Florida Privacy Law
Florida has a comprehensive privacy statute in name, but the Florida Digital Bill of Rights reaches only a handful of companies: section 501.702(9) requires more than $1 billion in global gross annual revenue plus one of three specific business characteristics. The statute that touches ordinary Florida businesses is the Florida Information Protection Act at section 501.171, whose definition of personal information is among the broadest in the country — it counts medical information, health-insurance identifiers, biometric data and geolocation — and whose failure-to-notify penalties escalate on a published schedule.
The Florida Digital Bill of Rights (FDBR)
The FDBR’s reach turns on the definition of “controller” in section 501.702(9). An entity is a controller only if it is organized or operated for profit, makes in excess of $1 billion in global gross annual revenues, and satisfies at least one of three tests: it derives 50 percent or more of its global gross annual revenues from selling online advertisements including targeted advertising; it operates a consumer smart speaker and voice-command service with an integrated virtual assistant connected to a cloud service using hands-free verbal activation; or it operates an app store or digital distribution platform offering at least 250,000 different software applications. The definition also captures any entity that controls or is controlled by a controller.
| Effective date | July 1, 2024 |
|---|---|
| Citation | Fla. Stat. §§ 501.701–501.722 |
| Enforced by | Florida Department of Legal Affairs |
| Maximum penalty | Up to $50,000 per violation, treble in three defined circumstances |
| Private right of action | No, enforcement by the state only |
| Right to cure | 45 days, discretionary; unavailable for known-child violations |
Who Must Comply
The FDBR applies where a business has organized or operated for the profit or financial benefit of its shareholders or owners, and makes in excess of $1 billion in global gross annual revenues, and derives 50%+ of global gross annual revenue from online advertising, or operates a smart speaker and voice-command service with an integrated virtual assistant, or operates an app store or digital distribution platform offering 250,000+ applications.
The revenue floor and the three-part alternative test together make the FDBR the narrowest of the state comprehensive laws by design. Most Florida businesses that would be controllers under the Virginia or Connecticut model are outside it, and their obligations run instead through section 501.171 and the general unfair-and-deceptive-practices provisions
Consumer Rights Under the FDBR
Residents of Florida can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.
Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.
Sector-Specific Privacy Laws in Florida
Social media use for minors — Fla. Stat. § 501.1736
The section applies to a “social media platform,” defined by four cumulative criteria: it lets users upload content or view other users’ content or activity; ten percent or more of its daily active users younger than sixteen spend on average two hours a day or longer on it; it employs algorithms that analyse user data to select content; and it has at least one of the named addictive features — infinite scrolling, push notifications or alerts about account activity, display of personal interactive metrics showing reactions, shares or reposts, or auto-play video. “Daily active users” is itself defined by a strict measure: unique United States users who used the service at least 80 percent of the days in the previous twelve months.
Disposal of customer records — Fla. Stat. § 501.171(8)
Each covered entity or third-party agent must take all reasonable measures to dispose, or arrange for the disposal, of customer records containing personal information within its custody or control when the records are no longer to be retained. The subsection specifies the method: shredding, erasing, or otherwise modifying the personal information in the records to make it unreadable or undecipherable through any means.
Confidentiality of breach filings — Fla. Stat. § 501.171(11)
Information the Department of Legal Affairs receives through a breach notification, or through its own or a law-enforcement investigation, is confidential and exempt from the public-records law and from article I, section 24(a) of the Florida Constitution until the investigation is completed or ceases to be active. Once it closes, five categories stay exempt permanently: information covered by another exemption, personal information, computer forensic reports, information that would reveal weaknesses in a covered entity’s data security, and the entity’s proprietary information as the subsection defines it.
Data Breach Notification in Florida
Section 501.171 defines personal information more broadly than most breach statutes. Beyond a Social Security number, a government identification number and a financial account number with its access code, subsection (1)(g)1.a. counts information regarding an individual’s medical history, mental or physical condition or treatment; a health-insurance policy or subscriber identification number; biometric data as defined in section 501.702; and any information regarding an individual’s geolocation. Sub-subparagraph b. separately counts a user name or email address combined with a password or security question and answer permitting access to an online account. Subsection (3)(b) prescribes what the notice to the department must contain, including a synopsis of the events, the number of Florida individuals affected, any services being offered without charge, and a copy of the individual notice; under subsection (3)(c) the department may then require a police, incident or computer forensics report, the entity’s breach policies, and the steps taken to rectify the breach. Subsection (4)(c) supplies a harm exception: individual notice is not required where, after an appropriate investigation and consultation with law enforcement, the covered entity reasonably determines the breach has not and will not likely result in identity theft or other financial harm, provided the determination is documented in writing, maintained for at least five years, and provided to the department within 30 days.
Residents must be notified as expeditiously as practicable and without unreasonable delay, no later than 30 days after determination of a breach. Notify the Department of Legal Affairs of any breach affecting 500 or more Florida individuals, no later than 30 days after determination, with 15 additional days available for written good cause. Complaints are taken by the Florida Department of Legal Affairs, which enforces the statute.
How the FDBR Is Enforced
How the Digital Bill of Rights is enforced. Section 501.72(1) makes a violation of the FDBR an unfair and deceptive trade practice actionable under part II of chapter 501 “solely by the Department of Legal Affairs,” and expressly disapplies sections 501.211 and 501.212 for those actions. The department may collect a civil penalty of up to $50,000 per violation, and the penalty may be tripled in three defined circumstances: a violation involving a Florida consumer who is a known child, with a controller that willfully disregards the consumer’s age deemed to have actual knowledge of it; a failure to delete or correct personal data after an authenticated consumer request; and continuing to sell or share personal data after the consumer has opted out. Subsection (8) provides that the part does not establish a private cause of action.
The 45-day cure period, and where it does not apply. Section 501.72(2) gives the department discretion, after notifying a person in writing of an alleged violation, to grant a 45-day cure period and issue a letter of guidance. The subsection directs the department to weigh the number and frequency of violations, the substantial likelihood of injury to the public, and the safety of persons or property in deciding whether to grant it, and provides that the cure period “does not apply to an alleged violation of paragraph (1)(a)” — the known-child provision. Where a violation is cured to the department’s satisfaction and proof is provided, the department may not bring an action for it, but may issue a letter of guidance stating that no future cure period will be offered.
The statutory annual enforcement report. Section 501.72(4) requires the Department of Legal Affairs to publish a report on its website by February 1 each year describing the actions it has taken to enforce the FDBR. The statute specifies the contents: the number of complaints received and the categories or types of violations alleged, the number and type of enforcement actions taken and their outcomes including penalties issued and collected, and the number of complaints resolved without litigation. Subsection (5) directs the department to adopt rules covering standards for authenticated consumer requests, enforcement, data security, and who may act on a consumer’s behalf.
Pending Privacy Legislation
The Florida Digital Bill of Rights and the current version of section 501.171 are both in force, and section 501.1736 governs social media accounts held by minors. Under section 501.72(4) the Department of Legal Affairs publishes a report each February describing its FDBR enforcement activity for the prior year, which is the statutory record of how the narrow controller definition has been applied in practice.
Federal Privacy Laws That Apply in Florida
Federal privacy law applies in Florida by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The FDBR sits alongside those rules rather than displacing them: the Florida Department of Legal Affairs enforces the state law, while the federal regulators continue to reach the sectors and activities they cover.
Florida Privacy Law FAQ
Does the Florida Digital Bill of Rights apply to my small business?
What are the penalties under the FDBR?
When must a Florida business report a breach to the state?
What counts as personal information in a Florida breach?
What is the penalty for failing to give breach notice in Florida?
Are Florida breach filings available to the public?
Which platforms does Florida’s minors social-media law cover?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- Fla. Stat. § 501.171 — Security of confidential personal information statute
- Fla. Stat. § 501.702 — Florida Digital Bill of Rights, definitions statute
- Fla. Stat. § 501.72 — Enforcement and implementation by the Department of Legal Affairs statute
- Fla. Stat. § 501.1736 — Social media use for minors statute
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.