Alabama
Alabama Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 5 primary sources cited on this page. How we verify our legal content

Alabama's Data Breach Notification Act of 2018 (Ala. Code 8-38-5) requires covered entities to notify affected residents within 45 days of determining a qualifying breach occurred. Businesses must also notify the Alabama Attorney General within that same 45-day window when the number of residents they are required to notify exceeds 1,000.
Alabama was the last state in the country to enact a data breach notification law. Governor Kay Ivey signed the Data Breach Notification Act of 2018 (Act 2018-396) on March 28, 2018, with an effective date of June 1, 2018. The law is codified at Ala. Code 8-38-1 through 8-38-12.
For a broader overview of the state's privacy framework, see the parent guide to Alabama Data Privacy Laws.
The act requires businesses, government agencies, and other entities that handle sensitive personal information of Alabama residents to investigate potential breaches, notify affected individuals, and report large-scale incidents to the Attorney General.
Who Must Comply With the Alabama Data Breach Notification Act
The law applies to any "covered entity," which Ala. Code 8-38-2 defines broadly. It includes any person, sole proprietorship, partnership, government entity, corporation, nonprofit, trust, estate, cooperative association, or other business entity that acquires or uses sensitive personally identifying information.
Third-party agents, meaning entities that have been contracted to maintain, store, or process data on behalf of a covered entity, are also subject to the law. They must notify the covered entity no later than 10 days after determining that a breach occurred, or after having reason to believe one occurred, per Ala. Code 8-38-8.
Government entities are covered and are subject to the notice requirements. A government entity that acquires and maintains SPII from a government employer, and that has to notify an individual under the act, must also notify that individual's employing government entity, per Ala. Code 8-38-9.
What Information Triggers Notification
Alabama's law protects "sensitive personally identifying information" (SPII). Under Ala. Code 8-38-2, SPII means an Alabama resident's first name or first initial and last name combined with one or more of the following data elements:
- Non-truncated Social Security number or tax identification number
- Non-truncated driver's license number, state-issued ID number, passport number, military ID number, or other unique government-issued identification number
- Financial account number, credit card number, or debit card number combined with any security code, access code, password, expiration date, or PIN needed to access the account
- Medical information, defined as any information about an individual's medical history, mental or physical condition, or medical treatment or diagnosis by a healthcare professional
- Health insurance policy number or subscriber identification number, along with any unique identifier used by a health insurer to identify the individual
- Username or email address combined with a password or security question and answer that would permit access to an online account affiliated with the covered entity that is reasonably likely to contain, or is used to obtain, SPII
The law only applies to data in electronic form. Paper records are not covered by the notification requirements.
How Alabama Defines a Data Breach
Under Ala. Code 8-38-2, a "breach of security" means the unauthorized acquisition of data in electronic form containing SPII. Multiple unauthorized acquisitions by the same entity over a period of time count as a single breach.
The definition excludes three categories of events:
- Good faith acquisition of data by an employee or agent of a covered entity, as long as the information is not used for an unrelated purpose or subject to further unauthorized disclosure
- Release of public records not otherwise subject to confidentiality requirements
- Lawful investigative, protective, or intelligence activity by law enforcement or intelligence agencies
The Substantial Harm Threshold
Alabama's notification requirement includes a threshold that many other states lack. Under Ala. Code 8-38-4, notification is only required when the covered entity determines, after a good-faith and prompt investigation, that the breach is "reasonably likely to cause substantial harm" to affected individuals.
This means not every technical breach triggers a notification obligation. The covered entity must assess factors including:
- Whether the information is in the physical possession and control of an unauthorized person (for example, a lost or stolen device)
- Whether the information has been downloaded or copied
- Whether the information was used by an unauthorized person, such as through fraudulent accounts or reported identity theft
If the entity concludes after a good-faith investigation that substantial harm is unlikely, it may choose not to notify. However, the entity must document this determination in writing and keep the documentation for at least five years.
Investigation Requirements Before Notification
When a covered entity determines that a breach has or may have occurred, Ala. Code 8-38-4 requires a good-faith and prompt investigation that covers four areas:
- Assessing the nature and scope of the breach
- Identifying the SPII involved and the individuals to whom it relates
- Determining whether the data was acquired or is reasonably believed to have been acquired by an unauthorized person and is reasonably likely to cause substantial harm
- Implementing measures to restore the security and confidentiality of the compromised systems
Notification Timeline and Methods
Once a covered entity determines that notification is required, Ala. Code 8-38-5 mandates that notice be provided "as expeditiously as possible and without unreasonable delay," but no later than 45 days after the entity's determination or receipt of notice from a third-party agent.
Notification may be delivered through:
- Written notice sent to the individual's mailing address on file
- Email notice sent to the individual's email address on file

What Must Be Included in the Notice
Every breach notification letter must contain, at minimum:
- The date, estimated date, or estimated date range of the breach
- A description of the types of SPII acquired by the unauthorized person
- A general description of the actions the covered entity has taken to restore security and confidentiality
- A general description of steps the affected individual can take to protect themselves from identity theft
- Contact information (including a way to reach the covered entity for additional questions about the breach)
Substitute Notice
A covered entity may use substitute notice instead of direct notification when any of the following conditions apply, per Ala. Code 8-38-5:
- Direct notice would be an excessive cost, which the act defines as either a cost that is excessive relative to the covered entity's own resources or a cost to the entity above $500,000
- The entity lacks sufficient contact information for the individuals
- The affected individuals exceed 100,000 persons
Because the excessive-cost test has a resources prong, a small entity can qualify for substitute notice well below the $500,000 figure.
Substitute notice requires posting a conspicuous notice on the entity's website for at least 30 days and providing notice through print and broadcast media in both urban and rural areas where affected individuals reside. An alternative form of substitute notice may be used with the approval of the Attorney General.
Law Enforcement Delay
Notification may be delayed if a law enforcement agency determines in writing that notice would impede a criminal investigation or jeopardize national security. Once the agency lifts the written request, the 45-day notification clock resumes.
Attorney General Notification Requirements
Under Ala. Code 8-38-6, if the number of individuals the covered entity is required to notify under Ala. Code 8-38-5 exceeds 1,000, the entity must also provide written notice to the Alabama Attorney General within the same 45-day window. The trigger is the number of people the entity has to notify, not the raw number of people whose data was involved, so a breach touching more than 1,000 residents that fails the substantial harm test requires no notice to individuals or to the Attorney General.
The AG notification must include:
- A synopsis of the events surrounding the breach at the time notice is given
- The approximate number of affected Alabama residents
- Any free services the entity is offering to affected individuals, along with instructions for using those services
- The name, address, telephone number, and email address of a contact person at the covered entity
The entity may submit supplemental or updated information to the AG at any time. Information marked as confidential that is submitted to the AG is not subject to Alabama's open records laws.
The AG's office provides a Data Breach Notification Form online. Supplemental documentation for previously reported breaches can be sent to ConsumerInterest@AlabamaAG.gov.

Consumer Reporting Agency Notification
When a covered entity discovers circumstances requiring notice under Ala. Code 8-38-5 to more than 1,000 individuals at a single time, Ala. Code 8-38-7 also requires it to notify the consumer reporting agencies that compile and maintain files on consumers on a nationwide basis. The entity must provide notice of the timing, distribution, and content of the notifications sent to affected individuals.
Required Security Measures
Alabama's law goes beyond notification. Ala. Code 8-38-3 requires every covered entity and third-party agent to implement and maintain "reasonable security measures" to protect SPII. These measures must be practicable given the entity's resources and must include:
- Designating an employee or employees to coordinate security measures (an owner or manager may serve in this role)
- Identifying internal and external risks of a breach and adopting appropriate safeguards
- Retaining service providers that are contractually required to maintain appropriate safeguards
- Evaluating and adjusting security measures as circumstances change
The law does not prescribe specific technical controls. Instead, it uses a reasonableness standard that accounts for the entity's cost of implementation relative to its available resources.
Record Disposal Requirements
Ala. Code 8-38-10 requires covered entities and third-party agents to take reasonable measures to dispose of records containing SPII when those records are no longer needed for business or legal purposes. Acceptable disposal methods include shredding, erasing, or otherwise modifying the information to make it unreadable through any reasonable means consistent with industry standards.
Encryption Safe Harbor
Alabama's law includes an encryption safe harbor. If SPII was encrypted, secured, or otherwise rendered unreadable or unusable, no notification is required. However, this protection does not apply if the covered entity knows or has reason to know that the encryption key or security credential was compromised along with the protected data.
Penalties for Noncompliance
Violations of Alabama's breach notification law are treated as unlawful trade practices under the Alabama Deceptive Trade Practices Act (Ala. Code Chapter 19), per Ala. Code 8-38-9. This means:
- A covered entity or third-party agent that knowingly (willfully or with reckless disregard) violates the notice requirements is subject to a civil penalty under Ala. Code 8-19-11, capped at $500,000 per breach
- Separately, and notwithstanding that cap, any covered entity that fails to take reasonable action to comply with the notice provisions is liable for a civil penalty of up to $5,000 per day for each consecutive day of noncompliance, with no stated dollar ceiling
- The Attorney General has exclusive authority to bring enforcement actions for civil penalties
- The AG may also bring actions for actual damages on behalf of affected individuals, plus reasonable attorney's fees and costs
Government entities are the exception to the penalty scheme. Ala. Code 8-38-9 exempts all government entities from any civil penalty authorized by the act, even though they remain subject to its notice requirements. Instead of seeking penalties, the Attorney General may bring an action against a state, county, or municipal official or employee, in his or her official capacity, to compel performance of that person's duties or ministerial acts under the act, or to enjoin the official from acting in bad faith, fraudulently, beyond his or her authority, or under a mistaken interpretation of the law.

Violations do not constitute criminal offenses under the Deceptive Trade Practices Act, and there is no private right of action. Alabama residents cannot individually sue for breach notification failures.
Federal and State Exemptions
HIPAA-Covered Entities
Under Ala. Code 8-38-11, entities regulated by federal data breach notification laws (including HIPAA) are exempt from the Alabama statute, provided they maintain procedures under the applicable federal authority, provide notice as required by federal law, and timely give the Alabama AG a copy of the notice when the number of individuals they notified exceeds 1,000.
State-Regulated Entities
Ala. Code 8-38-12 provides a similar exemption for entities subject to state laws with breach notification requirements that are at least as thorough as the Alabama act. These entities must comply with the applicable state requirements and give the AG a copy of the notice when the number of individuals they notified exceeds 1,000.
Financial Institutions
Financial institutions subject to the Gramm-Leach-Bliley Act (GLBA) are also exempt if they comply with applicable federal breach notification requirements and meet the AG notification threshold.
AG Enforcement in Practice
Alabama has participated in multistate data breach enforcement actions since the law took effect. In October 2023, Attorney General Steve Marshall announced a $49.5 million settlement with Blackbaud, a cloud software company whose 2020 data breach exposed sensitive information from more than 13,000 customers nationwide, including nonprofits, schools, and healthcare entities. Alabama received $1.6 million from the settlement. The action alleged that Blackbaud failed to implement reasonable security measures, delayed notification, and misrepresented the scope of the breach to affected customers.
Sources and References
This article references the Alabama Data Breach Notification Act of 2018 (Ala. Code 8-38-1 through 8-38-12). For the full statutory text, visit the Alabama Legislature website. For information about filing a breach notification or a consumer complaint, visit the Alabama Attorney General's Data Breach Notification page.
This article provides general legal information about Alabama's data breach notification requirements. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official Alabama government sources.
More Alabama Laws
Frequently Asked Questions
Does Alabama's data breach notification law apply to paper records?
No. The Alabama Data Breach Notification Act of 2018 only applies to sensitive personally identifying information in electronic form. Paper records that are lost, stolen, or improperly accessed are not covered by the notification requirements, though the record disposal provisions under Ala. Code 8-38-10 apply to records in any format.
Can an Alabama resident sue a company that fails to send a breach notification?
No. Alabama's law does not create a private right of action. Only the Alabama Attorney General can bring enforcement actions for notification failures. For knowing violations, the AG can seek civil penalties of up to $500,000 per breach under Ala. Code 8-19-11. A covered entity that simply fails to comply with the notice requirements also faces a separate penalty of up to $5,000 per day of noncompliance. Government entities are exempt from every civil penalty under the act, though the AG can sue an official in his or her official capacity to compel compliance. The AG may also pursue actual damages on behalf of named individuals. Residents who believe a company failed to comply can file a complaint with the AG's Consumer Interest Division.
What is the 'substantial harm' threshold in Alabama's breach notification law?
Alabama only requires notification when a breach is 'reasonably likely to cause substantial harm' to affected individuals. The covered entity must conduct a good-faith investigation and assess factors like whether the data was downloaded, whether it is in an unauthorized person's possession, and whether there is evidence of misuse. If the entity determines substantial harm is unlikely, it may forgo notification, but must document that decision in writing and retain the documentation for five years.
How does Alabama's 45-day notification deadline compare to other states?
Alabama's 45-day deadline falls in the middle of the national range. Some states require notification within as few as 30 days (like Colorado and Florida), while others have no specific deadline beyond 'most expedient time possible.' The 45-day clock starts when the covered entity determines a qualifying breach has occurred, or when it receives notice from a third-party agent that a breach occurred.
Are healthcare providers in Alabama subject to both HIPAA and state breach notification rules?
HIPAA-covered entities that comply with federal breach notification requirements under the HIPAA Breach Notification Rule are exempt from Alabama's state law under Ala. Code 8-38-11. However, these entities must still give the Alabama Attorney General a copy of the notice when the number of individuals they notified exceeds 1,000, even when relying on the federal exemption. The exemption only applies if the entity maintains procedures and provides notice as required by federal law.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the 45-day notice trigger and the 1,000-individual Attorney General and credit-bureau thresholds, widened the substitute-notice cost test to include the statute’s relative-to-resources prong, and added Alabama’s exemption of government entities from civil penalties under Ala. Code 8-38-9.
Corrected the penalties section to describe two separate enforcement tracks under Ala. Code 8-38-9: a knowing-violation penalty capped at $500,000 per breach, and a separate uncapped penalty of up to $5,000 per day for noncompliance. Also updated two outdated Alabama government links to their current live addresses.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Code of Alabama 1975, Title 8: Commercial Law and Consumer Protection.
§ 8-38-5Notice of Security Breach - Individuals Affected.In forcecited in 3 of our articles
(a) A covered entity that is not a third-party agent that determines under Section 8-38-4 that, as a result of a breach of security, sensitive personally identifying information has been acquired or is reasonably believed to have been acquired by an unauthorized person, and is reasonably likely to cause substantial harm to the individuals to whom the information relates, shall give notice of the breach to each individual. (b) Notice to individuals under subsection (a) shall be made as expeditiously as possible and without unreasonable delay, taking into account the time necessary to allow the covered entity to conduct an investigation in accordance with Section 8-38-4. Except as provided in subsection (c), the covered entity shall provide notice within 45 days of the covered entity’s receipt of notice from a third-party agent that a breach has occurred or upon the covered entity’s determination that a breach has occurred and is reasonably likely to cause substantial harm to the individuals to whom the information relates.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at alison.legislature.state.al.us
Also relied on in: Alabama Biometric Privacy Laws: Collection, Consent & Penalties (2026), Alabama Data Privacy Laws: Breach Notification & Consumer Rights (2026)
§ 8-38-4Investigation of Security Breach.In force
(a) If a covered entity determines that a breach of security has or may have occurred in relation to sensitive personally identifying information that is accessed, acquired, maintained, stored, utilized, or communicated by, or on behalf of, the covered entity, the covered entity shall conduct a good faith and prompt investigation that includes all of the following: (1) An assessment of the nature and scope of the breach. (2) Identification of any sensitive personally identifying information that may have been involved in the breach and the identity of any individuals to whom that information relates. (3) A determination of whether the sensitive personally identifying information has been acquired or is reasonably believed to have been acquired by an unauthorized person, and is reasonably likely to cause substantial harm to the individuals to whom the information relates. (4) Identification and implementation of measures to restore the security and confidentiality of the systems compromised in the breach.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at alison.legislature.state.al.us
§ 8-38-6Notice of Security Breach - Attorney General.In force
(a) If the number of individuals a covered entity is required to notify under Section 8-38-5 exceeds 1,000, the entity shall provide written notice of the breach to the Attorney General as expeditiously as possible and without unreasonable delay. Except as provided in subsection (c) of Section 8-38-5, the covered entity shall provide the notice within 45 days of the covered entity’s receipt of notice from a third-party agent that a breach has occurred or upon the entity’s determination that a breach has occurred and is reasonably likely to cause substantial harm to the individuals to whom the information relates. (b) Written notice to the Attorney General shall include all of the following: (1) A synopsis of the events surrounding the breach at the time that notice is provided. (2) The approximate number of individuals in the state who were affected by the breach. (3) Any services related to the breach being offered or scheduled to be offered, without charge, by the covered entity to individuals and instructions on how to use the services.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at alison.legislature.state.al.us
§ 8-38-7Notice of Security Breach - Consumer Reporting Agencies.In force
If a covered entity discovers circumstances requiring notice under Section 8-38-5 of more than 1,000 individuals at a single time, the entity shall also notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, as defined in the Fair Credit Reporting Act, 15 U.S.C. §1681a, of the timing, distribution, and content of the notices.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at alison.legislature.state.al.us
§ 8-38-8Notice of Security Breach - Covered Entity.In force
In the event a third-party agent has experienced a breach of security in the system maintained by the agent, the agent shall notify the covered entity of the breach of security as expeditiously as possible and without unreasonable delay, but no later than 10 days following the determination of the breach of security or reason to believe the breach occurred. After receiving notice from a third-party agent, a covered entity shall provide notices required under Sections 8-38-5 and 8-38-6. A third-party agent, in cooperation with a covered entity, shall provide information in the possession of the third-party agent so that the covered entity can comply with its notice requirements. A covered entity may enter into a contractual agreement with a third-party agent whereby the third-party agent agrees to handle notifications required under this chapter.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at alison.legislature.state.al.us
§ 8-38-3Reasonable Security Measures; Assessment.In forcecited in 2 of our articles
(a) Each covered entity and third-party agent shall implement and maintain reasonable security measures to protect sensitive personally identifying information against a breach of security. (b) Reasonable security measures means security measures practicable for the covered entity subject to subsection (c), to implement and maintain, including consideration of all of the following: (1) Designation of an employee or employees to coordinate the covered entity’s security measures to protect against a breach of security. An owner or manager may designate himself or herself. (2) Identification of internal and external risks of a breach of security. (3) Adoption of appropriate information safeguards to address identified risks of a breach of security and assess the effectiveness of such safeguards. (4) Retention of service providers, if any, that are contractually required to maintain appropriate safeguards for sensitive personally identifying information. (5) Evaluation and adjustment of security measures to account for changes in circumstances affecting the security of sensitive personally identifying information.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at alison.legislature.state.al.us
§ 8-38-10Disposal of Records Containing Sensitive Personally Identifying Information.In forcecited in 2 of our articles
A covered entity or third-party agent shall take reasonable measures to dispose, or arrange for the disposal, of records containing sensitive personally identifying information within its custody or control when the records are no longer to be retained pursuant to applicable law, regulations, or business needs. Disposal shall include shredding, erasing, or otherwise modifying the personal information in the records to make it unreadable or undecipherable through any reasonable means consistent with industry standards.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at alison.legislature.state.al.us
§ 8-38-11Exemptions - Federal.In forcecited in 2 of our articles
An entity subject to or regulated by federal laws, rules, regulations, procedures, or guidance on data breach notification established or enforced by the federal government is exempt from this chapter as long as the entity does all of the following: (1) Maintains procedures pursuant to those laws, rules, regulations, procedures, or guidance. (2) Provides notice to affected individuals pursuant to those laws, rules, regulations, procedures, or guidance. (3) Timely provides a copy of the notice to the Attorney General when the number of individuals the entity notified exceeds 1,000.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at alison.legislature.state.al.us
§ 8-38-12Exemptions - State.In force
An entity subject to or regulated by state laws, rules, regulations, procedures, or guidance on data breach notification that are established or enforced by state government, and are at least as thorough as the notice requirements provided by this chapter, is exempt from this chapter so long as the entity does all of the following: (1) Maintains procedures pursuant to those laws, rules, regulations, procedures, or guidance. (2) Provides notice to affected individuals pursuant to the notice requirements of those laws, rules, regulations, procedures, or guidance. (3) Timely provides a copy of the notice to the Attorney General when the number of individuals the entity notified exceeds 1,000.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at alison.legislature.state.al.us
§ 8-38-9Violations of Notification Requirements.In forcecited in 2 of our articles
(a) A violation of the notification provisions of this chapter is an unlawful trade practice under the Alabama Deceptive Trade Practices Act, Chapter 19 of this title, but does not constitute a criminal offense under Section 8-19-12. The Attorney General shall have the exclusive authority to bring an action for civil penalties under this chapter. (1) A violation of this chapter does not establish a private cause of action under Section 8-19-10. Nothing in this chapter may otherwise be construed to affect any right a person may have at common law, by statute, or otherwise. (2) Any covered entity or third-party agent who is knowingly engaging in or has knowingly engaged in a violation of the notification provisions of this chapter is subject to the penalty provisions set out in Section 8-19-11. For the purposes of this chapter, knowingly shall mean willfully or with reckless disregard in failing to comply with the notice requirements of Sections 8-38-5 and 8-38-6. Civil penalties assessed under Section 8-19-11, shall not exceed five hundred thousand dollars ($500,000) per breach.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at alison.legislature.state.al.us
§ 8-19-11Penalties.In forcecited in 3 of our articles
(a) Any person who violates the terms of an injunction or order issued under this chapter shall forfeit and pay a civil penalty of not more than $25,000 per violation and shall be adjudged in contempt. For the purpose of this section, any circuit court issuing an injunction or order under this chapter shall retain jurisdiction, and in such cases the Attorney General or the district attorney acting in the name of the state may petition for recovery of such civil penalties. (b) Any person who is knowingly engaging in or has knowingly engaged in any act or practice declared unlawful by Section 8-19-5 shall forfeit and pay a civil penalty of not more than $2,000 per violation upon petition by the Attorney General or a district attorney acting in the name of the state to the circuit court for the county in which the defendant resides, is doing business, or has his/her principal place of business, or the county in which the unlawful act or practice was or is being committed.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at alison.legislature.state.al.us
Cited in 4 court opinions in our collectionLatest citing opinion in our collection: 1999
Opinions citing this section in our collection:
- BMW of North America, Inc. v. Gore (Supreme Court of Alabama 1997, 701 So. 2d 507)“…willful violation of the Deceptive Trade Practices Act. See Ala.Code 1975, § 8-19-11. After this action was filed, the Legis…”
- Ford Motor Co. v. Sperau (Supreme Court of Alabama 1997, 708 So. 2d 111)“…nd it specifically used the $2,000 civil fine imposed under Ala.Code 1975, § 8-19-11(b), not the private right of action of…”
- Inter Medical Supplies, Ltd. v. Ebi Medical Systems, Inc. Electro-Biology, Inc. Biomet, Inc. v. Orthofix, Ltd. Orthofix International, N v. Orthofix, Inc. Orthofix S.R.L. v. Ebi Medical Systems, Inc. Electro-Biology, Inc. Biomet, Inc. Ebi Medical Systems, Inc. Electro-Biology, Inc. Biomet, Inc. (Court of Appeals for the Third Circuit 1999, 181 F.3d 446)“…2000 fine under the state's Deceptive Trade Practices Act, Ala. Code § 8-19-11 (b) (1993), could result in a multimill…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 8-38-2Definitions.In forcecited in 3 of our articles
For the purposes of this chapter, the following terms have the following meanings: (1) BREACH OF SECURITY or BREACH. The unauthorized acquisition of data in electronic form containing sensitive personally identifying information. Acquisition occurring over a period of time committed by the same entity constitutes one breach. The term does not include any of the following: a. Good faith acquisition of sensitive personally identifying information by an employee or agent of a covered entity, unless the information is used for a purpose unrelated to the business or subject to further unauthorized use. b. The release of a public record not otherwise subject to confidentiality or nondisclosure requirements. c. Any lawful investigative, protective, or intelligence activity of a law enforcement or intelligence agency of the state, or a political subdivision of the state. (2) COVERED ENTITY. A person, sole proprietorship, partnership, government entity, corporation, nonprofit, trust, estate, cooperative association, or other business entity that acquires or uses sensitive personally identifying information. (3) DATA IN ELECTRONIC FORM.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at alison.legislature.state.al.us
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2020
Opinions citing this section in our collection:
- Blahous v. Sarrell Regional Dental Center for Public Health, Inc. (District Court, M.D. Alabama 2020)“…or used by an individual unauthorized to do so. See, e.g., Ala. Code § 8-38-2(1). In the usual case, these attac…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 8-38-1Short Title.In forcecited in 3 of our articles
This chapter may be cited and shall be known as the Alabama Data Breach Notification Act of 2018.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at alison.legislature.state.al.us
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Alabama Data Breach Notification Act of 2018(alabamaag.gov).gov
- Act 2018-396 Full Text(alabamaag.gov).gov
- AG Marshall Announces Final Passage of Data Breach Notification Act(alabamaag.gov).gov
- AG Marshall $49.5M Blackbaud Settlement(alabamaag.gov).gov
- Alabama Code Title 8 Chapter 38 (Code of Alabama)(alison.legislature.state.al.us).gov
- Alabama Data Breach Notification Act, Ala. Code 8-38-1 through 8-38-12 (full chapter text)(acua.alabama.gov)