Florida
Florida Data Privacy Laws: Digital Bill of Rights & Breach Rules (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 15 primary sources cited on this page. How we verify our legal content

Florida data privacy law runs on two tracks: the Florida Digital Bill of Rights (Fla. Stat. 501.701-501.722), which took effect July 1, 2024 and whose main compliance duties reach only companies earning over $1 billion in global revenue meeting Big Tech criteria, and FIPA (Fla. Stat. 501.171), which covers all businesses handling Floridians' personal information. One FDBR provision is far broader than the rest: the sensitive-data rule at Fla. Stat. 501.715 binds any for-profit business that operates in Florida and collects consumer data, whatever its size.
Florida has taken a unique approach to data privacy. Rather than passing a broad consumer privacy law that covers all businesses operating in the state, the legislature created the Florida Digital Bill of Rights (FDBR), a statute aimed squarely at the largest technology companies in the world.
For the vast majority of Florida businesses, the primary data privacy obligation remains the Florida Information Protection Act (FIPA), which focuses on data security and breach notification rather than comprehensive consumer privacy rights.
This two-track system means that understanding Florida data privacy law requires looking at both statutes, along with the federal frameworks that fill gaps for most organizations.
The Florida Digital Bill of Rights (FDBR): What It Actually Covers
Governor Ron DeSantis signed the Florida Digital Bill of Rights into law on June 6, 2023, as SB 262. It took effect on July 1, 2024, and is codified at Fla. Stat. 501.701-501.722.

What sets the FDBR apart from every other state privacy law in the country is its applicability threshold. This is not a law that applies to your local dentist's office or a mid-size e-commerce company.
Who Must Comply: The $1 Billion Threshold
Most FDBR duties apply only to entities that meet all of the following criteria:
- Conduct business in Florida or produce products or services consumed by Florida residents
- Collect personal data about consumers (or have someone collect it on their behalf)
- Earn more than $1 billion in global gross annual revenue
- Meet at least one of these three additional conditions:
- Derive 50% or more of global revenue from online advertising sales, including targeted advertising
- Operate a consumer smart speaker with a voice-activated virtual assistant connected to cloud computing
- Operate an app store or digital distribution platform offering at least 250,000 software applications
In practical terms, this means the FDBR targets companies like Google, Amazon, Apple, and Meta. A company earning $999 million in global revenue is not covered, no matter how much consumer data it processes.
The Florida Senate bill summary confirms this narrow scope was intentional. Legislators designed the law to address the outsized data collection practices of Big Tech companies specifically.
One section breaks that pattern, and small businesses should not skip past it. Fla. Stat. 501.715, the sensitive-data rule, applies to "a person who meets the requirements of s. 501.702(9)(a)1.-3. for the definition of a controller." Those are only the first three prongs of the controller definition: organized or operated for profit, conducts business in this state, and collects personal data about consumers. The $1 billion revenue prong is 501.702(9)(a)5. and the three Big Tech tests are 501.702(9)(a)6., and 501.715 incorporates neither one. A small Florida for-profit that sells sensitive data is therefore covered by that section even though the rest of the FDBR passes it by. See the sensitive data section below.
Consumer Rights Under the FDBR
For Florida consumers whose data is held by a qualifying controller, the FDBR grants the following rights under Fla. Stat. 501.705:
Right to Confirm and Access. Consumers can confirm whether a controller is processing their personal data and access that data.
Right to Correct. Consumers can request correction of inaccuracies in their personal data, taking into account the nature and purposes of the processing.
Right to Delete. Consumers can request deletion of any or all personal data provided by or obtained about them.
Right to Data Portability. Consumers can obtain a copy of their personal data in a portable and, to the extent technically feasible, readily usable format.
Right to Opt Out. Consumers can opt out of:
- Processing of personal data for targeted advertising
- The sale of personal data
- Profiling that produces legal or similarly significant effects
- Collection of sensitive data, including precise geolocation data
- Data collection through voice recognition or facial recognition features
Controllers must respond to consumer requests within 45 days, with one 45-day extension permitted if reasonably necessary.
Sensitive Data Protections
The FDBR treats certain categories of personal data with heightened protection, and this is the one part of the law that is not limited to billion-dollar companies.
Fla. Stat. 501.715(1) applies to "a person who meets the requirements of s. 501.702(9)(a)1.-3. for the definition of a controller," meaning any entity organized or operated for profit that conducts business in Florida and collects personal data about consumers. The revenue and Big Tech prongs of the controller definition are not carried into this section. Such a person may not sell sensitive data without prior consent from the consumer. Where the data belongs to a known child under 13, the processing must instead comply with COPPA (15 U.S.C. ss. 6501 et seq.); for a known child 13 or older but under 18, the statute requires affirmative authorization for the processing.
Fla. Stat. 501.715(2) adds a disclosure duty in fixed words. A person covered by subsection (1) who sells sensitive personal data must provide this notice: "NOTICE: This website may sell your sensitive personal data."
Under Fla. Stat. 501.715(3), a violation of this section is subject to the penalties in Fla. Stat. 501.72, which reach up to $50,000 per violation and can be tripled.
Sensitive data under the FDBR includes:
- Racial or ethnic origin
- Religious beliefs
- Mental or physical health diagnosis
- Sexual orientation
- Citizenship or immigration status
- Genetic or biometric data
- Personal data of a known child
- Precise geolocation data
For data collected through voice recognition or facial recognition features, the FDBR adds an additional protection: devices with these features cannot use them for surveillance when the consumer is not actively using the device, unless the consumer expressly authorizes it.
Controller Duties and Data Protection Assessments
Covered controllers under the FDBR must:
- Limit data collection to what is adequate, relevant, and reasonably necessary
- Implement reasonable data security practices
- Provide clear and meaningful privacy notices
- Conduct and document data protection assessments for processing activities that present a heightened risk, including targeted advertising, the sale of personal data, profiling, and processing sensitive data
These assessments must weigh the benefits of the processing against the potential risks to consumers, considering the use of de-identification, reasonable consumer expectations, and the context of the processing.
Government Content Moderation Restrictions
The FDBR includes provisions that are unique among state privacy laws. Government employees are prohibited from using their position or state resources to communicate with social media platforms to request content removal. Governmental entities cannot initiate or maintain agreements with social media platforms for content moderation purposes.
These restrictions do not apply to routine account maintenance, efforts to remove content related to criminal activity, or actions to prevent bodily harm, loss of life, or property damage. Certain government-related provisions took effect earlier, on July 1, 2023.
Exemptions
The FDBR exempts several categories of entities and data from its requirements:
- Entities governed by the Gramm-Leach-Bliley Act (GLBA) for financial institutions
- Entities subject to HIPAA privacy, security, and breach notification rules
- Nonprofit organizations
- Data subject to the Fair Credit Reporting Act
- Data covered by the Children's Online Privacy Protection Act (COPPA)
- Various other federal regulatory frameworks
These exemptions mean that banks, healthcare providers, and nonprofits operating in Florida are not subject to the FDBR, even if they otherwise meet the revenue threshold.
FDBR Enforcement and First Enforcement Action
The FDBR is enforced exclusively by the Florida Attorney General through the Department of Legal Affairs. There is no private right of action, meaning individual consumers cannot sue companies directly for FDBR violations.
Before bringing an enforcement action, the Attorney General must notify the controller in writing of the alleged violation. A cure period is discretionary, not something a controller is entitled to. Under Fla. Stat. 501.72(2), after that written notice the department "may grant a 45-day period to cure the alleged violation and issue a letter of guidance," and in deciding whether to do so it "may consider the number and frequency of violations, the substantial likelihood of injury to the public, and the safety of persons or property." The same subsection states that the 45-day cure period does not apply to a violation involving a Florida consumer who is a known child, so in that category the Attorney General may proceed directly to enforcement, as happened in the Roku matter below.

On October 14, 2025, Attorney General James Uthmeier's Office of Parental Rights filed the state's first FDBR enforcement action against Roku, Inc. and its Florida subsidiary. The complaint was filed in Florida's 20th Judicial Circuit. The allegations: Roku "collected, sold, and enabled reidentification of sensitive personal data, including viewing habits, voice recordings, and other information from children, without authorization or meaningful notice to Florida families." Roku's 2024 operating revenue of $3.4 billion placed the company well above the FDBR's $1 billion threshold.
The FDBR authorizes civil penalties of up to $50,000 per violation. Fla. Stat. 501.72(1) triples that figure, to $150,000 per violation, in three situations: a violation involving a Florida consumer who is a known child, a failure to delete or correct the consumer's personal data after an authenticated request, and continuing to sell or share the consumer's personal data after the consumer opts out. The Florida AG and Roku resolved the case on June 26, 2026: Roku agreed to invest approximately $25 million in child-protection engineering and features, with nationwide rollout expected within 12 months. The resolution included no civil penalty and no finding of wrongdoing.
In February 2026, Attorney General Uthmeier announced the creation of the CHINA Prevention Unit, a specialized enforcement initiative within the AG's office. The unit investigates foreign-owned corporations, particularly those with Chinese ownership, that collect consumer data from Florida residents. It has issued subpoenas to medical device manufacturers demanding audits and verification of whether biometric or patient data transfers to foreign servers.
Children's Online Protections: Fla. Stat. 501.1735 and 501.1736
Florida law provides a layered set of protections for children in online spaces through two distinct statutes.
Fla. Stat. 501.1735 prohibits covered online platforms from:
-
Processing children's data harmfully. Platforms cannot process a child's personal information if they have actual knowledge or willfully disregard that the processing may result in substantial harm or privacy risk to children.
-
Profiling children without safeguards. Platforms cannot profile a child unless they can demonstrate appropriate safeguards are in place.
-
Using dark patterns. Platforms cannot use manipulative design techniques to lead or encourage children to provide personal information beyond what would be reasonably expected, to forego privacy protections, or to take actions that may cause substantial harm.
-
Misusing age estimation data. Any personal information collected to estimate a user's age cannot be used for any other purpose and cannot be retained longer than necessary for age estimation.
Platforms may not collect, sell, share, or retain a child's personal information beyond what is necessary to provide the requested service, unless the platform can demonstrate a compelling reason that doing so does not pose a substantial harm or privacy risk to children. The platform, not the child or parent, bears the burden of proving that standard is met.
Fla. Stat. 501.1736 (enacted as HB 3 during the 2024 session) goes further. It requires social media platforms to:
- Prohibit accounts for children under 14. Platforms must terminate existing accounts held by minors under 14 and block new account creation.
- Require parental consent for 14- and 15-year-olds. Covered platforms must obtain verifiable parental or guardian consent before minors in this age group may create accounts.
Fla. Stat. 501.1736 targets social media platforms that "use algorithms to exploit psychological vulnerabilities" in minors. A federal district court initially enjoined the law, but on November 25, 2025, a 2-1 panel of the U.S. Court of Appeals for the Eleventh Circuit lifted the injunction, finding the state made a strong showing that the law is likely content-neutral and satisfies intermediate scrutiny. Florida's Attorney General announced immediate plans for aggressive enforcement. The underlying constitutional litigation (CCIA and NetChoice v. Uthmeier) continues.
The Florida Information Protection Act (FIPA): Fla. Stat. 501.171
While the FDBR targets Big Tech, the Florida Information Protection Act (FIPA) is the data privacy law that actually applies to most businesses operating in Florida. Originally enacted in 2014 as SB 1524, FIPA focuses on two core requirements: data security and breach notification.
Who FIPA Covers
FIPA applies broadly to:
- Covered entities: Any entity that acquires, maintains, stores, or uses personal information (this includes businesses of all sizes)
- Governmental entities: State and local government agencies
- Third-party agents: Any entity that has been contracted to maintain, store, or process personal information on behalf of a covered entity or governmental entity
There is no revenue threshold, employee count minimum, or data volume requirement. If your business handles personal information of Florida residents, FIPA applies to you.
What Counts as Personal Information Under FIPA
FIPA defines "personal information" as an individual's first name (or first initial) and last name combined with one or more of the following:
- A driver's license number, identification card number, passport number, military ID number, or similar government-issued identifier
- A financial account number, credit card number, or debit card number, combined with any security code, access code, or password needed to access the account
- Medical history information, mental or physical health condition, or medical treatment or diagnosis by a healthcare professional
- A health insurance policy number or subscriber identification number, plus any unique identifier used by a health insurer
The definition also includes a user name or email address combined with a password or security question and answer that would permit access to an online account.
Data Security Requirements
FIPA requires each covered entity, governmental entity, and third-party agent to take reasonable measures to protect and secure data in electronic form containing personal information.
The statute does not prescribe specific technical controls. Instead, "reasonable measures" is a flexible standard that considers the size and complexity of the organization, the nature and scope of its activities, and the sensitivity of the data involved.
Breach Notification Rules
FIPA's breach notification requirements are among the most detailed in the country.

Timeline for notification:
- Notice to affected individuals must be provided no later than 30 days after determination of the breach or reason to believe a breach occurred
- The entity may receive a 15-day extension if good cause for delay is provided in writing to the Florida Department of Legal Affairs within the initial 30-day window
- Law enforcement may authorize a reasonable delay if notification would interfere with a criminal investigation
Notice to the Florida Department of Legal Affairs:
If a breach affects 500 or more individuals in Florida, the covered entity must also notify the Department. If the breach affects more than 1,000 individuals at a single time, the entity must also notify all nationwide consumer credit reporting agencies without unreasonable delay. This notice must include:
- A synopsis of the events surrounding the breach
- The number of individuals in Florida affected
- Any services being offered to affected individuals at no charge (such as credit monitoring)
- The name, address, telephone number, and email of an employee or agent who can provide additional information
When notice is NOT required:
An entity is not required to notify individuals if, after investigation and consultation with law enforcement, it reasonably determines the breach has not and will not likely result in identity theft or financial harm. This determination must be documented in writing and maintained for at least five years.
FIPA Penalties
A covered entity that violates the notification requirements faces civil penalties structured as follows:
- $1,000 per day for each day of violation during the first 30 days
- $50,000 per 30-day period (or portion thereof) for each subsequent 30-day period, up to 180 days
- A total cap of $500,000 per breach
Penalties are calculated per breach, not per individual affected. The Florida Attorney General enforces FIPA through the Florida Deceptive and Unfair Trade Practices Act (FDUTPA). There is no private right of action under FIPA.
Third-Party Agent Obligations
When a breach occurs in a system maintained by a third-party agent, that agent must notify the covered entity no later than 10 days after determining the breach occurred or having reason to believe it occurred. The covered entity, not the third-party agent, is then responsible for consumer notification.
Florida Telephone Solicitation Act: Consent for Calls and Texts
Florida's Telephone Solicitation Act, Fla. Stat. 501.059, governs telemarketing and automated calling practices for businesses that sell goods or services to Florida consumers. It applies to any person or entity doing business in Florida making telephonic sales calls to Florida residents, whether from within or outside the state.
Automated calls and texts. Section 501.059(8)(a) prohibits making unsolicited telephonic sales calls using an automated system for the selection and dialing of telephone numbers (or playing a recorded message when a connection is completed) without the prior express written consent of the called party. The 2023 amendments to the FTSA changed the phrase from "selection or dialing" to "selection and dialing," narrowing the definition of covered automated systems.
Prior express written consent requirements. Valid consent must be a written agreement bearing the called party's signature (including electronic or digital signatures) that clearly authorizes automated calls or texts to a specific telephone number, includes a clear and conspicuous disclosure explaining the authorization, and states that signing is not a condition of any purchase. Consent may also be demonstrated by checking a box or responding affirmatively to an email or text campaign.
Text message opt-out rule. Before filing a lawsuit for unwanted text messages, a recipient must first reply "STOP" to the sender. The solicitor then has 15 days to cease sending text message solicitations, or it faces statutory liability.
The FTSA does not independently require businesses to record calls, but it does require consent before automated or pre-recorded calls are placed. Florida recording consent laws under Fla. Stat. 934.03 separately govern whether call recording is lawful.
Digital Voyeurism: Fla. Stat. 810.145
Florida's digital voyeurism statute was renamed from "video voyeurism" to "digital voyeurism" by 2024 legislative changes effective October 1, 2024. The law prohibits secretly viewing, recording, or broadcasting images of individuals in private settings (bathrooms, changing rooms, residential dwellings) where they have a reasonable expectation of privacy.
Key offenses include:
- Secretly using an imaging device to view or record a person who is dressing or privately exposing their body without consent
- Upskirt photography (recording under or through clothing without consent)
- Dissemination or commercial distribution of such recordings
Penalties under the 2024 amendments:
- Adults 19 and older who commit digital voyeurism face third-degree felony charges
- Minors under 19 face first-degree misdemeanor charges
- Dissemination of digital voyeurism recordings constitutes a third-degree felony regardless of the offender's age
- When the offender is a family or household member of the victim, or holds a position of authority or trust over the victim, penalties increase to the next higher felony degree
Each instance of secretly viewing a person, or of broadcasting or distributing a recording, constitutes a separate offense under the statute.
Federal Frameworks That Apply in Florida
Because most FDBR duties cover only the largest technology companies, most Florida businesses rely on federal privacy frameworks for their primary compliance obligations.
HIPAA (Health Insurance Portability and Accountability Act)
Healthcare providers, health plans, healthcare clearinghouses, and their business associates must comply with HIPAA's Privacy Rule, Security Rule, and Breach Notification Rule. HIPAA preempts less-protective state laws but not more-protective ones.
GLBA (Gramm-Leach-Bliley Act)
Financial institutions including banks, credit unions, insurance companies, and securities firms must comply with GLBA's privacy and safeguards requirements. GLBA requires financial privacy notices and limits sharing of nonpublic personal information.
COPPA (Children's Online Privacy Protection Act)
Websites and online services directed at children under 13, or that knowingly collect information from children under 13, must comply with COPPA's parental consent requirements and data minimization principles.
FCRA (Fair Credit Reporting Act)
Consumer reporting agencies, users of consumer reports, and furnishers of information must comply with FCRA's accuracy, disclosure, and dispute resolution requirements.
FTC Act Section 5
The Federal Trade Commission can bring enforcement actions against any company engaging in unfair or deceptive practices regarding consumer data, providing a baseline of protection for all Florida consumers.
TAKE IT DOWN Act (Pub. L. 119-12)
President Trump signed the TAKE IT DOWN Act (Tools to Address Known Exploitation by Immobilizing Technological Deepfakes On Websites and Networks Act) on May 19, 2025. The law criminalizes the publication of nonconsensual intimate imagery (NCII), including AI-generated deepfakes, with penalties of up to two years in prison (harsher for imagery involving minors). Criminal prohibitions took effect immediately. Covered platforms have until May 19, 2026 to establish notice-and-removal procedures: upon a victim's request, platforms must remove NCII within 48 hours and delete all copies. The FTC enforces the platform-obligation provisions. Florida Rep. Maria Salazar was a primary House sponsor of the bill.

2025-2026 Legislative Developments
Florida's legislature continues to expand data privacy protections in specific sectors.
Social Media Age Verification (Fla. Stat. 501.1736 / HB 3). Enacted during the 2024 session and codified as Fla. Stat. 501.1736, this law prohibits social media platforms from allowing account creation by children under 14 and requires parental consent for 14- and 15-year-olds. After an initial federal injunction, the Eleventh Circuit lifted the block on November 25, 2025, allowing active enforcement. Litigation on the merits continues as of May 2026.
Motor Vehicle Data Privacy (HB 1557, 2026 session). This bill would have addressed operator data and personal identifying information collected by vehicle manufacturers, prohibiting manufacturers from certain actions relating to operator data and requiring them to provide vehicle owners access to and control of their data. HB 1557 died in the Industries & Professional Activities Subcommittee on March 13, 2026 and was not enacted. It never advanced past that first committee or received a floor vote.
Florida AI Bill of Rights (SB 482, 2026 session). The Florida Senate passed SB 482 by a 35-2 vote on March 4, 2026. The bill would have required parental consent before minors could use companion chatbots, restricted state agency contracts with AI providers linked to foreign governments, and imposed data-de-identification requirements. The bill died in the Florida House on March 13, 2026, and was not signed into law.
CHINA Prevention Unit (February 2026). Attorney General Uthmeier established a specialized unit within the AG's office to investigate foreign-owned corporations, particularly those with Chinese ownership, that collect consumer data from Florida residents. The unit has issued subpoenas to medical device manufacturers.
Government Contracting Restrictions. Beginning July 1, 2025, a governmental entity may not extend or renew a contract with certain foreign entities if the contract would give that entity access to individuals' personal identifying information.
How Florida Compares to Other State Privacy Laws
Florida's approach stands in sharp contrast to comprehensive state privacy laws like the California Consumer Privacy Act (CCPA), Colorado Privacy Act, and Connecticut Data Privacy Act.
| Feature | Florida FDBR | California CCPA/CPRA | Colorado CPA | Connecticut CTDPA |
|---|---|---|---|---|
| Revenue threshold | $1 billion+ global | $25 million+ | None | None |
| Additional criteria | Must meet 1 of 3 Big Tech tests | Data volume or revenue % | 100K consumers or 25K + revenue % | 100K consumers or 25K + revenue % |
| Approximate businesses covered | ~20-30 companies | Millions | Thousands | Thousands |
| Consumer rights | Access, correct, delete, portability, opt out | Access, correct, delete, portability, opt out, limit sensitive data | Access, correct, delete, portability, opt out | Access, correct, delete, portability, opt out |
| Private right of action | No | Limited (data breaches) | No | No |
| Enforcement | AG only | AG + limited private | AG only | AG only |
| Cure period | Up to 45 days, at the AG's discretion | 30 days (expired 2023) | 60 days (expires 2025) | 60 days (expires 2025) |
The practical effect is that a Florida-based online retailer doing $50 million in annual revenue and handling significant consumer data would be subject to California, Colorado, and Connecticut privacy laws if it serves residents of those states, but would not be subject to the FDBR in its home state.
Practical Steps for Florida Businesses
Given Florida's framework, businesses operating in the state should focus on the following:
1. Comply with FIPA's breach notification requirements. This is the baseline obligation for every Florida business handling personal information. Ensure you have an incident response plan that can meet the 30-day notification deadline.
2. Implement reasonable security measures. FIPA's "reasonable measures" standard requires data security practices proportional to your organization's size and the sensitivity of the data you handle.
3. Assess federal privacy obligations. Determine whether HIPAA, GLBA, COPPA, FCRA, or other federal frameworks apply to your specific industry and data practices.
4. Monitor multi-state compliance. If you serve consumers in states with comprehensive privacy laws (California, Colorado, Connecticut, Virginia, and others), those laws likely apply to you even though the FDBR does not.
5. Watch children's data carefully. Florida's children's protections under Fla. Stat. 501.1735 and 501.1736 apply to online platforms regardless of revenue thresholds. If your platform is accessible to minors, review these requirements before the AG's enforcement ramps up further.
6. Review TAKE IT DOWN Act obligations. If your platform hosts user-generated content, platform-side NCII removal obligations under the TAKE IT DOWN Act took effect May 19, 2026. Establish notice-and-removal procedures.
7. Document your data practices. Maintaining records of what data you collect, how you use it, where you store it, and who you share it with positions your business for compliance as privacy laws continue to evolve.
In-depth guides
- What Is the FDBR? Florida Digital Bill of Rights
- FDBR Consumer Rights: Your Data Privacy Rights
- FDBR Compliance Checklist for Businesses (2026)
Related news
More Florida Laws
Frequently Asked Questions
Does the Florida Digital Bill of Rights apply to my small business?
Mostly not, but not entirely. The FDBR's main duties apply only to companies with more than $1 billion in global gross annual revenue that also meet at least one of three additional criteria: deriving 50% or more of revenue from online advertising, operating a consumer smart speaker with a virtual assistant, or operating an app store with at least 250,000 applications. That effectively limits those duties to a handful of Big Tech companies. One section is different. Fla. Stat. 501.715 reaches any entity that is organized for profit, conducts business in Florida, and collects consumers' personal data, with no revenue threshold at all. If your business sells sensitive personal data, you need prior consent from the consumer and must provide the notice 'NOTICE: This website may sell your sensitive personal data.', and a violation carries the Fla. Stat. 501.72 penalties of up to $50,000. Apart from that section, small and mid-size Florida businesses are governed by the Florida Information Protection Act (FIPA) for data security and breach notification.
What are the penalties for a data breach in Florida?
Under FIPA (Fla. Stat. 501.171), a business that fails to comply with breach notification requirements faces civil penalties of $1,000 per day for the first 30 days of violation, $50,000 for each subsequent 30-day period up to 180 days, and a maximum cap of $500,000 per breach. Penalties are calculated per breach, not per affected individual. The Florida Attorney General enforces these penalties through the Deceptive and Unfair Trade Practices Act. Under the FDBR, Fla. Stat. 501.72 authorizes up to $50,000 per violation, tripled to $150,000 for a violation involving a known child, for a failure to delete or correct data after an authenticated request, or for continuing to sell or share data after an opt-out.
How quickly must I notify customers of a data breach in Florida?
Florida law requires notification to affected individuals no later than 30 days after you determine a breach has occurred or have reason to believe one occurred. You can request a 15-day extension by providing good cause in writing to the Florida Department of Legal Affairs within the initial 30-day window. If the breach affects 500 or more Floridians, you must also notify the Department within the same timeframe. Breaches affecting more than 1,000 individuals additionally require notification to nationwide consumer credit reporting agencies. Third-party agents who experience a breach must notify the covered entity within 10 days.
What consumer rights does the FDBR provide?
The FDBR grants Florida consumers the right to confirm whether a covered controller is processing their data, access their personal data, correct inaccuracies, delete their data, and obtain a portable copy. Consumers can also opt out of targeted advertising, data sales, profiling that produces legal effects, collection of sensitive data, and data collection through voice or facial recognition features. These rights only apply against companies that meet the FDBR's $1 billion revenue threshold and additional criteria.
Does Florida law protect children's data online?
Yes. Under Fla. Stat. 501.1735, online platforms are prohibited from processing a child's (under 18) personal information in ways that may cause substantial harm, using dark patterns to manipulate children into sharing data, or profiling children without appropriate safeguards. Under Fla. Stat. 501.1736 (HB 3), social media platforms must prohibit accounts for children under 14 and require parental consent for 14- and 15-year-olds. The Eleventh Circuit lifted the injunction on this law in November 2025, allowing active enforcement.
Does Florida require consent before recording a phone call?
Yes. Under Fla. Stat. 934.03, Florida is a two-party (all-party) consent state for call recording: all parties to a conversation must consent before it is recorded. Separately, the Florida Telephone Solicitation Act (Fla. Stat. 501.059) requires prior express written consent before businesses make automated or pre-recorded calls or send automated text messages to Florida consumers. Violations of the FTSA can result in statutory civil penalties.
What is the TAKE IT DOWN Act and does it apply in Florida?
The TAKE IT DOWN Act (Pub. L. 119-12), signed May 19, 2025, is a federal law that criminalizes the publication of nonconsensual intimate images (NCII), including AI-generated deepfakes, and requires platforms to remove such content within 48 hours of a victim's request. Platform takedown obligations became effective May 19, 2026. The law applies nationwide, including in Florida. The FTC enforces the platform provisions. Florida Rep. Maria Salazar was a primary House sponsor.
What is Florida's digital voyeurism law?
Florida Statute 810.145 (renamed from video voyeurism to digital voyeurism effective October 1, 2024) prohibits secretly recording or viewing individuals in settings where they have a reasonable expectation of privacy, such as bathrooms or changing rooms. Adults 19 and older who commit digital voyeurism face third-degree felony charges. Dissemination of such recordings is also a third-degree felony. Penalties increase when the offender is a family member or person in authority over the victim.
Updates
Corrected the sensitive-data section to show that Fla. Stat. 501.715 binds any Florida for-profit business that collects consumer data rather than only billion-dollar controllers, added the statute's required sale notice, clarified that the Attorney General's 45-day cure period is discretionary rather than a right, listed all three grounds that triple penalties under Fla. Stat. 501.72(1), and fixed the Florida Digital Bill of Rights section range to 501.701-501.722.
Updated the Roku FDBR enforcement case to reflect its June 26, 2026 settlement (no civil penalty, no finding of wrongdoing, ~$25 million child-protection investment); corrected the status of the 2026 motor-vehicle-data bill (HB 1557), which died in committee and was not enacted; added the statutory carve-out that the 45-day cure period does not apply to violations involving a known child; and replaced a dead bill-summary citation with a working official source.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected the FIPA credit-bureau breach-notice threshold and timing (more than 1,000 individuals, without unreasonable delay), restated the children's-data standard under Fla. Stat. 501.1735 as a harm/burden-of-proof test rather than a consent requirement, and removed a fabricated 10 p.m. notification curfew that does not appear in Fla. Stat. 501.1736.
Governing law re-checked for recent changes
May 2026 refresh: Added Fla. Stat. 501.1736 (HB 3 social media age verification law, Eleventh Circuit lifted injunction November 25, 2025, active enforcement); expanded FDBR enforcement section with Roku action details (October 14, 2025, Florida's 20th Judicial Circuit, up to $150,000 per child violation); added CHINA Prevention Unit (February 2026); added TAKE IT DOWN Act federal overlay (Pub. L. 119-12, signed May 19, 2025, platform obligations effective May 19, 2026); added Florida Telephone Solicitation Act section (Fla. Stat. 501.059, 2023 amendments); added Digital Voyeurism section (Fla. Stat. 810.145, renamed and updated October 1, 2024); added SB 482 AI Bill of Rights (passed Senate March 4, 2026, died in House March 13, 2026, not enacted); added credit-bureau notification threshold (more than 1,000 affected individuals) to FIPA breach rules; expanded FAQ to 8 questions. Word count increased from 2,847 to approximately 5,334.
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Florida Statutes
§ 501.705Consumer rights.In forcecited in 5 of our articles
(1) A consumer is entitled to exercise the consumer rights authorized by this section at any time by submitting a request to a controller which specifies the consumer rights that the consumer wishes to exercise. With respect to the processing of personal data belonging to a known child, a parent or legal guardian of the child may exercise these rights on behalf of the child. (2) A controller shall comply with an authenticated consumer request to exercise any of the following rights:(a) To confirm whether a controller is processing the consumer’s personal data and to access the personal data. (b) To correct inaccuracies in the consumer’s personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer’s personal data. (c) To delete any or all personal data provided by or obtained about the consumer. (d) To obtain a copy of the consumer’s personal data in a portable and, to the extent technically feasible, readily usable format if the data is available in a digital format. (e) To opt out of the processing of the personal data for purposes of:1. Targeted advertising; 2. The sale of personal data; or 3.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at leg.state.fl.us
Also relied on in: Florida Biometric Privacy Laws: Collection, Consent & Penalties (2026), FDBR Compliance Checklist: Florida Data Privacy, FDBR Consumer Rights: Florida Data Privacy Rights
§ 501.171Security of confidential personal information.In forcecited in 4 of our articles
(1) DEFINITIONS.—As used in this section, the term:(a) “Breach of security” or “breach” means unauthorized access of data in electronic form containing personal information. Good faith access of personal information by an employee or agent of the covered entity does not constitute a breach of security, provided that the information is not used for a purpose unrelated to the business or subject to further unauthorized use. (b) “Covered entity” means a sole proprietorship, partnership, corporation, trust, estate, cooperative, association, or other commercial entity that acquires, maintains, stores, or uses personal information. For purposes of the notice requirements in subsections (3)-(6), the term includes a governmental entity. (c) “Customer records” means any material, regardless of the physical form, on which personal information is recorded or preserved by any means, including, but not limited to, written or spoken words, graphically depicted, printed, or electromagnetically transmitted that are provided by an individual in this state to a covered entity for the purpose of purchasing or leasing a product or obtaining a service.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at leg.state.fl.us
Also relied on in: Florida Data Breach Notification Laws: Reporting Rules & Timelines (2026), Florida Identity Theft Laws: Penalties, Protected Classes, and Victim Rights
§ 501.1736Social media use for minors.In forcecited in 3 of our articles
(1) As used in this section, the term:(a) “Account holder” means a resident who opens an account or creates a profile or is identified by the social media platform by a unique identifier while using or accessing a social media platform when the social media platform knows or has reason to believe the resident is located in this state. (b) “Daily active users” means the number of unique users in the United States who used the online forum, website, or application at least 80 percent of the days during the previous 12 months, or, if the online forum, website, or application did not exist during the previous 12 months, the number of unique users in the United States who used the online forum, website, or application at least 80 percent of the days during the previous month. (c) “Department” means the Department of Legal Affairs. (d) “Resident” means a person who lives in this state for more than 6 months of the year. (e) “Social media platform” means an online forum, website, or application that satisfies each of the following criteria:1. Allows users to upload content or view the content or activity of other users; 2.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leg.state.fl.us
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- NetChoice v. Carr (District Court, N.D. Georgia 2025)“…cope, and reveal SB 351’s content- based framework. Compare Fla. Stat. §§ 501.1736 et seq, with O.C.G.A. §§ 39-6-1 et seq…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Florida Sues TikTok Under HB3 Social Media Minors Law (2026), Florida Age Verification Law: Two Provisions, Two Lawsuits, One AG Crackdown
§ 501.1735Protection of children in online spaces; public records exemption.In force
(1) DEFINITIONS.—As used in this section, the term:(a) “Child” or “children” means a consumer or consumers who are under 18 years of age. (b) “Collect” means to buy, rent, gather, obtain, receive, save, store, or access any personal information pertaining to a child. (c) “Dark pattern” means a user interface designed or manipulated with the substantial effect of subverting or impairing user autonomy, decisionmaking, or choice and includes, but is not limited to, any practice the Federal Trade Commission refers to as a dark pattern. (d) “Department” means the Department of Legal Affairs. (e) “Online platform” means a social media platform as defined in s. 112.23(1), online game, or online gaming platform. (f) “Personal information” means information that is linked or reasonably linkable to an identified or identifiable child, including biometric information and unique identifiers to the child. (g) “Precise geolocation data” means information identified through technology which enables the online platform to collect specific location data which directly identifies the specific location of a child with precision and accuracy within a radius of 1,750 feet.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leg.state.fl.us
§ 501.72Enforcement and implementation by the Department of Legal Affairs.In forcecited in 5 of our articles
(1) A violation of this part is an unfair and deceptive trade practice actionable under part II of this chapter solely by the Department of Legal Affairs. If the department has reason to believe that a person is in violation of this section, the department may, as the enforcing authority, bring an action against such person for an unfair or deceptive act or practice. For the purpose of bringing an action pursuant to this section, ss. 501.211 and 501.212 do not apply. In addition to other remedies under part II of this chapter, the department may collect a civil penalty of up to $50,000 per violation. Civil penalties may be tripled for any of the following violations:(a) A violation involving a Florida consumer who is a known child. A controller that willfully disregards the consumer’s age is deemed to have actual knowledge of the consumer’s age. (b) Failure to delete or correct the consumer’s personal data pursuant to this section after receiving an authenticated consumer request or directions from a controller to delete or correct such personal data, unless an exception to the requirements to delete or correct such personal data under this section applies.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leg.state.fl.us
Also relied on in: What Is the FDBR? Florida Digital Bill of Rights
§ 501.701Short title.In forcecited in 6 of our articles
This part may be cited as the “Florida Digital Bill of Rights.”
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leg.state.fl.us
Also relied on in: Florida Employee Monitoring Laws: Employer Rules (2026)
§ 501.059Telephone solicitation.In force
(1) As used in this section, the term:(a) “Called party” means a person who is the regular user of the telephone number that receives a telephonic sales call. (b) “Consumer” means an actual or prospective purchaser, lessee, or recipient of consumer goods or services. (c) “Consumer goods or services” means real property or tangible or intangible personal property that is normally used for personal, family, or household purposes, including, but not limited to, any such property intended to be attached to or installed in any real property without regard to whether it is so attached or installed, as well as cemetery lots and timeshare estates, and any services related to such property. (d) “Department” means the Department of Agriculture and Consumer Services. (e) “Doing business in this state” means businesses that conduct telephonic sales calls from a location in Florida or from other states or nations to consumers located in Florida. (f) “Merchant” means a person who, directly or indirectly, offers or makes available to consumers any consumer goods or services. (g) “Prior express written consent” means a written agreement that:1. Bears the signature of the called party; 2.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leg.state.fl.us
Cited in 48 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- TSA STORES v. Department of Agriculture (District Court of Appeal of Florida 2007, 957 So. 2d 25)“…MONACO, J. This case causes us to examine the reach of section 501.059, Florida Statutes (2004), the statute that governs teleph…”
- DLL v. Cricket's Termite Control (District Court of Appeal of Florida 2006, 942 So. 2d 1001)“…ncerning violations of Florida's No Sales Solicitation Law, section 501.059, Florida Statutes (2003). The notice stated that the Depa…”
- United States v. Dish Network LLC (District Court, C.D. Illinois 2017, 256 F. Supp. 3d 810)“…Fed. Reg. 4580 , 4629 . n. 592 (January 29, 2003) (citing Fla. Stat. Ann. § 501.059 ) (2003 TSR Statement of Basis and Purp…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 810.145Digital voyeurism.In forcecited in 15 of our articles
(1) As used in this section, the term:(a) “Broadcast” means electronically transmitting a visual image or visual recording with the intent that it be viewed by another person. (b) “Family or household member” has the same meaning as in s. 741.28. (c) “Imaging device” means any mechanical, digital, or electronic viewing device; still camera; camcorder; motion picture camera; or any other instrument, equipment, or format capable of recording, storing, or transmitting visual images of another person. (d) “Position of authority or trust” means a position occupied by a person 18 years of age or older who is a relative, caregiver, coach, employer, or other person who, by reason of his or her relationship with the victim, is able to exercise undue influence over him or her or exploit his or her trust. (e) “Privately exposing the body” means exposing a sexual organ.
Official text (excerpt) · last checked 2026-08-31 · Read the full text in our law library · Verify at leg.state.fl.us
Cited in 3 court opinions in our collectionLatest citing opinion in our collection: 2024
In the courts (editorial summary, independently checked):Kenneth Isaac Parkerson v. State of Florida (2015) rejected a facial overbreadth challenge to section 810.145, holding the video voyeurism statute regulates conduct, not pure speech. Clemen v. Surterra Holdings, Inc. (2024) drew on its privacy definition and exemption for clearly visible cameras when dismissing an intrusion claim.
Opinions citing this section in our collection:
- Kenneth Isaac Parkerson v. State of Florida (District Court of Appeal of Florida 2015, 163 So. 3d 683)✓A man caught watching people inside their homes, once carrying a camera, argued Florida's video voyeurism statute was facially overbroad because it could reach journalists and investigators; the court held section 810.145 is not overbroad and affirmed his convictions.
- Clemen v. Surterra Holdings, Inc. (District Court, M.D. Florida 2024)✓A worker sued over cameras aimed at a workplace changing area; dismissing her intrusion on seclusion claim, the court drew on section 810.145's privacy definition and its exclusion for obvious cameras, and found no authority making an alleged violation outrageous per se.
- Keith Taig v. City of Vero Beach (Court of Appeals for the Eleventh Circuit 2023)✓A spa customer recorded by covert police cameras installed under a court order argued Florida statutes including section 810.145 gave officers clear notice of customers' privacy rights; the court held those state statutes do not clearly establish a federal constitutional right.
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Florida Recording Laws (2026): All-Party Consent Rules, Is It Illegal to Video Record Someone Without Their Consent? (2026), Florida Landlord-Tenant Recording Laws: Cameras and Privacy Rules (2026)
§ 934.03Interception and disclosure of wire, oral, or electronic communications prohibited.In forcecited in 51 of our articles
(1) Except as otherwise specifically provided in this chapter, any person who:(a) Intentionally intercepts, endeavors to intercept, or procures any other person to intercept or endeavor to intercept any wire, oral, or electronic communication; (b) Intentionally uses, endeavors to use, or procures any other person to use or endeavor to use any electronic, mechanical, or other device to intercept any oral communication when:1. Such device is affixed to, or otherwise transmits a signal through, a wire, cable, or other like connection used in wire communication; or 2.
Official text (excerpt) · last checked 2026-08-31 · Read the full text in our law library · Verify at leg.state.fl.us
Cited in 74 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):State v. Walls (1978) held that recording an in-home oral communication without the consent of all parties violated section 934.03 and required suppression, and State v. Inciarrano (1985) held the statute protects only communications uttered with a reasonable expectation of privacy.
Opinions citing this section in our collection:
- State v. Walls (Supreme Court of Florida 1978, 356 So. 2d 294)✓An extortion victim secretly recorded threats made to him in his own home; the court held that was a protected oral communication, that recording it without every party's consent violated Section 934.03, and that Section 934.06 barred using the tape as evidence.
- SHARRON TASHA FORD v. CITY OF BOYNTON BEACH (District Court of Appeal of Florida 2021)“…ng oral communications in violation of the wiretap statute, section 934.03, Florida Statutes (2009), and for obstructing without vio…”
- State v. Calhoun (Circuit Court for the Judicial Circuits of Florida 1984, 7 Fla. Supp. 2d 3)“…hall not be violated” . . . (emphasis mine) Furthermore, section 934.03, Florida Statutes, makes it unlawful for *6 any person (…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Florida Dashcam Laws: Rules for Dashboard Cameras (2026), Can an Employer Record Conversations Without Consent? (2026), Can You Record ICE Agents? Know Your Rights by State (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Florida Statutes 501.701-501.721 (Florida Digital Bill of Rights) -- The 2025 Florida Statutes(leg.state.fl.us).gov
- SB 262 Enrolled Text -- Florida Digital Bill of Rights(flsenate.gov).gov
- Florida Statute 501.171 -- Security of Confidential Personal Information (FIPA)(leg.state.fl.us).gov
- Florida Statute 501.1735 -- Protection of Children in Online Spaces(leg.state.fl.us).gov
- Florida Statute 501.1736 -- Social Media Platforms; Minor Users(flsenate.gov).gov
- Florida Statute 501.059 -- Telephone Solicitation -- The 2025 Florida Statutes(leg.state.fl.us).gov
- Florida Statute 810.145 -- Digital Voyeurism -- The 2025 Florida Statutes(leg.state.fl.us).gov
- SB 262 Bill Summary -- Florida Senate 2023 Session(flsenate.gov).gov
- Florida Digital Bill of Rights Annual Enforcement Report (2026)(myfloridalegal.com).gov
- Attorney General Enforcement Action Against Roku -- My Florida Legal (Oct. 14, 2025)(myfloridalegal.com).gov
- SB 1524 (2014) -- Florida Information Protection Act Original Legislation(flsenate.gov).gov
- Data Security Consumer Protection -- My Florida Legal(myfloridalegal.com).gov
- HB 1557 (2026) -- Motor Vehicle Data Privacy(flsenate.gov).gov
- 11th Circuit Order Lifting HB 3 Injunction -- CCIA and NetChoice v. Uthmeier (Nov. 25, 2025)(netchoice.org)
- TAKE IT DOWN Act -- Congress.gov CRS Summary (Pub. L. 119-12)(congress.gov).gov
- Florida Statute 810.145 -- 2024 Amendment History (ch. 2024-132) -- Florida Senate(flsenate.gov).gov
- Florida enters the privacy enforcement arena: Roku analysis -- Freeman Mathis & Gary(fmglaw.com)
- Florida Statute 501.715 -- Requirements for Sensitive Data (prior consent to sell; required sale notice)(leg.state.fl.us)
- Florida Statute 501.702 -- Definitions (controller definition, s. 501.702(9)(a)1.-6.)(leg.state.fl.us)
- Florida Statute 501.72 -- Enforcement and Implementation by the Department of Legal Affairs (penalties; discretionary 45-day cure)(leg.state.fl.us)