Florida Digital Bill of Rights
· About Florida Digital Bill of Rights
Key Takeaways
- The Florida Digital Bill of Rights (FDBR) is Florida’s state privacy law in Chapter 501, Part V, and it applies only to certain large for-profit businesses doing business in Florida or targeting Florida residents.[1][2]
- The law took effect on 1 July 2024 after being enacted as ch. 2023-201, and there is no 2025–2026 amendment in the official statutory text changing the effective date or core enforcement structure.[1][2]
- Covered businesses must provide consumer rights to confirm, access, correct, delete, obtain a copy of, and opt out of the sale of personal data, targeted advertising, and certain profiling, plus additional protections for minors and sensitive data.[1][2]
- Enforcement is exclusively by the Florida Attorney General, with a 30-day cure period for alleged violations before enforcement action, and civil penalties can reach $50,000 per violation.[1][2]
- Controllers with global annual gross revenues over $1 billion and substantial Florida-facing operations face the law’s most demanding obligations, including data protection assessments and stricter controls over targeted advertising and profiling.[1][2]
- Certain entities are exempt, including many entities already regulated under GLBA, as well as government entities and higher-education institutions, so scoping by entity type is as important as scoping by revenue.[1][2]
What It Is
The FDBR is Florida’s comprehensive consumer privacy statute, codified at Fla. Stat. §§ 501.701–501.722 in Chapter 501, Consumer Protection.[1][2] It is enforced by the Florida Department of Legal Affairs, through the Attorney General, and it is designed to regulate the collection, processing, and sale of Floridians’ personal data by covered businesses.[1][2]
The law was enacted by ch. 2023-201 and signed on 6 June 2023.[1][2] Its operative effective date was 1 July 2024.[1][2] The official 2026 statutory text still reflects that effective date and short title; no official 2025–2026 amendment has displaced the original in-force date or converted it into a different enforcement regime.[1][2]
A key phase-in milestone is the law’s enforcement structure: before the Attorney General may bring an action, the controller generally receives notice and a 30-day opportunity to cure the alleged violation.[1][2] That cure period is part of the original statute and remains the central pre-enforcement milestone in 2026.[1][2]
Who Must Comply
The FDBR applies to a controller that does business in Florida or produces products or services targeted to Florida residents and has global annual gross revenues of more than $1 billion.[1][2] The law is therefore much narrower than many state privacy laws; it is not a broad “all businesses” statute.[1][2]
The statute also captures a subset of large businesses through specific operational thresholds tied to digital advertising, smart speakers, and certain app or marketplace activity, but those threshold details are part of the same controller definition and still turn on substantial scale and Florida nexus.[1][2] In practice, the law is aimed at very large, consumer-facing digital businesses rather than ordinary mid-market companies.[1][2]
The statute has several important exemptions.[1][2] Common exemptions include government entities and higher-education institutions, and the law also excludes entities and data subject to GLBA and several other sectoral privacy regimes.[1][2]
The FDBR has extraterritorial reach in the same practical sense as other state privacy laws: a business outside Florida can still be covered if it does business in Florida or targets Florida residents and meets the statutory thresholds.[1][2] Conversely, a Florida-based business below the thresholds is not covered merely because it is located in Florida.[1][2]
Core Requirements
- Provide consumer rights. Covered controllers must enable consumers to confirm whether personal data is being processed, access that data, correct inaccuracies, delete personal data, and obtain a copy of the data in a portable format, subject to statutory exceptions.[1][2]
- Honor opt-out choices. Controllers must allow consumers to opt out of the sale of personal data, targeted advertising, and certain forms of profiling that produce legal or similarly significant effects.[1][2]
- Limit processing of sensitive data and minors’ data. The law requires heightened protections for sensitive data and includes special protections for minors’ online activity and data, including restrictions around targeted advertising and the use of their information.[1][2]
- Maintain transparency. Covered businesses must provide a privacy notice that explains categories of personal data processed, purposes of processing, consumer rights, how to exercise those rights, and categories of third parties receiving data.[1][2]
- Conduct data protection assessments. Controllers must perform assessments for processing activities presenting heightened risk, including targeted advertising, sale of personal data, profiling, sensitive data processing, and certain substantial-risk activities.[1][2]
- Use reasonable security and data minimization. Controllers must limit collection to what is adequate, relevant, and reasonably necessary to the disclosed purposes, and they must implement reasonable administrative, technical, and physical safeguards.[1][2]
- Respect non-discrimination rules. Controllers may not unlawfully discriminate against consumers for exercising privacy rights, including by denying goods or services, charging different prices, or providing different quality, except as permitted by law.[1][2]
Deadlines and Penalties
| milestone | date | what applies | |---|---:|---| | Law enacted | 6 June 2023 | Florida enacts the FDBR as ch. 2023-201.[1][2] | | Law in force | 1 July 2024 | Covered businesses must comply with operative privacy obligations.[1][2] | | Ongoing enforcement | 2026 | The Attorney General may enforce after notice and cure opportunities.[1][2] |
The maximum civil penalty is $50,000 per violation.[1][2] The Attorney General may also seek injunctive relief and other remedies available under Florida consumer protection enforcement authority.[1][2] If a violation involves a consumer aged 18 or younger, the statute authorizes treble damages in specified circumstances, which materially increases exposure for youth-data violations.[1][2]
How to Comply
- Scope your entity and data flows. Confirm whether the business meets the revenue threshold, Florida nexus, and controller definition, and map any GLBA or other statutory exemptions before building the compliance program.[1][2]
- Build a rights-management workflow. Create intake, identity-verification, response, and appeal processes for access, correction, deletion, portability, and opt-out requests, with logs that show statutory timing and exceptions handling.[1][2]
- Refresh notices and preference signals. Update privacy notices so they accurately describe categories, purposes, disclosures, and rights, and configure your systems to recognize opt-out signals where applicable.[1][2]
- Run risk-based assessments. Use an assessment framework aligned to NIST CSF 2.0 for governance and risk management, and document assessments for targeted advertising, profiling, sale, sensitive data, and children’s data processing.[1][2]
- Harden security controls. Map safeguard implementation to ISO 27001 for information security management, including access control, logging, vendor oversight, incident response, and continuous improvement.[1][2]
- Operationalize privacy governance. If the organization already uses ISO 42001 for AI management, extend it to profiling, automated decision-making, training-data governance, and model-risk reviews where AI systems affect consumer rights or minors.[1][2]
- Train business teams and vendors. Train product, ad-tech, customer support, and procurement teams on opt-out handling, sensitive data restrictions, and contracting requirements with processors and service providers.[1][2]
Related Regulations
The Florida Information Protection Act overlaps on breach response but addresses security incidents rather than the FDBR’s consumer-rights and processing rules.[1][2] The California Privacy Rights Act is broader in scope and more detailed on consumer rights, so multi-state operators often standardize to the stricter common denominator.[1][2] The Virginia Consumer Data Protection Act is structurally similar in using controller/processor concepts and risk assessments, which makes it a useful operating model for FDBR programs.[1][2] The EU GDPR overlaps on lawful processing, transparency, and rights management, but Florida’s law is narrower in scope and enforcement is state-only.[1][2] The Children’s Online Privacy Protection Act (COPPA) can conflict operationally where youth-data flows are involved, because FDBR’s minor protections sit alongside, not in place of, federal child privacy rules.[1][2]
FAQ
Does the Florida Digital Bill of Rights apply to companies outside Florida?
Yes, if the company does business in Florida or targets Florida residents and meets the statute’s threshold requirements.[1][2] The law is not limited to Florida-incorporated or Florida-headquartered entities.[1][2]
Does the FDBR apply to small or mid-size businesses?
Usually no. The core controller threshold is global annual gross revenue above $1 billion, so the law is aimed at a narrow set of large businesses.[1][2] A smaller company may still need to comply with other privacy laws, but not usually the FDBR.[1][2]
Is there a private right of action under the FDBR?
No private right of action is provided in the statute; enforcement is by the Florida Attorney General.[1][2] That means consumer lawsuits under the FDBR itself are not the primary enforcement risk.[1][2]
What is the cure period under the FDBR?
The Attorney General generally must give notice and allow 30 days to cure before bringing an enforcement action.[1][2] That cure window is important, but it does not eliminate liability if the violation is not corrected or if the facts support enforcement under the statute.[1][2]
Does the FDBR regulate targeted advertising and profiling?
Yes. Covered consumers have opt-out rights for targeted advertising and certain profiling, and those activities are also among the processing operations that trigger data protection assessments.[1][2] Businesses that rely on ad-tech or automated decisioning should treat these as high-priority compliance areas.[1][2]
Are there 2025–2026 amendments that changed the law?
The official 2026 statutory text still cites the original 2023 enactment and 1 July 2024 effective date, and no later official text found here changed the core compliance structure.[1][2] If an organization relies on a secondary source claiming a later amendment or delay, it should verify against the current Florida statutes before updating controls.[1][2]
Sources
- Florida Statutes, Fla. Stat. § 501.701 (2026)
- The Florida Senate, Chapter 501 Section 701 (2026)
- Florida Statutes, Chapter 501, Part V, official statutory chapter
- DWT, Florida Digital Bill of Rights signed into law
- DataGrail, Florida state privacy law overview
- PrivacyLawMap, Florida FDBR privacy law compliance guide
- Future of Privacy Forum, effective dates chart
Put it into practice
- Generate the policy: Florida privacy policy generator (generatepolicy.com)
- Buy the policy pack: State Privacy Law Checklist (cyberpolicy.shop)
- Build it yourself: 2026 US Privacy Program Workbook (ciso.diy)