Alabama
Alabama Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 7 primary sources cited on this page. How we verify our legal content

Alabama has no standalone biometric privacy law in effect today, and its Data Breach Notification Act (Ala. Code 8-38-1 et seq.) does not list biometric data among the categories that trigger a breach notice. That changes on May 1, 2027, when the Alabama Personal Data Protection Act (HB 351, signed into law April 2026) takes effect and classifies biometric data processed to identify a specific person as sensitive data requiring a consumer''s opt-in consent.
Alabama does not have a standalone biometric privacy law. Unlike Illinois, Texas, and Washington, the state has not enacted legislation that specifically regulates how private businesses collect, store, use, or share biometric identifiers such as fingerprints, facial geometry, or iris scans.
Alabama''s breach notification law does not include biometric data in its definition of protected sensitive personally identifying information, so a breach exposing only biometric identifiers does not, by itself, trigger a notice obligation under current law. That gap narrows in 2027, when the Alabama Personal Data Protection Act begins treating biometric data used to identify a person as sensitive data requiring opt-in consent before it can be processed.
This guide explains the current legal framework, what protections exist, where the gaps are, and what may change.
For broader context on Alabama''s overall privacy framework, see the parent guide to Alabama Data Privacy Laws.
How Alabama Defines Biometric Data
Alabama''s Data Breach Notification Act does not currently define biometric data at all. Ala. Code 8-38-2 defines "sensitive personally identifying information" as a person''s first name or initial and last name combined with categories such as a Social Security number, a driver''s license or state ID number, a financial account number with a security code, medical history or health-insurance information, or a username or email address paired with a password. Biometric identifiers such as fingerprints, voiceprints, or retina and iris images are not among the enumerated categories, so a breach that exposes only biometric data does not by itself trigger the Act''s 45-day notice requirement.
That changes on May 1, 2027, when the Alabama Personal Data Protection Act (HB 351, signed into law April 2026) takes effect. It defines biometric data as data generated by automatic measurements of an individual''s biological characteristics, such as a fingerprint, voiceprint, retina, or iris, used to identify a specific person, and classifies it as sensitive data. Covered businesses will need a consumer''s affirmative opt-in consent before processing it.
Until then, biometric data collected in Alabama can still receive indirect protection if it is combined with other information the Act does cover, such as a name plus a financial account number, but the biometric identifier itself is not the trigger.
Alabama Data Breach Notification Act of 2018 (Ala. Code 8-38-1 et seq.)
Alabama''s primary biometric protection comes from the Data Breach Notification Act of 2018, signed into law as Acts 2018-396. This law was among the last state breach notification laws enacted in the United States. Alabama and South Dakota were the final two states to adopt breach notification requirements.
What the Law Requires
Any covered entity that acquires or uses sensitive personally identifying information of Alabama residents must follow several requirements under this law.
Reasonable security measures. Covered entities must implement and maintain reasonable security measures to protect sensitive personally identifying information against a breach of security (Ala. Code 8-38-3).
Good faith investigation. After discovering or being notified of a breach, a covered entity must conduct a good faith and prompt investigation to determine the likelihood that the information has been or will be misused.
Individual notification within 45 days. If a breach compromises information within the Act''s definition of sensitive personally identifying information, such as a name combined with a Social Security number, financial account number, or medical information, and is reasonably likely to cause substantial harm, the entity must notify affected Alabama residents as expeditiously as possible but no later than 45 days after the determination that a breach occurred (Ala. Code 8-38-5). Biometric data alone, without a name and one of the Act''s other enumerated categories, does not trigger this requirement under current law.
Attorney General notification. If the breach affects more than 1,000 individuals, the entity must also notify the Alabama Attorney General within 45 days.
Third-party agent notification. Third-party agents that maintain data on behalf of a covered entity must notify the covered entity within 10 days of discovering a breach.
Penalties for Non-Compliance
A covered entity that fails to comply with notification requirements faces penalties under Ala. Code 8-38-9.
Ala. Code 8-38-9 sets out two separate penalty tracks rather than a single capped one. A covered entity that knowingly (willfully or with reckless disregard) violates the notice requirements is subject to the penalty under Ala. Code 8-19-11, which is capped at $500,000 per breach. Separately, and notwithstanding that cap, any covered entity that fails to take reasonable action to comply with the notice provisions is liable for a civil penalty of up to $5,000 per day for each consecutive day of non-compliance, with no stated dollar ceiling on that track.
A violation of the Act constitutes an unlawful trade practice under the Alabama Deceptive Trade Practices Act (Ala. Code 8-19-1 et seq.).
The Alabama Attorney General holds exclusive authority to bring enforcement actions for civil penalties and to pursue damages on behalf of named individuals. Recovery in such actions is limited to actual damages plus reasonable attorney fees and costs.
No Private Right of Action
Alabama''s breach notification law does not create a private cause of action. Individuals cannot sue a covered entity directly under this statute for failing to provide timely notification. Only the Attorney General can bring enforcement actions.
This is a significant distinction from states like Illinois, where BIPA grants individuals the right to sue and recover statutory damages of $1,000 to $5,000 per violation.
Exemptions
The law includes several exemptions. Information that has been encrypted, secured, or modified by any method or technology that removes personally identifying elements or renders the information unusable is excluded from the definition of sensitive personally identifying information.
Financial institutions that comply with the Gramm-Leach-Bliley Act and entities that comply with HIPAA are deemed in compliance with Alabama''s security requirements.
What Alabama Law Does Not Cover
Alabama''s existing laws leave significant gaps in biometric privacy protection.
No general consent requirement. Alabama does not require businesses or employers to obtain consent before collecting biometric data from adults. An employer can implement fingerprint time clocks or facial recognition systems without notifying employees or getting their approval.
No retention or destruction timelines. The state does not mandate specific retention schedules or destruction timelines for biometric data held by private entities.
No restrictions on biometric data sales. Alabama does not prohibit or restrict the sale or sharing of biometric data with third parties.
No private right of action for collection practices. There is no state law allowing individuals to sue because a company collected their fingerprints or facial scans without consent.
One narrow law enforcement limit, and nothing broader. Alabama''s only statutory restriction on government biometric surveillance covers facial recognition match results. Under Ala. Code 15-10-111, enacted as Act 2022-420, a state or local law enforcement agency may not use facial recognition technology match results as the sole basis to establish probable cause in a criminal investigation or to make an arrest, and may use those results only in conjunction with other lawfully obtained information and evidence. Ala. Code 15-10-110 supplies the definitions of facial biometric data and facial recognition technology. Outside that rule, Alabama has not limited government collection, retention, or sharing of biometric data.
Employer Use of Biometric Data in Alabama
Alabama has no state law that restricts employers from collecting biometric data from employees. Companies operating in Alabama that use fingerprint scanners for timekeeping, facial recognition for building access, or other biometric systems are not required by state law to:
- Provide written notice before collecting biometric data
- Obtain employee consent
- Establish data retention or destruction policies
- Limit sharing of employee biometric data with vendors or third parties
This stands in sharp contrast to Illinois, where employers face statutory damages of $1,000 to $5,000 per violation of the Biometric Information Privacy Act.
That said, employers should still implement reasonable security measures for biometric data as a matter of practice. Under current Alabama law, a breach that exposes only employee biometric data does not by itself trigger the Data Breach Notification Act''s 45-day notice requirement, since biometric data is not among the Act''s enumerated categories; the duty applies only if the biometric data is exposed together with a name and one of the Act''s other covered categories, such as a Social Security or financial account number.
Alabama's New Comprehensive Privacy Law: What Changes for Biometric Data in 2027
Alabama enacted its first comprehensive consumer privacy law in 2026, and it directly addresses biometric data in a way the 2018 breach notification law does not.
HB 351, the Alabama Personal Data Protection Act (APDPA). The Alabama Legislature passed HB 351 in April 2026, and the governor signed it into law that same month. The Act takes effect May 1, 2027, and applies to businesses that control or process the personal data of more than 25,000 Alabama residents, or that derive more than 25 percent of gross revenue from selling personal data. The APDPA classifies genetic or biometric data processed to uniquely identify a person as sensitive data, and it prohibits a covered controller from processing sensitive data concerning a consumer without first obtaining that consumer''s affirmative opt-in consent. The Act''s definition of consumer excludes an individual acting in a commercial or employment context or as an employee or contractor, so that consent duty runs to consumer-facing processing and does not reach biometric data an employer collects from its own workforce.
One earlier bill did not become this law: HB283 (2025 Regular Session) proposed an earlier version of a comprehensive privacy framework and did not pass. HB 351 is the bill that succeeded. A separate 2026 bill, SB272, introduced by Senator Orr, is unrelated to the comprehensive privacy framework. It requires redaction of financial-transaction information, such as account and routing numbers, from public records requested from local boards of education, and it restricts reselling address lists derived from those records, citing the Data Breach Notification Act''s Section 8-38-2 definition of sensitive personally identifying information.
Once the APDPA takes effect, Alabama''s biometric data protection will move closer to the opt-in consent model used by states like Colorado, Connecticut, and Virginia, though Alabama''s law will only apply to businesses that meet its size or revenue thresholds.
Federal Protections That Apply in Alabama
Because Alabama lacks a comprehensive biometric privacy law, federal statutes provide additional protections for residents.
Section 5 of the FTC Act allows the Federal Trade Commission to take enforcement action against companies engaged in unfair or deceptive practices involving biometric data, including failures to secure biometric information.
HIPAA protects biometric data collected or used by covered healthcare entities and their business associates under the Privacy Rule.
COPPA requires parental consent before collecting biometric data from children under 13, enforced by the FTC.
How Alabama Compares to Other States
Alabama falls into a lower tier of states for biometric privacy protection today, though that will change in 2027. Because Alabama''s breach notification law does not separately cover biometric data, and because the state''s new comprehensive privacy law will not take effect until May 2027, Alabama currently lacks both breach-notification coverage and the collection-level protections found in more protective states.
- Illinois has the strongest biometric law in the nation (BIPA), with a private right of action and statutory damages of $1,000 to $5,000 per violation
- Texas and Washington have biometric-specific statutes enforced by their attorneys general
- States with comprehensive privacy laws (Colorado, Connecticut, Virginia) classify biometric data as sensitive and require opt-in consent
- Alabama currently has no biometric-specific protection; a breach exposing only biometric data does not trigger its 2018 breach notification law. Starting May 1, 2027, the Alabama Personal Data Protection Act will require opt-in consent for consumer biometric data processed by covered businesses
This article provides general legal information about Alabama biometric privacy laws. It is not legal advice. Laws and regulations change frequently, and this content may not reflect the most recent developments. Consult a qualified attorney licensed in Alabama for advice about your specific situation.
More Alabama Laws
Frequently Asked Questions
Does Alabama have a biometric privacy law?
Not yet in a comprehensive way. Alabama does not have a standalone biometric privacy statute like Illinois BIPA, and its Data Breach Notification Act of 2018 (Ala. Code 8-38-1 et seq.) does not include biometric data among the categories that trigger a breach notice. That changes on May 1, 2027, when the Alabama Personal Data Protection Act (HB 351, enacted 2026) takes effect and requires covered businesses to obtain opt-in consent before processing biometric data used to identify a person.
Can my employer collect my fingerprints without consent in Alabama?
Yes, under current law. Alabama has no statute requiring employers to obtain consent before collecting biometric data such as fingerprints or facial scans from employees, and employers can implement fingerprint time clocks, facial recognition access systems, or other biometric tools without providing written notice or obtaining approval. A breach that exposes only biometric data does not by itself trigger a notification duty under Alabama''s current breach notification law. The Alabama Personal Data Protection Act does not close this gap when it takes effect on May 1, 2027. The Act defines a consumer to exclude an individual acting in a commercial or employment context or as an employee, owner, director, officer, or contractor, and its opt-in consent duty reaches only sensitive data concerning a consumer, so biometric data an employer collects from its own workforce in that role falls outside it.
What are the penalties for a biometric data breach in Alabama?
Alabama''s Data Breach Notification Act does not treat a breach of biometric data alone as a reportable breach, so its penalties apply only if the biometric data was exposed together with a name and another covered category, such as a Social Security or financial account number. In that scenario, Ala. Code 8-38-9 sets two separate penalty tracks: a covered entity that knowingly violates the notice requirements faces a civil penalty under Ala. Code 8-19-11, capped at $500,000 per breach, while any covered entity that fails to take reasonable action to comply, regardless of intent, is separately liable for up to $5,000 per day for each day of non-compliance, with no stated dollar cap on that track. The Attorney General has exclusive enforcement authority. Starting May 1, 2027, the Alabama Personal Data Protection Act adds separate consent obligations for biometric data, also enforced by the Attorney General.
Can I sue a company in Alabama for collecting my biometric data without permission?
No. Alabama does not provide a private right of action for the unauthorized collection of biometric data. The state''s breach notification law also does not allow individuals to sue directly. Only the Alabama Attorney General can bring enforcement actions. This differs from Illinois, where individuals can recover $1,000 to $5,000 per violation of the Biometric Information Privacy Act.
Does Alabama require businesses to delete biometric data?
No. Alabama does not have a law that requires businesses to delete biometric data after a specific period or upon request. The state has no retention schedule or destruction mandate for biometric information held by private entities. The only data-related destruction requirement exists within the breach notification framework, which focuses on notification obligations rather than data lifecycle management.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected two errors: Alabama does restrict law enforcement use of facial recognition match results under Ala. Code 15-10-111, and the Alabama Personal Data Protection Act's 2027 opt-in consent duty covers consumers, not employees.
Corrected the description of Alabama's breach-notification penalties, which are two separate tracks (an uncapped $5,000-per-day track and a $500,000-per-breach cap that applies only to knowing violations) rather than one $5,000/day-capped-at-$500,000 structure; fixed a mischaracterization of a 2026 bill (SB272) as a competing privacy proposal when it is an unrelated public-records bill; and replaced several dead source links, including one that pointed to the wrong statutory section.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected the page's central premise: Alabama's Data Breach Notification Act (Ala. Code 8-38-2) does not define or cover biometric data, so a biometric-only breach does not trigger the 45-day notice. Added the real, newly enacted protection: the Alabama Personal Data Protection Act (HB 351, signed April 2026, effective May 1, 2027) classifies biometric data as sensitive data requiring opt-in consent. Also swapped two competitor-domain (Justia) citations for official Alabama Legislature sources.
Governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Code of Alabama 1975, Title 8: Commercial Law and Consumer Protection.
§ 8-44-7In force
(a) A controller shall do all of the following: (1) Limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which the personal data is processed. (2) Establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data appropriate to the volume and nature of the personal data at issue. (3) Provide an effective mechanism for a consumer to revoke the consumer’s consent under this chapter which is at least as easy as the mechanism by which the consumer provided the consumer’s consent and, on revocation of the consent, cease to further process the personal data as soon as practicable, but no later than 45 days after complying with the consumer’s opt-out request consistent with this chapter. (b) A controller may not do any of the following: (1) Except as provided in this chapter, process personal data for purposes that are not reasonably necessary to or compatible with the disclosed purposes for which the personal data is processed as disclosed by the controller.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at alison.legislature.state.al.us
§ 8-38-2Definitions.In forcecited in 3 of our articles
For the purposes of this chapter, the following terms have the following meanings: (1) BREACH OF SECURITY or BREACH. The unauthorized acquisition of data in electronic form containing sensitive personally identifying information. Acquisition occurring over a period of time committed by the same entity constitutes one breach. The term does not include any of the following: a. Good faith acquisition of sensitive personally identifying information by an employee or agent of a covered entity, unless the information is used for a purpose unrelated to the business or subject to further unauthorized use. b. The release of a public record not otherwise subject to confidentiality or nondisclosure requirements. c. Any lawful investigative, protective, or intelligence activity of a law enforcement or intelligence agency of the state, or a political subdivision of the state. (2) COVERED ENTITY. A person, sole proprietorship, partnership, government entity, corporation, nonprofit, trust, estate, cooperative association, or other business entity that acquires or uses sensitive personally identifying information. (3) DATA IN ELECTRONIC FORM.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at alison.legislature.state.al.us
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2020
Opinions citing this section in our collection:
- Blahous v. Sarrell Regional Dental Center for Public Health, Inc. (District Court, M.D. Alabama 2020)“…or used by an individual unauthorized to do so. See, e.g., Ala. Code § 8-38-2(1). In the usual case, these attac…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Alabama Data Privacy Laws: Breach Notification & Consumer Rights (2026), Alabama Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 8-38-5Notice of Security Breach - Individuals Affected.In forcecited in 3 of our articles
(a) A covered entity that is not a third-party agent that determines under Section 8-38-4 that, as a result of a breach of security, sensitive personally identifying information has been acquired or is reasonably believed to have been acquired by an unauthorized person, and is reasonably likely to cause substantial harm to the individuals to whom the information relates, shall give notice of the breach to each individual. (b) Notice to individuals under subsection (a) shall be made as expeditiously as possible and without unreasonable delay, taking into account the time necessary to allow the covered entity to conduct an investigation in accordance with Section 8-38-4. Except as provided in subsection (c), the covered entity shall provide notice within 45 days of the covered entity’s receipt of notice from a third-party agent that a breach has occurred or upon the covered entity’s determination that a breach has occurred and is reasonably likely to cause substantial harm to the individuals to whom the information relates.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at alison.legislature.state.al.us
§ 8-38-9Violations of Notification Requirements.In forcecited in 2 of our articles
(a) A violation of the notification provisions of this chapter is an unlawful trade practice under the Alabama Deceptive Trade Practices Act, Chapter 19 of this title, but does not constitute a criminal offense under Section 8-19-12. The Attorney General shall have the exclusive authority to bring an action for civil penalties under this chapter. (1) A violation of this chapter does not establish a private cause of action under Section 8-19-10. Nothing in this chapter may otherwise be construed to affect any right a person may have at common law, by statute, or otherwise. (2) Any covered entity or third-party agent who is knowingly engaging in or has knowingly engaged in a violation of the notification provisions of this chapter is subject to the penalty provisions set out in Section 8-19-11. For the purposes of this chapter, knowingly shall mean willfully or with reckless disregard in failing to comply with the notice requirements of Sections 8-38-5 and 8-38-6. Civil penalties assessed under Section 8-19-11, shall not exceed five hundred thousand dollars ($500,000) per breach.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at alison.legislature.state.al.us
§ 8-19-11Penalties.In forcecited in 3 of our articles
(a) Any person who violates the terms of an injunction or order issued under this chapter shall forfeit and pay a civil penalty of not more than $25,000 per violation and shall be adjudged in contempt. For the purpose of this section, any circuit court issuing an injunction or order under this chapter shall retain jurisdiction, and in such cases the Attorney General or the district attorney acting in the name of the state may petition for recovery of such civil penalties. (b) Any person who is knowingly engaging in or has knowingly engaged in any act or practice declared unlawful by Section 8-19-5 shall forfeit and pay a civil penalty of not more than $2,000 per violation upon petition by the Attorney General or a district attorney acting in the name of the state to the circuit court for the county in which the defendant resides, is doing business, or has his/her principal place of business, or the county in which the unlawful act or practice was or is being committed.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at alison.legislature.state.al.us
Cited in 4 court opinions in our collectionLatest citing opinion in our collection: 1999
Opinions citing this section in our collection:
- BMW of North America, Inc. v. Gore (Supreme Court of Alabama 1997, 701 So. 2d 507)“…willful violation of the Deceptive Trade Practices Act. See Ala.Code 1975, § 8-19-11. After this action was filed, the Legis…”
- Ford Motor Co. v. Sperau (Supreme Court of Alabama 1997, 708 So. 2d 111)“…nd it specifically used the $2,000 civil fine imposed under Ala.Code 1975, § 8-19-11(b), not the private right of action of…”
- Inter Medical Supplies, Ltd. v. Ebi Medical Systems, Inc. Electro-Biology, Inc. Biomet, Inc. v. Orthofix, Ltd. Orthofix International, N v. Orthofix, Inc. Orthofix S.R.L. v. Ebi Medical Systems, Inc. Electro-Biology, Inc. Biomet, Inc. Ebi Medical Systems, Inc. Electro-Biology, Inc. Biomet, Inc. (Court of Appeals for the Third Circuit 1999, 181 F.3d 446)“…2000 fine under the state's Deceptive Trade Practices Act, Ala. Code § 8-19-11 (b) (1993), could result in a multimill…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 8-38-3Reasonable Security Measures; Assessment.In forcecited in 2 of our articles
(a) Each covered entity and third-party agent shall implement and maintain reasonable security measures to protect sensitive personally identifying information against a breach of security. (b) Reasonable security measures means security measures practicable for the covered entity subject to subsection (c), to implement and maintain, including consideration of all of the following: (1) Designation of an employee or employees to coordinate the covered entity’s security measures to protect against a breach of security. An owner or manager may designate himself or herself. (2) Identification of internal and external risks of a breach of security. (3) Adoption of appropriate information safeguards to address identified risks of a breach of security and assess the effectiveness of such safeguards. (4) Retention of service providers, if any, that are contractually required to maintain appropriate safeguards for sensitive personally identifying information. (5) Evaluation and adjustment of security measures to account for changes in circumstances affecting the security of sensitive personally identifying information.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at alison.legislature.state.al.us
§ 8-38-1Short Title.In forcecited in 3 of our articles
This chapter may be cited and shall be known as the Alabama Data Breach Notification Act of 2018.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at alison.legislature.state.al.us
§ 8-19-1Short Title.In forcecited in 2 of our articles
This chapter shall be known and may be cited as the “Deceptive Trade Practices Act.”
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at alison.legislature.state.al.us
Cited in 48 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- Sam v. Beaird (Court of Civil Appeals of Alabama 1996, 685 So. 2d 742)“…d also hold that the Alabama Deceptive Trade Practices Act, Ala. Code 1975, §§ 8-19-1 through -15, applies to landlord-tenan…”
- Dodd v. Nelda Stephenson Chevrolet, Inc. (Supreme Court of Alabama 1993, 626 So. 2d 1288)“…ty to disclose, Hembree Motors also has an obligation under Ala.Code 1975, § 8-19-1 et seq., to disclose material facts reg…”
- Cheminova America Corporation v. Corker (Supreme Court of Alabama 2000, 779 So. 2d 1175)“…s are preempted by Alabama's Deceptive Trade Practices Act, Ala. Code 1975, §§ 8-19-1 to -15, specifically § 8-19-10 (f). T…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Alabama Code 8-38-2, definitions of sensitive personally identifying information (does not include biometric data)(law.justia.com)
- Alabama Data Breach Notification Act of 2018 (Acts 2018-396)(alabamaag.gov).gov
- Ala. Code 8-38-5 individual breach notification requirements(law.justia.com)
- Ala. Code 8-38-9: two penalty tracks -- up to $5,000/day (uncapped) for any noncompliant covered entity, and separately up to $500,000 per breach under 8-19-11 for knowing violations(law.justia.com)
- Alabama Attorney General data breach notification page(alabamaag.gov).gov
- Alabama SB272 (2026 Regular Session)(alison.legislature.state.al.us).gov
- Alabama HB283 Personal Data Protection Act (2025)(alison.legislature.state.al.us).gov
- FTC Act Section 5 enforcement authority(ftc.gov).gov
- HIPAA Privacy Rule(hhs.gov).gov
- COPPA rule on children online privacy(ftc.gov).gov
- Alabama HB 351 (2026), Alabama Personal Data Protection Act, enrolled bill (signed April 2026, effective May 1, 2027)(alison.legislature.state.al.us)
- Alabama SB56 (2022 Regular Session), enrolled: prohibits state and local law enforcement from using facial recognition match results as the sole basis for probable cause or arrest (Act 2022-420)(alison.legislature.state.al.us)
- Ala. Code 15-10-111, use of facial recognition technology match results to establish probable cause or to make an arrest(alison.legislature.state.al.us)