A recurring obligation already runs under the 2018 breach statute: § 8-38-9(b)(7) requires the Attorney General, by February 1 of each year, to report to the Governor, the President Pro Tempore of the Senate and the Speaker of the House on the nature of any reported breaches of security by government entities or their third-party agents in the preceding calendar year, together with recommendations for security improvements, and to identify any government entity that violated the chapter’s requirements in that year.
Federal Privacy Laws That Apply in Alabama
Federal privacy law applies in Alabama by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The Alabama PDPA sits alongside those rules rather than displacing them: the Alabama Attorney General enforces the state law, while the federal regulators continue to reach the sectors and activities they cover. The state-law counterpart to section 5 is the Alabama Deceptive Trade Practices Act (Ala. Code §§ 8-19-1 et seq.), which the Alabama Attorney General enforces against businesses whose stated data practices differ from their actual ones.
Alabama Privacy Law FAQ
When does an Alabama breach have to be reported to the Attorney General?
What counts as sensitive personally identifying information in Alabama?
What does a failure to give breach notice cost in Alabama?
Can an individual sue over an Alabama breach-notice failure?
Which businesses will the Alabama Personal Data Protection Act reach in 2027?
Does the Alabama Personal Data Protection Act require data protection assessments?
Does the Alabama Personal Data Protection Act’s correction period expire?
What consent does the Alabama Personal Data Protection Act require for teenagers?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- Alabama HB 351 (2026) — enrolled text, Alabama Personal Data Protection Act legislation
- Ala. Code § 8-38-2 — Data breach notification; definitions statute
- Ala. Code § 8-38-5 — Notice of security breach to individuals affected statute
- Ala. Code § 8-38-6 — Notice of security breach to the Attorney General statute
- Ala. Code § 8-38-9 — Violations of notification requirements statute
- Ala. Code § 8-19-10 — Deceptive Trade Practices Act; private right of action statute
- Ala. Code § 8-19-11 — Deceptive Trade Practices Act; penalties statute
- Ala. Code § 27-62-6 — Insurance Data Security Law; notification of cybersecurity event statute
- Alabama Attorney General — Data Breach Notification agency
- Alabama Attorney General — 23andMe genetic data breach settlement agency
- Alabama Attorney General — $49.5 million Blackbaud data breach settlement agency
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.