🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-AL · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 9 sources retrieved model claude-sonnet-5 ·

United States – Alabama

US-AL schema gdpri-v2 trajectory: not recordedregulated (sectoral)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 25 claims · 9 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
25Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A comprehensive framework exists on paper (HB 351) but is not yet legally operative; current in-force coverage is limited to breach notification and sectoral rules.

Primary frameworkAlabama Data Breach Notification Act of 2018 (in force); Alabama Personal Data Protection Act, HB 351 (enacted, not yet effective 2027-05-01)
Traffic-light rationale — AmberA comprehensive framework exists on paper (HB 351) but is not yet legally operative; current in-force coverage is limited to breach notification and sectoral rules.

Sub-modules (5)

Regulator And AuthorityGreen

The Alabama AG (currently Steve Marshall) enforces the breach notification act and will hold exclusive enforcement authority under the incoming PDPA; there is no dedicated data-protection authority (DPA).

Claims (2):

  • The Alabama Attorney General has authority to issue penalties for violations of the Alabama Data Breach Notification Act of 2018.
  • The Alabama Personal Data Protection Act grants residents various data rights and sets obligations for data controllers and processors, with enforcement by the Attorney General.

Act And InstrumentsAmber

Two primary instruments identified: the 2018 Data Breach Notification Act (in force) and the 2026-signed Personal Data Protection Act (enacted_not_yet_effective).

Claims (2):

  • Governor Kay Ivey signed the Alabama Data Breach Notification Act of 2018, following passage by the Alabama House and Senate (SB 318).
  • Governor Kay Ivey signed House Bill 351, the Alabama Personal Data Protection Act, into law on 16 April 2026; the law takes effect 1 May 2027.

Material ScopeAmber

The PDPA's applicability thresholds (25,000+ AL residents, or any-volume data sales generating 25% of revenue) and exemptions are documented; the breach act's scope is defined by its notification triggers rather than a general material-scope clause.

Claims (2):

  • The Alabama Personal Data Protection Act generally applies to businesses that control or process the data of more than 25,000 Alabama residents, or that derive 25% of their revenue from data sales involving any number of data subjects.
  • The Alabama Personal Data Protection Act exempts small businesses with fewer than 500 employees and nonprofits with fewer than 100 employees, unless they sell personal data, and also exempts defined political organizations.

Territorial ScopeRed

No source located specifying an extraterritorial-application clause beyond the resident-count/revenue thresholds used to define 'controller' status.

Absence provenance: not recorded. Searched: not recorded.

Regulator Registration And FilingRed

No controller/processor registration or filing regime (e.g., data-broker registry) was found for Alabama's breach act or the PDPA; this differs from states like California and Vermont.

Absence provenance: not recorded. Searched: not recorded.

Category narrative59 words

Alabama currently has no operative comprehensive data-protection statute; the field is governed by the Alabama Data Breach Notification Act of 2018 (in force) plus the newly enacted but not-yet-effective Alabama Personal Data Protection Act (HB 351, effective 1 May 2027) and a scatter of sectoral statutes. The Alabama Attorney General is the consistent enforcement authority across all instruments identified.

Sources and claims (6)
  1. ConfirmedDataGuidance (reporting AG announcement)The Alabama Attorney General has authority to issue penalties for violations of the Alabama Data Breach Notification Act of 2018.observed
  2. ConfirmedDataGuidanceThe Alabama Personal Data Protection Act grants residents various data rights and sets obligations for data controllers and processors, with enforcement by the Attorney General.observed
  3. ConfirmedDataGuidance (reporting AG announcement)Governor Kay Ivey signed the Alabama Data Breach Notification Act of 2018, following passage by the Alabama House and Senate (SB 318).observed
  4. ConfirmedIAPPGovernor Kay Ivey signed House Bill 351, the Alabama Personal Data Protection Act, into law on 16 April 2026; the law takes effect 1 May 2027.observed
  5. ConfirmedIAPPThe Alabama Personal Data Protection Act generally applies to businesses that control or process the data of more than 25,000 Alabama residents, or that derive 25% of their revenue from data sales involving any number of data subjects.observed
  6. ProbableIAPPThe Alabama Personal Data Protection Act exempts small businesses with fewer than 500 employees and nonprofits with fewer than 100 employees, unless they sell personal data, and also exempts defined political organizations.observed

#

No in-force lawful-basis regime exists; the incoming PDPA's granular consent/special-category text could not be confirmed from available secondary sources.

Primary frameworkAlabama Personal Data Protection Act, HB 351 (enacted, not yet effective); House Bill 263 (biological/neural data, status unconfirmed)
Traffic-light rationale — RedNo in-force lawful-basis regime exists; the incoming PDPA's granular consent/special-category text could not be confirmed from available secondary sources.

Sub-modules (4)

Lawful BasesRed

No enumerated lawful-basis list (analogous to GDPR Art. 6) was confirmed for the PDPA in the sources reviewed.

Absence provenance: not recorded. Searched: not recorded.

Special CategoriesAmber

HB 263 proposes consumer protections for biological and neural data, requiring consent for transfer and prohibiting marketing based on such data; the PDPA aligns its definition of 'child' with COPPA (under 13), implying heightened treatment of children's data as a sensitive category.

Claims (2):

  • House Bill 263 introduces consumer protections for biological and neural data, requiring consent for data transfer and prohibiting marketing based on such data.
  • The Alabama Personal Data Protection Act's children's privacy provisions follow the Children's Online Privacy Protection Act definition of a child, and the bill's definition of minors for PDPA purposes covers children under age 13.

Pseudonymisation And AnonymisationRed

No pseudonymisation/anonymisation safe-harbour provisions specific to Alabama statutes were identified.

Absence provenance: not recorded. Searched: not recorded.

Category narrative65 words

Alabama has no enacted, operative lawful-basis or consent framework analogous to GDPR Art. 6/7. The forthcoming PDPA's consent architecture and enumerated lawful bases were not directly retrievable from bill text via secondary sources. Sensitive/special data protections are emerging piecemeal, notably via a proposed bill (HB 263) targeting biological and neural data, and via the PDPA's COPPA-aligned treatment of children under 13 as a sensitive population.

Sources and claims (2)
  1. UncertainDataGuidanceHouse Bill 263 introduces consumer protections for biological and neural data, requiring consent for data transfer and prohibiting marketing based on such data.observed
  2. ProbableIAPPThe Alabama Personal Data Protection Act's children's privacy provisions follow the Children's Online Privacy Protection Act definition of a child, and the bill's definition of minors for PDPA purposes covers children under age 13.observed

#

A rights regime is legislated but not yet effective, and its granular contours are not independently confirmed in the sources gathered.

Primary frameworkAlabama Personal Data Protection Act, HB 351 (enacted, not yet effective 2027-05-01)
Traffic-light rationale — AmberA rights regime is legislated but not yet effective, and its granular contours are not independently confirmed in the sources gathered.

Sub-modules (5)

Access RightAmber

General grant of 'data rights' confirmed; a specific right-of-access provision was not independently verified.

Claims (1):

  • The Alabama Personal Data Protection Act grants Alabama residents various consumer data rights, enforceable exclusively by the Attorney General.

Rectification And ErasureRed

Not independently confirmed from bill text; typical of comparable 2020s-era state comprehensive laws but unverified for Alabama specifically.

Absence provenance: not recorded. Searched: not recorded.

Restriction And ObjectionRed

Not independently confirmed.

Absence provenance: not recorded. Searched: not recorded.

Data PortabilityRed

Not independently confirmed.

Absence provenance: not recorded. Searched: not recorded.

Deadlines And Response WindowsRed

No confirmed statutory response-window deadlines for consumer rights requests under the PDPA were located.

Absence provenance: not recorded. Searched: not recorded.

Category narrative45 words

Sources confirm the Alabama Personal Data Protection Act grants residents 'various data rights' with AG enforcement, but granular right-by-right text (access, rectification/erasure, restriction/objection, portability, and specific response-window deadlines) was not retrievable from the secondary reporting reviewed. This module is assessed conservatively pending primary bill-text confirmation.

Sources and claims (1)
  1. ConfirmedDataGuidanceThe Alabama Personal Data Protection Act grants Alabama residents various consumer data rights, enforceable exclusively by the Attorney General.observed

#

Breach-notification duties are well-evidenced and in force; DPIA/DPO/ROPA/retention duties under the incoming PDPA remain unconfirmed.

Primary frameworkAlabama Data Breach Notification Act of 2018 (in force); Insurance Data Security Law, Ala. Code Title 27, Ch. 62 (in force, insurance sector); Alabama Personal Data Protection Act (enacted, not yet effective)
Traffic-light rationale — AmberBreach-notification duties are well-evidenced and in force; DPIA/DPO/ROPA/retention duties under the incoming PDPA remain unconfirmed.

Sub-modules (7)

Accountability And DpiaRed

No DPIA trigger or accountability-principle text specific to the PDPA was confirmed.

Absence provenance: not recorded. Searched: not recorded.

Dpo RequirementsRed

No DPO-appointment threshold specific to Alabama was confirmed.

Absence provenance: not recorded. Searched: not recorded.

Ropa RequirementsRed

No records-of-processing obligation specific to Alabama was confirmed.

Absence provenance: not recorded. Searched: not recorded.

Joint Controller ArrangementsRed

No joint-controller provision specific to Alabama was confirmed.

Absence provenance: not recorded. Searched: not recorded.

Security MeasuresAmber

Insurance licensees must implement an information security program to protect personal information under the Insurance Data Security Law; a general (non-insurance) security-of-processing mandate under the PDPA was not confirmed.

Claims (1):

  • Under the Insurance Data Security Law, insurance licensees are required to protect personal information and to investigate and respond to breaches of security.

Breach NotificationGreen

The 2018 Act requires notice to affected Alabama residents within 45 days of discovery, notice to the AG within 45 days (and to nationwide consumer reporting agencies) if a breach affects more than 1,000 individuals, and notice from third-party agents to covered entities within 10 days. Insurance licensees separately must notify the Alabama Department of Insurance within three business days of determining a breach occurred.

Claims (2):

  • The Alabama Data Breach Notification Act of 2018 requires entities to notify Alabama residents of a breach within 45 days of its discovery, and to notify the Attorney General within 45 days if the breach affects more than 1,000 individuals, as well as all nationwide consumer reporting agencies; third-party agents must notify the covered entity within ten days of discovering a breach.
  • Under the Insurance Data Security Law, insurance licensees must notify the Alabama Department of Insurance within three business days of determining that a security breach has occurred.

Retention And DisposalRed

No general retention-limitation or disposal-duty statute specific to Alabama personal data was confirmed.

Absence provenance: not recorded. Searched: not recorded.

Category narrative52 words

The clearest, currently in-force controller duty in Alabama is breach notification under the 2018 Act (45-day consumer/AG notice, 10-day third-party-agent notice). Sector-specific security-of-processing duties exist for insurance licensees under the Insurance Data Security Law. DPIA, DPO, ROPA, joint-controller and retention/disposal duties under the incoming PDPA were not confirmed from available secondary sources.

Sources and claims (3)
  1. ConfirmedDataGuidanceUnder the Insurance Data Security Law, insurance licensees are required to protect personal information and to investigate and respond to breaches of security.observed
  2. ConfirmedDataGuidance (reporting AG announcement)The Alabama Data Breach Notification Act of 2018 requires entities to notify Alabama residents of a breach within 45 days of its discovery, and to notify the Attorney General within 45 days if the breach affects more than 1,000 individuals, as well as all nationwide consumer reporting agencies; third-party agents must notify the covered entity within ten days of discovering a breach.observed
  3. ConfirmedDataGuidanceUnder the Insurance Data Security Law, insurance licensees must notify the Alabama Department of Insurance within three business days of determining that a security breach has occurred.observed

#

No comprehensive cross-border transfer regime exists at the Alabama state level; this is an explicit and legitimate gap finding rather than a silent omission.

Traffic-light rationale — RedNo comprehensive cross-border transfer regime exists at the Alabama state level; this is an explicit and legitimate gap finding rather than a silent omission.

Sub-modules (6)

Transfer MechanismsRed

No Alabama-specific transfer-mechanism statute was located.

Absence provenance: not recorded. Searched: not recorded.

Adequacy ReceivedRed

Not applicable at US sub-federal level; no adequacy-receipt mechanism exists for Alabama.

Absence provenance: not recorded. Searched: not recorded.

Adequacy GrantedRed

Not applicable; Alabama grants no adequacy decisions.

Absence provenance: not recorded. Searched: not recorded.

Sccs And BcrsRed

No Alabama-specific SCC/BCR framework was located.

Absence provenance: not recorded. Searched: not recorded.

Transfer Impact AssessmentRed

No Alabama-specific TIA requirement was located.

Absence provenance: not recorded. Searched: not recorded.

Data LocalisationRed

No Alabama data-localisation mandate was located.

Absence provenance: not recorded. Searched: not recorded.

Category narrative43 words

Alabama, as a US state, has no adequacy-decision framework, SCC/BCR regime, or data-localisation mandate of its own; cross-border personal-data transfer questions touching Alabama residents are governed by general U.S. federal law rather than a state-specific transfer mechanism. No Alabama-specific data-localisation statute was identified.

Sources and claims (1)
  1. UncertainDataGuidanceAlabama has no comprehensive privacy law establishing a cross-border data-transfer mechanism; general U.S. federal frameworks apply instead of a state-specific regime.observed

#

Insurance overlay is well-evidenced and in force; health, financial, telecoms, employment, credit-scoring and education overlays are only generically referenced without confirmed Alabama-specific statutory text.

Primary frameworkInsurance Data Security Law, Ala. Code Title 27, Ch. 62 (in force)
Supervisory authorityAlabama Department of Insurance
Traffic-light rationale — AmberInsurance overlay is well-evidenced and in force; health, financial, telecoms, employment, credit-scoring and education overlays are only generically referenced without confirmed Alabama-specific statutory text.

Sub-modules (7)

Financial Sector OverlayAmber

Alabama statutes are noted to regulate 'financial information' generally, implying reliance on federal GLBA overlay rather than a dedicated state financial-privacy statute.

Claims (1):

  • There are other Alabama statutes that regulate patient and medical records, financial information, and telemarketing and telephone communications.

Health Sector OverlayAmber

Alabama statutes regulate patient and medical records generally, implying reliance on federal HIPAA overlay; recent breach reports (e.g., Aesto Health, Norwood Clinic) were filed under HIPAA/HHS OCR channels.

Claims (1):

  • There are other Alabama statutes that regulate patient and medical records, financial information, and telemarketing and telephone communications.

Telecoms And EprivacyAmber

Alabama statutes regulate telemarketing and telephone communications generally; no dedicated ePrivacy/cookie-consent statute was identified.

Claims (1):

  • There are other Alabama statutes that regulate patient and medical records, financial information, and telemarketing and telephone communications.

Employment DataRed

No Alabama-specific employment-data privacy statute was located.

Absence provenance: not recorded. Searched: not recorded.

Credit And ScoringRed

No Alabama-specific credit-scoring privacy statute was located beyond reliance on federal FCRA.

Absence provenance: not recorded. Searched: not recorded.

EducationRed

No Alabama-specific education-sector data-privacy statute was located.

Absence provenance: not recorded. Searched: not recorded.

InsuranceGreen

Insurance licensees are required to protect personal information and to notify the Alabama Department of Insurance within three business days of determining a breach occurred.

Claims (1):

  • Under the Insurance Data Security Law, insurance licensees must notify the Alabama Department of Insurance within three business days of determining that a security breach has occurred.
Category narrative49 words

Alabama layers several sector-specific statutes atop the general breach-notification baseline: the Insurance Data Security Law (Title 27, Ch. 62) for insurance licensees, and general references to statutes governing patient/medical records, financial information, and telemarketing/telephone communications (implying reliance on federal HIPAA/GLBA/TCPA overlays rather than dedicated Alabama enactments in those areas).

Sources and claims (1)
  1. UncertainDataGuidanceThere are other Alabama statutes that regulate patient and medical records, financial information, and telemarketing and telephone communications.observed

#

Only the PDPA's sale-threshold provision is confirmed as enacted (not yet effective); dark-pattern and marketing-restriction bills have uncertain enactment status.

Primary frameworkAlabama Personal Data Protection Act, HB 351 (enacted, not yet effective)
Traffic-light rationale — AmberOnly the PDPA's sale-threshold provision is confirmed as enacted (not yet effective); dark-pattern and marketing-restriction bills have uncertain enactment status.

Sub-modules (6)

Cookies And TrackersRed

No Alabama-specific cookie/tracker consent statute was located.

Absence provenance: not recorded. Searched: not recorded.

Dark PatternsAmber

House Bill 283 is reported to empower consumers to control their personal data and to address manipulative user interfaces (dark patterns), but its enactment status was not independently confirmed.

Claims (1):

  • Alabama's House Bill 283 empowers consumers to control their personal data and addresses manipulative user interfaces.

Opt Out SignalsRed

No universal opt-out signal (e.g., Global Privacy Control) recognition requirement was located for Alabama.

Absence provenance: not recorded. Searched: not recorded.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rule specific to Alabama was located.

Absence provenance: not recorded. Searched: not recorded.

Cross Context AdvertisingAmber

The PDPA's 'sale' threshold is unusual in applying regardless of data volume where 25% of revenue derives from data sales, a novelty compared with most other state comprehensive laws.

Claims (1):

  • The Alabama Personal Data Protection Act's sale-related applicability threshold is unique in applying when any number of individuals' data is sold in combination with the 25%-of-revenue test, unlike most other states which pair the 25% revenue test with a 25,000-individual threshold.

Direct MarketingAmber

House Bill 263, if enacted, would prohibit marketing based on biological/neural data; no general direct-marketing consent/suppression statute for Alabama was otherwise confirmed.

Claims (1):

  • House Bill 263 introduces consumer protections for biological and neural data, requiring consent for data transfer and prohibiting marketing based on such data.
Category narrative57 words

Commercial/adtech-specific privacy rules in Alabama are emergent and largely tied to the not-yet-effective PDPA and several 2026 bills of uncertain enactment status: House Bill 283 (dark patterns / consumer control over personal data) and the PDPA's unusual 'sale' threshold (any-volume data sales generating 25% of revenue). No dedicated cookie-consent, opt-out-signal (e.g., GPC), or clean-room statute was identified.

Sources and claims (2)
  1. UncertainDataGuidanceAlabama's House Bill 283 empowers consumers to control their personal data and addresses manipulative user interfaces.observed
  2. ProbableIAPPThe Alabama Personal Data Protection Act's sale-related applicability threshold is unique in applying when any number of individuals' data is sold in combination with the 25%-of-revenue test, unlike most other states which pair the 25% revenue test with a 25,000-individual threshold.observed

#

Several AI-specific bills are documented but enactment status and full scope are only partially confirmed; core ADM/profiling/biometric rights are unconfirmed.

Primary frameworkSenate Bill 129 (AI-generated content transparency); House Bills 324/325 (AI chatbot regulation) — enactment status not fully confirmed
Traffic-light rationale — AmberSeveral AI-specific bills are documented but enactment status and full scope are only partially confirmed; core ADM/profiling/biometric rights are unconfirmed.

Sub-modules (6)

Profiling RestrictionsRed

No confirmed profiling-restriction provision analogous to GDPR Art. 22 was located for Alabama.

Absence provenance: not recorded. Searched: not recorded.

Automated Decision Making TransparencyRed

No confirmed ADM transparency/explanation right was located for Alabama.

Absence provenance: not recorded. Searched: not recorded.

Ai Risk AssessmentsAmber

Senate Bill 129 mandates transparency for AI-generated content, requiring clear disclosures and metadata marking, with enforcement starting 1 October 2026; House Bills 324/325 mandate age verification, emergency protocols, and data-collection limits for AI chatbots, enforced by the AG.

Claims (2):

  • Senate Bill 129 mandates transparency for AI-generated content in Alabama, requiring clear disclosures and metadata marking, with enforcement starting 1 October 2026.
  • House Bill 324 mandates age verification, emergency protocols, and data-collection limits for AI chatbots, with enforcement by the Attorney General of Alabama; House Bill 325 regulates AI chatbot use, requiring consumer notification and establishing penalties for violations.

Biometric RegimeAmber

House Bill 263's biological data provisions are the closest analogue to a biometric regime identified, but its enactment status is unconfirmed; no dedicated facial-recognition/fingerprint statute was located.

Claims (1):

  • House Bill 263 introduces consumer protections for biological and neural data, requiring consent for data transfer and prohibiting marketing based on such data.

Genetic DataRed

No dedicated Alabama genetic-data statute distinct from HB 263's biological-data language was located.

Absence provenance: not recorded. Searched: not recorded.

State Surveillance CarveoutsRed

No Alabama-specific state-surveillance/national-security carveout provision was located.

Absence provenance: not recorded. Searched: not recorded.

Category narrative67 words

Alabama's algorithmic/biometric governance activity in 2026 clusters around AI-specific bills: Senate Bill 129 (AI-generated content transparency, disclosures and metadata marking, enforcement from 1 October 2026) and House Bills 324/325 (AI chatbot regulation, age verification, emergency protocols, data-collection limits, AG enforcement). House Bill 263's biological/neural data protections also touch this module. No confirmed Art. 22-style profiling restriction, ADM transparency right, or dedicated biometric/genetic-data statute was located for Alabama.

Sources and claims (2)
  1. ProbableDataGuidanceSenate Bill 129 mandates transparency for AI-generated content in Alabama, requiring clear disclosures and metadata marking, with enforcement starting 1 October 2026.observed
  2. UncertainDataGuidanceHouse Bill 324 mandates age verification, emergency protocols, and data-collection limits for AI chatbots, with enforcement by the Attorney General of Alabama; House Bill 325 regulates AI chatbot use, requiring consumer notification and establishing penalties for violations.observed

#

Multiple children's-privacy instruments are documented, but a material date conflict (HB 161 effective date) and uncertain enactment status of related bills prevent a green rating.

Primary frameworkAlabama App Store Accountability Act, HB 161 (age/effective-date conflict unresolved); Alabama Personal Data Protection Act, HB 351 (enacted, not yet effective)
Traffic-light rationale — AmberMultiple children's-privacy instruments are documented, but a material date conflict (HB 161 effective date) and uncertain enactment status of related bills prevent a green rating.

Sub-modules (5)

Age VerificationAmber

The App Store Accountability Act (HB 161) requires age verification for minors under 18 using app stores; reported effective dates conflict between 1 October 2026 and 1 January 2027 across sources.

Claims (1):

  • Alabama's App Store Accountability Act (House Bill 161) mandates age verification for minors using app stores; secondary sources report conflicting effective dates of 1 October 2026 and 1 January 2027, which remains unresolved.

Minor Profiling BansAmber

No dedicated minor-profiling ban was located; the PDPA's COPPA-aligned 'child' definition (under 13) is the closest analogue for heightened protection of minors' data.

Claims (1):

  • The Alabama Personal Data Protection Act's children's privacy provisions follow the Children's Online Privacy Protection Act definition of a child, and the bill's definition of minors for PDPA purposes covers children under age 13.

Education SettingsRed

No education-setting-specific children's data statute was located for Alabama.

Absence provenance: not recorded. Searched: not recorded.

Dependent AdultsRed

No dependent-adult (elderly/incapacitated) data-protection statute was located for Alabama.

Absence provenance: not recorded. Searched: not recorded.

Category narrative96 words

Alabama has the most active children's-privacy legislative track of any module reviewed: the App Store Accountability Act (HB 161) mandates age verification and verifiable parental consent for minors under 18 using app stores, though its effective date is reported inconsistently (1 October 2026 in one summary vs. 1 January 2027 in another — flagged as an open question). The PDPA separately defines 'minor' by reference to COPPA (under 13) for its own sensitive-data purposes. House Bill 276 requires social media platforms to protect minors and cooperate with law enforcement. No education-setting-specific or dependent-adult-specific protection was located.

Sources and claims (2)
  1. UncertainDataGuidanceAlabama's App Store Accountability Act (House Bill 161) mandates age verification for minors using app stores; secondary sources report conflicting effective dates of 1 October 2026 and 1 January 2027, which remains unresolved.observed
  2. ProbableIAPPAlabama's App Store Accountability Act, which requires verifiable parental consent in addition to age verification, applies to minors under age 18.observed

#

Enforcement powers and penalty structures are clearly documented and the AG has a track record of active, recent enforcement (multistate settlements) even absent a comprehensive law currently in force.

Primary frameworkAlabama Data Breach Notification Act of 2018 (in force); Alabama Personal Data Protection Act, HB 351 (enacted, not yet effective)
Traffic-light rationale — GreenEnforcement powers and penalty structures are clearly documented and the AG has a track record of active, recent enforcement (multistate settlements) even absent a comprehensive law currently in force.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The AG can impose penalties up to $500,000 per breach for knowing violations of the 2018 Act's notice provisions, and up to $5,000/day for continuing non-compliance; the PDPA is exclusively AG-enforced.

Claims (2):

  • Covered entities or third-party agents who knowingly violate the Alabama Data Breach Notification Act's notification provisions can be subject to a penalty not exceeding $500,000 per breach, and covered entities can be liable for a civil penalty of not more than $5,000 per day for each consecutive day of continued non-compliance.
  • The Alabama Personal Data Protection Act includes a non-sunsetting 45-day cure provision together with exclusive Attorney General enforcement.

Enforcement Activity IndexGreen

Alabama reached a $12.2 million settlement with Roblox Corporation to enhance child-safety measures on the platform, and joined a 42-state AG coalition settlement with 23andMe's bankruptcy trustee over a 2023 breach affecting 6.9 million customers.

Claims (2):

  • Alabama reached a $12.2 million settlement with Roblox Corporation to enhance child-safety measures on the platform.
  • A coalition of 42 attorneys general, including Alabama, reached a settlement with 23andMe's bankruptcy trustee over a 2023 data breach affecting 6.9 million customers.

Regulator Funding And CapacityRed

No specific funding or headcount data for the AG's Consumer Protection Division's privacy enforcement function was located.

Absence provenance: not recorded. Searched: not recorded.

Collective Redress And Class ActionsAmber

No Alabama-specific consumer class-action mechanism for data-privacy claims was located; the 23andMe matter was a multistate AG settlement rather than a private class action.

Claims (1):

  • A coalition of 42 attorneys general, including Alabama, reached a settlement with 23andMe's bankruptcy trustee over a 2023 data breach affecting 6.9 million customers.

Private Right Of ActionAmber

The PDPA provides for exclusive Attorney General enforcement together with a non-sunsetting 45-day cure provision, indicating the absence of a private right of action.

Claims (1):

  • The Alabama Personal Data Protection Act's exclusive Attorney General enforcement model, combined with its 45-day cure provision, indicates the statute does not create a private right of action for consumers.

Recent Developments 180DAmber

Within the last 180 days, the most significant development is the Governor's 16 April 2026 signature enacting the Alabama Personal Data Protection Act (HB 351), alongside a wave of related 2026-session bills (App Store Accountability Act, AI-transparency and AI-chatbot bills, data-broker and dark-pattern bills) of varying enactment status.

Claims (1):

  • Governor Kay Ivey signed House Bill 351, the Alabama Personal Data Protection Act, into law on 16 April 2026; the law takes effect 1 May 2027.
Category narrative72 words

Enforcement is centralized in the Alabama Attorney General across all identified instruments. The 2018 breach act carries defined civil penalties ($500,000 per breach for knowing violations; $5,000/day for continuing non-compliance). The PDPA (not yet effective) provides a non-sunsetting 45-day cure period and exclusive AG enforcement, implying no private right of action. Recent multistate AG enforcement activity involving Alabama includes the 23andMe bankruptcy-trustee settlement and a $12.2 million Roblox settlement on child-safety grounds.

Sources and claims (5)
  1. ConfirmedDataGuidance (reporting AG announcement)Covered entities or third-party agents who knowingly violate the Alabama Data Breach Notification Act's notification provisions can be subject to a penalty not exceeding $500,000 per breach, and covered entities can be liable for a civil penalty of not more than $5,000 per day for each consecutive day of continued non-compliance.observed
  2. ProbableIAPPThe Alabama Personal Data Protection Act includes a non-sunsetting 45-day cure provision together with exclusive Attorney General enforcement.observed
  3. ConfirmedDataGuidanceAlabama reached a $12.2 million settlement with Roblox Corporation to enhance child-safety measures on the platform.observed
  4. ConfirmedDataGuidanceA coalition of 42 attorneys general, including Alabama, reached a settlement with 23andMe's bankruptcy trustee over a 2023 data breach affecting 6.9 million customers.observed
  5. ProbableIAPPThe Alabama Personal Data Protection Act's exclusive Attorney General enforcement model, combined with its 45-day cure provision, indicates the statute does not create a private right of action for consumers.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Alabama
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 25 claim(s), 9 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Breach-notification duties, AG enforcement powers/penalties, and the Insurance Data Security Law overlay are grounded in T2 (AG-announcement-derived) sources and are high-confidence. The Alabama Personal Data Protection Act's existence, signing date, effective date, applicability thresholds, exemptions, and cure/enforcement model are grounded in T3 (IAPP/DataGuidance) analysis and are Probable-to-Confirmed. Granular PDPA provisions (enumerated lawful bases, DPIA/DPO/ROPA duties, itemized consumer rights, response-window deadlines) and the enactment status of several 2026-session bills (HB 263, HB 283, SB 213, HB 324/325, HB 276, HB 171/173/219) could not be verified against primary bill text and are marked Uncertain/Speculative with absent_field_provenance. cross_border_and_adequacy is legitimately near-empty, reflecting the absence of any state-level transfer regime.

Unresolved questions (7):

  • What is the correct effective date for the App Store Accountability Act (HB 161) — 1 October 2026 or 1 January 2027 — given conflicting statements in the same secondary source?
  • Has House Bill 263 (biological/neural data) been signed into law, and if so, on what date and with what effective date?
  • Has House Bill 283 (dark patterns / consumer control) been signed into law?
  • Has Senate Bill 213 (data broker obligations) been enacted, and what obligations does it impose?
  • Have House Bills 324/325 (AI chatbot regulation) and House Bill 276 (social media minor protections) been signed into law?
  • Does the Alabama Personal Data Protection Act include a GDPR-style enumerated lawful-bases list, DPIA triggers, DPO thresholds, or ROPA obligations, and what are the exact consumer-rights response deadlines?
  • What is the exact statutory citation and effective date for the Alabama Data Breach Notification Act of 2018 (Ala. Code Title 8, Chapter 38) beyond its 28 March 2018 signing?

Escalate to primary-source review: yes