Alabama
Alabama Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Alabama's Data Breach Notification Act of 2018 (Ala. Code 8-38-5) requires covered entities to notify affected residents within 45 days of determining a qualifying breach occurred. Businesses must also notify the Alabama Attorney General within that same 45-day window when more than 1,000 residents are affected.
Alabama was the last state in the country to enact a data breach notification law. Governor Kay Ivey signed the Data Breach Notification Act of 2018 (Act 2018-396) on March 28, 2018, with an effective date of June 1, 2018. The law is codified at Ala. Code 8-38-1 through 8-38-12.
For a broader overview of the state's privacy framework, see the parent guide to Alabama Data Privacy Laws.
The act requires businesses, government agencies, and other entities that handle sensitive personal information of Alabama residents to investigate potential breaches, notify affected individuals, and report large-scale incidents to the Attorney General.
Who Must Comply With the Alabama Data Breach Notification Act
The law applies to any "covered entity," which Ala. Code 8-38-2 defines broadly. It includes any person, sole proprietorship, partnership, government entity, corporation, nonprofit, trust, estate, cooperative association, or other business entity that acquires or uses sensitive personally identifying information.
Third-party agents, meaning entities that have been contracted to maintain, store, or process data on behalf of a covered entity, are also subject to the law. They must notify the covered entity within 10 days of discovering a breach, per Ala. Code 8-38-8.
What Information Triggers Notification
Alabama's law protects "sensitive personally identifying information" (SPII). Under Ala. Code 8-38-2, SPII means an Alabama resident's first name or first initial and last name combined with one or more of the following data elements:
- Non-truncated Social Security number or tax identification number
- Non-truncated driver's license number, state-issued ID number, passport number, military ID number, or other unique government-issued identification number
- Financial account number, credit card number, or debit card number combined with any security code, access code, password, expiration date, or PIN needed to access the account
- Medical information, defined as any information about an individual's medical history, mental or physical condition, or medical treatment or diagnosis by a healthcare professional
- Health insurance policy number or subscriber identification number, along with any unique identifier used by a health insurer to identify the individual
- Username or email address combined with a password or security question and answer that would allow access to an online account reasonably likely to contain SPII
The law only applies to data in electronic form. Paper records are not covered by the notification requirements.
How Alabama Defines a Data Breach
Under Ala. Code 8-38-2, a "breach of security" means the unauthorized acquisition of data in electronic form containing SPII. Multiple unauthorized acquisitions by the same entity over a period of time count as a single breach.
The definition excludes three categories of events:
- Good faith acquisition of data by an employee or agent of a covered entity, as long as the information is not used for an unrelated purpose or subject to further unauthorized disclosure
- Release of public records not otherwise subject to confidentiality requirements
- Lawful investigative, protective, or intelligence activity by law enforcement or intelligence agencies
The Substantial Harm Threshold
Alabama's notification requirement includes a threshold that many other states lack. Under Ala. Code 8-38-4, notification is only required when the covered entity determines, after a good-faith and prompt investigation, that the breach is "reasonably likely to cause substantial harm" to affected individuals.
This means not every technical breach triggers a notification obligation. The covered entity must assess factors including:
- Whether the information is in the physical possession and control of an unauthorized person (for example, a lost or stolen device)
- Whether the information has been downloaded or copied
- Whether the information was used by an unauthorized person, such as through fraudulent accounts or reported identity theft
If the entity concludes after a good-faith investigation that substantial harm is unlikely, it may choose not to notify. However, the entity must document this determination in writing and keep the documentation for at least five years.
Investigation Requirements Before Notification
When a covered entity determines that a breach has or may have occurred, Ala. Code 8-38-4 requires a good-faith and prompt investigation that covers four areas:
- Assessing the nature and scope of the breach
- Identifying the SPII involved and the individuals to whom it relates
- Determining whether the data was acquired or is reasonably believed to have been acquired by an unauthorized person and is reasonably likely to cause substantial harm
- Implementing measures to restore the security and confidentiality of the compromised systems
Notification Timeline and Methods
Once a covered entity determines that notification is required, Ala. Code 8-38-5 mandates that notice be provided "as expeditiously as possible and without unreasonable delay," but no later than 45 days after the entity's determination or receipt of notice from a third-party agent.
Notification may be delivered through:
- Written notice sent to the individual's mailing address on file
- Email notice sent to the individual's email address on file

What Must Be Included in the Notice
Every breach notification letter must contain, at minimum:
- The date, estimated date, or estimated date range of the breach
- A description of the types of SPII acquired by the unauthorized person
- A general description of the actions the covered entity has taken to restore security and confidentiality
- A general description of steps the affected individual can take to protect themselves from identity theft
- Contact information (including a way to reach the covered entity for additional questions about the breach)
Substitute Notice
A covered entity may use substitute notice instead of direct notification when any of the following conditions apply, per Ala. Code 8-38-5:
- The cost of direct notice exceeds $500,000
- The affected class exceeds 100,000 individuals
- The entity lacks sufficient contact information for the individuals
Substitute notice requires posting a conspicuous notice on the entity's website for at least 30 days and providing notice through print and broadcast media in both urban and rural areas where affected individuals reside.
Law Enforcement Delay
Notification may be delayed if a law enforcement agency determines in writing that notice would impede a criminal investigation or jeopardize national security. Once the agency lifts the written request, the 45-day notification clock resumes.
Attorney General Notification Requirements
Under Ala. Code 8-38-6, if a breach affects more than 1,000 Alabama residents, the covered entity must also provide written notice to the Alabama Attorney General within the same 45-day window.
The AG notification must include:
- A synopsis of the events surrounding the breach at the time notice is given
- The approximate number of affected Alabama residents
- Any free services the entity is offering to affected individuals, along with instructions for using those services
- The name, address, telephone number, and email address of a contact person at the covered entity
The entity may submit supplemental or updated information to the AG at any time. Information marked as confidential that is submitted to the AG is not subject to Alabama's open records laws.
The AG's office provides a Data Breach Notification Form online. Supplemental documentation for previously reported breaches can be sent to ConsumerInterest@AlabamaAG.gov.

Consumer Reporting Agency Notification
When a breach affects more than 1,000 individuals, Ala. Code 8-38-7 also requires the covered entity to notify consumer reporting agencies. The entity must provide notice of the timing, distribution, and content of the notifications sent to affected individuals.
Required Security Measures
Alabama's law goes beyond notification. Ala. Code 8-38-3 requires every covered entity and third-party agent to implement and maintain "reasonable security measures" to protect SPII. These measures must be practicable given the entity's resources and must include:
- Designating an employee or employees to coordinate security measures (an owner or manager may serve in this role)
- Identifying internal and external risks of a breach and adopting appropriate safeguards
- Retaining service providers that are contractually required to maintain appropriate safeguards
- Evaluating and adjusting security measures as circumstances change
The law does not prescribe specific technical controls. Instead, it uses a reasonableness standard that accounts for the entity's cost of implementation relative to its available resources.
Record Disposal Requirements
Ala. Code 8-38-10 requires covered entities and third-party agents to take reasonable measures to dispose of records containing SPII when those records are no longer needed for business or legal purposes. Acceptable disposal methods include shredding, erasing, or otherwise modifying the information to make it unreadable through any reasonable means consistent with industry standards.
Encryption Safe Harbor
Alabama's law includes an encryption safe harbor. If SPII was encrypted, secured, or otherwise rendered unreadable or unusable, no notification is required. However, this protection does not apply if the covered entity knows or has reason to know that the encryption key or security credential was compromised along with the protected data.
Penalties for Noncompliance
Violations of Alabama's breach notification law are treated as unlawful trade practices under the Alabama Deceptive Trade Practices Act (Ala. Code Chapter 19), per Ala. Code 8-38-9. This means:
- Civil penalties of up to $5,000 per day for each consecutive day a covered entity fails to take reasonable action to comply with notification requirements
- A maximum cap of $500,000 per breach
- The Attorney General has exclusive authority to bring enforcement actions for civil penalties
- The AG may also bring actions for actual damages on behalf of affected individuals, plus reasonable attorney's fees and costs

Violations do not constitute criminal offenses under the Deceptive Trade Practices Act, and there is no private right of action. Alabama residents cannot individually sue for breach notification failures.
Federal and State Exemptions
HIPAA-Covered Entities
Under Ala. Code 8-38-11, entities regulated by federal data breach notification laws (including HIPAA) are exempt from the Alabama statute, provided they maintain procedures under the applicable federal authority, provide notice as required by federal law, and timely notify the Alabama AG when more than 1,000 residents are affected.
State-Regulated Entities
Ala. Code 8-38-12 provides a similar exemption for entities subject to state laws with breach notification requirements that are at least as thorough as the Alabama act. These entities must comply with the applicable state requirements and notify the AG when breaches exceed the 1,000-resident threshold.
Financial Institutions
Financial institutions subject to the Gramm-Leach-Bliley Act (GLBA) are also exempt if they comply with applicable federal breach notification requirements and meet the AG notification threshold.
AG Enforcement in Practice
Alabama has participated in multistate data breach enforcement actions since the law took effect. In October 2023, Attorney General Steve Marshall announced a $49.5 million settlement with Blackbaud, a cloud software company whose 2020 data breach exposed sensitive information from more than 13,000 customers nationwide, including nonprofits, schools, and healthcare entities. Alabama received $1.6 million from the settlement. The action alleged that Blackbaud failed to implement reasonable security measures, delayed notification, and misrepresented the scope of the breach to affected customers.
Sources and References
This article references the Alabama Data Breach Notification Act of 2018 (Ala. Code 8-38-1 through 8-38-12). For the full statutory text, visit the Alabama Legislature website. For information about filing a breach notification or a consumer complaint, visit the Alabama Attorney General's Data Breach Notification page.
This article provides general legal information about Alabama's data breach notification requirements. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official Alabama government sources.
More Alabama Laws
Frequently Asked Questions
Does Alabama's data breach notification law apply to paper records?
No. The Alabama Data Breach Notification Act of 2018 only applies to sensitive personally identifying information in electronic form. Paper records that are lost, stolen, or improperly accessed are not covered by the notification requirements, though the record disposal provisions under Ala. Code 8-38-10 apply to records in any format.
Can an Alabama resident sue a company that fails to send a breach notification?
No. Alabama's law does not create a private right of action. Only the Alabama Attorney General can bring enforcement actions for notification failures. The AG can seek civil penalties of up to $500,000 per breach and may also pursue actual damages on behalf of named individuals. Residents who believe a company failed to comply can file a complaint with the AG's Consumer Interest Division.
What is the 'substantial harm' threshold in Alabama's breach notification law?
Alabama only requires notification when a breach is 'reasonably likely to cause substantial harm' to affected individuals. The covered entity must conduct a good-faith investigation and assess factors like whether the data was downloaded, whether it is in an unauthorized person's possession, and whether there is evidence of misuse. If the entity determines substantial harm is unlikely, it may forgo notification, but must document that decision in writing and retain the documentation for five years.
How does Alabama's 45-day notification deadline compare to other states?
Alabama's 45-day deadline falls in the middle of the national range. Some states require notification within as few as 30 days (like Colorado and Florida), while others have no specific deadline beyond 'most expedient time possible.' The 45-day clock starts when the covered entity determines a qualifying breach has occurred, or when it receives notice from a third-party agent that a breach occurred.
Are healthcare providers in Alabama subject to both HIPAA and state breach notification rules?
HIPAA-covered entities that comply with federal breach notification requirements under the HIPAA Breach Notification Rule are exempt from Alabama's state law under Ala. Code 8-38-11. However, these entities must still notify the Alabama Attorney General when a breach affects more than 1,000 Alabama residents, even when relying on the federal exemption. The exemption only applies if the entity maintains procedures and provides notice as required by federal law.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 12 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
Code of Alabama 1975, Title 8: Commercial Law and Consumer Protection.
§ 8-38-1Short Title.In forcecited in 3 of our articles
This chapter may be cited and shall be known as the Alabama Data Breach Notification Act of 2018.
Official text (excerpt) · as of 2026-07-29 · Read the full section at alison.legislature.state.al.us
Also relied on in: Alabama Data Privacy Laws: Breach Notification & Consumer Rights (2026), Alabama Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 8-38-10Disposal of Records Containing Sensitive Personally Identifying Information.In forcecited in 2 of our articles
A covered entity or third-party agent shall take reasonable measures to dispose, or arrange for the disposal, of records containing sensitive personally identifying information within its custody or control when the records are no longer to be retained pursuant to applicable law, regulations, or business needs. Disposal shall include shredding, erasing, or otherwise modifying the personal information in the records to make it unreadable or undecipherable through any reasonable means consistent with industry standards.
Official text (excerpt) · as of 2026-07-29 · Read the full section at alison.legislature.state.al.us
§ 8-38-11Exemptions - Federal.In forcecited in 2 of our articles
An entity subject to or regulated by federal laws, rules, regulations, procedures, or guidance on data breach notification established or enforced by the federal government is exempt from this chapter as long as the entity does all of the following: (1) Maintains procedures pursuant to those laws, rules, regulations, procedures, or guidance. (2) Provides notice to affected individuals pursuant to those laws, rules, regulations, procedures, or guidance. (3) Timely provides a copy of the notice to the Attorney General when the number of individuals the entity notified exceeds 1,000.
Official text (excerpt) · as of 2026-07-29 · Read the full section at alison.legislature.state.al.us
§ 8-38-12Exemptions - State.In force
An entity subject to or regulated by state laws, rules, regulations, procedures, or guidance on data breach notification that are established or enforced by state government, and are at least as thorough as the notice requirements provided by this chapter, is exempt from this chapter so long as the entity does all of the following: (1) Maintains procedures pursuant to those laws, rules, regulations, procedures, or guidance. (2) Provides notice to affected individuals pursuant to the notice requirements of those laws, rules, regulations, procedures, or guidance. (3) Timely provides a copy of the notice to the Attorney General when the number of individuals the entity notified exceeds 1,000.
Official text (excerpt) · as of 2026-07-29 · Read the full section at alison.legislature.state.al.us
§ 8-38-2Definitions.In forcecited in 3 of our articles
For the purposes of this chapter, the following terms have the following meanings: (1) BREACH OF SECURITY or BREACH. The unauthorized acquisition of data in electronic form containing sensitive personally identifying information. Acquisition occurring over a period of time committed by the same entity constitutes one breach. The term does not include any of the following: a. Good faith acquisition of sensitive personally identifying information by an employee or agent of a covered entity, unless the information is used for a purpose unrelated to the business or subject to further unauthorized use. b. The release of a public record not otherwise subject to confidentiality or nondisclosure requirements. c. Any lawful investigative, protective, or intelligence activity of a law enforcement or intelligence agency of the state, or a political subdivision of the state. (2) COVERED ENTITY. A person, sole proprietorship, partnership, government entity, corporation, nonprofit, trust, estate, cooperative association, or other business entity that acquires or uses sensitive personally identifying information. (3) DATA IN ELECTRONIC FORM.
Official text (excerpt) · as of 2026-07-29 · Read the full section at alison.legislature.state.al.us
§ 8-38-3Reasonable Security Measures; Assessment.In forcecited in 2 of our articles
(a) Each covered entity and third-party agent shall implement and maintain reasonable security measures to protect sensitive personally identifying information against a breach of security. (b) Reasonable security measures means security measures practicable for the covered entity subject to subsection (c), to implement and maintain, including consideration of all of the following: (1) Designation of an employee or employees to coordinate the covered entity’s security measures to protect against a breach of security. An owner or manager may designate himself or herself. (2) Identification of internal and external risks of a breach of security. (3) Adoption of appropriate information safeguards to address identified risks of a breach of security and assess the effectiveness of such safeguards. (4) Retention of service providers, if any, that are contractually required to maintain appropriate safeguards for sensitive personally identifying information. (5) Evaluation and adjustment of security measures to account for changes in circumstances affecting the security of sensitive personally identifying information.
Official text (excerpt) · as of 2026-07-29 · Read the full section at alison.legislature.state.al.us
§ 8-38-4Investigation of Security Breach.In force
(a) If a covered entity determines that a breach of security has or may have occurred in relation to sensitive personally identifying information that is accessed, acquired, maintained, stored, utilized, or communicated by, or on behalf of, the covered entity, the covered entity shall conduct a good faith and prompt investigation that includes all of the following: (1) An assessment of the nature and scope of the breach. (2) Identification of any sensitive personally identifying information that may have been involved in the breach and the identity of any individuals to whom that information relates. (3) A determination of whether the sensitive personally identifying information has been acquired or is reasonably believed to have been acquired by an unauthorized person, and is reasonably likely to cause substantial harm to the individuals to whom the information relates. (4) Identification and implementation of measures to restore the security and confidentiality of the systems compromised in the breach.
Official text (excerpt) · as of 2026-07-29 · Read the full section at alison.legislature.state.al.us
§ 8-38-5Notice of Security Breach - Individuals Affected.In forcecited in 3 of our articles
(a) A covered entity that is not a third-party agent that determines under Section 8-38-4 that, as a result of a breach of security, sensitive personally identifying information has been acquired or is reasonably believed to have been acquired by an unauthorized person, and is reasonably likely to cause substantial harm to the individuals to whom the information relates, shall give notice of the breach to each individual. (b) Notice to individuals under subsection (a) shall be made as expeditiously as possible and without unreasonable delay, taking into account the time necessary to allow the covered entity to conduct an investigation in accordance with Section 8-38-4. Except as provided in subsection (c), the covered entity shall provide notice within 45 days of the covered entity’s receipt of notice from a third-party agent that a breach has occurred or upon the covered entity’s determination that a breach has occurred and is reasonably likely to cause substantial harm to the individuals to whom the information relates.
Official text (excerpt) · as of 2026-07-29 · Read the full section at alison.legislature.state.al.us
§ 8-38-6Notice of Security Breach - Attorney General.In force
(a) If the number of individuals a covered entity is required to notify under Section 8-38-5 exceeds 1,000, the entity shall provide written notice of the breach to the Attorney General as expeditiously as possible and without unreasonable delay. Except as provided in subsection (c) of Section 8-38-5, the covered entity shall provide the notice within 45 days of the covered entity’s receipt of notice from a third-party agent that a breach has occurred or upon the entity’s determination that a breach has occurred and is reasonably likely to cause substantial harm to the individuals to whom the information relates. (b) Written notice to the Attorney General shall include all of the following: (1) A synopsis of the events surrounding the breach at the time that notice is provided. (2) The approximate number of individuals in the state who were affected by the breach. (3) Any services related to the breach being offered or scheduled to be offered, without charge, by the covered entity to individuals and instructions on how to use the services.
Official text (excerpt) · as of 2026-07-29 · Read the full section at alison.legislature.state.al.us
§ 8-38-7Notice of Security Breach - Consumer Reporting Agencies.In force
If a covered entity discovers circumstances requiring notice under Section 8-38-5 of more than 1,000 individuals at a single time, the entity shall also notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, as defined in the Fair Credit Reporting Act, 15 U.S.C. §1681a, of the timing, distribution, and content of the notices.
Official text (excerpt) · as of 2026-07-29 · Read the full section at alison.legislature.state.al.us
§ 8-38-8Notice of Security Breach - Covered Entity.In force
In the event a third-party agent has experienced a breach of security in the system maintained by the agent, the agent shall notify the covered entity of the breach of security as expeditiously as possible and without unreasonable delay, but no later than 10 days following the determination of the breach of security or reason to believe the breach occurred. After receiving notice from a third-party agent, a covered entity shall provide notices required under Sections 8-38-5 and 8-38-6. A third-party agent, in cooperation with a covered entity, shall provide information in the possession of the third-party agent so that the covered entity can comply with its notice requirements. A covered entity may enter into a contractual agreement with a third-party agent whereby the third-party agent agrees to handle notifications required under this chapter.
Official text (excerpt) · as of 2026-07-29 · Read the full section at alison.legislature.state.al.us
§ 8-38-9Violations of Notification Requirements.In forcecited in 2 of our articles
(a) A violation of the notification provisions of this chapter is an unlawful trade practice under the Alabama Deceptive Trade Practices Act, Chapter 19 of this title, but does not constitute a criminal offense under Section 8-19-12. The Attorney General shall have the exclusive authority to bring an action for civil penalties under this chapter. (1) A violation of this chapter does not establish a private cause of action under Section 8-19-10. Nothing in this chapter may otherwise be construed to affect any right a person may have at common law, by statute, or otherwise. (2) Any covered entity or third-party agent who is knowingly engaging in or has knowingly engaged in a violation of the notification provisions of this chapter is subject to the penalty provisions set out in Section 8-19-11. For the purposes of this chapter, knowingly shall mean willfully or with reckless disregard in failing to comply with the notice requirements of Sections 8-38-5 and 8-38-6. Civil penalties assessed under Section 8-19-11, shall not exceed five hundred thousand dollars ($500,000) per breach.
Official text (excerpt) · as of 2026-07-29 · Read the full section at alison.legislature.state.al.us
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- Alabama Data Breach Notification Act of 2018(alabamaag.gov).gov
- Act 2018-396 Full Text(alabamaag.gov).gov
- AG Marshall Announces Final Passage of Data Breach Notification Act(alabamaag.gov).gov
- AG Marshall $49.5M Blackbaud Settlement(alabamaag.gov).gov
- Alabama Code Title 8 Chapter 38(legislature.state.al.us).gov