Florida
Florida Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Florida regulates biometric data through the Florida Digital Bill of Rights (FDBR), which classifies fingerprints, voiceprints, and iris scans as sensitive personal data under Fla. Stat. 501.702(4). The FDBR, effective July 1, 2024, grants consumers opt-out rights but limits its full protections to companies earning over $1 billion in global annual revenue.
Florida does not have a standalone biometric privacy law like Illinois (BIPA) or Texas (CUBI). Instead, biometric data protections are woven into the Florida Digital Bill of Rights (FDBR), which took effect on July 1, 2024, and the Florida Information Protection Act (FIPA), which covers breach notification.
The FDBR treats biometric data as a subset of sensitive personal data and grants consumers specific opt-out rights. However, the law's narrow applicability threshold means that most of these protections apply only against the largest technology companies operating in the state.
What Counts as Biometric Data Under Florida Law
Fla. Stat. 501.702(4) defines biometric data as "data generated by automatic measurements of an individual's biological characteristics." The statute specifically lists:
- Fingerprints
- Voiceprints
- Eye retinas or irises
- Other unique biological patterns or characteristics used to identify a specific individual
The definition is broad enough to capture newer biometric technologies, such as gait analysis or vein pattern recognition, as long as the data is generated through automatic measurement and used for identification.
What Biometric Data Does Not Include
The statute explicitly carves out three categories:
- Photographs (including digital photos)
- Video or audio recordings (the recording itself, as opposed to biometric identifiers extracted from recordings)
- Data collected under HIPAA (health information governed by federal health privacy rules)
This exclusion means a security camera recording of someone walking through a store is not biometric data. But if software analyzes that footage to extract a faceprint or gait signature, the extracted identifier falls under the biometric data definition.
The $1 Billion Controller Threshold

The FDBR's biometric protections are powerful on paper but narrow in practice. Under Fla. Stat. 501.702(9), a company qualifies as a "controller" subject to the full FDBR requirements only if it meets all of these conditions:
- Conducts business in Florida or produces products/services consumed by Florida residents
- Collects personal data about consumers
- Earns more than $1 billion in global gross annual revenue
- Meets at least one additional condition:
- Derives 50% or more of global revenue from online advertising sales
- Operates a consumer smart speaker with a voice-activated virtual assistant
- Operates an app store or digital distribution platform offering at least 250,000 applications
This threshold is the highest of any state privacy law in the United States. By comparison, the California Consumer Privacy Act kicks in at $25 million in annual revenue.
In practice, only a handful of companies qualify: think Google, Amazon, Apple, and Meta. A Florida-based employer using fingerprint scanners for time tracking almost certainly falls below the threshold and is not subject to the FDBR's opt-out requirements for biometric data.
The Broader Sale-of-Sensitive-Data Rule
One provision reaches beyond the $1 billion threshold. Under Fla. Stat. 501.715, any controller that sells sensitive personal data (which includes biometric data) must obtain prior consumer consent before the sale. For children under 13, federal COPPA rules apply. For minors aged 13 to 17, the controller must obtain the child's affirmative authorization.
This consent requirement for the sale of sensitive data, combined with the biometric sale notice requirement in Fla. Stat. 501.711(3), creates obligations that may reach more businesses than the core FDBR framework.
Consumer Rights for Biometric Data

Consumers whose data is processed by qualifying controllers have several rights specific to biometric information.
Opt-Out of Biometric Data Processing
Under Fla. Stat. 501.705(2)(f), consumers may opt out of the collection and processing of sensitive data, which includes biometric data.
Opt-Out of Voice and Facial Recognition
Fla. Stat. 501.705(2)(g) creates a separate, specific right to opt out of personal data collection through "the operation of a voice recognition or facial recognition feature." This provision targets smart devices, apps, and platforms that use facial or voice recognition to identify or authenticate users.
No Background Surveillance
Fla. Stat. 501.705(3) prohibits controllers from using voice recognition, facial recognition, video recording, audio recording, or similar sensing features "when such features are not in active use by the consumer," unless the consumer has expressly authorized it. This targets always-on microphones and cameras in smart home devices and similar products.
Opt-In vs. Opt-Out: How Florida Compares
Florida uses an opt-out model for most biometric data processing. Covered controllers can collect and process biometric data by default, and consumers must take affirmative action to stop it.
This differs significantly from Illinois' Biometric Information Privacy Act (BIPA), which requires opt-in written consent before any collection of biometric identifiers. Under BIPA, collection without prior consent is a violation from the start. Under the FDBR, collection without consent is generally permissible until a consumer exercises their opt-out right.
The one exception is the sale of biometric data. Selling biometric data requires prior consent under Fla. Stat. 501.715, making that specific activity opt-in.
Notice Requirements for Biometric Data
Controllers that sell biometric personal data must display a specific notice under Fla. Stat. 501.711(3):
"NOTICE: This website may sell your biometric personal data."
This notice must appear in the same location as the company's general privacy notice. Controllers must also disclose:
- The categories of personal data processed, including whether sensitive data is involved
- How consumers can exercise their opt-out rights
- Categories of third parties that receive personal data
- The purposes for processing
Privacy notices must be updated at least annually.
Data Protection Assessments
Under Fla. Stat. 501.713, controllers must conduct data protection assessments for activities that present a "heightened risk of harm to consumers." Processing sensitive data, including biometric data, triggers this requirement.
Each assessment must weigh the benefits of the processing activity against the potential risks to consumer rights, considering factors such as:
- Whether the data has been deidentified
- Consumer expectations regarding the processing
- The context and relationship between the controller and consumer
- Available safeguards to reduce risk
These assessments are confidential but must be made available to the Department of Legal Affairs upon request during an investigation.
Biometric Data and Breach Notification
Separately from the FDBR, the Florida Information Protection Act (Fla. Stat. 501.171) includes biometric data in its definition of personal information subject to breach notification requirements.
If a breach exposes an individual's biometric data (as defined in Fla. Stat. 501.702) along with their first name or first initial and last name, the entity must:
- Notify affected individuals within 30 days of discovering the breach
- Notify the Florida Department of Legal Affairs within 30 days (with a possible 15-day extension upon written request)
- Notify credit reporting agencies if the breach affects more than 1,000 individuals at a single time
FIPA's breach notification rules apply to all covered entities in Florida, not just $1 billion companies. Any business or government entity that maintains, stores, or uses Floridians' biometric data must comply.
Penalties for failing to meet notification deadlines under FIPA reach up to $500,000 per breach: $1,000 per day for the first 30 days, then $50,000 for each subsequent 30-day period, up to 180 days.
Enforcement: Attorney General Only

The FDBR is enforced exclusively by the Florida Department of Legal Affairs (the Attorney General's office) under Fla. Stat. 501.72.
There is no private right of action. Individual consumers cannot sue companies for biometric data violations under Florida law. This is one of the sharpest contrasts with Illinois' BIPA, where private lawsuits (including class actions) have produced hundreds of millions of dollars in settlements.
Penalty Structure
| Violation Type | Maximum Penalty |
|---|---|
| Standard FDBR violation | $50,000 per violation |
| Violation involving a known child | $150,000 per violation (treble damages) |
| Failure to delete/correct data after consumer request | $150,000 per violation (treble damages) |
| Continuing data sale after opt-out | $150,000 per violation (treble damages) |
| FIPA breach notification failure | Up to $500,000 per incident |
Cure Period
Controllers receive a 45-day cure period after written notice from the AG's office. If the violation is cured within that window, the department may choose not to pursue action. The one exception: violations involving children's data have no cure period.
Enforcement Activity to Date
The Florida AG's office issued its first annual enforcement report covering January through December 2025. During that period, the department received 1,496 consumer complaints, placed 811 under active review, issued 186 Notices of Alleged Violation to controllers, and initiated 60 inquiries to determine whether entities fell within the FDBR's scope.
The first major enforcement action came in October 2025, when the AG filed suit against Roku, Inc. for alleged violations involving children's data, including geolocation and voice recordings. Florida sought civil penalties of up to $150,000 per violation.
Employer Use of Biometric Data
Florida does not have a separate employer-specific biometric privacy law. Businesses that use fingerprint scanners for timekeeping, facial recognition for building access, or other biometric tools in the workplace are generally not subject to the FDBR unless they meet the $1 billion controller threshold.
However, employers should be aware of two considerations:
Breach notification still applies. If an employer stores employees' fingerprints or other biometric data and suffers a data breach, the FIPA notification requirements apply regardless of company size. Failure to notify within 30 days exposes the employer to penalties.
No BIPA-style lawsuit risk. Unlike in Illinois, where employees have filed thousands of class action lawsuits over biometric data collection in the workplace, Florida's lack of a private right of action means employees cannot bring similar claims. Enforcement runs through the AG's office only.
Pending Legislation: 2025-2026 Session
The Florida Legislature has not advanced a standalone biometric privacy act in recent sessions. A 2019 proposal, the Florida Biometric Information Privacy Act (SB 1270), modeled on Illinois' BIPA, did not pass. No comparable bill has been filed in the 2025 or 2026 legislative sessions.
The 2026 session did see SB 482, an Artificial Intelligence Bill of Rights, which passed the Senate 35-2 but died in the House. That bill addressed AI governance and chatbot consent but did not amend the FDBR's biometric provisions.
As of March 2026, there is no pending legislation that would lower the FDBR's $1 billion threshold, create a private right of action for biometric data violations, or establish a standalone biometric privacy statute in Florida.
How Florida Compares to Other States
| Feature | Florida (FDBR) | Illinois (BIPA) | Texas (CUBI) |
|---|---|---|---|
| Standalone biometric law | No (part of broader privacy law) | Yes | Yes |
| Consent model | Opt-out (opt-in for sale only) | Opt-in written consent | Opt-in notice and consent |
| Applicability | $1B+ revenue Big Tech only | All private entities | All persons |
| Private right of action | No | Yes (statutory damages) | No (AG only) |
| Penalty per violation | $50,000 ($150,000 for children) | $1,000-$5,000 per violation | $25,000 per violation |
| Breach notification | Yes (via FIPA, all businesses) | Not specifically | Not specifically |
This comparison matters for businesses operating across multiple states. A company that collects fingerprints in both Florida and Illinois faces vastly different compliance burdens and litigation risks in each jurisdiction.
This article provides general legal information about Florida biometric privacy laws and is not legal advice. Laws and enforcement practices change over time. Consult an attorney for advice specific to your situation.
More Florida Laws
Frequently Asked Questions
Does Florida have a biometric privacy law?
Florida does not have a standalone biometric privacy law. Biometric data protections are included within the Florida Digital Bill of Rights (Fla. Stat. 501.701-501.721), which classifies biometric data as sensitive personal data. These protections took effect on July 1, 2024, but apply primarily to companies with over $1 billion in global annual revenue that also meet specific Big Tech criteria.
Can I sue a company in Florida for collecting my fingerprints without consent?
No. The FDBR does not create a private right of action. Only the Florida Attorney General can enforce biometric data violations. This contrasts sharply with Illinois, where individuals can bring lawsuits (including class actions) under BIPA for unauthorized biometric data collection.
Do Florida employers need consent to use fingerprint time clocks?
Most Florida employers are not subject to the FDBR's biometric consent requirements because they fall below the $1 billion revenue threshold. However, if an employer suffers a data breach involving stored biometric data, the Florida Information Protection Act (Fla. Stat. 501.171) requires notification to affected individuals within 30 days.
What biometric data is covered under Florida law?
Fla. Stat. 501.702(4) defines biometric data as data generated by automatic measurements of biological characteristics, including fingerprints, voiceprints, eye retinas or irises, and other unique biological patterns used to identify a specific individual. Photographs, video/audio recordings, and HIPAA-covered health data are excluded.
What are the penalties for biometric data violations in Florida?
Under the FDBR, civil penalties reach up to $50,000 per violation, or $150,000 (treble damages) for violations involving children, failure to delete data after a consumer request, or continuing data sales after an opt-out. Under FIPA, failing to notify individuals of a biometric data breach can result in penalties up to $500,000 per incident.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the biometric-sale notice requirement to apply only to FDBR controllers meeting the $1 billion revenue threshold, and fixed the credit-reporting-agency breach threshold to match the statute (more than 1,000 individuals, not 500).
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 8 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
Florida Statutes
§ 501.171Security of confidential personal information.In forcecited in 3 of our articles
(1) DEFINITIONS.—As used in this section, the term:(a) “Breach of security” or “breach” means unauthorized access of data in electronic form containing personal information. Good faith access of personal information by an employee or agent of the covered entity does not constitute a breach of security, provided that the information is not used for a purpose unrelated to the business or subject to further unauthorized use. (b) “Covered entity” means a sole proprietorship, partnership, corporation, trust, estate, cooperative, association, or other commercial entity that acquires, maintains, stores, or uses personal information. For purposes of the notice requirements in subsections (3)-(6), the term includes a governmental entity. (c) “Customer records” means any material, regardless of the physical form, on which personal information is recorded or preserved by any means, including, but not limited to, written or spoken words, graphically depicted, printed, or electromagnetically transmitted that are provided by an individual in this state to a covered entity for the purpose of purchasing or leasing a product or obtaining a service.
Official text (excerpt) · as of 2026-07-28 · Read the full section at leg.state.fl.us
Also relied on in: Florida Data Privacy Laws: Digital Bill of Rights & Breach Rules (2026), Florida Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 501.701Short title.In forcecited in 6 of our articles
This part may be cited as the “Florida Digital Bill of Rights.”
Official text (excerpt) · as of 2026-07-28 · Read the full section at leg.state.fl.us
Also relied on in: FDBR Compliance Checklist: Florida Data Privacy, FDBR Consumer Rights: Florida Data Privacy Rights, What Is the FDBR? Florida Digital Bill of Rights
§ 501.702Definitions.In forcecited in 4 of our articles
As used in this part, the term:(1) “Affiliate” means a legal entity that controls, is controlled by, or is under common control with another legal entity or that shares common branding with another legal entity. For purposes of this subsection, the term “control” or “controlled” means any of the following:(a) The ownership of, or power to vote, more than 50 percent of the outstanding shares of any class of voting security of a company. (b) The control in any manner over the election of a majority of the directors or of individuals exercising similar functions. (c) The power to exercise controlling influence over the management of a company. (2) “Aggregate consumer information” means information that relates to a group or category of consumers from which the identity of an individual consumer has been removed and is not reasonably capable of being directly or indirectly associated or linked with any consumer, household, or device. The term does not include information about a group or category of consumers used to facilitate targeted advertising or the display of ads online. The term does not include personal information that has been deidentified.
Official text (excerpt) · as of 2026-07-28 · Read the full section at leg.state.fl.us
§ 501.705Consumer rights.In forcecited in 5 of our articles
(1) A consumer is entitled to exercise the consumer rights authorized by this section at any time by submitting a request to a controller which specifies the consumer rights that the consumer wishes to exercise. With respect to the processing of personal data belonging to a known child, a parent or legal guardian of the child may exercise these rights on behalf of the child. (2) A controller shall comply with an authenticated consumer request to exercise any of the following rights:(a) To confirm whether a controller is processing the consumer’s personal data and to access the personal data. (b) To correct inaccuracies in the consumer’s personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer’s personal data. (c) To delete any or all personal data provided by or obtained about the consumer. (d) To obtain a copy of the consumer’s personal data in a portable and, to the extent technically feasible, readily usable format if the data is available in a digital format. (e) To opt out of the processing of the personal data for purposes of:1. Targeted advertising; 2. The sale of personal data; or 3.
Official text (excerpt) · as of 2026-07-28 · Read the full section at leg.state.fl.us
§ 501.711Privacy notices.In forcecited in 2 of our articles
(1) A controller shall provide consumers with a reasonably accessible and clear privacy notice, updated at least annually, that includes all of the following information:(a) The categories of personal data processed by the controller, including, if applicable, any sensitive data processed by the controller. (b) The purpose of processing personal data. (c) How consumers may exercise their rights under s. 501.705(2), including the process by which a consumer may appeal a controller’s decision with regard to the consumer’s request. (d) If applicable, the categories of personal data that the controller shares with third parties. (e) If applicable, the categories of third parties with whom the controller shares personal data. (f) A description of the methods specified in s. 501.709 by which consumers can submit requests to exercise their consumer rights under this part. (2) If a controller engages in the sale of personal data that is sensitive data, the controller must provide the following notice: “NOTICE: This website may sell your sensitive personal data.” The notice must be posted in accordance with subsection (1).
Official text (excerpt) · as of 2026-07-28 · Read the full section at leg.state.fl.us
§ 501.713Data protection assessments.In force
(1) A controller shall conduct and document a data protection assessment of each of the following processing activities involving personal data:(a) The processing of personal data for purposes of targeted advertising. (b) The sale of personal data. (c) The processing of personal data for purposes of profiling if the profiling presents a reasonably foreseeable risk of:1. Unfair or deceptive treatment of or unlawful disparate impact on consumers; 2. Financial, physical, or reputational injury to consumers; 3. A physical or other intrusion on the solitude or seclusion, or the private affairs or concerns, of consumers, if the intrusion would be offensive to a reasonable person; or 4. Other substantial injury to consumers. (d) The processing of sensitive data. (e) Any processing activities involving personal data which present a heightened risk of harm to consumers.
Official text (excerpt) · as of 2026-07-28 · Read the full section at leg.state.fl.us
§ 501.715Requirements for sensitive data.In forcecited in 4 of our articles
(1) A person who meets the requirements of s. 501.702(9)(a)1.-3. for the definition of a controller may not engage in the sale of personal data that is sensitive data without receiving prior consent from the consumer or, if the sensitive data is of a known child, without processing that data with the affirmative authorization for such processing by a known child who is between 13 and 18 years of age or in accordance with the Children’s Online Privacy Protection Act, 15 U.S.C. ss. 6501 et seq. for a known child under the age of 13. (2) A person in subsection (1) who engages in the sale of personal data that is sensitive data must provide the following notice: “NOTICE: This website may sell your sensitive personal data.” (3) A person who violates this section is subject to the penalty imposed under s. 501.72.
Official text (excerpt) · as of 2026-07-28 · Read the full section at leg.state.fl.us
§ 501.72Enforcement and implementation by the Department of Legal Affairs.In forcecited in 4 of our articles
(1) A violation of this part is an unfair and deceptive trade practice actionable under part II of this chapter solely by the Department of Legal Affairs. If the department has reason to believe that a person is in violation of this section, the department may, as the enforcing authority, bring an action against such person for an unfair or deceptive act or practice. For the purpose of bringing an action pursuant to this section, ss. 501.211 and 501.212 do not apply. In addition to other remedies under part II of this chapter, the department may collect a civil penalty of up to $50,000 per violation. Civil penalties may be tripled for any of the following violations:(a) A violation involving a Florida consumer who is a known child. A controller that willfully disregards the consumer’s age is deemed to have actual knowledge of the consumer’s age. (b) Failure to delete or correct the consumer’s personal data pursuant to this section after receiving an authenticated consumer request or directions from a controller to delete or correct such personal data, unless an exception to the requirements to delete or correct such personal data under this section applies.
Official text (excerpt) · as of 2026-07-28 · Read the full section at leg.state.fl.us
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- Fla. Stat. 501.702 - Definitions (biometric data, sensitive data, controller)(leg.state.fl.us).gov
- Fla. Stat. 501.705 - Consumer rights (opt-out of biometric and facial/voice recognition)(leg.state.fl.us).gov
- Fla. Stat. 501.711 - Privacy notices (biometric sale notice requirement)(leg.state.fl.us).gov
- Fla. Stat. 501.715 - Requirements for sensitive data (consent for sale)(leg.state.fl.us).gov
- Fla. Stat. 501.713 - Data protection assessments(leg.state.fl.us).gov
- Fla. Stat. 501.72 - Enforcement and implementation (AG-only, penalties, cure period)(leg.state.fl.us).gov
- Fla. Stat. 501.171 - Security of confidential personal information (breach notification)(leg.state.fl.us).gov
- SB 262 (2023) - Florida Digital Bill of Rights enrolled text(flsenate.gov).gov
- Florida AG Digital Bill of Rights Annual Enforcement Report (2025)(myfloridalegal.com).gov
- Florida AG enforcement action against Roku - Holland & Knight analysis(hklaw.com)