Alabama
Alabama Data Privacy Laws: Breach Notification & Consumer Rights (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 17 primary sources cited on this page. How we verify our legal content

Alabama governs consumer data privacy through two statutes: the Data Breach Notification Act of 2018 (Ala. Code 8-38-1) requiring breach notice within 45 days, and the Alabama Personal Data Protection Act (HB 351), signed April 17, 2026 and effective May 1, 2027, granting residents rights to access, correct, and delete personal data.
Alabama became the 21st state to enact a comprehensive consumer data privacy law when Governor Kay Ivey signed House Bill 351, the Alabama Personal Data Protection Act (ALDPA), on April 17, 2026. The House passed the bill on February 24, 2026; the Senate amended and passed it on April 7, 2026, and the House concurred in the Senate amendment the same day. The law takes effect May 1, 2027.
Before that signing, Alabama's only dedicated data protection statute was the Data Breach Notification Act of 2018 (Ala. Code 8-38-1 through 8-38-12), which made Alabama the last of all 50 states to pass a breach notification law when Governor Ivey signed it on March 28, 2018. That law remains in force alongside the new ALDPA and continues to govern breach notification obligations.
This guide covers both laws in full, along with Alabama's Insurance Data Security Law (Ala. Code 27-62), key enforcement actions, federal laws that apply in Alabama, and practical steps for businesses and residents ahead of the May 2027 effective date.
Alabama also maintains criminal identity theft protections under the Consumer Identity Protection Act (Ala. Code 13A-8-190 through 13A-8-201) and a supplementary enforcement mechanism in the Alabama Deceptive Trade Practices Act (Ala. Code 8-19-1 et seq.).

The Alabama Personal Data Protection Act (ALDPA)
Governor Ivey signed HB 351 into law on April 17, 2026. The ALDPA is a comprehensive consumer privacy statute modeled on the controller-processor framework used in Virginia, Texas, and most other second-wave state privacy laws. It takes effect on May 1, 2027, giving businesses roughly a year to comply.
Who Must Comply
The ALDPA applies to any person that conducts business in Alabama or produces products or services targeted to Alabama residents, and that meets at least one of two thresholds:
- Controls or processes the personal data of more than 25,000 Alabama consumers in a calendar year (excluding data processed solely to complete a payment transaction); or
- Derives more than 25% of gross revenue from the sale of personal data, regardless of the number of consumers whose data is processed.
The 25,000-consumer threshold is the lowest numerical floor among all enacted state comprehensive privacy laws. The revenue-from-sales test also applies regardless of processing volume, a combination no other state law uses. Both factors will bring more businesses into scope than comparable state laws with higher thresholds.
Exemptions
The ALDPA exempts several categories of entities and data:
- Financial institutions and data subject to the Gramm-Leach-Bliley Act (GLBA)
- HIPAA-covered entities and protected health information
- Higher education institutions
- Employee and business-to-business (B2B) data
- Small businesses with fewer than 500 employees that do not sell personal data
- Nonprofit organizations with fewer than 100 employees that do not sell personal data
The exemptions for small businesses and nonprofits are conditional: if the entity sells personal data, the exemptions do not apply. That is a meaningful distinction for data brokers organized as small businesses.
Consumer Rights Under the ALDPA
The ALDPA grants Alabama residents the following rights against controllers:
| Right | Description |
|---|---|
| Confirm | Know whether a controller is processing your personal data |
| Access | Obtain a copy of the personal data being processed |
| Correct | Request correction of inaccurate personal data |
| Delete | Request deletion of personal data the consumer provided or that the controller collected |
| Portability | Receive a portable copy in a commonly used, machine-readable format |
| Opt out of targeted advertising | Stop processing for targeted advertising purposes |
| Opt out of data sales | Stop the sale of personal data to third parties |
| Opt out of profiling | Stop processing for profiling in furtherance of solely automated significant decisions |
"Significant decisions" under the ALDPA are those that result in the provision or denial of critical services, including credit or lending, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunity, health care service, or access to basic necessities such as food or water. Consumers can opt out of profiling that feeds into those outcomes without any human review.
One notable absence: the version of HB 351 that passed the House would have required controllers to respond to opt-out preference signals by January 1, 2028, and the Senate amendment adopted before final passage struck that requirement. The enacted act sets out no mechanism for sending or recognizing universal opt-out signals such as the Global Privacy Control, and Section 6(b) requires only a clear opt-out link on the controller's website or up-to-date contact information for submitting a request. One residual clause survives: under Section 6(c)(1), where a consumer's opt-out preference signal conflicts with an existing controller-specific privacy setting or the consumer's participation in a loyalty, rewards, or club card program, the controller "shall comply with the consumer's opt-out preference signal." Outside that conflict scenario, Alabama consumers should expect to submit individual opt-out requests.
Sensitive Data
The ALDPA defines sensitive data to include:
- Personal data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, information about an individual's sex life, sexual orientation, or citizenship or immigration status
- Genetic or biometric data processed to uniquely identify an individual
- Personal data collected from a known child under age 13
- Precise geolocation data
Controllers must obtain consumer consent before processing sensitive data. For consumers between 13 and 15 years old, consent is required for targeted advertising and data sales.

Controller and Processor Obligations
Controllers (entities that determine the purpose and means of processing) must:
- Limit data collection to what is adequate, relevant, and reasonably necessary for the stated processing purpose (data minimization)
- Implement reasonable administrative, technical, and physical data security practices
- Establish a clear and accessible privacy notice describing what data is processed, why, with whom it is shared, and how consumers can exercise their rights
- Obtain consent before processing sensitive data
- Execute data processing agreements (DPAs) with processors that bind the processor to confidentiality, security, and processing-scope requirements
Unlike Virginia-, Colorado-, and Connecticut-style privacy laws, the ALDPA does not require controllers to conduct or document data protection assessments for high-risk processing activities. That is a notable omission from the statute as enacted.
Consumers have 45 days to receive a response to a rights request. Controllers may extend that period by an additional 45 days with notice to the consumer.
Enforcement and Penalties
The Alabama Attorney General has exclusive enforcement authority under the ALDPA. There is no private right of action. Before filing suit, the Attorney General must issue a notice of violation and give the controller 45 days to cure. The cure period is permanent and does not sunset, which is more business-favorable than states that have eliminated or capped cure periods.
If a controller fails to cure within 45 days, or if the violation cannot be cured, the AG may seek civil penalties of up to $15,000 per violation. The ALDPA does not specify an aggregate cap per investigation or per incident, which means exposure can compound across multiple violations.
The ALDPA does not authorize the AG to recover investigative costs or attorney fees; the injunction action described above is the AG's only additional remedy beyond the civil penalty.
What the ALDPA Does Not Include
The ALDPA notably omits several features present in some other state privacy laws:
- No general universal opt-out signal requirement (the House-passed version's January 1, 2028 signal mandate was removed by Senate amendment, leaving only the residual compliance clause in Section 6(c)(1))
- No data protection assessment (DPA) requirement for high-risk processing activities
- No data broker-specific registration or opt-out framework
- No private right of action for consumers
- No dedicated state privacy agency (enforcement stays with the AG)
- No specific requirements around automated decision-making transparency notices beyond the opt-out right
The Alabama Data Breach Notification Act of 2018
The Data Breach Notification Act (Ala. Code 8-38-1 through 8-38-12, Act 2018-396) took effect June 1, 2018. Governor Ivey signed Senate Bill 318 on March 28, 2018, after it passed both chambers unanimously: 101-0 in the House and 30-0 in the Senate. Alabama was the 50th and final state to enact a breach notification law.
The Act applies to any "covered entity" that acquires or uses sensitive personally identifying information (SPII), including corporations, nonprofits, government entities, sole proprietorships, and third-party agents who maintain or process data on behalf of covered entities.
What Is Sensitive Personally Identifying Information?
Under Ala. Code 8-38-2, SPII means an Alabama resident's first name or first initial plus last name combined with one or more of:
| Element | What Counts |
|---|---|
| Social Security number | Non-truncated SSN |
| Government-issued ID | Driver's license, state ID, passport, military ID |
| Financial account data | Account or card number plus access code, password, PIN, or expiration date needed to access the account |
| Medical information | Medical history, physical or mental condition, diagnosis by a health professional |
| Health insurance information | Policy number, subscriber ID, or unique insurer identifier |
| Username or email plus password | Login credentials permitting access to an online account |
Information that has been effectively encrypted, truncated, or rendered unusable is excluded. If the encryption key itself was breached, the exclusion does not apply.
The Substantial Harm Standard
Alabama uses a "substantial harm" threshold: notification is required only when a covered entity determines, after a good-faith and prompt investigation, that the breach is reasonably likely to cause substantial harm to affected individuals. Entities that conclude no substantial harm is likely must document that finding in writing and retain it for at least five years.
This standard is more permissive than states requiring notification for any unauthorized access, regardless of likely injury.
Notification Timeline and Recipients
When substantial harm is reasonably likely, covered entities must notify:
-
Affected Alabama residents: Within 45 days of determining the breach occurred and is likely to cause substantial harm. Notice must describe the breach date (or estimated range), the SPII exposed, the steps taken to restore security, steps the individual can take to protect against identity theft, and a contact for further questions.
-
The Alabama Attorney General: If more than 1,000 individuals are affected, written notice is due within 45 days. The AG maintains a breach notification reporting portal for submissions.
-
Consumer reporting agencies: If more than 1,000 individuals receive notice simultaneously, the covered entity must also notify all nationwide consumer reporting agencies (as defined under the FCRA) without unreasonable delay.
Substitute notice (website posting plus media coverage) is available when direct notice is not feasible due to cost exceeding $500,000, insufficient contact information, or the number of affected individuals exceeding 100,000.
Third-Party Agent Obligations
If a third-party agent determines that a breach has occurred involving data it holds on behalf of a covered entity, it must notify that covered entity within 10 days of determining a breach occurred or having reason to believe one occurred.
Penalties
The Alabama AG has exclusive enforcement authority. A covered entity that fails to timely notify faces civil penalties of up to $5,000 per consecutive day of noncompliance, with no aggregate cap stated for that daily penalty. A separate track applies to knowing violations: under Ala. Code 8-38-9(a)(2), a covered entity or third-party agent that knowingly violates the notification provisions is subject to the penalty provisions of the Alabama Deceptive Trade Practices Act (Ala. Code 8-19-11), and civil penalties assessed under that section "shall not exceed five hundred thousand dollars ($500,000) per breach." There is no private right of action under the breach notification statute, though consumers may pursue claims under the Alabama Deceptive Trade Practices Act.
Record Disposal
Ala. Code 8-38-10 requires covered entities to take reasonable measures to dispose of records containing SPII when those records are no longer needed for legal or business purposes. Disposal must render the information unreadable or undecipherable by any reasonable means, consistent with industry standards. This applies equally to paper and electronic records.
Federal Exemptions
Entities already subject to federal breach notification requirements are exempt from the state Act under Ala. Code 8-38-11, provided they comply with applicable federal law and provide a copy of any required breach notice to the Alabama AG when more than 1,000 individuals are affected. This exemption primarily covers HIPAA-regulated entities and GLBA-regulated financial institutions.

Enforcement Actions
Blackbaud (October 2023)
Attorney General Steve Marshall announced Alabama's participation in a $49.5 million multistate settlement with Blackbaud, a cloud software company. A 2020 ransomware attack exposed sensitive data of millions of consumers at nonprofits and healthcare organizations worldwide. Alabama received $1.6 million from the settlement. The coalition found that Blackbaud failed to implement reasonable security measures and delayed providing accurate information about the scope of the breach to its customers.
Marriott (October 2024)
Alabama joined a coalition of state attorneys general in a $52 million multistate settlement with Marriott International, resolving claims arising from multiple data breaches between 2014 and 2018. The breaches collectively exposed the personal data of hundreds of millions of guests globally, including names, payment card numbers, passport numbers, and dates of birth.
Equifax (2019)
Alabama participated in the $600 million multistate settlement with Equifax following the 2017 breach that exposed the personal and financial data of approximately 147 million Americans.
Alabama Insurance Data Security Law
The Alabama Insurance Data Security Law (Ala. Code 27-62, Act No. 2019-98) was enacted in 2019 and modeled on the NAIC Insurance Data Security Model Law. It applies to insurance licensees regulated by the Alabama Department of Insurance.
Key obligations include:
- Implementing and maintaining a written information security program based on a risk assessment
- Exercising due diligence in selecting and overseeing service providers
- Developing a written incident response plan covering roles, responsibilities, remediation steps, and documentation
- Notifying the Commissioner of Insurance within three business days of determining a cybersecurity event has occurred
- Retaining documentation of cybersecurity events for at least five years
Licensees domiciled in Alabama must certify compliance in writing annually. Licensees subject to HIPAA that maintain a compliant information security program are deemed to meet the Insurance Data Security Law's requirements, provided they submit a written certification.
Alabama Consumer Identity Protection Act
The Consumer Identity Protection Act (Ala. Code 13A-8-190 through 13A-8-201) makes identity theft a criminal offense. Under Ala. Code 13A-8-192, using another person's identifying information without their authorization, consent, or permission and with intent to defraud is identity theft, a Class B felony. The offense is complete on those elements; the statute sets no dollar threshold. Trafficking in stolen identities is also a Class B felony, under Ala. Code 13A-8-193, and possession of five or more identification documents of the same person, or of identifying information of five or more separate persons, creates an inference of the intent that offense requires.
The Act includes restitution provisions, court orders to correct records, and mechanisms to block false information on credit reports.
Alabama Deceptive Trade Practices Act
The Alabama Deceptive Trade Practices Act (Ala. Code 8-19-1 et seq.) prohibits deceptive or unconscionable acts in trade or commerce. While not a dedicated privacy statute, it applies to misleading privacy policy claims, false representations about data security, and failure to honor disclosed privacy commitments.
Unlike the breach notification statute, the Deceptive Trade Practices Act provides a private right of action for consumers. The Attorney General and district attorneys can also seek injunctive relief and civil penalties.
Alabama Wiretap Law and Recording Consent
Alabama follows a one-party consent standard for recording conversations under Ala. Code 13A-11-30 et seq. A person may lawfully record a conversation in which they are a participant, or with the consent of at least one party. Recording a conversation without any party's consent is a criminal violation. For more detail, see the Alabama Recording Laws page.

Federal Laws That Apply in Alabama
Because the ALDPA does not take effect until May 1, 2027, and because it exempts significant sectors, federal law remains a critical layer of privacy protection for Alabama residents.
HIPAA
The Health Insurance Portability and Accountability Act applies to covered entities (healthcare providers, health plans, health clearinghouses) and their business associates. The HIPAA Privacy Rule governs the use and disclosure of protected health information. The Breach Notification Rule requires covered entities to notify affected individuals, HHS, and (for breaches affecting 500+ residents of a state) the media within 60 days of discovering a breach.
GLBA
The Gramm-Leach-Bliley Act applies to financial institutions and requires them to explain data sharing practices, safeguard consumer financial information, and protect nonpublic personal information (NPI). The FTC's updated Safeguards Rule (effective June 9, 2023) strengthened technical security requirements for GLBA-covered entities.
FCRA
The Fair Credit Reporting Act governs consumer reporting agencies and the use of consumer credit information. Alabama residents can dispute inaccurate information in their credit files, place security freezes, and request free annual credit reports under the FCRA and FACTA.
COPPA
The Children's Online Privacy Protection Act requires operators of websites and online services directed to children under 13 to obtain verifiable parental consent before collecting personal information. The FTC enforces COPPA and has issued substantial penalties for violations.
FTC Act Section 5
The FTC's authority under Section 5 of the FTC Act to prohibit unfair or deceptive practices applies broadly to data security failures and misleading privacy representations. Companies that fail to implement reasonable security measures or make false statements in privacy policies have faced FTC enforcement, consent orders, and in some cases civil penalties.
TAKE IT DOWN Act (2025)
The TAKE IT DOWN Act (Pub. L. 119-12, signed May 19, 2025) created a federal criminal prohibition on nonconsensual intimate images (NCII), including AI-generated deepfakes. Section 2 (criminal prohibition) took effect immediately upon signing. Section 3 (platform obligations) became enforceable by the FTC on May 19, 2026. Covered platforms now must provide a process for removal requests and remove qualifying content within 48 hours of a valid request. Violations are subject to FTC civil penalties of up to $53,088 per violation. Alabama residents who are victims of NCII can report noncompliant platforms at TakeItDown.ftc.gov.
APRA Status
The American Privacy Rights Act (APRA), a bipartisan federal comprehensive privacy bill, was introduced in 2024 but did not pass. A revised version (sometimes called APRA 2.0) was introduced in 2025. As of May 2026, no federal comprehensive privacy law has been enacted.

How Alabama Compares to Other States
With the ALDPA signed, Alabama joins a growing majority of states with comprehensive privacy protections. Several distinctions stand out:
Lower threshold: The 25,000-consumer threshold is the lowest of any enacted state comprehensive privacy law, meaning even mid-sized businesses targeting Alabama residents will likely be covered.
No general universal opt-out signal duty: Most states enacted after 2023 require controllers to honor browser-based opt-out signals like the Global Privacy Control. Alabama's enacted text imposes no general recognition requirement, though Section 6(c)(1) still directs a controller to comply with a signal that conflicts with a controller-specific privacy setting or a loyalty program.
Permanent cure period: The 45-day cure period does not sunset. States like Virginia and Connecticut have moved toward eliminating or limiting cure periods. Alabama's permanent cure period is among the most business-favorable provisions in the class of 2026 privacy laws.
No private right of action: Only the AG can sue. Individual residents cannot bring civil claims under the ALDPA, unlike California residents under the CCPA's limited private right for data breaches.
AG-only enforcement: Similar to Virginia, Texas, Indiana, and most other states outside California.
For comparison with laws in other states, see the Data Privacy Laws hub.
Compliance Steps for Businesses
For businesses that will be subject to the ALDPA by May 1, 2027:
-
Determine if the law applies: Assess whether you process data of more than 25,000 Alabama consumers, or whether more than 25% of gross revenue comes from data sales.
-
Conduct a data inventory: Map what personal data you collect, why, and where it goes. This is the foundation for data minimization compliance and for building an accurate privacy notice.
-
Update privacy notices: The ALDPA requires clear disclosure of processing purposes, data categories, third-party sharing, and consumer rights.
-
Build a rights-request process: Establish a mechanism to receive and respond to access, correction, deletion, portability, and opt-out requests within the 45-day window.
-
Audit data processing agreements: Ensure all processors you work with have executed DPAs meeting the ALDPA's requirements.
-
Note the assessment gap: Unlike Virginia, Colorado, and Connecticut, the ALDPA does not require controllers to conduct or document data protection assessments. No formal assessment step is needed to comply with the statute as enacted.
-
Verify breach notification procedures: The Data Breach Notification Act is already in force. Confirm you have a 45-day notification workflow and a mechanism to report to the AG when more than 1,000 residents are affected.
-
Check Insurance Data Security compliance: If you hold an Alabama insurance license, verify your written information security program and incident response plan meet Ala. Code 27-62.
How Alabama Residents Can Exercise Rights
Until May 1, 2027, the ALDPA consumer rights are not yet enforceable. After that date, residents can:
- Submit rights requests directly to controllers through their designated privacy channels (typically a web form or email address listed in the privacy policy)
- Expect a response within 45 days, with up to a 45-day extension
- File a complaint with the Alabama Attorney General's Consumer Protection Section if a controller fails to honor a request
Currently enforceable rights:
- Data breach notification: Report a breach notification failure to the AG's office
- Credit file rights: Request a free credit freeze or dispute inaccurate data with Equifax, Experian, and TransUnion under the FCRA
- HIPAA complaints: File with the HHS Office for Civil Rights
- NCII removal: Report noncompliant platforms to the FTC at TakeItDown.ftc.gov
- FTC complaints: File at ReportFraud.ftc.gov for deceptive privacy practices
For recording laws and wiretap consent in Alabama, see Alabama Recording Laws. For data privacy laws across all states, visit the Data Privacy Laws hub.
This article is for informational purposes only and does not constitute legal advice. Consult a qualified attorney licensed in Alabama for guidance on your specific situation. Laws and regulations may change; verify all information with official state sources.
More Alabama Laws
Frequently Asked Questions
Does Alabama have a comprehensive consumer data privacy law?
Yes, as of April 17, 2026. Governor Kay Ivey signed the Alabama Personal Data Protection Act (ALDPA, HB 351) into law that day, making Alabama the 21st state with a comprehensive consumer privacy statute. The law does not take effect until May 1, 2027, so consumer rights under the ALDPA are not yet enforceable. Until then, the Data Breach Notification Act of 2018 (Ala. Code 8-38-1 through 8-38-12) remains the primary operative state data protection statute.
Who does the Alabama Personal Data Protection Act cover?
The ALDPA applies to any person conducting business in Alabama or targeting Alabama residents that either (1) processes the personal data of more than 25,000 Alabama consumers per year, excluding data processed solely to complete a payment transaction, or (2) derives more than 25% of gross revenue from selling personal data regardless of processing volume. Financial institutions subject to the GLBA, HIPAA-covered entities, higher education institutions, and small businesses with fewer than 500 employees that do not sell data are exempt.
How long does a business have to notify me of a data breach in Alabama?
Under the Alabama Data Breach Notification Act (Ala. Code 8-38-5), businesses must notify affected Alabama residents within 45 days of determining that a breach has occurred and is reasonably likely to cause substantial harm. The notice must include the date or estimated date of the breach, a description of the information exposed, what steps the business is taking to restore security, what steps the individual can take to protect against identity theft, and contact information for a representative who can answer questions.
What penalties can Alabama impose on businesses that violate data privacy laws?
Under the Data Breach Notification Act, failure to notify carries civil penalties of up to $5,000 per consecutive day of noncompliance, with no aggregate cap on that daily penalty. A separate track applies to knowing failures to notify: Ala. Code 8-38-9(a)(2) subjects them to the Deceptive Trade Practices Act penalty provisions in Ala. Code 8-19-11 and caps the civil penalties assessed under that section at $500,000 per breach. Under the ALDPA (effective May 1, 2027), violations carry penalties of up to $15,000 per violation, enforced by the Attorney General after a mandatory 45-day cure period. Neither statute provides a private right of action for individual consumers.
Does Alabama recognize the Global Privacy Control or other universal opt-out signals?
Not as a general obligation. The version of HB 351 that passed the House would have required controllers to respond to opt-out preference signals by January 1, 2028, and the Senate amendment adopted before final passage on April 7, 2026 struck that requirement. The enacted act sets out no mechanism for recognizing universal signals such as the Global Privacy Control, so Alabama consumers should expect to submit individual opt-out requests to each controller. One residual clause survives: under Section 6(c)(1), if a consumer's opt-out preference signal conflicts with a controller-specific privacy setting or participation in a loyalty or rewards program, the controller must comply with the signal.
What sensitive data categories require consent under Alabama law?
The ALDPA requires controller consent before processing sensitive personal data, defined to include data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnoses, information about an individual's sex life, sexual orientation, citizenship or immigration status, genetic or biometric data processed to uniquely identify a person, precise geolocation data, and personal data collected from a known child under 13. For consumers aged 13 to 15, consent is required specifically for targeted advertising and data sales.
What is the Alabama Insurance Data Security Law?
The Alabama Insurance Data Security Law (Ala. Code 27-62, Act No. 2019-98) applies to insurance licensees regulated by the Alabama Department of Insurance. It requires a written information security program, a risk assessment process, due diligence in service-provider oversight, a written incident response plan, and notification to the Commissioner of Insurance within three business days of detecting a cybersecurity event. It is based on the NAIC Insurance Data Security Model Law.
How does the TAKE IT DOWN Act affect Alabama residents?
The TAKE IT DOWN Act (Pub. L. 119-12, signed May 19, 2025) is a federal law prohibiting nonconsensual intimate images, including AI-generated deepfakes. The criminal prohibition took effect immediately in May 2025. The platform-removal obligations took effect May 19, 2026, with the FTC now enforcing. Covered platforms must process removal requests and remove qualifying content within 48 hours. Alabama residents can report noncompliant platforms at TakeItDown.ftc.gov.
Is Alabama a one-party or two-party consent state for recording?
Alabama is a one-party consent state. Under Ala. Code 13A-11-30 et seq., a person may lawfully record a conversation in which they participate, or with the consent of at least one party to the conversation. Recording without any party's consent is a criminal violation. Federal wiretap law under the Electronic Communications Privacy Act (ECPA) also sets a one-party consent floor for interstate calls.
Are HIPAA-covered entities exempt from Alabama's breach notification law?
Yes. Under Ala. Code 8-38-11, entities already subject to federal breach notification requirements, including HIPAA-covered entities and GLBA-regulated financial institutions, are exempt from the Alabama Data Breach Notification Act, provided they comply with the applicable federal requirements. However, when a breach affects more than 1,000 Alabama residents, they must still provide a copy of any required notice to the Alabama Attorney General.
Updates
Corrected Alabama's identity theft and identity trafficking offenses to Class B felonies with no dollar threshold and the statutory five-document inference, sourced the $500,000 breach-notice penalty cap to Ala. Code 8-38-9(a)(2), qualified the universal opt-out signal discussion to reflect the clause that survives in Section 6(c)(1) of the enacted law, and replaced unverified legislative vote tallies with the dates certified on the enrolled act.
Corrected the Alabama Personal Data Protection Act description to remove a data-protection-assessment requirement and an Attorney General cost/fee-recovery power that the enacted statute does not contain, fixed the individual data-breach notice content list, clarified that the $500,000 penalty cap applies to a separate enforcement track from the $5,000-per-day fine, completed two incomplete statutory category lists (sensitive data and significant decisions), and updated several outdated citation links.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
May 2026 refresh: Updated to reflect Alabama Personal Data Protection Act (HB 351) signed into law by Governor Ivey on April 17, 2026 (effective May 1, 2027). Added ALDPA coverage including scope thresholds, consumer rights, sensitive data definitions, enforcement model ($15,000 per violation, 45-day cure), and notable omissions (no universal opt-out signal, no private right of action). Added Marriott $52M multistate settlement (2024). Added TAKE IT DOWN Act FTC enforcement effective May 19, 2026. Added Alabama Insurance Data Security Law (Act No. 2019-98) section. Added one-party consent recording law reference. Expanded FAQ to 10 questions. Added 20 citations.
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Code of Alabama 1975, Title 8: Commercial Law and Consumer Protection.
§ 8-38-5Notice of Security Breach - Individuals Affected.In forcecited in 3 of our articles
(a) A covered entity that is not a third-party agent that determines under Section 8-38-4 that, as a result of a breach of security, sensitive personally identifying information has been acquired or is reasonably believed to have been acquired by an unauthorized person, and is reasonably likely to cause substantial harm to the individuals to whom the information relates, shall give notice of the breach to each individual. (b) Notice to individuals under subsection (a) shall be made as expeditiously as possible and without unreasonable delay, taking into account the time necessary to allow the covered entity to conduct an investigation in accordance with Section 8-38-4. Except as provided in subsection (c), the covered entity shall provide notice within 45 days of the covered entity’s receipt of notice from a third-party agent that a breach has occurred or upon the covered entity’s determination that a breach has occurred and is reasonably likely to cause substantial harm to the individuals to whom the information relates.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at alison.legislature.state.al.us
Also relied on in: Alabama Biometric Privacy Laws: Collection, Consent & Penalties (2026), Alabama Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 8-38-2Definitions.In forcecited in 3 of our articles
For the purposes of this chapter, the following terms have the following meanings: (1) BREACH OF SECURITY or BREACH. The unauthorized acquisition of data in electronic form containing sensitive personally identifying information. Acquisition occurring over a period of time committed by the same entity constitutes one breach. The term does not include any of the following: a. Good faith acquisition of sensitive personally identifying information by an employee or agent of a covered entity, unless the information is used for a purpose unrelated to the business or subject to further unauthorized use. b. The release of a public record not otherwise subject to confidentiality or nondisclosure requirements. c. Any lawful investigative, protective, or intelligence activity of a law enforcement or intelligence agency of the state, or a political subdivision of the state. (2) COVERED ENTITY. A person, sole proprietorship, partnership, government entity, corporation, nonprofit, trust, estate, cooperative association, or other business entity that acquires or uses sensitive personally identifying information. (3) DATA IN ELECTRONIC FORM.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at alison.legislature.state.al.us
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2020
Opinions citing this section in our collection:
- Blahous v. Sarrell Regional Dental Center for Public Health, Inc. (District Court, M.D. Alabama 2020)“…or used by an individual unauthorized to do so. See, e.g., Ala. Code § 8-38-2(1). In the usual case, these attac…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 8-38-10Disposal of Records Containing Sensitive Personally Identifying Information.In forcecited in 2 of our articles
A covered entity or third-party agent shall take reasonable measures to dispose, or arrange for the disposal, of records containing sensitive personally identifying information within its custody or control when the records are no longer to be retained pursuant to applicable law, regulations, or business needs. Disposal shall include shredding, erasing, or otherwise modifying the personal information in the records to make it unreadable or undecipherable through any reasonable means consistent with industry standards.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at alison.legislature.state.al.us
§ 8-38-11Exemptions - Federal.In forcecited in 2 of our articles
An entity subject to or regulated by federal laws, rules, regulations, procedures, or guidance on data breach notification established or enforced by the federal government is exempt from this chapter as long as the entity does all of the following: (1) Maintains procedures pursuant to those laws, rules, regulations, procedures, or guidance. (2) Provides notice to affected individuals pursuant to those laws, rules, regulations, procedures, or guidance. (3) Timely provides a copy of the notice to the Attorney General when the number of individuals the entity notified exceeds 1,000.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at alison.legislature.state.al.us
§ 8-38-1Short Title.In forcecited in 3 of our articles
This chapter may be cited and shall be known as the Alabama Data Breach Notification Act of 2018.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at alison.legislature.state.al.us
§ 8-19-11Penalties.In forcecited in 3 of our articles
(a) Any person who violates the terms of an injunction or order issued under this chapter shall forfeit and pay a civil penalty of not more than $25,000 per violation and shall be adjudged in contempt. For the purpose of this section, any circuit court issuing an injunction or order under this chapter shall retain jurisdiction, and in such cases the Attorney General or the district attorney acting in the name of the state may petition for recovery of such civil penalties. (b) Any person who is knowingly engaging in or has knowingly engaged in any act or practice declared unlawful by Section 8-19-5 shall forfeit and pay a civil penalty of not more than $2,000 per violation upon petition by the Attorney General or a district attorney acting in the name of the state to the circuit court for the county in which the defendant resides, is doing business, or has his/her principal place of business, or the county in which the unlawful act or practice was or is being committed.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at alison.legislature.state.al.us
Cited in 4 court opinions in our collectionLatest citing opinion in our collection: 1999
Opinions citing this section in our collection:
- BMW of North America, Inc. v. Gore (Supreme Court of Alabama 1997, 701 So. 2d 507)“…willful violation of the Deceptive Trade Practices Act. See Ala.Code 1975, § 8-19-11. After this action was filed, the Legis…”
- Ford Motor Co. v. Sperau (Supreme Court of Alabama 1997, 708 So. 2d 111)“…nd it specifically used the $2,000 civil fine imposed under Ala.Code 1975, § 8-19-11(b), not the private right of action of…”
- Inter Medical Supplies, Ltd. v. Ebi Medical Systems, Inc. Electro-Biology, Inc. Biomet, Inc. v. Orthofix, Ltd. Orthofix International, N v. Orthofix, Inc. Orthofix S.R.L. v. Ebi Medical Systems, Inc. Electro-Biology, Inc. Biomet, Inc. Ebi Medical Systems, Inc. Electro-Biology, Inc. Biomet, Inc. (Court of Appeals for the Third Circuit 1999, 181 F.3d 446)“…2000 fine under the state's Deceptive Trade Practices Act, Ala. Code § 8-19-11 (b) (1993), could result in a multimill…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 8-19-1Short Title.In forcecited in 2 of our articles
This chapter shall be known and may be cited as the “Deceptive Trade Practices Act.”
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at alison.legislature.state.al.us
Cited in 48 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- Sam v. Beaird (Court of Civil Appeals of Alabama 1996, 685 So. 2d 742)“…d also hold that the Alabama Deceptive Trade Practices Act, Ala. Code 1975, §§ 8-19-1 through -15, applies to landlord-tenan…”
- Dodd v. Nelda Stephenson Chevrolet, Inc. (Supreme Court of Alabama 1993, 626 So. 2d 1288)“…ty to disclose, Hembree Motors also has an obligation under Ala.Code 1975, § 8-19-1 et seq., to disclose material facts reg…”
- Cheminova America Corporation v. Corker (Supreme Court of Alabama 2000, 779 So. 2d 1175)“…s are preempted by Alabama's Deceptive Trade Practices Act, Ala. Code 1975, §§ 8-19-1 to -15, specifically § 8-19-10 (f). T…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Code of Alabama 1975, Title 13A: Criminal Code.
§ 13A-8-190Short Title.In force
This article shall be known as “The Consumer Identity Protection Act.”
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at alison.legislature.state.al.us
§ 13A-11-30Definitions.In forcecited in 21 of our articles
The following definitions apply to this article: (1) EAVESDROP. To overhear, record, amplify or transmit any part of the private communication of others without the consent of at least one of the persons engaged in the communication, except as otherwise provided by law. (2) PRIVATE PLACE. A place where one may reasonably expect to be safe from casual or hostile intrusion or surveillance, but such term does not include a place to which the public or a substantial group of the public has access. (3) SURVEILLANCE. Secret observation of the activities of another person for the purpose of spying upon and invading the privacy of the person observed.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at alison.legislature.state.al.us
Cited in 5 court opinions in our collectionLatest citing opinion in our collection: 2024
Opinions citing this section in our collection:
- Stinson v. Larson (Court of Civil Appeals of Alabama 2004, 893 So. 2d 462)“…ons Privacy Act of 1986, 18 U.S.C. §§ 2510 et seq., and Ala. Code 1975, §§ 13A-11-30 and 13A-11-31 (a). We note that the f…”
- Ages Group, LP v. Raytheon Aircraft Co., Inc. (District Court, M.D. Alabama 1998, 22 F. Supp. 2d 1310)“…f at least one of the persons engaged in the communication. Ala. Code § 13A-11-30 (1994). Alabama Code § 13A-11-32, prohi…”
- Bartnicki v. Vopper (Supreme Court of the United States 2001, 532 U.S. 514)“…[1] See 18 U. S. C. § 2511 (1) (1994 ed. and Supp. V); Ala. Code § 13A-11-30 et seq. (1994); Alaska Stat. Ann. §…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: One-Party Consent States: Complete 2026 Guide, Alabama Audio Recording Laws: Consent Rules and Penalties, Alabama Dashcam Laws: Legality, Mounting Rules, and Evidence Use
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Alabama Data Breach Notification Act of 2018 (Full Text)(acua.alabama.gov).gov
- Data Breach Notification - Alabama AG(alabamaag.gov).gov
- Alabama Code Title 8, Chapter 38(alison.legislature.state.al.us).gov
- Section 8-38-2: Definitions(alison.legislature.state.al.us).gov
- AG Announces Final Passage of Breach Notification Act(alabamaag.gov).gov
- Governor Ivey Signs Breach Notification Act(alabamaag.gov).gov
- Blackbaud $49.5M Settlement - Alabama AG(alabamaag.gov).gov
- Section 8-38-10: Disposal of Records(alison.legislature.state.al.us).gov
- Consumer Identity Protection Act(law.justia.com)
- HB 351: Alabama Personal Data Protection Act(alison.legislature.state.al.us).gov
- HIPAA Privacy Rule - HHS(hhs.gov).gov
- Gramm-Leach-Bliley Act - FTC(ftc.gov).gov
- HB 351 Enrolled Text - Alabama Personal Data Protection Act (2026)(alison.legislature.state.al.us).gov
- Alabama Insurance Data Security Law (Act No. 2019-98) - Full Text(aldoi.gov).gov
- Fair Credit Reporting Act - Federal Trade Commission(ftc.gov).gov
- FTC Begins Enforcing the TAKE IT DOWN Act (May 2026)(ftc.gov).gov
- TAKE IT DOWN Act - Federal Trade Commission Legal Library(ftc.gov).gov
- Children's Online Privacy Protection Rule (COPPA) - Federal Trade Commission(ftc.gov).gov
- Alabama Becomes 21st State With Comprehensive Consumer Privacy Law - Hunton Andrews Kurth(hunton.com)
- Alabama Becomes 21st State to Enact Comprehensive Privacy Law - DLA Piper Privacy Matters(privacymatters.dlapiper.com)
- Alabama Enacts Comprehensive Privacy Law - Inside Privacy (Covington)(insideprivacy.com)
- Alabama Personal Data Protection Act - Future of Privacy Forum(fpf.org)
- What Businesses Need to Know About the Alabama Personal Data Protection Act - Davis Wright Tremaine(dwt.com)
- Alabama Set to Add Variation to US State Privacy Patchwork - IAPP(iapp.org)
- Ala. Code 8-38-9: Violations of Notification Requirements (source of the $500,000 per-breach cap)(alison.legislature.state.al.us)
- Ala. Code 13A-8-192: Identity Theft (Class B felony)(alison.legislature.state.al.us)
- Ala. Code 13A-8-193: Trafficking in Stolen Identities (Class B felony)(alison.legislature.state.al.us)
- HB 351 Engrossed (House-passed) text: the opt-out preference signal requirement later struck by Senate amendment(alison.legislature.state.al.us)