EnglishEspañol
Alabama flag

Alabama

Alabama Data Privacy Laws: Breach Notification & Consumer Rights (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 17 primary sources cited on this page. How we verify our legal content

Alabama Data Privacy Laws: Breach Notification & Consumer Rights (2026)

Frequently Asked Questions

Does Alabama have a comprehensive consumer data privacy law?

Yes, as of April 17, 2026. Governor Kay Ivey signed the Alabama Personal Data Protection Act (ALDPA, HB 351) into law that day, making Alabama the 21st state with a comprehensive consumer privacy statute. The law does not take effect until May 1, 2027, so consumer rights under the ALDPA are not yet enforceable. Until then, the Data Breach Notification Act of 2018 (Ala. Code 8-38-1 through 8-38-12) remains the primary operative state data protection statute.

Who does the Alabama Personal Data Protection Act cover?

The ALDPA applies to any person conducting business in Alabama or targeting Alabama residents that either (1) processes the personal data of more than 25,000 Alabama consumers per year, excluding data processed solely to complete a payment transaction, or (2) derives more than 25% of gross revenue from selling personal data regardless of processing volume. Financial institutions subject to the GLBA, HIPAA-covered entities, higher education institutions, and small businesses with fewer than 500 employees that do not sell data are exempt.

How long does a business have to notify me of a data breach in Alabama?

Under the Alabama Data Breach Notification Act (Ala. Code 8-38-5), businesses must notify affected Alabama residents within 45 days of determining that a breach has occurred and is reasonably likely to cause substantial harm. The notice must include the date or estimated date of the breach, a description of the information exposed, what steps the business is taking to restore security, what steps the individual can take to protect against identity theft, and contact information for a representative who can answer questions.

What penalties can Alabama impose on businesses that violate data privacy laws?

Under the Data Breach Notification Act, failure to notify carries civil penalties of up to $5,000 per consecutive day of noncompliance, with no aggregate cap on that daily penalty. A separate track applies to knowing failures to notify: Ala. Code 8-38-9(a)(2) subjects them to the Deceptive Trade Practices Act penalty provisions in Ala. Code 8-19-11 and caps the civil penalties assessed under that section at $500,000 per breach. Under the ALDPA (effective May 1, 2027), violations carry penalties of up to $15,000 per violation, enforced by the Attorney General after a mandatory 45-day cure period. Neither statute provides a private right of action for individual consumers.

Does Alabama recognize the Global Privacy Control or other universal opt-out signals?

Not as a general obligation. The version of HB 351 that passed the House would have required controllers to respond to opt-out preference signals by January 1, 2028, and the Senate amendment adopted before final passage on April 7, 2026 struck that requirement. The enacted act sets out no mechanism for recognizing universal signals such as the Global Privacy Control, so Alabama consumers should expect to submit individual opt-out requests to each controller. One residual clause survives: under Section 6(c)(1), if a consumer's opt-out preference signal conflicts with a controller-specific privacy setting or participation in a loyalty or rewards program, the controller must comply with the signal.

What sensitive data categories require consent under Alabama law?

The ALDPA requires controller consent before processing sensitive personal data, defined to include data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnoses, information about an individual's sex life, sexual orientation, citizenship or immigration status, genetic or biometric data processed to uniquely identify a person, precise geolocation data, and personal data collected from a known child under 13. For consumers aged 13 to 15, consent is required specifically for targeted advertising and data sales.

What is the Alabama Insurance Data Security Law?

The Alabama Insurance Data Security Law (Ala. Code 27-62, Act No. 2019-98) applies to insurance licensees regulated by the Alabama Department of Insurance. It requires a written information security program, a risk assessment process, due diligence in service-provider oversight, a written incident response plan, and notification to the Commissioner of Insurance within three business days of detecting a cybersecurity event. It is based on the NAIC Insurance Data Security Model Law.

How does the TAKE IT DOWN Act affect Alabama residents?

The TAKE IT DOWN Act (Pub. L. 119-12, signed May 19, 2025) is a federal law prohibiting nonconsensual intimate images, including AI-generated deepfakes. The criminal prohibition took effect immediately in May 2025. The platform-removal obligations took effect May 19, 2026, with the FTC now enforcing. Covered platforms must process removal requests and remove qualifying content within 48 hours. Alabama residents can report noncompliant platforms at TakeItDown.ftc.gov.

Is Alabama a one-party or two-party consent state for recording?

Alabama is a one-party consent state. Under Ala. Code 13A-11-30 et seq., a person may lawfully record a conversation in which they participate, or with the consent of at least one party to the conversation. Recording without any party's consent is a criminal violation. Federal wiretap law under the Electronic Communications Privacy Act (ECPA) also sets a one-party consent floor for interstate calls.

Are HIPAA-covered entities exempt from Alabama's breach notification law?

Yes. Under Ala. Code 8-38-11, entities already subject to federal breach notification requirements, including HIPAA-covered entities and GLBA-regulated financial institutions, are exempt from the Alabama Data Breach Notification Act, provided they comply with the applicable federal requirements. However, when a breach affects more than 1,000 Alabama residents, they must still provide a copy of any required notice to the Alabama Attorney General.

Updates

Corrected Alabama's identity theft and identity trafficking offenses to Class B felonies with no dollar threshold and the statutory five-document inference, sourced the $500,000 breach-notice penalty cap to Ala. Code 8-38-9(a)(2), qualified the universal opt-out signal discussion to reflect the clause that survives in Section 6(c)(1) of the enacted law, and replaced unverified legislative vote tallies with the dates certified on the enrolled act.

Corrected the Alabama Personal Data Protection Act description to remove a data-protection-assessment requirement and an Attorney General cost/fee-recovery power that the enacted statute does not contain, fixed the individual data-breach notice content list, clarified that the $500,000 penalty cap applies to a separate enforcement track from the $5,000-per-day fine, completed two incomplete statutory category lists (sensitive data and significant decisions), and updated several outdated citation links.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

May 2026 refresh: Updated to reflect Alabama Personal Data Protection Act (HB 351) signed into law by Governor Ivey on April 17, 2026 (effective May 1, 2027). Added ALDPA coverage including scope thresholds, consumer rights, sensitive data definitions, enforcement model ($15,000 per violation, 45-day cure), and notable omissions (no universal opt-out signal, no private right of action). Added Marriott $52M multistate settlement (2024). Added TAKE IT DOWN Act FTC enforcement effective May 19, 2026. Added Alabama Insurance Data Security Law (Act No. 2019-98) section. Added one-party consent recording law reference. Expanded FAQ to 10 questions. Added 20 citations.

Reviewed and approved by an editor

Sources and References

  1. Alabama Data Breach Notification Act of 2018 (Full Text)(acua.alabama.gov).gov
  2. Data Breach Notification - Alabama AG(alabamaag.gov).gov
  3. Alabama Code Title 8, Chapter 38(alison.legislature.state.al.us).gov
  4. Section 8-38-2: Definitions(alison.legislature.state.al.us).gov
  5. AG Announces Final Passage of Breach Notification Act(alabamaag.gov).gov
  6. Governor Ivey Signs Breach Notification Act(alabamaag.gov).gov
  7. Blackbaud $49.5M Settlement - Alabama AG(alabamaag.gov).gov
  8. Section 8-38-10: Disposal of Records(alison.legislature.state.al.us).gov
  9. Consumer Identity Protection Act(law.justia.com)
  10. HB 351: Alabama Personal Data Protection Act(alison.legislature.state.al.us).gov
  11. HIPAA Privacy Rule - HHS(hhs.gov).gov
  12. Gramm-Leach-Bliley Act - FTC(ftc.gov).gov
  13. HB 351 Enrolled Text - Alabama Personal Data Protection Act (2026)(alison.legislature.state.al.us).gov
  14. Alabama Insurance Data Security Law (Act No. 2019-98) - Full Text(aldoi.gov).gov
  15. Fair Credit Reporting Act - Federal Trade Commission(ftc.gov).gov
  16. FTC Begins Enforcing the TAKE IT DOWN Act (May 2026)(ftc.gov).gov
  17. TAKE IT DOWN Act - Federal Trade Commission Legal Library(ftc.gov).gov
  18. Children's Online Privacy Protection Rule (COPPA) - Federal Trade Commission(ftc.gov).gov
  19. Alabama Becomes 21st State With Comprehensive Consumer Privacy Law - Hunton Andrews Kurth(hunton.com)
  20. Alabama Becomes 21st State to Enact Comprehensive Privacy Law - DLA Piper Privacy Matters(privacymatters.dlapiper.com)
  21. Alabama Enacts Comprehensive Privacy Law - Inside Privacy (Covington)(insideprivacy.com)
  22. Alabama Personal Data Protection Act - Future of Privacy Forum(fpf.org)
  23. What Businesses Need to Know About the Alabama Personal Data Protection Act - Davis Wright Tremaine(dwt.com)
  24. Alabama Set to Add Variation to US State Privacy Patchwork - IAPP(iapp.org)
  25. Ala. Code 8-38-9: Violations of Notification Requirements (source of the $500,000 per-breach cap)(alison.legislature.state.al.us)
  26. Ala. Code 13A-8-192: Identity Theft (Class B felony)(alison.legislature.state.al.us)
  27. Ala. Code 13A-8-193: Trafficking in Stolen Identities (Class B felony)(alison.legislature.state.al.us)
  28. HB 351 Engrossed (House-passed) text: the opt-out preference signal requirement later struck by Senate amendment(alison.legislature.state.al.us)
Share: