Florida
FDBR Compliance Checklist: Florida Data Privacy
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 9 primary sources cited on this page. How we verify our legal content

Florida Digital Bill of Rights (FDBR) compliance starts with one question most businesses can answer quickly: are you a "controller" under Fla. Stat. 501.702(9)? The core controller duties apply only to a for-profit business that makes more than $1 billion in global gross annual revenues and meets one of three big-technology prongs, so most companies are outside the central obligations. But several broader provisions reach ordinary businesses, so no Florida company should assume it has zero FDBR exposure.
As of 2026, a covered controller must publish a clear privacy notice, honor consumer rights within 45 days, obtain opt-in consent before processing sensitive data, support the sale, targeted-advertising, profiling, sensitive-data, and voice and facial recognition opt-outs, and contract properly with processors. The Florida Department of Legal Affairs enforces the FDBR with a discretionary 45-day cure period and civil penalties up to $50,000 per violation, triplable in defined cases. There is no private right of action.
Jurisdiction scope: This covers Florida's Florida Digital Bill of Rights (Fla. Stat. 501.701 et seq.). It is general legal information, not legal advice.
Step 1: Run the applicability analysis
The first step is the most decisive. The FDBR's core controller obligations apply only to a person that qualifies as a "controller" under 501.702(9). That definition requires the business to be organized for profit, to conduct business in this state, to collect personal data and determine the purposes and means of processing, to make in excess of $1 billion in global gross annual revenues, and to satisfy one of three prongs. Keep that test separate from the general applicability gate for the whole part: 501.703(1)(a) reaches a person who "conducts business in this state or produces a product or service used by residents of this state." A controller must clear both, but the controller definition itself uses only the narrower "conducts business in this state" language.
The three prongs in 501.702(9)(a)6. are: deriving 50 percent or more of global gross annual revenues from the sale of online advertisements; operating a consumer smart speaker and voice command service with an integrated virtual assistant connected to a cloud computing service; or operating an app store or digital distribution platform offering at least 250,000 different software applications.
A business that does not clear the $1 billion revenue line, or that exceeds it but fits none of the three prongs, is not a controller. Document this analysis in writing. The conclusion that you are not a controller is itself a compliance artifact worth keeping, because it explains why the core duties below do not apply to you.
Step 2: Check the broader provisions any business must heed
Concluding that you are not a controller does not end the inquiry. SB 262 created several provisions that reach businesses well beyond the $1 billion threshold, and these are where ordinary Florida companies most often have FDBR exposure.
The children's online protections in 501.1735 apply to an online platform that provides an online service, product, game, or feature likely to be predominantly accessed by children, regardless of revenue. "Online platform" is a defined term, and it is narrower than it sounds: 501.1735(1)(e) limits it to a social media platform as defined in s. 112.23(1), an online game, or an online gaming platform, so an ordinary e-commerce or content site falls outside it. Note also that 501.1735(1)(a) defines a "child" as a consumer under 18, a different trigger from the FDBR's "known child."
Within that scope, the section restricts processing a child's personal information in ways that may result in substantial harm or privacy risk, prohibits certain dark patterns, and imposes a strict-necessity rule rather than a consent rule on location data. Under 501.1735(2)(e), an online platform may not collect, sell, or share a child's precise geolocation data unless the collection is strictly necessary to provide the requested service, product, or feature, and then only for the limited time that it is necessary. Under 501.1735(2)(f), it may not collect that data without providing an obvious sign to the child for the duration of the collection. There is no consent exception, so the compliance controls here are necessity, time limits, and a visible signal, not a consent box. A social media, gaming, or online-gaming business with a youthful audience should review the section closely.
The breach-notification statute 501.171 was amended to add biometric data (as defined in 501.702) and geolocation information to the categories of personal information that trigger breach-notification duties. That broadens incident-response obligations for businesses generally. Finally, the sale-of-sensitive-data consent rule in 501.715 should be reviewed by any business that monetizes sensitive data. Map your exposure to each before assuming the FDBR does not touch you.

Step 3: Privacy notice
A covered controller must provide consumers a reasonably accessible and clear privacy notice under 501.711, updated at least annually. The notice must describe the categories of personal data the controller processes, the purposes for processing, how consumers may exercise their rights and appeal a decision, the categories of personal data the controller shares with third parties, and the categories of those third parties.
If the controller sells personal data to third parties or processes personal data for targeted advertising, the notice must clearly and conspicuously disclose that and explain how a consumer may exercise the right to opt out. The disclosure should be specific enough that a consumer can act on it, not buried in general terms of use.
If the controller sells sensitive data, 501.711(2) requires the notice to include the exact sentence "NOTICE: This website may sell your sensitive personal data." If it sells biometric data, 501.711(3) requires the exact sentence "NOTICE: This website may sell your biometric personal data." These statutory sentences must appear verbatim, not paraphrased.
Because "consent" under 501.702 excludes acceptance of general terms and the use of dark patterns, a privacy program should keep notice and consent distinct. A notice informs; consent is a separate, affirmative act. Treating a single terms-of-use acceptance as both is a common compliance gap.
Step 4: Opt-in for sensitive data, opt-outs including voice and facial recognition
A covered controller must obtain opt-in consent before processing sensitive data. Under 501.71(2)(d), a controller may not process a consumer's sensitive data without consent, and for a known child must obtain authorization from a child between 13 and 18 or comply with COPPA for a child under 13. Sensitive data under 501.702 includes health, religious, racial or ethnic, sexual orientation, immigration, genetic, biometric, known-child, and precise geolocation data.
If your business operates a search engine, 501.71(4) imposes a separate duty: publish a plain-language description of the main parameters that determine ranking, including whether political partisanship or ideology is prioritized or deprioritized, in a location that does not require a consumer to log in or register. Algorithms themselves do not need to be disclosed.
On the opt-out side, a controller must build and honor several mechanisms. Under 501.705(2)(e), consumers can opt out of the sale of personal data, targeted advertising, and profiling. Under 501.705(2)(f), consumers can opt out of the collection of sensitive data, including precise geolocation. Under 501.705(2)(g), consumers can opt out of the collection of personal data through a voice recognition or facial recognition feature.
The voice and facial recognition opt-out is the one businesses most often overlook, because it sits at the collection stage rather than the use or sale stage. A controller operating devices or features that collect voiceprints or facial geometry must give consumers a way to turn that collection off, and must not use those features for surveillance when they are not actively in use without authorization. The opt-out and opt-in mechanics are explained for consumers in the FDBR consumer rights guide.

Step 5: Consumer-request handling and processor contracts
A controller must operationalize the consumer-request lifecycle. Under 501.709(1), it must establish two or more methods for consumers to submit a request to exercise their rights under the part; a single request channel does not satisfy that express minimum. Under 501.709(2) it may not require a consumer to create a new account to exercise those rights, though it may require use of an existing account, and under 501.709(3) it must provide a mechanism on its website for a consumer to submit a request for information the part requires to be disclosed. Under 501.706(2), it must respond within 45 days, with one 15-day extension allowed when reasonably necessary. Information must be free at least twice annually per consumer, and a refusal must come with a justification and appeal instructions under 501.707.
A controller must also bind its processors. Under 501.712, a processor must adhere to the controller's instructions and assist the controller in meeting its FDBR obligations, and the relationship must be governed by a contract that sets out processing instructions, the nature and purpose of processing, the type of data, the duration, and the rights and obligations of both parties. The contract should require the processor to ensure a duty of confidentiality, delete or return data at the end of the engagement, and make available information needed to demonstrate compliance.
These contracts are a frequent enforcement focus because they allocate responsibility across the data-handling chain. A controller that relies on vendors for ad targeting, voice processing, or analytics should confirm each vendor relationship is papered to the 501.712 standard.
Step 6: Enforcement, cure period, and penalties
The Florida Department of Legal Affairs, within the Attorney General's office, has exclusive enforcement authority under 501.72. A violation of the FDBR is treated as an unfair and deceptive trade practice actionable solely by the department. Under 501.72(8), the part does not establish a private cause of action, so there is no consumer lawsuit risk under the FDBR itself.
The department may, at its discretion, grant a 45-day period to cure an alleged violation and issue a letter of guidance. Because the cure period is discretionary rather than guaranteed, a business should not count on it. The cure period is also unavailable by law for a violation involving a known child under 501.72(1)(a): 501.72(2) expressly excludes that category from the cure option, so the department can proceed straight to enforcement. Civil penalties run up to $50,000 per violation, and the department may seek injunctive relief and other remedies available under the consumer-protection chapter.
Penalties may be tripled in three defined situations under 501.72: a violation involving a Florida consumer who is a known child; a controller's failure to delete or correct a consumer's personal data after receiving an authenticated request; and a controller's continued sale or sharing of a consumer's personal data after the consumer has opted out. The penalty matrix below summarizes the enforcement structure.
| Item | FDBR provision | Detail |
|---|---|---|
| Enforcer | 501.72(1) | Department of Legal Affairs only; unfair and deceptive practice |
| Cure period | 501.72(2) | Discretionary 45-day cure plus letter of guidance; unavailable for known-child violations |
| Base penalty | 501.72(1) | Up to $50,000 per violation |
| Tripled penalty | 501.72(1)(a)-(c) | Known child; failure to delete or correct; continued sale after opt-out |
| Private action | 501.72(8) | None |
The department's enforcement posture is real. Its February 2026 annual enforcement report covers January through December 2025 and shows 1,496 complaints or inquiries, 186 Notices of Alleged Violation, 64 resolved without litigation, and one active case, with no penalties yet issued or collected. That case grew out of the department's October 2025 suit against Roku alleging the company collected and sold children's viewing, voice, and geolocation data without proper parental consent or notice; Roku resolved the matter in June 2026 by committing an estimated $25 million to new parental-control and child-privacy engineering, without admitting wrongdoing or paying a civil penalty. For the law's identity, history, and the $1 billion threshold in context, see what is the FDBR.
Related guides
- Florida data privacy laws parent hub
- What is the FDBR?
- FDBR consumer rights
- State data privacy law comparison
- What is the CCPA?
More Florida Laws
Frequently Asked Questions
Does my business have to comply with the Florida Digital Bill of Rights?
The core controller duties apply only if your business is for-profit, makes more than $1 billion in global gross annual revenues, and meets one of three prongs under 501.702(9): 50 percent or more revenue from online advertising, operating a consumer smart-speaker voice assistant, or operating an app store with at least 250,000 applications. Most businesses fail this test, but broader provisions like the children's protections in 501.1735 can still apply.
What is the FDBR $1 billion threshold?
Under 501.702(9), a covered controller must make in excess of $1 billion in global gross annual revenues, in addition to being for-profit and meeting one of three big-technology prongs. This revenue floor is the highest in the country for a comprehensive state privacy law and is why the FDBR's core obligations effectively target only the largest platforms.
What provisions apply to businesses under $1 billion in revenue?
Several. The children's online protections in 501.1735 apply, regardless of revenue, to an online platform (defined in 501.1735(1)(e) as a social media platform, online game, or online gaming platform) that provides a service, product, game, or feature likely to be predominantly accessed by children. The breach-notification statute 501.171 was amended to add biometric and geolocation data for businesses generally. And the sale-of-sensitive-data consent rule in 501.715 should be reviewed by any business monetizing sensitive data.
What does an FDBR privacy notice have to include?
Under 501.711, a covered controller's privacy notice must disclose the categories of personal data processed, the purposes of processing, how consumers exercise rights and appeal, the categories of data shared with third parties, and the categories of those third parties, and it must be updated at least annually. If the controller sells data or runs targeted advertising, it must clearly and conspicuously disclose that and how to opt out. A controller that sells sensitive or biometric data must also post the exact statutory notice sentence for each.
Do I need consent to collect voice or facial recognition data in Florida?
Yes for sensitive data generally. Under 501.71(2)(d), a controller must obtain opt-in consent before processing sensitive data, which includes biometric data. Separately, under 501.705(2)(g), consumers may opt out of the collection of personal data through a voice or facial recognition feature, and such features may not be used for surveillance when inactive without authorization.
How long does a controller have to honor an FDBR request?
Under 501.706(2), a controller must respond within 45 days of receiving an authenticated request, with one 15-day extension allowed when reasonably necessary. The controller must also offer two or more methods for submitting the request under 501.709(1). Information is free at least twice annually per consumer. A refusal must include the justification and instructions on how to appeal under 501.707, all within the 45-day window.
What are the penalties under the Florida Digital Bill of Rights?
Under 501.72, the Department of Legal Affairs may seek civil penalties of up to $50,000 per violation. Penalties may be tripled for violations involving a known child, a controller's failure to delete or correct after a request, or continued sale or sharing after an opt-out. The department may grant a discretionary 45-day cure period, and there is no private right of action under 501.72(8).
Is the FDBR cure period guaranteed?
No. Under 501.72, the 45-day cure period is discretionary, and 501.72(2) makes it unavailable altogether for a violation involving a known child. The Department of Legal Affairs may grant it and issue a letter of guidance for other violations, but it is not required to. A business should not assume it will get a chance to cure before penalties attach, and should build compliance proactively rather than relying on a cure window.
Updates
Corrected the consumer-request rule to the statutory minimum of two or more submission methods under 501.709(1), replaced the consent framing of Florida's children's geolocation rule with the strict-necessity, time-limit and visible-sign standards in 501.1735(2)(e) and (f), narrowed that section's scope to the platforms its 'online platform' definition actually covers, and separated the 501.702(9) controller test from the general applicability gate in 501.703(1)(a).
Added the omitted search-engine ranking-disclosure duty (501.71(4)), clarified that Florida's 45-day cure period does not apply to violations involving a known child, replaced an uncited enforcement claim with the actual Roku children's-data case (filed Oct. 2025, resolved June 2026) and the current Feb. 2026 AG enforcement report, and added the privacy notice's annual-update requirement and mandatory verbatim sale-notice sentences.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected five citations that pinned the FDBR's opt-out rights (sale/advertising/profiling, sensitive data, voice/facial recognition) to Fla. Stat. 501.705(1) instead of the correct 501.705(2), where the statute's enumerated consumer rights actually appear.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Florida Statutes
§ 501.71Controller duties.In forcecited in 2 of our articles
(1) A controller shall:(a) Limit the collection of personal data to data that is adequate, relevant, and reasonably necessary in relation to the purposes for which it is processed, as disclosed to the consumer; and (b) For purposes of protecting the confidentiality, integrity, and accessibility of personal data, establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal data at issue. (2) A controller may not do any of the following:(a) Except as otherwise provided by this part, process personal data for a purpose that is neither reasonably necessary nor compatible with the purpose for which the personal data is processed, as disclosed to the consumer, unless the controller obtains the consumer’s consent. (b) Process personal data in violation of state or federal laws that prohibit unlawful discrimination against consumers.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at leg.state.fl.us
Also relied on in: FDBR Consumer Rights: Florida Data Privacy Rights
§ 501.705Consumer rights.In forcecited in 5 of our articles
(1) A consumer is entitled to exercise the consumer rights authorized by this section at any time by submitting a request to a controller which specifies the consumer rights that the consumer wishes to exercise. With respect to the processing of personal data belonging to a known child, a parent or legal guardian of the child may exercise these rights on behalf of the child. (2) A controller shall comply with an authenticated consumer request to exercise any of the following rights:(a) To confirm whether a controller is processing the consumer’s personal data and to access the personal data. (b) To correct inaccuracies in the consumer’s personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer’s personal data. (c) To delete any or all personal data provided by or obtained about the consumer. (d) To obtain a copy of the consumer’s personal data in a portable and, to the extent technically feasible, readily usable format if the data is available in a digital format. (e) To opt out of the processing of the personal data for purposes of:1. Targeted advertising; 2. The sale of personal data; or 3.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at leg.state.fl.us
Also relied on in: Florida Data Privacy Laws: Digital Bill of Rights & Breach Rules (2026), Florida Biometric Privacy Laws: Collection, Consent & Penalties (2026), What Is the FDBR? Florida Digital Bill of Rights
§ 501.711Privacy notices.In forcecited in 2 of our articles
(1) A controller shall provide consumers with a reasonably accessible and clear privacy notice, updated at least annually, that includes all of the following information:(a) The categories of personal data processed by the controller, including, if applicable, any sensitive data processed by the controller. (b) The purpose of processing personal data. (c) How consumers may exercise their rights under s. 501.705(2), including the process by which a consumer may appeal a controller’s decision with regard to the consumer’s request. (d) If applicable, the categories of personal data that the controller shares with third parties. (e) If applicable, the categories of third parties with whom the controller shares personal data. (f) A description of the methods specified in s. 501.709 by which consumers can submit requests to exercise their consumer rights under this part. (2) If a controller engages in the sale of personal data that is sensitive data, the controller must provide the following notice: “NOTICE: This website may sell your sensitive personal data.” The notice must be posted in accordance with subsection (1).
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leg.state.fl.us
§ 501.706Controller response to consumer requests.In forcecited in 2 of our articles
(1) Except as otherwise provided by this part, a controller shall comply with a request submitted by a consumer to exercise the consumer’s rights pursuant to s. 501.705, as provided in this section. (2) A controller shall respond to the consumer request without undue delay, which may not be later than 45 days after the date of receipt of the request. The controller may extend the response period once by an additional 15 days when reasonably necessary, taking into account the complexity and number of the consumer’s requests, so long as the controller informs the consumer of the extension within the initial 45-day response period, together with the reason for the extension. (3) If a controller cannot take action regarding the consumer’s request, the controller must inform the consumer without undue delay, which may not be later than 45 days after the date of receipt of the request, of the justification for the inability to take action on the request and provide instructions on how to appeal the decision in accordance with s. 501.707. A controller is not required to comply with a consumer request submitted under s. 501.705 if the controller cannot authenticate the request.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leg.state.fl.us
§ 501.712Duties of processor.In force
(1) A processor shall adhere to the instructions of a controller and shall assist the controller in meeting or complying with the controller’s duties under this section and the requirements of this part, including the following:(a) Assisting the controller in responding to consumer rights requests submitted pursuant to ss. 501.705 and 501.709, by using appropriate technical and organizational measures, as reasonably practicable, taking into account the nature of processing and the information available to the processor. (b) Assisting the controller with regard to complying with the requirement relating to the security of processing personal data and to the notification of a breach of security of the processor’s system under s. 501.171, taking into account the nature of processing and the information available to the processor. (c) Providing necessary information to enable the controller to conduct and document data protection assessments under s. 501.713. (2) A contract between a controller and a processor governs the processor’s data processing procedures with respect to processing performed on behalf of the controller.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leg.state.fl.us
§ 501.715Requirements for sensitive data.In forcecited in 4 of our articles
(1) A person who meets the requirements of s. 501.702(9)(a)1.-3. for the definition of a controller may not engage in the sale of personal data that is sensitive data without receiving prior consent from the consumer or, if the sensitive data is of a known child, without processing that data with the affirmative authorization for such processing by a known child who is between 13 and 18 years of age or in accordance with the Children’s Online Privacy Protection Act, 15 U.S.C. ss. 6501 et seq. for a known child under the age of 13. (2) A person in subsection (1) who engages in the sale of personal data that is sensitive data must provide the following notice: “NOTICE: This website may sell your sensitive personal data.” (3) A person who violates this section is subject to the penalty imposed under s. 501.72.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leg.state.fl.us
§ 501.72Enforcement and implementation by the Department of Legal Affairs.In forcecited in 5 of our articles
(1) A violation of this part is an unfair and deceptive trade practice actionable under part II of this chapter solely by the Department of Legal Affairs. If the department has reason to believe that a person is in violation of this section, the department may, as the enforcing authority, bring an action against such person for an unfair or deceptive act or practice. For the purpose of bringing an action pursuant to this section, ss. 501.211 and 501.212 do not apply. In addition to other remedies under part II of this chapter, the department may collect a civil penalty of up to $50,000 per violation. Civil penalties may be tripled for any of the following violations:(a) A violation involving a Florida consumer who is a known child. A controller that willfully disregards the consumer’s age is deemed to have actual knowledge of the consumer’s age. (b) Failure to delete or correct the consumer’s personal data pursuant to this section after receiving an authenticated consumer request or directions from a controller to delete or correct such personal data, unless an exception to the requirements to delete or correct such personal data under this section applies.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leg.state.fl.us
§ 501.703Applicability.In forcecited in 2 of our articles
(1) This part applies only to a person who:(a) Conducts business in this state or produces a product or service used by residents of this state; and (b) Processes or engages in the sale of personal data. (2) This part does not apply to any of the following:(a) A state agency or a political subdivision of the state. (b) A financial institution or data subject to Title V, Gramm-Leach-Bliley Act, 15 U.S.C. ss. 6801 et seq. (c) A covered entity or business associate governed by the privacy, security, and breach notification regulations issued by the United States Department of Health and Human Services, 45 C.F.R. parts 160 and 164, established under the Health Insurance Portability and Accountability Act of 1996, 42 U.S.C. ss. 1320d et seq., and the Health Information Technology for Economic and Clinical Health Act, Division A, Title XIII and Division B, Title IV, Pub. L. No. 111-5. (d) A nonprofit organization. (e) A postsecondary education institution. (f) The processing of personal data:1. By a person in the course of a purely personal or household activity. 2. Solely for measuring or reporting advertising performance, reach, or frequency.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leg.state.fl.us
§ 501.702Definitions.In forcecited in 4 of our articles
As used in this part, the term:(1) “Affiliate” means a legal entity that controls, is controlled by, or is under common control with another legal entity or that shares common branding with another legal entity. For purposes of this subsection, the term “control” or “controlled” means any of the following:(a) The ownership of, or power to vote, more than 50 percent of the outstanding shares of any class of voting security of a company. (b) The control in any manner over the election of a majority of the directors or of individuals exercising similar functions. (c) The power to exercise controlling influence over the management of a company. (2) “Aggregate consumer information” means information that relates to a group or category of consumers from which the identity of an individual consumer has been removed and is not reasonably capable of being directly or indirectly associated or linked with any consumer, household, or device. The term does not include information about a group or category of consumers used to facilitate targeted advertising or the display of ads online. The term does not include personal information that has been deidentified.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leg.state.fl.us
§ 501.701Short title.In forcecited in 6 of our articles
This part may be cited as the “Florida Digital Bill of Rights.”
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leg.state.fl.us
Also relied on in: Florida Employee Monitoring Laws: Employer Rules (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Fla. Stat. 501.702: Definitions, including the Controller definition and $1 billion threshold(flsenate.gov).gov
- Fla. Stat. 501.703: Applicability(flsenate.gov).gov
- Fla. Stat. 501.705: Consumer rights and opt-outs(flsenate.gov).gov
- Fla. Stat. 501.706: Controller response to consumer requests(flsenate.gov).gov
- Fla. Stat. 501.71: Controller duties (sensitive data consent, nondiscrimination)(flsenate.gov).gov
- Fla. Stat. 501.711: Privacy notices(flsenate.gov).gov
- Fla. Stat. 501.712: Duties of processor(flsenate.gov).gov
- Fla. Stat. 501.715: Requirements for sensitive data(flsenate.gov).gov
- Fla. Stat. 501.72: Enforcement and implementation by the Department of Legal Affairs(flsenate.gov).gov
- Florida Department of Legal Affairs: Florida Digital Bill of Rights Annual Enforcement Report (Feb. 1, 2026, covering 2025)(myfloridalegal.com)
- Fla. Stat. 501.709: Submitting consumer requests (two or more methods; no new-account requirement; website mechanism)(leg.state.fl.us)
- Fla. Stat. 501.1735: Protection of children in online spaces (online platform definition; precise geolocation strict-necessity rule)(leg.state.fl.us)