A comprehensive framework exists on paper (HB 351) but is not yet legally operative; current in-force coverage is limited to breach notification and sectoral rules.
Primary frameworkAlabama Data Breach Notification Act of 2018 (in force); Alabama Personal Data Protection Act, HB 351 (enacted, not yet effective 2027-05-01)
Traffic-light rationale — AmberA comprehensive framework exists on paper (HB 351) but is not yet legally operative; current in-force coverage is limited to breach notification and sectoral rules.
Sub-modules (5)
Regulator And AuthorityGreen
The Alabama AG (currently Steve Marshall) enforces the breach notification act and will hold exclusive enforcement authority under the incoming PDPA; there is no dedicated data-protection authority (DPA).
Claims (2):
The Alabama Attorney General has authority to issue penalties for violations of the Alabama Data Breach Notification Act of 2018.
The Alabama Personal Data Protection Act grants residents various data rights and sets obligations for data controllers and processors, with enforcement by the Attorney General.
Act And InstrumentsAmber
Two primary instruments identified: the 2018 Data Breach Notification Act (in force) and the 2026-signed Personal Data Protection Act (enacted_not_yet_effective).
Claims (2):
Governor Kay Ivey signed the Alabama Data Breach Notification Act of 2018, following passage by the Alabama House and Senate (SB 318).
Governor Kay Ivey signed House Bill 351, the Alabama Personal Data Protection Act, into law on 16 April 2026; the law takes effect 1 May 2027.
Material ScopeAmber
The PDPA's applicability thresholds (25,000+ AL residents, or any-volume data sales generating 25% of revenue) and exemptions are documented; the breach act's scope is defined by its notification triggers rather than a general material-scope clause.
Claims (2):
The Alabama Personal Data Protection Act generally applies to businesses that control or process the data of more than 25,000 Alabama residents, or that derive 25% of their revenue from data sales involving any number of data subjects.
The Alabama Personal Data Protection Act exempts small businesses with fewer than 500 employees and nonprofits with fewer than 100 employees, unless they sell personal data, and also exempts defined political organizations.
Territorial ScopeRed
No source located specifying an extraterritorial-application clause beyond the resident-count/revenue thresholds used to define 'controller' status.
Absence provenance: not recorded. Searched: not recorded.
Regulator Registration And FilingRed
No controller/processor registration or filing regime (e.g., data-broker registry) was found for Alabama's breach act or the PDPA; this differs from states like California and Vermont.
Absence provenance: not recorded. Searched: not recorded.
Category narrative59 words
Alabama currently has no operative comprehensive data-protection statute; the field is governed by the Alabama Data Breach Notification Act of 2018 (in force) plus the newly enacted but not-yet-effective Alabama Personal Data Protection Act (HB 351, effective 1 May 2027) and a scatter of sectoral statutes. The Alabama Attorney General is the consistent enforcement authority across all instruments identified.
Sources and claims (6)
ConfirmedDataGuidance (reporting AG announcement) — The Alabama Attorney General has authority to issue penalties for violations of the Alabama Data Breach Notification Act of 2018.observed
ConfirmedDataGuidance — The Alabama Personal Data Protection Act grants residents various data rights and sets obligations for data controllers and processors, with enforcement by the Attorney General.observed
ConfirmedDataGuidance (reporting AG announcement) — Governor Kay Ivey signed the Alabama Data Breach Notification Act of 2018, following passage by the Alabama House and Senate (SB 318).observed
ConfirmedIAPP — Governor Kay Ivey signed House Bill 351, the Alabama Personal Data Protection Act, into law on 16 April 2026; the law takes effect 1 May 2027.observed
ConfirmedIAPP — The Alabama Personal Data Protection Act generally applies to businesses that control or process the data of more than 25,000 Alabama residents, or that derive 25% of their revenue from data sales involving any number of data subjects.observed
ProbableIAPP — The Alabama Personal Data Protection Act exempts small businesses with fewer than 500 employees and nonprofits with fewer than 100 employees, unless they sell personal data, and also exempts defined political organizations.observed
No in-force lawful-basis regime exists; the incoming PDPA's granular consent/special-category text could not be confirmed from available secondary sources.
Primary frameworkAlabama Personal Data Protection Act, HB 351 (enacted, not yet effective); House Bill 263 (biological/neural data, status unconfirmed)
Traffic-light rationale — RedNo in-force lawful-basis regime exists; the incoming PDPA's granular consent/special-category text could not be confirmed from available secondary sources.
Sub-modules (4)
Lawful BasesRed
No enumerated lawful-basis list (analogous to GDPR Art. 6) was confirmed for the PDPA in the sources reviewed.
Absence provenance: not recorded. Searched: not recorded.
Consent ThresholdsAmber
General consent standards under the PDPA were not confirmed beyond the fact that HB 263 (biological/neural data) requires consent for data transfer.
Claims (1):
House Bill 263 introduces consumer protections for biological and neural data, requiring consent for data transfer and prohibiting marketing based on such data.
Special CategoriesAmber
HB 263 proposes consumer protections for biological and neural data, requiring consent for transfer and prohibiting marketing based on such data; the PDPA aligns its definition of 'child' with COPPA (under 13), implying heightened treatment of children's data as a sensitive category.
Claims (2):
House Bill 263 introduces consumer protections for biological and neural data, requiring consent for data transfer and prohibiting marketing based on such data.
The Alabama Personal Data Protection Act's children's privacy provisions follow the Children's Online Privacy Protection Act definition of a child, and the bill's definition of minors for PDPA purposes covers children under age 13.
Pseudonymisation And AnonymisationRed
No pseudonymisation/anonymisation safe-harbour provisions specific to Alabama statutes were identified.
Absence provenance: not recorded. Searched: not recorded.
Category narrative65 words
Alabama has no enacted, operative lawful-basis or consent framework analogous to GDPR Art. 6/7. The forthcoming PDPA's consent architecture and enumerated lawful bases were not directly retrievable from bill text via secondary sources. Sensitive/special data protections are emerging piecemeal, notably via a proposed bill (HB 263) targeting biological and neural data, and via the PDPA's COPPA-aligned treatment of children under 13 as a sensitive population.
Sources and claims (2)
UncertainDataGuidance — House Bill 263 introduces consumer protections for biological and neural data, requiring consent for data transfer and prohibiting marketing based on such data.observed
ProbableIAPP — The Alabama Personal Data Protection Act's children's privacy provisions follow the Children's Online Privacy Protection Act definition of a child, and the bill's definition of minors for PDPA purposes covers children under age 13.observed
Traffic-light rationale — AmberA rights regime is legislated but not yet effective, and its granular contours are not independently confirmed in the sources gathered.
Sub-modules (5)
Access RightAmber
General grant of 'data rights' confirmed; a specific right-of-access provision was not independently verified.
Claims (1):
The Alabama Personal Data Protection Act grants Alabama residents various consumer data rights, enforceable exclusively by the Attorney General.
Rectification And ErasureRed
Not independently confirmed from bill text; typical of comparable 2020s-era state comprehensive laws but unverified for Alabama specifically.
Absence provenance: not recorded. Searched: not recorded.
Restriction And ObjectionRed
Not independently confirmed.
Absence provenance: not recorded. Searched: not recorded.
Data PortabilityRed
Not independently confirmed.
Absence provenance: not recorded. Searched: not recorded.
Deadlines And Response WindowsRed
No confirmed statutory response-window deadlines for consumer rights requests under the PDPA were located.
Absence provenance: not recorded. Searched: not recorded.
Category narrative45 words
Sources confirm the Alabama Personal Data Protection Act grants residents 'various data rights' with AG enforcement, but granular right-by-right text (access, rectification/erasure, restriction/objection, portability, and specific response-window deadlines) was not retrievable from the secondary reporting reviewed. This module is assessed conservatively pending primary bill-text confirmation.
Sources and claims (1)
ConfirmedDataGuidance — The Alabama Personal Data Protection Act grants Alabama residents various consumer data rights, enforceable exclusively by the Attorney General.observed
Breach-notification duties are well-evidenced and in force; DPIA/DPO/ROPA/retention duties under the incoming PDPA remain unconfirmed.
Primary frameworkAlabama Data Breach Notification Act of 2018 (in force); Insurance Data Security Law, Ala. Code Title 27, Ch. 62 (in force, insurance sector); Alabama Personal Data Protection Act (enacted, not yet effective)
Traffic-light rationale — AmberBreach-notification duties are well-evidenced and in force; DPIA/DPO/ROPA/retention duties under the incoming PDPA remain unconfirmed.
Sub-modules (7)
Accountability And DpiaRed
No DPIA trigger or accountability-principle text specific to the PDPA was confirmed.
Absence provenance: not recorded. Searched: not recorded.
Dpo RequirementsRed
No DPO-appointment threshold specific to Alabama was confirmed.
Absence provenance: not recorded. Searched: not recorded.
Ropa RequirementsRed
No records-of-processing obligation specific to Alabama was confirmed.
Absence provenance: not recorded. Searched: not recorded.
Joint Controller ArrangementsRed
No joint-controller provision specific to Alabama was confirmed.
Absence provenance: not recorded. Searched: not recorded.
Security MeasuresAmber
Insurance licensees must implement an information security program to protect personal information under the Insurance Data Security Law; a general (non-insurance) security-of-processing mandate under the PDPA was not confirmed.
Claims (1):
Under the Insurance Data Security Law, insurance licensees are required to protect personal information and to investigate and respond to breaches of security.
Breach NotificationGreen
The 2018 Act requires notice to affected Alabama residents within 45 days of discovery, notice to the AG within 45 days (and to nationwide consumer reporting agencies) if a breach affects more than 1,000 individuals, and notice from third-party agents to covered entities within 10 days. Insurance licensees separately must notify the Alabama Department of Insurance within three business days of determining a breach occurred.
Claims (2):
The Alabama Data Breach Notification Act of 2018 requires entities to notify Alabama residents of a breach within 45 days of its discovery, and to notify the Attorney General within 45 days if the breach affects more than 1,000 individuals, as well as all nationwide consumer reporting agencies; third-party agents must notify the covered entity within ten days of discovering a breach.
Under the Insurance Data Security Law, insurance licensees must notify the Alabama Department of Insurance within three business days of determining that a security breach has occurred.
Retention And DisposalRed
No general retention-limitation or disposal-duty statute specific to Alabama personal data was confirmed.
Absence provenance: not recorded. Searched: not recorded.
Category narrative52 words
The clearest, currently in-force controller duty in Alabama is breach notification under the 2018 Act (45-day consumer/AG notice, 10-day third-party-agent notice). Sector-specific security-of-processing duties exist for insurance licensees under the Insurance Data Security Law. DPIA, DPO, ROPA, joint-controller and retention/disposal duties under the incoming PDPA were not confirmed from available secondary sources.
Sources and claims (3)
ConfirmedDataGuidance — Under the Insurance Data Security Law, insurance licensees are required to protect personal information and to investigate and respond to breaches of security.observed
ConfirmedDataGuidance (reporting AG announcement) — The Alabama Data Breach Notification Act of 2018 requires entities to notify Alabama residents of a breach within 45 days of its discovery, and to notify the Attorney General within 45 days if the breach affects more than 1,000 individuals, as well as all nationwide consumer reporting agencies; third-party agents must notify the covered entity within ten days of discovering a breach.observed
ConfirmedDataGuidance — Under the Insurance Data Security Law, insurance licensees must notify the Alabama Department of Insurance within three business days of determining that a security breach has occurred.observed
No comprehensive cross-border transfer regime exists at the Alabama state level; this is an explicit and legitimate gap finding rather than a silent omission.
Traffic-light rationale — RedNo comprehensive cross-border transfer regime exists at the Alabama state level; this is an explicit and legitimate gap finding rather than a silent omission.
Sub-modules (6)
Transfer MechanismsRed
No Alabama-specific transfer-mechanism statute was located.
Absence provenance: not recorded. Searched: not recorded.
Adequacy ReceivedRed
Not applicable at US sub-federal level; no adequacy-receipt mechanism exists for Alabama.
Absence provenance: not recorded. Searched: not recorded.
Adequacy GrantedRed
Not applicable; Alabama grants no adequacy decisions.
Absence provenance: not recorded. Searched: not recorded.
Sccs And BcrsRed
No Alabama-specific SCC/BCR framework was located.
Absence provenance: not recorded. Searched: not recorded.
Transfer Impact AssessmentRed
No Alabama-specific TIA requirement was located.
Absence provenance: not recorded. Searched: not recorded.
Data LocalisationRed
No Alabama data-localisation mandate was located.
Absence provenance: not recorded. Searched: not recorded.
Category narrative43 words
Alabama, as a US state, has no adequacy-decision framework, SCC/BCR regime, or data-localisation mandate of its own; cross-border personal-data transfer questions touching Alabama residents are governed by general U.S. federal law rather than a state-specific transfer mechanism. No Alabama-specific data-localisation statute was identified.
Sources and claims (1)
UncertainDataGuidance — Alabama has no comprehensive privacy law establishing a cross-border data-transfer mechanism; general U.S. federal frameworks apply instead of a state-specific regime.observed
Insurance overlay is well-evidenced and in force; health, financial, telecoms, employment, credit-scoring and education overlays are only generically referenced without confirmed Alabama-specific statutory text.
Primary frameworkInsurance Data Security Law, Ala. Code Title 27, Ch. 62 (in force)
Supervisory authorityAlabama Department of Insurance
Traffic-light rationale — AmberInsurance overlay is well-evidenced and in force; health, financial, telecoms, employment, credit-scoring and education overlays are only generically referenced without confirmed Alabama-specific statutory text.
Sub-modules (7)
Financial Sector OverlayAmber
Alabama statutes are noted to regulate 'financial information' generally, implying reliance on federal GLBA overlay rather than a dedicated state financial-privacy statute.
Claims (1):
There are other Alabama statutes that regulate patient and medical records, financial information, and telemarketing and telephone communications.
Health Sector OverlayAmber
Alabama statutes regulate patient and medical records generally, implying reliance on federal HIPAA overlay; recent breach reports (e.g., Aesto Health, Norwood Clinic) were filed under HIPAA/HHS OCR channels.
Claims (1):
There are other Alabama statutes that regulate patient and medical records, financial information, and telemarketing and telephone communications.
Telecoms And EprivacyAmber
Alabama statutes regulate telemarketing and telephone communications generally; no dedicated ePrivacy/cookie-consent statute was identified.
Claims (1):
There are other Alabama statutes that regulate patient and medical records, financial information, and telemarketing and telephone communications.
Employment DataRed
No Alabama-specific employment-data privacy statute was located.
Absence provenance: not recorded. Searched: not recorded.
Credit And ScoringRed
No Alabama-specific credit-scoring privacy statute was located beyond reliance on federal FCRA.
Absence provenance: not recorded. Searched: not recorded.
EducationRed
No Alabama-specific education-sector data-privacy statute was located.
Absence provenance: not recorded. Searched: not recorded.
InsuranceGreen
Insurance licensees are required to protect personal information and to notify the Alabama Department of Insurance within three business days of determining a breach occurred.
Claims (1):
Under the Insurance Data Security Law, insurance licensees must notify the Alabama Department of Insurance within three business days of determining that a security breach has occurred.
Category narrative49 words
Alabama layers several sector-specific statutes atop the general breach-notification baseline: the Insurance Data Security Law (Title 27, Ch. 62) for insurance licensees, and general references to statutes governing patient/medical records, financial information, and telemarketing/telephone communications (implying reliance on federal HIPAA/GLBA/TCPA overlays rather than dedicated Alabama enactments in those areas).
Sources and claims (1)
UncertainDataGuidance — There are other Alabama statutes that regulate patient and medical records, financial information, and telemarketing and telephone communications.observed
Only the PDPA's sale-threshold provision is confirmed as enacted (not yet effective); dark-pattern and marketing-restriction bills have uncertain enactment status.
Primary frameworkAlabama Personal Data Protection Act, HB 351 (enacted, not yet effective)
Traffic-light rationale — AmberOnly the PDPA's sale-threshold provision is confirmed as enacted (not yet effective); dark-pattern and marketing-restriction bills have uncertain enactment status.
Sub-modules (6)
Cookies And TrackersRed
No Alabama-specific cookie/tracker consent statute was located.
Absence provenance: not recorded. Searched: not recorded.
Dark PatternsAmber
House Bill 283 is reported to empower consumers to control their personal data and to address manipulative user interfaces (dark patterns), but its enactment status was not independently confirmed.
Claims (1):
Alabama's House Bill 283 empowers consumers to control their personal data and addresses manipulative user interfaces.
Opt Out SignalsRed
No universal opt-out signal (e.g., Global Privacy Control) recognition requirement was located for Alabama.
Absence provenance: not recorded. Searched: not recorded.
Clean Rooms And DcrRed
No clean-room/data-collaboration-room rule specific to Alabama was located.
Absence provenance: not recorded. Searched: not recorded.
Cross Context AdvertisingAmber
The PDPA's 'sale' threshold is unusual in applying regardless of data volume where 25% of revenue derives from data sales, a novelty compared with most other state comprehensive laws.
Claims (1):
The Alabama Personal Data Protection Act's sale-related applicability threshold is unique in applying when any number of individuals' data is sold in combination with the 25%-of-revenue test, unlike most other states which pair the 25% revenue test with a 25,000-individual threshold.
Direct MarketingAmber
House Bill 263, if enacted, would prohibit marketing based on biological/neural data; no general direct-marketing consent/suppression statute for Alabama was otherwise confirmed.
Claims (1):
House Bill 263 introduces consumer protections for biological and neural data, requiring consent for data transfer and prohibiting marketing based on such data.
Category narrative57 words
Commercial/adtech-specific privacy rules in Alabama are emergent and largely tied to the not-yet-effective PDPA and several 2026 bills of uncertain enactment status: House Bill 283 (dark patterns / consumer control over personal data) and the PDPA's unusual 'sale' threshold (any-volume data sales generating 25% of revenue). No dedicated cookie-consent, opt-out-signal (e.g., GPC), or clean-room statute was identified.
Sources and claims (2)
UncertainDataGuidance — Alabama's House Bill 283 empowers consumers to control their personal data and addresses manipulative user interfaces.observed
ProbableIAPP — The Alabama Personal Data Protection Act's sale-related applicability threshold is unique in applying when any number of individuals' data is sold in combination with the 25%-of-revenue test, unlike most other states which pair the 25% revenue test with a 25,000-individual threshold.observed
Several AI-specific bills are documented but enactment status and full scope are only partially confirmed; core ADM/profiling/biometric rights are unconfirmed.
Primary frameworkSenate Bill 129 (AI-generated content transparency); House Bills 324/325 (AI chatbot regulation) — enactment status not fully confirmed
Traffic-light rationale — AmberSeveral AI-specific bills are documented but enactment status and full scope are only partially confirmed; core ADM/profiling/biometric rights are unconfirmed.
Sub-modules (6)
Profiling RestrictionsRed
No confirmed profiling-restriction provision analogous to GDPR Art. 22 was located for Alabama.
Absence provenance: not recorded. Searched: not recorded.
Automated Decision Making TransparencyRed
No confirmed ADM transparency/explanation right was located for Alabama.
Absence provenance: not recorded. Searched: not recorded.
Ai Risk AssessmentsAmber
Senate Bill 129 mandates transparency for AI-generated content, requiring clear disclosures and metadata marking, with enforcement starting 1 October 2026; House Bills 324/325 mandate age verification, emergency protocols, and data-collection limits for AI chatbots, enforced by the AG.
Claims (2):
Senate Bill 129 mandates transparency for AI-generated content in Alabama, requiring clear disclosures and metadata marking, with enforcement starting 1 October 2026.
House Bill 324 mandates age verification, emergency protocols, and data-collection limits for AI chatbots, with enforcement by the Attorney General of Alabama; House Bill 325 regulates AI chatbot use, requiring consumer notification and establishing penalties for violations.
Biometric RegimeAmber
House Bill 263's biological data provisions are the closest analogue to a biometric regime identified, but its enactment status is unconfirmed; no dedicated facial-recognition/fingerprint statute was located.
Claims (1):
House Bill 263 introduces consumer protections for biological and neural data, requiring consent for data transfer and prohibiting marketing based on such data.
Genetic DataRed
No dedicated Alabama genetic-data statute distinct from HB 263's biological-data language was located.
Absence provenance: not recorded. Searched: not recorded.
State Surveillance CarveoutsRed
No Alabama-specific state-surveillance/national-security carveout provision was located.
Absence provenance: not recorded. Searched: not recorded.
Category narrative67 words
Alabama's algorithmic/biometric governance activity in 2026 clusters around AI-specific bills: Senate Bill 129 (AI-generated content transparency, disclosures and metadata marking, enforcement from 1 October 2026) and House Bills 324/325 (AI chatbot regulation, age verification, emergency protocols, data-collection limits, AG enforcement). House Bill 263's biological/neural data protections also touch this module. No confirmed Art. 22-style profiling restriction, ADM transparency right, or dedicated biometric/genetic-data statute was located for Alabama.
Sources and claims (2)
ProbableDataGuidance — Senate Bill 129 mandates transparency for AI-generated content in Alabama, requiring clear disclosures and metadata marking, with enforcement starting 1 October 2026.observed
UncertainDataGuidance — House Bill 324 mandates age verification, emergency protocols, and data-collection limits for AI chatbots, with enforcement by the Attorney General of Alabama; House Bill 325 regulates AI chatbot use, requiring consumer notification and establishing penalties for violations.observed
Multiple children's-privacy instruments are documented, but a material date conflict (HB 161 effective date) and uncertain enactment status of related bills prevent a green rating.
Primary frameworkAlabama App Store Accountability Act, HB 161 (age/effective-date conflict unresolved); Alabama Personal Data Protection Act, HB 351 (enacted, not yet effective)
Traffic-light rationale — AmberMultiple children's-privacy instruments are documented, but a material date conflict (HB 161 effective date) and uncertain enactment status of related bills prevent a green rating.
Sub-modules (5)
Age VerificationAmber
The App Store Accountability Act (HB 161) requires age verification for minors under 18 using app stores; reported effective dates conflict between 1 October 2026 and 1 January 2027 across sources.
Claims (1):
Alabama's App Store Accountability Act (House Bill 161) mandates age verification for minors using app stores; secondary sources report conflicting effective dates of 1 October 2026 and 1 January 2027, which remains unresolved.
Parental ConsentAmber
HB 161 also requires verifiable parental consent for minors under 18 downloading/using app-store content.
Claims (1):
Alabama's App Store Accountability Act, which requires verifiable parental consent in addition to age verification, applies to minors under age 18.
Minor Profiling BansAmber
No dedicated minor-profiling ban was located; the PDPA's COPPA-aligned 'child' definition (under 13) is the closest analogue for heightened protection of minors' data.
Claims (1):
The Alabama Personal Data Protection Act's children's privacy provisions follow the Children's Online Privacy Protection Act definition of a child, and the bill's definition of minors for PDPA purposes covers children under age 13.
Education SettingsRed
No education-setting-specific children's data statute was located for Alabama.
Absence provenance: not recorded. Searched: not recorded.
Dependent AdultsRed
No dependent-adult (elderly/incapacitated) data-protection statute was located for Alabama.
Absence provenance: not recorded. Searched: not recorded.
Category narrative96 words
Alabama has the most active children's-privacy legislative track of any module reviewed: the App Store Accountability Act (HB 161) mandates age verification and verifiable parental consent for minors under 18 using app stores, though its effective date is reported inconsistently (1 October 2026 in one summary vs. 1 January 2027 in another — flagged as an open question). The PDPA separately defines 'minor' by reference to COPPA (under 13) for its own sensitive-data purposes. House Bill 276 requires social media platforms to protect minors and cooperate with law enforcement. No education-setting-specific or dependent-adult-specific protection was located.
Sources and claims (2)
UncertainDataGuidance — Alabama's App Store Accountability Act (House Bill 161) mandates age verification for minors using app stores; secondary sources report conflicting effective dates of 1 October 2026 and 1 January 2027, which remains unresolved.observed
ProbableIAPP — Alabama's App Store Accountability Act, which requires verifiable parental consent in addition to age verification, applies to minors under age 18.observed
Enforcement powers and penalty structures are clearly documented and the AG has a track record of active, recent enforcement (multistate settlements) even absent a comprehensive law currently in force.
Primary frameworkAlabama Data Breach Notification Act of 2018 (in force); Alabama Personal Data Protection Act, HB 351 (enacted, not yet effective)
Traffic-light rationale — GreenEnforcement powers and penalty structures are clearly documented and the AG has a track record of active, recent enforcement (multistate settlements) even absent a comprehensive law currently in force.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
The AG can impose penalties up to $500,000 per breach for knowing violations of the 2018 Act's notice provisions, and up to $5,000/day for continuing non-compliance; the PDPA is exclusively AG-enforced.
Claims (2):
Covered entities or third-party agents who knowingly violate the Alabama Data Breach Notification Act's notification provisions can be subject to a penalty not exceeding $500,000 per breach, and covered entities can be liable for a civil penalty of not more than $5,000 per day for each consecutive day of continued non-compliance.
The Alabama Personal Data Protection Act includes a non-sunsetting 45-day cure provision together with exclusive Attorney General enforcement.
Enforcement Activity IndexGreen
Alabama reached a $12.2 million settlement with Roblox Corporation to enhance child-safety measures on the platform, and joined a 42-state AG coalition settlement with 23andMe's bankruptcy trustee over a 2023 breach affecting 6.9 million customers.
Claims (2):
Alabama reached a $12.2 million settlement with Roblox Corporation to enhance child-safety measures on the platform.
A coalition of 42 attorneys general, including Alabama, reached a settlement with 23andMe's bankruptcy trustee over a 2023 data breach affecting 6.9 million customers.
Regulator Funding And CapacityRed
No specific funding or headcount data for the AG's Consumer Protection Division's privacy enforcement function was located.
Absence provenance: not recorded. Searched: not recorded.
Collective Redress And Class ActionsAmber
No Alabama-specific consumer class-action mechanism for data-privacy claims was located; the 23andMe matter was a multistate AG settlement rather than a private class action.
Claims (1):
A coalition of 42 attorneys general, including Alabama, reached a settlement with 23andMe's bankruptcy trustee over a 2023 data breach affecting 6.9 million customers.
Private Right Of ActionAmber
The PDPA provides for exclusive Attorney General enforcement together with a non-sunsetting 45-day cure provision, indicating the absence of a private right of action.
Claims (1):
The Alabama Personal Data Protection Act's exclusive Attorney General enforcement model, combined with its 45-day cure provision, indicates the statute does not create a private right of action for consumers.
Recent Developments 180DAmber
Within the last 180 days, the most significant development is the Governor's 16 April 2026 signature enacting the Alabama Personal Data Protection Act (HB 351), alongside a wave of related 2026-session bills (App Store Accountability Act, AI-transparency and AI-chatbot bills, data-broker and dark-pattern bills) of varying enactment status.
Claims (1):
Governor Kay Ivey signed House Bill 351, the Alabama Personal Data Protection Act, into law on 16 April 2026; the law takes effect 1 May 2027.
Category narrative72 words
Enforcement is centralized in the Alabama Attorney General across all identified instruments. The 2018 breach act carries defined civil penalties ($500,000 per breach for knowing violations; $5,000/day for continuing non-compliance). The PDPA (not yet effective) provides a non-sunsetting 45-day cure period and exclusive AG enforcement, implying no private right of action. Recent multistate AG enforcement activity involving Alabama includes the 23andMe bankruptcy-trustee settlement and a $12.2 million Roblox settlement on child-safety grounds.
Sources and claims (5)
ConfirmedDataGuidance (reporting AG announcement) — Covered entities or third-party agents who knowingly violate the Alabama Data Breach Notification Act's notification provisions can be subject to a penalty not exceeding $500,000 per breach, and covered entities can be liable for a civil penalty of not more than $5,000 per day for each consecutive day of continued non-compliance.observed
ProbableIAPP — The Alabama Personal Data Protection Act includes a non-sunsetting 45-day cure provision together with exclusive Attorney General enforcement.observed
ConfirmedDataGuidance — Alabama reached a $12.2 million settlement with Roblox Corporation to enhance child-safety measures on the platform.observed
ConfirmedDataGuidance — A coalition of 42 attorneys general, including Alabama, reached a settlement with 23andMe's bankruptcy trustee over a 2023 data breach affecting 6.9 million customers.observed
ProbableIAPP — The Alabama Personal Data Protection Act's exclusive Attorney General enforcement model, combined with its 45-day cure provision, indicates the statute does not create a private right of action for consumers.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for United States – Alabama
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 25 claim(s), 9 source(s) in the cumulative register.
GDPR article map
Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).
Breach-notification duties, AG enforcement powers/penalties, and the Insurance Data Security Law overlay are grounded in T2 (AG-announcement-derived) sources and are high-confidence. The Alabama Personal Data Protection Act's existence, signing date, effective date, applicability thresholds, exemptions, and cure/enforcement model are grounded in T3 (IAPP/DataGuidance) analysis and are Probable-to-Confirmed. Granular PDPA provisions (enumerated lawful bases, DPIA/DPO/ROPA duties, itemized consumer rights, response-window deadlines) and the enactment status of several 2026-session bills (HB 263, HB 283, SB 213, HB 324/325, HB 276, HB 171/173/219) could not be verified against primary bill text and are marked Uncertain/Speculative with absent_field_provenance. cross_border_and_adequacy is legitimately near-empty, reflecting the absence of any state-level transfer regime.
Unresolved questions (7):
What is the correct effective date for the App Store Accountability Act (HB 161) — 1 October 2026 or 1 January 2027 — given conflicting statements in the same secondary source?
Has House Bill 263 (biological/neural data) been signed into law, and if so, on what date and with what effective date?
Has House Bill 283 (dark patterns / consumer control) been signed into law?
Has Senate Bill 213 (data broker obligations) been enacted, and what obligations does it impose?
Have House Bills 324/325 (AI chatbot regulation) and House Bill 276 (social media minor protections) been signed into law?
Does the Alabama Personal Data Protection Act include a GDPR-style enumerated lawful-bases list, DPIA triggers, DPO thresholds, or ROPA obligations, and what are the exact consumer-rights response deadlines?
What is the exact statutory citation and effective date for the Alabama Data Breach Notification Act of 2018 (Ala. Code Title 8, Chapter 38) beyond its 28 March 2018 signing?