🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-FL · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 20 sources retrieved model claude-sonnet-5 ·

United States – Florida

US-FL schema gdpri-v2 trajectory: not recordedhybrid regimeoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 42 claims · 20 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
42Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Binding, in-force framework exists but applies to a very small universe of controllers; sectoral FIPA breach law has much broader reach.

Primary frameworkFlorida Digital Bill of Rights (SB 262, 2023, codified in Fla. Stat. Ch. 501, Part IX) and Florida Information Protection Act (Fla. Stat. §501.171)
Traffic-light rationale — AmberBinding, in-force framework exists but applies to a very small universe of controllers; sectoral FIPA breach law has much broader reach.

Sub-modules (5)

Regulator And AuthorityAmber

AG holds exclusive enforcement authority over FDBR and FIPA; no private cause of action under either.

Claims (1):

  • The Florida Attorney General (Department of Legal Affairs) holds exclusive statutory enforcement authority over the Florida Digital Bill of Rights and the Florida Information Protection Act, and neither statute provides a private cause of action.

Act And InstrumentsAmber

Two operative instruments: FDBR (SB 262) and FIPA (§501.171).

Claims (2):

  • Senate Bill 262, enacted as the Florida Digital Bill of Rights, made its consumer data protection provisions effective 1 July 2024.
  • The Florida Information Protection Act of 2014 (§501.171, Fla. Stat.) independently requires businesses and government entities to take reasonable measures to protect personal information and to report data breaches to affected consumers.

Material ScopeAmber

FDBR sensitive-data definition drives most substantive obligations.

Claims (1):

  • The FDBR defines 'sensitive data' to include racial or ethnic origin, religious beliefs, health diagnoses, sexual orientation, citizenship or immigration status, genetic or biometric data processed to uniquely identify an individual, data from a known child, and precise geolocation data limited to a 1,750-foot radius.

Territorial ScopeAmber

Controller definition keyed to $1B global revenue plus one of three business-model criteria.

Claims (1):

  • FDBR controller obligations apply only to for-profit entities doing business in Florida that meet a $1 billion global annual gross revenue threshold together with at least one of three specified business-model criteria: online-advertising revenue share, smart-speaker/voice-assistant operation, or large-scale app-store operation.

Regulator Registration And FilingRed

No controller registration or filing obligation identified under FDBR or FIPA.

Absence provenance: not recorded. Searched: Florida Digital Bill of Rights controller registration requirement, FIPA Florida Attorney General filing obligation.

Category narrative98 words

Florida operates a hybrid regime: a narrow-scope comprehensive statute (the Florida Digital Bill of Rights, enacted as SB 262, consumer-data provisions effective 1 July 2024) layered on top of the pre-existing sectoral breach-notification statute, the Florida Information Protection Act (FIPA, §501.171, Fla. Stat.). Both instruments are enforced exclusively by the Florida Attorney General's Department of Legal Affairs; neither carries a dedicated data-protection authority or a private right of action. FDBR's controller-level obligations apply only to for-profit entities exceeding a $1 billion global revenue threshold plus one of three narrow business-model triggers, making it materially narrower than CCPA/CPRA-style laws.

Sources and claims (5)
  1. ConfirmedIAPPThe Florida Attorney General (Department of Legal Affairs) holds exclusive statutory enforcement authority over the Florida Digital Bill of Rights and the Florida Information Protection Act, and neither statute provides a private cause of action.observed
  2. ConfirmedIAPPSenate Bill 262, enacted as the Florida Digital Bill of Rights, made its consumer data protection provisions effective 1 July 2024.observed
  3. ConfirmedMy Florida LegalThe Florida Information Protection Act of 2014 (§501.171, Fla. Stat.) independently requires businesses and government entities to take reasonable measures to protect personal information and to report data breaches to affected consumers.observed
  4. ConfirmedDataGuidanceThe FDBR defines 'sensitive data' to include racial or ethnic origin, religious beliefs, health diagnoses, sexual orientation, citizenship or immigration status, genetic or biometric data processed to uniquely identify an individual, data from a known child, and precise geolocation data limited to a 1,750-foot radius.observed
  5. ConfirmedIAPPFDBR controller obligations apply only to for-profit entities doing business in Florida that meet a $1 billion global annual gross revenue threshold together with at least one of three specified business-model criteria: online-advertising revenue share, smart-speaker/voice-assistant operation, or large-scale app-store operation.observed

#

Consent/lawful-basis architecture exists but is materially narrower than GDPR-analogue regimes and applies to a limited controller population.

Primary frameworkFlorida Digital Bill of Rights (SB 262)
Traffic-light rationale — AmberConsent/lawful-basis architecture exists but is materially narrower than GDPR-analogue regimes and applies to a limited controller population.

Sub-modules (4)

Lawful BasesAmber

Opt-out default model rather than enumerated lawful bases.

Claims (1):

  • The FDBR does not enumerate GDPR-style lawful bases; instead it follows an opt-out default model under which processing is permitted unless a consumer exercises a specific statutory opt-out right, with consent required only for narrowly defined activities such as the sale of sensitive data.

Special CategoriesAmber

Sensitive-data category drives heightened consent duties, including a COPPA-referenced children's-data rule.

Claims (1):

  • Sensitive data under the FDBR includes genetic or biometric data processed to uniquely identify an individual and personal data collected from a known child; processing a known child's sensitive data requires COPPA-referenced affirmative authorization even though the FDBR defines 'child' as under 18 rather than COPPA's under-13 threshold.

Pseudonymisation And AnonymisationAmber

Pseudonymous/aggregated/anonymized data excluded entirely from scope.

Claims (1):

  • The FDBR's definition of 'personal data' excludes pseudonymous data — including most third-party cookie identifiers and aggregated or anonymized consumer information — from the statute's coverage entirely, a narrower carve-out than most peer state laws.
Category narrative63 words

The FDBR does not adopt a GDPR-style enumerated-lawful-basis model. Processing is generally permitted by default, with opt-out rights layered on top and opt-in consent required only for narrow categories (notably the sale of sensitive data and children's data). Pseudonymous data, including most third-party cookie identifiers, is excluded entirely from the statute's 'personal data' definition — a narrower carve-out than most peer state laws.

Sources and claims (4)
  1. ProbableDataGuidanceThe FDBR does not enumerate GDPR-style lawful bases; instead it follows an opt-out default model under which processing is permitted unless a consumer exercises a specific statutory opt-out right, with consent required only for narrowly defined activities such as the sale of sensitive data.observed
  2. ConfirmedDataGuidanceAll businesses conducting business in Florida — not only those meeting the FDBR's controller thresholds — must obtain a consumer's opt-in consent before selling that consumer's sensitive personal data.observed
  3. ConfirmedIAPPSensitive data under the FDBR includes genetic or biometric data processed to uniquely identify an individual and personal data collected from a known child; processing a known child's sensitive data requires COPPA-referenced affirmative authorization even though the FDBR defines 'child' as under 18 rather than COPPA's under-13 threshold.observed
  4. ConfirmedIAPPThe FDBR's definition of 'personal data' excludes pseudonymous data — including most third-party cookie identifiers and aggregated or anonymized consumer information — from the statute's coverage entirely, a narrower carve-out than most peer state laws.observed

#

Rights framework is materially GDPR/CCPA-analogue in substance but narrow in applicability.

Primary frameworkFlorida Digital Bill of Rights (SB 262), §501.706, Fla. Stat.
Traffic-light rationale — AmberRights framework is materially GDPR/CCPA-analogue in substance but narrow in applicability.

Sub-modules (5)

Access RightAmber

Right to confirm processing and access a copy of data.

Claims (1):

  • FDBR-covered controllers must allow consumers to confirm whether their personal data is being processed and to access a copy of that data.

Rectification And ErasureAmber

Right to correct and delete personal data.

Claims (1):

  • Consumers have statutory rights to correct inaccuracies in and to delete their personal data held by FDBR-covered controllers.

Restriction And ObjectionAmber

Opt-out rights for targeted advertising, sale, profiling, and biometric/sensitive-data collection.

Claims (1):

  • Consumers may opt out of processing for targeted advertising, the sale of personal, sensitive, or biometric data, and certain forms of profiling under the FDBR.

Data PortabilityAmber

Right to obtain a portable copy of personal data.

Claims (1):

  • FDBR-covered controllers must provide consumers a portable copy of their personal data upon request.

Deadlines And Response WindowsAmber

45-day window, extendable to 60 days; two request methods; appeals process required.

Claims (1):

  • Controllers must respond to consumer rights requests within 45 days of receipt, with a possible extension to 60 days when reasonably necessary, must establish at least two methods for consumers to submit such requests, and must provide an appeals process for refusals.
Category narrative35 words

FDBR-covered controllers must honour access, correction, deletion, portability and opt-out rights, subject to a 45-day (extendable to 60-day) response window and a mandatory appeals process. Rights apply only against the narrow set of qualifying 'controllers.'

Sources and claims (5)
  1. ConfirmedIAPPFDBR-covered controllers must allow consumers to confirm whether their personal data is being processed and to access a copy of that data.observed
  2. ConfirmedIAPPConsumers have statutory rights to correct inaccuracies in and to delete their personal data held by FDBR-covered controllers.observed
  3. ConfirmedIAPPConsumers may opt out of processing for targeted advertising, the sale of personal, sensitive, or biometric data, and certain forms of profiling under the FDBR.observed
  4. ConfirmedIAPPFDBR-covered controllers must provide consumers a portable copy of their personal data upon request.observed
  5. ConfirmedIAPPControllers must respond to consumer rights requests within 45 days of receipt, with a possible extension to 60 days when reasonably necessary, must establish at least two methods for consumers to submit such requests, and must provide an appeals process for refusals.observed

#

Substantive duties exist and are enforced (see Roku action) but DPO/ROPA analogues are absent and FDBR duties bind only large controllers.

Primary frameworkFlorida Digital Bill of Rights (SB 262) and Florida Information Protection Act (§501.171, Fla. Stat.)
Traffic-light rationale — AmberSubstantive duties exist and are enforced (see Roku action) but DPO/ROPA analogues are absent and FDBR duties bind only large controllers.

Sub-modules (7)

Accountability And DpiaAmber

Mandatory data protection assessments for higher-risk processing, producible to AG on request.

Claims (1):

  • FDBR-covered controllers must conduct and document data protection assessments for processing activities presenting a heightened risk of harm, including targeted advertising, sale of personal data, certain profiling, and processing of sensitive data, and must produce such assessments to the Attorney General upon request.

Dpo RequirementsRed

No DPO-appointment mandate identified under FDBR or FIPA.

Absence provenance: not recorded. Searched: Florida Digital Bill of Rights data protection officer requirement.

Ropa RequirementsRed

No standalone records-of-processing-activities obligation identified distinct from the DPA regime.

Absence provenance: not recorded. Searched: Florida Digital Bill of Rights records of processing activities requirement.

Joint Controller ArrangementsAmber

Processor contractual and assistance duties exist; no distinct joint-controller liability regime.

Claims (1):

  • The FDBR requires specific contractual terms between controllers and processors, including a processor's duty to assist the controller's compliance, though it does not create a distinct joint-controller liability regime akin to GDPR Article 26.

Security MeasuresAmber

Reasonable administrative, technical and physical security measures required under both FDBR and FIPA.

Claims (1):

  • Controllers must adopt reasonable administrative, technical and physical measures to protect the confidentiality, integrity and accessibility of personal data and reduce foreseeable risk of harm to consumers; separately, FIPA requires all covered entities to take reasonable measures to protect personal information generally.

Breach NotificationAmber

FIPA breach notification to consumers and, for 500+ affected individuals, to the AG; scope expanded by SB 262 to cover biometric/geolocation data.

Claims (2):

  • Under FIPA (§501.171, Fla. Stat.), covered entities must notify affected individuals of a data breach and, for breaches affecting 500 or more Florida residents, must also notify the Florida Attorney General, with the statute defining the content required in the notice.
  • SB 262 expanded FIPA's definition of 'personal information' to include biometric data and precise geolocation data (when combined with a name), broadening the scope of Florida's breach-notification obligations.

Retention And DisposalAmber

Mandatory retention schedules tied to purpose completion, contract expiry, or two years of inactivity.

Claims (1):

  • Controllers and processors must adopt a data retention schedule that prohibits use or retention of personal data after the initial collection purpose is satisfied, after contract expiration, or two years after the consumer's last interaction, subject to certain exemptions.
Category narrative35 words

FDBR imposes data-protection-assessment, security, retention, and processor-contract duties on qualifying controllers; FIPA separately imposes reasonable-security and breach-notification duties on all covered entities regardless of FDBR-controller status. No DPO-appointment mandate or standalone ROPA obligation was identified.

Sources and claims (6)
  1. ConfirmedIAPPFDBR-covered controllers must conduct and document data protection assessments for processing activities presenting a heightened risk of harm, including targeted advertising, sale of personal data, certain profiling, and processing of sensitive data, and must produce such assessments to the Attorney General upon request.observed
  2. ProbableDataGuidanceThe FDBR requires specific contractual terms between controllers and processors, including a processor's duty to assist the controller's compliance, though it does not create a distinct joint-controller liability regime akin to GDPR Article 26.observed
  3. ConfirmedDataGuidanceControllers must adopt reasonable administrative, technical and physical measures to protect the confidentiality, integrity and accessibility of personal data and reduce foreseeable risk of harm to consumers; separately, FIPA requires all covered entities to take reasonable measures to protect personal information generally.observed
  4. ConfirmedMy Florida LegalUnder FIPA (§501.171, Fla. Stat.), covered entities must notify affected individuals of a data breach and, for breaches affecting 500 or more Florida residents, must also notify the Florida Attorney General, with the statute defining the content required in the notice.observed
  5. ConfirmedIAPPSB 262 expanded FIPA's definition of 'personal information' to include biometric data and precise geolocation data (when combined with a name), broadening the scope of Florida's breach-notification obligations.observed
  6. ConfirmedIAPPControllers and processors must adopt a data retention schedule that prohibits use or retention of personal data after the initial collection purpose is satisfied, after contract expiration, or two years after the consumer's last interaction, subject to certain exemptions.observed

#

No comprehensive cross-border transfer regime exists at the Florida state level.

Traffic-light rationale — RedNo comprehensive cross-border transfer regime exists at the Florida state level.

Sub-modules (6)

Transfer MechanismsRed

No FDBR/FIPA transfer-mechanism provision identified.

Absence provenance: not recorded. Searched: Florida Digital Bill of Rights cross-border data transfer mechanism.

Adequacy ReceivedRed

Not applicable — Florida is a US sub-national jurisdiction with no adequacy-receiving mechanism.

Absence provenance: not recorded. Searched: Florida adequacy decision received.

Adequacy GrantedRed

Not applicable — Florida issues no adequacy determinations.

Absence provenance: not recorded. Searched: Florida adequacy decision granted.

Sccs And BcrsRed

No SCC/BCR framework identified at Florida state level.

Absence provenance: not recorded. Searched: Florida standard contractual clauses binding corporate rules.

Transfer Impact AssessmentRed

No TIA requirement identified.

Absence provenance: not recorded. Searched: Florida transfer impact assessment requirement.

Data LocalisationRed

No data-localisation mandate identified.

Absence provenance: not recorded. Searched: Florida data localisation requirement personal data.

Category narrative44 words

No Florida-specific cross-border data-transfer mechanism, adequacy determination (received or granted), SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate was identified. This is consistent with the general absence of such mechanisms across US state comprehensive privacy statutes, which regulate in-state processing rather than international transfer flows.

#

Some overlays plausible but unverified against final enacted text; others confirmed absent.

Primary frameworkFlorida Digital Bill of Rights (SB 262); federal HIPAA/GLBA/FCRA/FERPA as background sectoral baselines
Traffic-light rationale — AmberSome overlays plausible but unverified against final enacted text; others confirmed absent.

Sub-modules (7)

Financial Sector OverlayAmber

Predecessor bills proposed GLBA exemptions; final-text confirmation pending.

Claims (1):

  • Florida's prior competing comprehensive-privacy bills (HB 969 / SB 1734, 2021) proposed exemptions for GLBA-covered financial institutions and HIPAA-covered entities/business associates; confirmation that the enacted FDBR (SB 262, 2023) preserves materially identical exemptions has not been independently verified against the final statutory text in this research pass.

Health Sector OverlayAmber

Health diagnosis data is 'sensitive data' under FDBR; HIPAA remains the primary federal health-data regime.

Claims (1):

  • Health data is separately protected in Florida through HIPAA's federal framework and through FDBR's classification of 'mental or physical health diagnosis' data as sensitive data requiring opt-in consent for sale.

Telecoms And EprivacyAmber

No dedicated ePrivacy/cookie statute; telemarketing regulated via FTSA and federal TCPA/TSR enforcement.

Claims (1):

  • Florida does not maintain a dedicated ePrivacy-style cookie/electronic-communications statute; telemarketing and robocall conduct is instead pursued by the Attorney General under Florida consumer-protection statutes together with the federal TCPA and Telemarketing Sales Rule.

Employment DataAmber

Predecessor-bill reporting indicates an employee-data exemption; unverified against final SB 262 text.

Claims (1):

  • Florida's 2021 predecessor comprehensive-privacy bills exempted personal data processed in an employment context from controller obligations; whether this carve-over exists in identical form in the enacted FDBR has not been independently confirmed.

Credit And ScoringRed

No FL-specific credit-scoring privacy rule beyond federal FCRA identified.

Absence provenance: not recorded. Searched: Florida credit scoring data privacy law.

EducationRed

No FL-specific education-sector DP overlay beyond FERPA identified.

Absence provenance: not recorded. Searched: Florida education sector student data privacy law.

InsuranceRed

No FL-specific insurance-sector DP overlay identified beyond general FDBR/FIPA.

Absence provenance: not recorded. Searched: Florida insurance sector data privacy overlay.

Category narrative64 words

Florida's earlier competing comprehensive-privacy bills (HB 969 / SB 1734, 2021) proposed GLBA and HIPAA entity/data exemptions; whether the enacted FDBR (SB 262, 2023) preserves materially identical exemptions has not been independently confirmed against final statutory text in this research pass. Health data receives indirect protection via FDBR's sensitive-data classification. No FL-specific overlays were found for credit-scoring, education, or insurance beyond federal baselines (FCRA/FERPA).

Sources and claims (4)
  1. UncertainDataGuidanceFlorida's prior competing comprehensive-privacy bills (HB 969 / SB 1734, 2021) proposed exemptions for GLBA-covered financial institutions and HIPAA-covered entities/business associates; confirmation that the enacted FDBR (SB 262, 2023) preserves materially identical exemptions has not been independently verified against the final statutory text in this research pass.observed
  2. ProbableIAPPHealth data is separately protected in Florida through HIPAA's federal framework and through FDBR's classification of 'mental or physical health diagnosis' data as sensitive data requiring opt-in consent for sale.observed
  3. ProbableMy Florida LegalFlorida does not maintain a dedicated ePrivacy-style cookie/electronic-communications statute; telemarketing and robocall conduct is instead pursued by the Attorney General under Florida consumer-protection statutes together with the federal TCPA and Telemarketing Sales Rule.observed
  4. UncertainDataGuidanceFlorida's 2021 predecessor comprehensive-privacy bills exempted personal data processed in an employment context from controller obligations; whether this carve-over exists in identical form in the enacted FDBR has not been independently confirmed.observed

#

Meaningful opt-out and dark-pattern provisions exist but scope is narrowed by the pseudonymous-data carve-out and controller threshold.

Primary frameworkFlorida Digital Bill of Rights (SB 262)
Traffic-light rationale — AmberMeaningful opt-out and dark-pattern provisions exist but scope is narrowed by the pseudonymous-data carve-out and controller threshold.

Sub-modules (6)

Cookies And TrackersAmber

Pseudonymous/cookie identifiers excluded from 'personal data' scope.

Claims (1):

  • The FDBR excludes pseudonymous data — including most third-party cookie identifiers — from its definition of 'personal data,' materially narrowing any cookie-consent obligations compared to ePrivacy-style regimes.

Dark PatternsAmber

'Dark patterns' is a defined term under FDBR.

Claims (1):

  • The FDBR incorporates 'dark patterns' among its defined terms, addressing manipulative user-interface design used to obtain consumer consent.

Opt Out SignalsRed

No confirmed universal opt-out signal (e.g., GPC) mandate.

Absence provenance: not recorded. Searched: Florida Digital Bill of Rights Global Privacy Control universal opt-out signal.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rule identified.

Absence provenance: not recorded. Searched: Florida data clean room data collaboration room rule.

Cross Context AdvertisingAmber

Targeted-advertising definition extends to affiliated-website tracking.

Claims (1):

  • The FDBR defines 'targeted advertising' broadly enough to include advertising based on data collected across a controller's affiliated websites, extending the opt-out right further than some peer state laws.

Direct MarketingAmber

Telemarketing/robocall conduct pursued via consumer-protection and federal telemarketing law.

Claims (1):

  • The Florida Attorney General enforces telemarketing conduct — including robocalls and National Do Not Call Registry violations — through Florida consumer-protection statutes and coordinated multistate actions under the federal Telemarketing Sales Rule and TCPA.
Category narrative60 words

FDBR provides an opt-out right for targeted advertising (broadly defined to include affiliated-website tracking) and references 'dark patterns' as a defined term, but excludes pseudonymous/cookie-only identifiers from its personal-data definition, narrowing practical cookie-consent impact. No universal opt-out signal (e.g., GPC) mandate or clean-room/data-collaboration rule was confirmed. Direct-marketing/telemarketing conduct is separately policed by the AG under consumer-protection and federal telemarketing law.

Sources and claims (4)
  1. ConfirmedIAPPThe FDBR excludes pseudonymous data — including most third-party cookie identifiers — from its definition of 'personal data,' materially narrowing any cookie-consent obligations compared to ePrivacy-style regimes.observed
  2. ConfirmedDataGuidanceThe FDBR incorporates 'dark patterns' among its defined terms, addressing manipulative user-interface design used to obtain consumer consent.observed
  3. ConfirmedDataGuidanceThe FDBR defines 'targeted advertising' broadly enough to include advertising based on data collected across a controller's affiliated websites, extending the opt-out right further than some peer state laws.observed
  4. ConfirmedMy Florida LegalThe Florida Attorney General enforces telemarketing conduct — including robocalls and National Do Not Call Registry violations — through Florida consumer-protection statutes and coordinated multistate actions under the federal Telemarketing Sales Rule and TCPA.observed

#

Sensitive-data consent rules and profiling opt-out exist; no dedicated biometric statute or ADM-transparency right.

Primary frameworkFlorida Digital Bill of Rights (SB 262)
Traffic-light rationale — AmberSensitive-data consent rules and profiling opt-out exist; no dedicated biometric statute or ADM-transparency right.

Sub-modules (6)

Profiling RestrictionsAmber

Opt-out right against certain profiling.

Claims (1):

  • Consumers may opt out of certain profiling as part of the FDBR's opt-out rights regime.

Automated Decision Making TransparencyRed

No distinct ADM-explanation/transparency right beyond the profiling opt-out identified.

Absence provenance: not recorded. Searched: Florida Digital Bill of Rights automated decision-making transparency right.

Ai Risk AssessmentsRed

No AI-specific risk-assessment statute beyond the general FDBR DPA requirement identified.

Absence provenance: not recorded. Searched: Florida AI-specific risk assessment statute.

Biometric RegimeAmber

Biometric data addressed within FDBR sensitive-data category; no standalone BIPA-style statute confirmed enacted.

Claims (2):

  • Biometric data is treated as 'sensitive data' under the FDBR, requiring consumer opt-in consent before sale and a specific website disclosure ('NOTICE: This website may sell your biometric personal data') when a qualifying controller sells it.
  • A standalone Florida Biometric Information Privacy Act, modeled on Illinois's BIPA and including a private right of action, was proposed in the Florida Legislature circa 2019; it is not confirmed to have been enacted, and Florida's operative biometric protections currently run through the FDBR and FIPA rather than a dedicated biometric statute.

Genetic DataAmber

Genetic data uniquely identifying an individual is 'sensitive data' under FDBR.

Claims (1):

  • Genetic data processed for the purpose of uniquely identifying an individual is classified as 'sensitive data' under the FDBR, triggering the same opt-in consent requirement for sale as other sensitive-data categories.

State Surveillance CarveoutsRed

No FL-specific national-security/state-surveillance carve-out beyond general law-enforcement exemptions identified.

Absence provenance: not recorded. Searched: Florida Digital Bill of Rights state surveillance national security carveout.

Category narrative76 words

FDBR provides an opt-out right against certain profiling and treats biometric and genetic data as 'sensitive data' requiring opt-in consent for sale plus a specific website disclosure. Florida has no standalone biometric-privacy statute comparable to Illinois's BIPA; a 2019 proposal for a Florida Biometric Information Privacy Act (with a private right of action) is not confirmed to have been enacted. No dedicated ADM-transparency/explanation right or AI-specific risk-assessment statute beyond the general FDBR data-protection-assessment requirement was identified.

Sources and claims (4)
  1. ConfirmedIAPPConsumers may opt out of certain profiling as part of the FDBR's opt-out rights regime.observed
  2. ConfirmedDataGuidanceBiometric data is treated as 'sensitive data' under the FDBR, requiring consumer opt-in consent before sale and a specific website disclosure ('NOTICE: This website may sell your biometric personal data') when a qualifying controller sells it.observed
  3. ProbableIAPPA standalone Florida Biometric Information Privacy Act, modeled on Illinois's BIPA and including a private right of action, was proposed in the Florida Legislature circa 2019; it is not confirmed to have been enacted, and Florida's operative biometric protections currently run through the FDBR and FIPA rather than a dedicated biometric statute.observed
  4. ConfirmedDataGuidanceGenetic data processed for the purpose of uniquely identifying an individual is classified as 'sensitive data' under the FDBR, triggering the same opt-in consent requirement for sale as other sensitive-data categories.observed

#

Binding, in-force, and actively enforced regime with multiple 2025-2026 AG actions.

Primary frameworkFlorida House Bill 3 (2024), codified at §§501.1736-501.1738, Fla. Stat.; Florida Digital Bill of Rights (SB 262)
Traffic-light rationale — GreenBinding, in-force, and actively enforced regime with multiple 2025-2026 AG actions.

Sub-modules (5)

Age VerificationGreen

HB 3 mandates age verification for online material harmful to minors, effective 1 Jan 2025, actively enforced.

Claims (1):

  • Florida House Bill 3 (2024) requires commercial entities that distribute online material harmful to minors to verify that users are at least 18 years of age; the requirement took effect 1 January 2025 and has been actively enforced by the Attorney General against multiple pornography websites, including litigation invoking penalties of up to $50,000 per violation.

Minor Profiling BansAmber

FDBR requires COPPA-referenced authorization before processing a known child's sensitive data for sale.

Claims (1):

  • FDBR treats personal data collected from a known child as 'sensitive data,' requiring COPPA-referenced affirmative authorization before such data may be sold, notwithstanding FDBR's broader definition of 'child' as under 18 rather than COPPA's under-13 threshold.

Education SettingsRed

No FL-specific education-sector children's-data statute distinct from FERPA identified.

Absence provenance: not recorded. Searched: Florida education sector children's data privacy statute.

Dependent AdultsRed

No FL-specific dependent/vulnerable-adult data protection provision identified.

Absence provenance: not recorded. Searched: Florida dependent adult vulnerable adult data protection statute.

Category narrative69 words

Florida has two distinct children's-data tracks: (1) FDBR's sensitive-data/parental-authorization rule for a 'known child' (under 18); and (2) House Bill 3 (2024), a standalone online-protections-for-minors statute requiring age verification for harmful material and parental consent for under-14 social-media accounts, effective 1 January 2025 and under active AG enforcement (Snapchat litigation; multiple pornography-website suits). No FL-specific education-sector children's-data statute or dependent/vulnerable-adult data provision distinct from general consumer law was identified.

Sources and claims (4)
  1. ConfirmedMy Florida LegalFlorida House Bill 3 (2024) requires commercial entities that distribute online material harmful to minors to verify that users are at least 18 years of age; the requirement took effect 1 January 2025 and has been actively enforced by the Attorney General against multiple pornography websites, including litigation invoking penalties of up to $50,000 per violation.observed
  2. ConfirmedDataGuidanceHB 3 prohibits social media platforms deploying certain addictive design features from contracting with and providing accounts to users known to be 13 years old or younger without parental consent, requires account termination absent such consent, and provides a 90-day dispute period.observed
  3. ConfirmedIAPPFDBR treats personal data collected from a known child as 'sensitive data,' requiring COPPA-referenced affirmative authorization before such data may be sold, notwithstanding FDBR's broader definition of 'child' as under 18 rather than COPPA's under-13 threshold.observed
  4. ConfirmedMy Florida LegalIn October 2025, the Florida Attorney General's Office of Parental Rights filed an enforcement action against Roku alleging collection, sale, and reidentification of children's sensitive personal data — including viewing habits and voice recordings — without parental consent, in violation of the FDBR.observed

#

Enforcement powers and activity exist and are growing, but no private right of action and penalty issuance under the FDBR remains unconfirmed/nil to date.

Primary frameworkFlorida Digital Bill of Rights (SB 262); Florida Information Protection Act (§501.171, Fla. Stat.); Florida Deceptive and Unfair Trade Practices Act (FDUTPA)
Traffic-light rationale — AmberEnforcement powers and activity exist and are growing, but no private right of action and penalty issuance under the FDBR remains unconfirmed/nil to date.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

Up to $50,000 per violation, triplable; discretionary 45-day cure period.

Claims (1):

  • The Florida Attorney General has exclusive enforcement authority over the FDBR, with statutory penalties of up to $50,000 per violation, which can be tripled under certain circumstances, and discretion to provide a notice and 45-day cure period before enforcement.

Enforcement Activity IndexAmber

2025-2026 complaint data and confirmed nil-penalty status as of most recent verified report.

Claims (1):

  • The Florida Attorney General's Annual Enforcement Report covering January 1 – December 31, 2025 recorded 97 consumer complaints alleging denial of the right to delete personal data and 53 alleging denial of the right to opt out of processing, continuing a pattern in which — as of the prior (2024) reporting period — no monetary penalties had yet been issued by the Department for FDBR violations.

Regulator Funding And CapacityRed

No FDBR-specific funding/headcount data identified; folded into general AG consumer-protection budget.

Absence provenance: not recorded. Searched: Florida Attorney General Digital Bill of Rights enforcement unit funding headcount.

Collective Redress And Class ActionsAmber

No private cause of action under FDBR/FIPA; class exposure runs through general law/FDUTPA instead.

Claims (1):

  • The FDBR and FIPA both lack a private cause of action, so Florida consumers cannot bring collective or class actions directly under either statute; class exposure for Florida data-breach or privacy harms instead arises under general common-law claims or other statutes such as FDUTPA.

Private Right Of ActionAmber

Neither FDBR nor FIPA provides a private right of action.

Claims (1):

  • Neither the FDBR nor FIPA provides a private right of action; enforcement runs exclusively through the Florida Attorney General's Department of Legal Affairs.

Recent Developments 180DAmber

HB 473 (Cybersecurity Incident Liability Act) passed the Legislature in 2026; the AG published its most recent Annual Enforcement Report in February 2026.

Claims (2):

  • Florida's Legislature passed HB 473, the Cybersecurity Incident Liability Act, which would grant qualifying companies conditional immunity from data-breach lawsuits where they substantially comply with FIPA's notification requirements and maintain a cybersecurity program aligned with recognized industry standards; as of research, the bill awaited action by the Governor.
  • The Attorney General published its most recent FDBR Annual Enforcement Report in February 2026, covering the January–December 2025 enforcement period and confirming continued rule-implementation activity under §501.72(5), Fla. Stat.
Category narrative109 words

The AG has exclusive enforcement authority with statutory penalties up to $50,000 per violation (triplable in certain circumstances) and discretionary 45-day cure periods. No private right of action exists under FDBR or FIPA, precluding direct consumer class actions under those statutes specifically. The AG's 2026 Annual Enforcement Report (covering 2025) shows continued complaint intake (97 deletion-right and 53 opt-out complaints) but, as of the prior reporting period, no monetary penalties had yet been issued under the FDBR. A 2026 legislative development (HB 473, Cybersecurity Incident Liability Act) would grant conditional breach-litigation immunity, at the time of research passed by the Legislature but not yet confirmed as signed into law.

Sources and claims (6)
  1. ConfirmedIAPPThe Florida Attorney General has exclusive enforcement authority over the FDBR, with statutory penalties of up to $50,000 per violation, which can be tripled under certain circumstances, and discretion to provide a notice and 45-day cure period before enforcement.observed
  2. ConfirmedFlorida Department of Legal AffairsThe Florida Attorney General's Annual Enforcement Report covering January 1 – December 31, 2025 recorded 97 consumer complaints alleging denial of the right to delete personal data and 53 alleging denial of the right to opt out of processing, continuing a pattern in which — as of the prior (2024) reporting period — no monetary penalties had yet been issued by the Department for FDBR violations.observed
  3. ConfirmedIAPPThe FDBR and FIPA both lack a private cause of action, so Florida consumers cannot bring collective or class actions directly under either statute; class exposure for Florida data-breach or privacy harms instead arises under general common-law claims or other statutes such as FDUTPA.observed
  4. ConfirmedIAPPNeither the FDBR nor FIPA provides a private right of action; enforcement runs exclusively through the Florida Attorney General's Department of Legal Affairs.observed
  5. ProbableIAPPFlorida's Legislature passed HB 473, the Cybersecurity Incident Liability Act, which would grant qualifying companies conditional immunity from data-breach lawsuits where they substantially comply with FIPA's notification requirements and maintain a cybersecurity program aligned with recognized industry standards; as of research, the bill awaited action by the Governor.observed
  6. ConfirmedFlorida Department of Legal AffairsThe Attorney General published its most recent FDBR Annual Enforcement Report in February 2026, covering the January–December 2025 enforcement period and confirming continued rule-implementation activity under §501.72(5), Fla. Stat.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Florida
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 42 claim(s), 20 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redresscollective redress and class actions
Art. 80Enforcement & Redressprivate right of action
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

T1 (Florida AG / myfloridalegal.com) primary-source anchoring achieved for regulator_and_framework, data_subject_rights (via IAPP synthesis of statutory text plus AG annual reports), controller_processor_duties (breach-notification and DPA duties), children_and_vulnerable_groups (HB3 enforcement actions, Roku/Snapchat/pornography-site litigation), and enforcement_and_redress (AG Annual Enforcement Reports 2025 and 2026). lawful_processing_and_special_data, sectoral_watch, adtech_and_commercial_privacy, and algorithmic_biometric_and_surveillance_governance rely primarily on T2 (IAPP) and T3 (DataGuidance) secondary legal-analysis sources triangulated against the FDBR's underlying provisions, since the full enacted statutory text (Fla. Stat. Ch. 501, Part IX) was not independently retrieved and parsed section-by-section in this pass. cross_border_and_adequacy carries no findings (T4/absent) and is emitted red with explicit absent_field_provenance, consistent with the general absence of cross-border transfer regimes in US state comprehensive privacy law.

Unresolved questions (5):

  • Has HB 473 (Cybersecurity Incident Liability Act) been signed into law by the Governor, and if so, what is its effective date and final text?
  • Does the enacted FDBR (SB 262, 2023 final text) preserve the GLBA/HIPAA entity- and data-level exemptions reported in 2021 predecessor bills HB 969/SB 1734, and does it exempt employment-context personal data in identical form?
  • Have any monetary penalties been assessed by the Attorney General under the FDBR since the most recent (February 2026) Annual Enforcement Report?
  • Is there any current, unrepealed Florida biometric-specific statute beyond the FDBR/FIPA framework, given the apparently unenacted 2019 Florida Biometric Information Privacy Act proposal?
  • Does the Florida Telephone Solicitation Act (§501.059, Fla. Stat.) carry its own private right of action distinct from FDUTPA, and what are its current opt-out/consent thresholds?

Escalate to primary-source review: yes