Alabama — Comprehensive Law

Alabama Privacy Law

Alabama was the last state in the country to enact a data breach notification law, and the statute it eventually passed in 2018 counts more categories of information than most of the laws that preceded it — medical history, health insurance identifiers and account credentials all sit inside its definition of sensitive personally identifying information. Its comprehensive statute, enacted in the 2026 Regular Session as House Bill 351 and effective May 1, 2027, moves in the same direction: it sets no revenue floor, applies from 25,000 consumers, and reaches any business deriving more than a quarter of gross revenue from selling personal data regardless of how few people that data describes. It also omits something almost every comparable statute contains — a data protection assessment requirement.

The Alabama Personal Data Protection Act (Alabama PDPA)

House Bill 351, by Representative Shaw and first read on January 29, 2026, was enacted in the 2026 Regular Session and takes effect May 1, 2027 under section 12. Section 1 names it the Alabama Personal Data Protection Act. Section 11(a) gives the Attorney General enforcement authority; subsection (b)(1) requires a notice of violation before any action; subsection (b)(2) allows an injunction action if the controller fails to correct within forty-five days and permits a court, on finding a violation and a failure to correct, to assess a civil penalty of not more than $15,000 per violation; and subsection (b)(3) bars any action where the controller corrects within the forty-five-day period and gives the Attorney General an express written statement that the alleged violations have been corrected and that no further violations will occur. No expiry date is attached to that correction right. The Act contains no data protection assessment requirement, and it neither creates nor references a private right of action.

Status: Enacted but not yet in force — the law takes effect May 1, 2027.

Effective dateMay 1, 2027
CitationHB 351, 2026 Regular Session
Enforced byAlabama Attorney General
Maximum penaltyUp to $15,000 per violation, assessed by a court after a failure to correct within 45 days
Private right of actionNo, enforcement by the state only
Right to cure45 days after a notice of violation, with no expiry date

Who Must Comply

The Alabama PDPA reaches a business that conducts business in Alabama or produces products or services targeted to Alabama residents, and controls or processes the personal data of more than 25,000 consumers, excluding data processed solely to complete a payment transaction, or derives more than 25% of gross revenue from the sale of personal data, regardless of the number of consumers whose data the person controls or processes.

Section 2(20) defines a sale of personal data as an exchange for monetary consideration, or for other valuable consideration where the controller receives a material benefit and the third party is not restricted in its subsequent uses of the data — a qualifier that appears in no other state definition. The portability right in section 5(a)(4) is limited to data the consumer previously provided to the controller rather than all data held. Section 4(a) exempts political subdivisions, boards, authorities, districts and public corporations organised under Title 11 or Chapter 7 of Title 39, two-year and four-year institutions of higher education and their affiliates, and principal campaign committees as defined in Section 17-5-2

Consumer Rights Under the Alabama PDPA

Residents of Alabama can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.

Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.

Sector-Specific Privacy Laws in Alabama

Insurance Data Security Law (Ala. Code §§ 27-62-1 et seq.)

Enacted as Act 2019-98, this chapter is declared by § 27-62-2(a) to establish the exclusive state standards applicable to licensees for data security, for the investigation of a cybersecurity event and for notification to the Commissioner of Insurance. Subsection (b) is explicit in both directions: the chapter may not be construed to create or imply a private cause of action for a violation, nor to curtail a private cause of action that would otherwise exist without it. Section 27-62-6(a) requires notice to the Commissioner as promptly as possible and in no event later than three business days from a determination that a cybersecurity event involving nonpublic information has occurred, on either of two triggers — Alabama domicile or home state combined with a reasonable likelihood of materially harming an Alabama consumer or the licensee’s normal operations, or a reasonable belief that 250 or more Alabama consumers are involved together with an existing reporting obligation to another body or that same likelihood of material harm. Subsection (d) layers the two regimes: the licensee also complies with the Alabama Data Breach Notification Act of 2018 as applicable and gives the Commissioner a copy of the consumer notice. The exemptions in § 27-62-9(a)(1) are set by size — fewer than 25 employees, less than $5 million in gross annual revenue, or less than $10 million in year-end total assets — and subsection (b) gives a licensee that ceases to qualify 180 days to comply.

Alabama Deceptive Trade Practices Act (Ala. Code §§ 8-19-1 et seq.)

The Deceptive Trade Practices Act is where breach-notification violations are prosecuted, and its remedial structure is distinctive on two points. Section 8-19-10(f) bars a consumer or other person bringing an action under the chapter from doing so on behalf of a class, and states that the limitation is a substantive one because allowing a class or representative action would abridge, enlarge or modify the substantive rights the chapter creates. Subsection (g) leaves representative actions to the Attorney General or a district attorney alone, and provides that in such an action the court awards neither minimum nor treble damages but limits recovery to actual damages plus reasonable attorney’s fees and costs. For individual claimants, § 8-19-10(a) provides actual damages or $100, whichever is greater, or up to three times actual damages in the court’s discretion, with subsection (e) requiring a written demand for relief at least fifteen days before filing. On the public side, § 8-19-11(b) sets a civil penalty of not more than $2,000 per knowing violation of § 8-19-5 and subsection (a) sets not more than $25,000 per violation of an injunction, while subsection (d) supplies a defence: the penalties do not apply to an offender who shows by a preponderance of the evidence that it had established reasonable procedures to comply with the chapter or with an injunction.

Data Breach Notification in Alabama

The Alabama Data Breach Notification Act of 2018, Act 2018-396, sits at Ala. Code §§ 8-38-1 through 8-38-12 and turns on a harm standard rather than on acquisition alone. Section 8-38-5(a) requires individual notice only where sensitive personally identifying information has been or is reasonably believed to have been acquired by an unauthorized person and is reasonably likely to cause substantial harm to the individuals concerned. What counts as sensitive personally identifying information under § 8-38-2(6)(a) is broader than the usual list: alongside a non-truncated Social Security or tax identification number and a non-truncated driver’s licence, state identification, passport, military identification or other government identification number, it reaches any information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional; a health insurance policy or subscriber identification number with any unique insurer identifier; and a user name or email address combined with a password or security question and answer permitting access to an affiliated online account. Section 8-38-2(1) also settles a question most statutes leave open, providing that acquisition occurring over a period of time committed by the same entity constitutes one breach. Section 8-38-5(d) lists five items the individual notice must contain, including the estimated date or date range of the breach and a general description of steps an affected individual can take against identity theft. Section 8-38-6(b) lists four items for the Attorney General notice, and subsection (d) protects information marked confidential from open-records disclosure. Section 8-38-11 exempts entities regulated under federal breach-notification regimes but still requires a copy of the federal notice to the Attorney General where more than 1,000 individuals were notified.

Residents must be notified as expeditiously as possible and without unreasonable delay, and within 45 days of the determination that a breach occurred and is reasonably likely to cause substantial harm, or of notice from a third-party agent. Written notice to the Attorney General is due where the number of individuals to be notified exceeds 1,000, on the same 45-day clock. Complaints are taken by the Alabama Attorney General, which enforces the statute.

How the Alabama PDPA Is Enforced

Breach violations are deceptive trade practices, but not crimes. Section 8-38-9(a) provides that a violation of the notification provisions of the chapter is an unlawful trade practice under the Alabama Deceptive Trade Practices Act, Chapter 19 of Title 8, but expressly does not constitute a criminal offense under § 8-19-12. The same subsection gives the Attorney General exclusive authority to bring an action for civil penalties. The routing has a ceiling written into it: civil penalties assessed under § 8-19-11 for these violations may not exceed $500,000 per breach, a figure that appears nowhere in the Deceptive Trade Practices Act itself.

No class actions, and a reasonable-procedures defence. Two features of the Deceptive Trade Practices Act shape what enforcement looks like in practice. Section 8-19-10(f) bars private class or representative actions in terms, describing the limitation as substantive rather than procedural, and subsection (g) reserves representative actions to the Attorney General or a district attorney while capping recovery in such actions at actual damages plus fees and costs. Section 8-19-11(d) then supplies a defence to civil penalties for any offender that shows by a preponderance of the evidence that it had established reasonable procedures to comply with the chapter or with an injunction issued under § 8-19-8.

Recent Enforcement in Alabama

23andMe — genetic data breach claims resolved in bankruptcy, July 2026. The Attorney General’s office announced on July 16, 2026 that Alabama had joined a coalition of 42 attorneys general settling with the bankruptcy trustee for 23andMe over a 2023 breach that compromised the genetic data of 6.9 million customers worldwide, including 69,950 in Alabama. The settlement includes $150 million in allowed claims for the states; because the bankruptcy estate is finite and other claims compete, recovery is limited to $18 million paid immediately from available funds, of which Alabama receives $260,817. The office states that the multistate investigation found unreasonable data security practices including a failure to guard against credential-stuffing attacks by comparing passwords against blocklists of known breached passwords or requiring multifactor authentication, a failure to implement rate limiting or intrusion prevention, a failure to implement logging and monitoring, a failure to investigate unusual login patterns including a massive spike in login attempts, a failure to remediate known vulnerabilities, and a failure to review and test design features. The office notes that the company’s consumer data was sold in the bankruptcy to TTAM Research Institute on terms including enhanced data security requirements, an advisory board, agreement to be bound by comprehensive privacy laws without exception, and continued consumer deletion rights.

Blackbaud — $49.5 million multistate settlement, $1.6 million to Alabama. The office announced on October 5, 2023 a 49-state settlement with the software company Blackbaud over its data security practices and its response to a 2020 breach, with $49.5 million paid to the states and $1.6 million to Alabama. The office states the settlement resolves allegations that the company violated state consumer protection laws, breach notification laws and HIPAA by failing to implement reasonable data security programs and to remediate known security gaps, and then failing to give its customers timely, complete or accurate information about the breach — with the result that notification to affected consumers was significantly delayed or never occurred, because the company downplayed the incident and led customers to believe notification was not required. The injunctive terms include total database encryption and dark web monitoring, network segmentation, patch management, intrusion detection, access controls, logging and monitoring, penetration testing, and third-party assessments of compliance for seven years. Alabama sat on the executive committee for the investigation, which was co-led by Indiana and Vermont.

Pending Privacy Legislation

House Bill 351 of the 2026 Regular Session carries the record status “Enacted” with a certain effective date of May 1, 2027, so the state’s comprehensive framework is settled rather than pending. What remains scheduled is administrative and reportorial. The Act grants no rulemaking authority to any agency, so its text rather than a regulation will supply its detail from the effective date. A recurring obligation already runs under the 2018 breach statute: § 8-38-9(b)(7) requires the Attorney General, by February 1 of each year, to report to the Governor, the President Pro Tempore of the Senate and the Speaker of the House on the nature of any reported breaches of security by government entities or their third-party agents in the preceding calendar year, together with recommendations for security improvements, and to identify any government entity that violated the chapter’s requirements in that year.

Federal Privacy Laws That Apply in Alabama

Federal privacy law applies in Alabama by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The Alabama PDPA sits alongside those rules rather than displacing them: the Alabama Attorney General enforces the state law, while the federal regulators continue to reach the sectors and activities they cover. The state-law counterpart to section 5 is the Alabama Deceptive Trade Practices Act (Ala. Code §§ 8-19-1 et seq.), which the Alabama Attorney General enforces against businesses whose stated data practices differ from their actual ones.

Alabama Privacy Law FAQ

When does an Alabama breach have to be reported to the Attorney General?
Section 8-38-6(a) sets a headcount rather than a harm test at this stage: written notice to the Attorney General is due where the number of individuals the covered entity is required to notify under § 8-38-5 exceeds 1,000. The clock is the same forty-five days that governs individual notice, running from receipt of notice from a third-party agent or from the entity’s determination that a breach occurred and is reasonably likely to cause substantial harm. Section 8-38-11(3) adds that an entity otherwise exempt because it follows a federal breach-notification regime still provides the Attorney General a copy of its notice where it notified more than 1,000 individuals.
What counts as sensitive personally identifying information in Alabama?
Section 8-38-2(6)(a) pairs an Alabama resident’s first name or first initial and last name with six categories: a non-truncated Social Security or tax identification number; a non-truncated driver’s licence, state identification card, passport, military identification or other government-document identification number; a financial account, credit card or debit card number with any security code, access code, password, expiration date or PIN needed to access the account; any information regarding medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional; a health insurance policy or subscriber identification number with any unique insurer identifier; and a user name or email address with a password or security question and answer permitting access to an affiliated online account.
What does a failure to give breach notice cost in Alabama?
Section 8-38-9(a)(2) treats a knowing violation — defined there as wilfully or with reckless disregard failing to comply with §§ 8-38-5 and 8-38-6 — as exposing the entity to the penalty provisions of § 8-19-11, capped for these purposes at $500,000 per breach. Subsection (b)(1) adds a separate civil penalty of not more than $5,000 per day for each consecutive day that a covered entity fails to take reasonable action to comply. Subsection (b)(6) exempts government entities from civil penalties, while allowing the Attorney General to sue an official or employee in their official capacity to compel performance of duties under the chapter.
Can an individual sue over an Alabama breach-notice failure?
Section 8-38-9(a)(1) states that a violation of the chapter does not establish a private cause of action under § 8-19-10, while adding that nothing in the chapter otherwise affects rights a person may have at common law, by statute or otherwise. Subsection (a) gives the Attorney General exclusive authority to bring an action for civil penalties, and subsection (b)(2) gives the office exclusive authority to bring an action for damages in a representative capacity on behalf of named individuals, with recovery in such an action limited to actual damages plus reasonable attorney’s fees and costs.
Which businesses will the Alabama Personal Data Protection Act reach in 2027?
Section 3 applies the Act to persons conducting business in Alabama or producing products or services targeted to Alabama residents that meet either of two qualifications: controlling or processing the personal data of more than 25,000 consumers, excluding personal data processed solely to complete a payment transaction; or deriving more than 25 percent of gross revenue from the sale of personal data, regardless of the number of consumers whose data the person controls or processes. There is no revenue floor in either branch, and the second branch has no consumer-count element at all.
Does the Alabama Personal Data Protection Act require data protection assessments?
The Act contains no such requirement. Most comprehensive state privacy statutes enacted since 2021 require a controller to conduct and document an assessment before processing that presents a heightened risk of harm, and to produce it to the Attorney General on request; Alabama’s statute has no equivalent provision. Section 7 sets the controller duties that do apply — limiting collection to what is adequate, relevant and reasonably necessary, maintaining reasonable administrative, technical and physical data security, and the prohibitions in subsection (b).
Does the Alabama Personal Data Protection Act’s correction period expire?
No date is attached to it. Section 11(b)(1) requires the Attorney General to issue a notice of violation to the controller before initiating any action for a violation of any provision of the Act. Subsection (b)(2) permits an injunction action only if the controller fails to correct within forty-five days after receipt of that notice, and subsection (b)(3) bars any action where within that period the controller corrects the noticed violation and provides an express written statement that the alleged violations have been corrected and that no such further violations will occur.
What consent does the Alabama Personal Data Protection Act require for teenagers?
Section 7(b)(4) bars a controller from processing a consumer’s personal data for targeted advertising or selling it without consent where the controller has actual knowledge that the consumer is at least 13 years of age but younger than 16. Separately, § 7(b)(2) bars processing sensitive data concerning a consumer other than a known child without that consumer’s consent, and requires processing of a known child’s personal data to follow the federal Children’s Online Privacy Protection Act. Sensitive data is defined at § 2(21) to include personal data collected from a known child and precise geolocation data.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.