EnglishEspañol
Florida flag

Florida

FDBR Compliance Checklist: Florida Data Privacy

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 9 primary sources cited on this page. How we verify our legal content

FDBR Compliance Checklist: Florida Data Privacy

Frequently Asked Questions

Does my business have to comply with the Florida Digital Bill of Rights?

The core controller duties apply only if your business is for-profit, makes more than $1 billion in global gross annual revenues, and meets one of three prongs under 501.702(9): 50 percent or more revenue from online advertising, operating a consumer smart-speaker voice assistant, or operating an app store with at least 250,000 applications. Most businesses fail this test, but broader provisions like the children's protections in 501.1735 can still apply.

What is the FDBR $1 billion threshold?

Under 501.702(9), a covered controller must make in excess of $1 billion in global gross annual revenues, in addition to being for-profit and meeting one of three big-technology prongs. This revenue floor is the highest in the country for a comprehensive state privacy law and is why the FDBR's core obligations effectively target only the largest platforms.

What provisions apply to businesses under $1 billion in revenue?

Several. The children's online protections in 501.1735 apply, regardless of revenue, to an online platform (defined in 501.1735(1)(e) as a social media platform, online game, or online gaming platform) that provides a service, product, game, or feature likely to be predominantly accessed by children. The breach-notification statute 501.171 was amended to add biometric and geolocation data for businesses generally. And the sale-of-sensitive-data consent rule in 501.715 should be reviewed by any business monetizing sensitive data.

What does an FDBR privacy notice have to include?

Under 501.711, a covered controller's privacy notice must disclose the categories of personal data processed, the purposes of processing, how consumers exercise rights and appeal, the categories of data shared with third parties, and the categories of those third parties, and it must be updated at least annually. If the controller sells data or runs targeted advertising, it must clearly and conspicuously disclose that and how to opt out. A controller that sells sensitive or biometric data must also post the exact statutory notice sentence for each.

Do I need consent to collect voice or facial recognition data in Florida?

Yes for sensitive data generally. Under 501.71(2)(d), a controller must obtain opt-in consent before processing sensitive data, which includes biometric data. Separately, under 501.705(2)(g), consumers may opt out of the collection of personal data through a voice or facial recognition feature, and such features may not be used for surveillance when inactive without authorization.

How long does a controller have to honor an FDBR request?

Under 501.706(2), a controller must respond within 45 days of receiving an authenticated request, with one 15-day extension allowed when reasonably necessary. The controller must also offer two or more methods for submitting the request under 501.709(1). Information is free at least twice annually per consumer. A refusal must include the justification and instructions on how to appeal under 501.707, all within the 45-day window.

What are the penalties under the Florida Digital Bill of Rights?

Under 501.72, the Department of Legal Affairs may seek civil penalties of up to $50,000 per violation. Penalties may be tripled for violations involving a known child, a controller's failure to delete or correct after a request, or continued sale or sharing after an opt-out. The department may grant a discretionary 45-day cure period, and there is no private right of action under 501.72(8).

Is the FDBR cure period guaranteed?

No. Under 501.72, the 45-day cure period is discretionary, and 501.72(2) makes it unavailable altogether for a violation involving a known child. The Department of Legal Affairs may grant it and issue a letter of guidance for other violations, but it is not required to. A business should not assume it will get a chance to cure before penalties attach, and should build compliance proactively rather than relying on a cure window.

Updates

Corrected the consumer-request rule to the statutory minimum of two or more submission methods under 501.709(1), replaced the consent framing of Florida's children's geolocation rule with the strict-necessity, time-limit and visible-sign standards in 501.1735(2)(e) and (f), narrowed that section's scope to the platforms its 'online platform' definition actually covers, and separated the 501.702(9) controller test from the general applicability gate in 501.703(1)(a).

Added the omitted search-engine ranking-disclosure duty (501.71(4)), clarified that Florida's 45-day cure period does not apply to violations involving a known child, replaced an uncited enforcement claim with the actual Roku children's-data case (filed Oct. 2025, resolved June 2026) and the current Feb. 2026 AG enforcement report, and added the privacy notice's annual-update requirement and mandatory verbatim sale-notice sentences.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Corrected five citations that pinned the FDBR's opt-out rights (sale/advertising/profiling, sensitive data, voice/facial recognition) to Fla. Stat. 501.705(1) instead of the correct 501.705(2), where the statute's enumerated consumer rights actually appear.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Fla. Stat. 501.702: Definitions, including the Controller definition and $1 billion threshold(flsenate.gov).gov
  2. Fla. Stat. 501.703: Applicability(flsenate.gov).gov
  3. Fla. Stat. 501.705: Consumer rights and opt-outs(flsenate.gov).gov
  4. Fla. Stat. 501.706: Controller response to consumer requests(flsenate.gov).gov
  5. Fla. Stat. 501.71: Controller duties (sensitive data consent, nondiscrimination)(flsenate.gov).gov
  6. Fla. Stat. 501.711: Privacy notices(flsenate.gov).gov
  7. Fla. Stat. 501.712: Duties of processor(flsenate.gov).gov
  8. Fla. Stat. 501.715: Requirements for sensitive data(flsenate.gov).gov
  9. Fla. Stat. 501.72: Enforcement and implementation by the Department of Legal Affairs(flsenate.gov).gov
  10. Florida Department of Legal Affairs: Florida Digital Bill of Rights Annual Enforcement Report (Feb. 1, 2026, covering 2025)(myfloridalegal.com)
  11. Fla. Stat. 501.709: Submitting consumer requests (two or more methods; no new-account requirement; website mechanism)(leg.state.fl.us)
  12. Fla. Stat. 501.1735: Protection of children in online spaces (online platform definition; precise geolocation strict-necessity rule)(leg.state.fl.us)
Share: