FL

Florida Privacy Law

Florida Digital Bill of Rights

Effective: July 1, 2024ActiveReviewed by PrivacyLawMap editorial teamLast verified: August 3, 2026

Overview

The Florida Digital Bill of Rights (FDBR) was signed into law on June 6, 2023, and became effective on July 1, 2024. As of August 3, 2026, the FDBR is the only US state privacy law whose applicability turns on your line of business as well as your size: to be a "controller" a for-profit entity must make in excess of $1 billion in global gross annual revenues AND satisfy at least one of three business-model tests — 50 percent or more of revenue from selling advertisements online, operating a cloud-connected smart-speaker voice assistant, or running an app store or digital distribution platform offering at least 250,000 different applications (Fla. Stat. § 501.702(9)(a)5.-6.). Every other comprehensive state law tests only consumer counts, revenue, or data-sale revenue share, so a $2 billion manufacturer or retailer with no ad, voice-assistant, or app-store business is outside the FDBR while being squarely inside California's CCPA.

The FDBR provides Florida consumers with privacy rights including the right to access, correct, delete, and port personal data, as well as opt-out rights for data sales, targeted advertising, and profiling. However, the combination of the $1 billion floor with the three business-model tests means very few businesses are actually subject to the law. The FDBR also includes specific provisions for social media platforms, particularly regarding minor safety.

The six controller requirements in § 501.702(9)(a) are cumulative: the entity must be organized or operated for profit, conduct business in Florida, collect personal data about consumers (or be the entity on whose behalf it is collected), determine the purposes and means of processing, exceed $1 billion in global gross annual revenues, and satisfy at least one of the three business-model tests. Paragraph (9)(b) extends controller status to any entity that controls or is controlled by a controller, where "control" means owning or having the power to vote more than 50 percent of a class of voting security, controlling the election of a majority of directors, or holding the power to exercise a controlling influence. The FDBR includes a 45-day cure period and penalties of up to $50,000 per violation, enforced by the Florida Department of Legal Affairs (Attorney General). Source check: Fla. Stat. § 501.702(9) (statutory text current as of January 1, 2025) and Squire Patton Boggs, "Florida Enacts Digital Bill of Rights Privacy Law," National Law Review, which cites the same subsection, date_retrieved: 2026-08-03. Note that the Florida Legislature's own hosts (leg.state.fl.us, flsenate.gov) were unreachable from our fetcher on 2026-08-03 — a network/egress failure, not a withdrawn document — so the verbatim text was read from a secondary republication of the code.

FDBR Florida: Does the Digital Bill of Rights Apply to Your Business?

FDBR stands for the Florida Digital Bill of Rights, Fla. Stat. §§ 501.701-501.722. For almost every business that searches "FDBR," the practical answer is no — the statute does not reach you, and the reason is a threshold structure no other state copies.

As of August 3, 2026, the FDBR is the only US state privacy law whose applicability turns on your line of business as well as your size. Six requirements in Fla. Stat. § 501.702(9)(a) are cumulative, and the last one is a menu: after clearing a $1 billion global gross annual revenue floor, an entity must ALSO satisfy at least one of three specific business-model tests. Miss all three and the FDBR does not apply no matter how large the company or how much Florida personal data it processes.

Two consequences worth planning around. First, a company can grow past $1 billion in revenue and still stay outside the FDBR indefinitely, which is not true of any consumer-count-based law. Second, the control provision in § 501.702(9)(b) sweeps in subsidiaries and parents: if a corporate affiliate meets the definition, an entity that controls it or is controlled by it becomes a controller too, so group structure matters more here than under other state laws.

Source check: Fla. Stat. § 501.702(9) (statutory text current as of January 1, 2025) and Squire Patton Boggs, "Florida Enacts Digital Bill of Rights Privacy Law," National Law Review, which cites the same subsection for the $1 billion floor and all three tests, date_retrieved: 2026-08-03. The Florida Legislature's own hosts were unreachable from our fetcher on that date (network failure, not a withdrawn document), so the verbatim code text was read from a secondary republication.

  • Revenue floor — § 501.702(9)(a)5.: makes in excess of $1 billion in global gross annual revenues. Global, not Florida-only, and gross, not profit.
  • Test 1, online advertising — § 501.702(9)(a)6.a.: derives 50 percent or more of global gross annual revenues from the sale of advertisements online, including providing targeted advertising or the sale of ads online. This is the test large ad-funded platforms meet.
  • Test 2, smart speakers — § 501.702(9)(a)6.b.: operates a consumer smart speaker and voice command component service with an integrated virtual assistant connected to a cloud computing service that uses hands-free verbal activation. The statute expressly excludes motor vehicles and speakers or devices associated with a vehicle operated by a motor vehicle manufacturer or its affiliate.
  • Test 3, app stores — § 501.702(9)(a)6.c.: operates an app store or a digital distribution platform that offers at least 250,000 different software applications for consumers to download and install. This is the only numeric app-catalogue threshold in any US state privacy law.
  • Affiliate reach — § 501.702(9)(b): any entity that controls or is controlled by a controller is itself a controller. "Control" means owning or having power to vote more than 50 percent of a class of voting security, controlling the election of a majority of directors, or the power to exercise a controlling influence.
  • Comparison — a $2 billion regional retailer, hospital system, or manufacturer that sells no online advertising, operates no voice assistant, and runs no app store is outside the FDBR entirely, while the same company clears California's CCPA revenue trigger (statutory $25 million in annual gross revenue, subject to CPPA inflation adjustment) forty times over. The FDBR floor is 40x the CCPA's, and the business-model menu is an additional gate on top of it.

Applicability Thresholds

Conditions are joined by AND ALL conditions must be met.

$1000M+
Annual gross revenue
In excess of $1 billion in global gross annual revenues AND at least one of three business-model tests under Fla. Stat. § 501.702(9)(a)6.: (a) derives 50% or more of global gross annual revenues from the sale of advertisements online, including targeted advertising; (b) operates a consumer smart speaker and voice command component service with a cloud-connected virtual assistant using hands-free verbal activation (motor-vehicle speakers excluded); or (c) operates an app store or digital distribution platform offering at least 250,000 different software applications. Also applies to entities controlled by or in control of qualifying organizations.

Consumer Rights

Right to Access
Right to Delete
Right to Correct
Data Portability
Opt-Out of Sale
Opt-Out of Targeted Ads
Opt-Out of Profiling
Limit Sensitive Data Use
Right to Appeal
Private Right of Action

Key Changes in 2025-2026

  • Continued enforcement of the very-high-threshold FDBR targeting major tech companies
  • Separate data broker registration law enforcement continues
  • Social media minor safety provisions under active enforcement
  • Potential amendments to lower thresholds or expand applicability

Enforcement Details

Enforced By
Florida Department of Legal Affairs (Attorney General)
Penalty Per Violation
$50,000
Cure Period
45 days
Private Right of Action
No — AG enforcement only

Sensitive Data Categories

Consent model: opt-in

Racial or ethnic originReligious beliefsMental or physical health diagnosisSexual orientationCitizenship or immigration statusBiometric data for identification

Universal Opt-Out / GPC Requirements

No Universal Opt-Out Requirement

The FDBR does not require businesses to honor universal opt-out mechanisms. Given the very high threshold, the law targets large tech companies that typically have sophisticated opt-out processes.

Minor / Child Protections

The FDBR includes strong social media-focused minor protections. It prohibits social media platforms from processing personal data of children under 13 and requires parental consent mechanisms. For teens under 18, platforms must provide age-appropriate privacy defaults and restrict certain data processing activities.

Compliance Checklist

  1. 1Determine whether your organization meets the $1 billion revenue threshold and additional qualifying conditions
  2. 2If applicable, update privacy notices with all FDBR-required disclosures
  3. 3Implement consumer rights request mechanisms with 45-day response period
  4. 4Obtain opt-in consent for processing sensitive personal data
  5. 5For social media platforms, implement age verification and minor safety protections
  6. 6If operating as a data broker, register with the Florida Department of Agriculture and Consumer Services
Put FDBR Into Practice on Your SiteSponsored

Termly builds and maintains a Florida-ready privacy policy, a cookie consent banner, opt-in consent capture for sensitive data, and a workflow for the access, deletion and correction requests FDBR grants.

Start Free with Termly

Florida Privacy Law FAQ

Official Resources