AI Services

Florida Digital Bill of Rights

Which Businesses Should Be Worried? — Fla. Stat. § 501.701 et seq.

The Florida Digital Bill of Rights (FDBR) was built to regulate Big Tech, not the typical Florida business — but its consent requirement reaches further than its headline thresholds suggest, and two years of Attorney General enforcement data now show exactly how the law is actually being used.

Our Miami team advises both impacted businesses that meet the FDBR’s controller thresholds and the much broader group of Florida businesses that should still be thinking about its consent standard.

FDBR Layout: Which Businesses Should Be Worried?

A regulatory framework aimed at a very specific slice of the economy

The Florida Digital Bill of Rights creates a regulatory framework that targets a select group of companies doing business in Florida. Under the act, Florida consumers have a right to opt out of solely automated profiling and a right to access their personal data. As a result, covered companies are required to obtain consumer consent before processing that data.

However, only for-profit controllers are subject to the act’s core obligations. To be a controller, a company must:

The FDBR “Controller” Test

  • Conduct business in Florida, or produce products or services targeted to Florida residents;
  • Determine the purpose and means of processing personal data;
  • Generate more than $1 billion in annual global revenue; AND
  • Derive at least 50% of revenue from online ad sales, OR operate an app store with at least 250,000 apps available for download, OR operate a consumer smart speaker or voice-command service with an integrated virtual assistant connected to cloud computing.

Nonprofits, HIPAA-covered entities, GLBA-covered financial institutions, and postsecondary educational institutions are explicitly exempt, along with roughly 21 categories of information, including health records, consumer reports, and emergency contact data. Because of these demanding thresholds, the FDBR functions almost entirely as a Big Tech statute, covering only platforms that resemble the revenue and business model of companies like Meta, Google, and Amazon — the same companies now driving much of the AI industry. Most Florida businesses, including mid-size and even large regional companies, fall outside the FDBR entirely.

Legislative History

From a technology-transparency bill to an active enforcement program

Date Event
Mar. 2023 Senate Bill 262 (“technology transparency”) is introduced in the Florida Senate
May 4, 2023 The Florida Senate and House both pass SB 262
Jun. 6, 2023 Governor DeSantis signs SB 262 into law as Chapter 2023-201, Laws of Florida, creating the Florida Digital Bill of Rights (Fla. Stat. §§ 501.701–.721) alongside related social-media and children’s-online-safety provisions
Jul. 1, 2023 The ban on government-directed social media content moderation and the children’s-online-safety provisions take effect; data protection assessment obligations begin applying to processing activity from this date forward
Jul. 1, 2024 The FDBR’s core consumer-privacy provisions — the controller/processor duties and consumer rights discussed below — take effect, after a one-year compliance runway
2024 Session The Florida Legislature enacts the related but separate Fla. Stat. § 501.1736 (HB 3), restricting social media platform design features aimed at minors
Feb. 1, 2025 The Florida Attorney General publishes the first FDBR Annual Enforcement Report, covering the law’s initial six months in effect and reporting approximately 800 consumer complaints
Oct. 2025 The Attorney General files the FDBR’s first reported enforcement action, against Roku, Inc., alleging unauthorized collection and sale of children’s sensitive data
Nov. 25, 2025 The Eleventh Circuit lifts a lower-court injunction against § 501.1736 in NetChoice v. Uthmeier, finding Florida made a strong initial showing the law is content-neutral
Feb. 1, 2026 The Attorney General publishes the second Annual Enforcement Report, covering all of 2025: 1,496 consumer complaints, 186 Notices of Alleged Violation, 1 active piece of litigation, and $0 in penalties collected to date

The federal TAKE IT DOWN Act, signed May 19, 2025 with Florida Rep. Maria Salazar as a primary House sponsor, runs on a parallel track addressing AI-generated intimate imagery — see our Brooke’s Law page for how that federal law interacts with Florida’s own state-level deepfake statute.

Consumer Rights Under the FDBR

What a Florida consumer can actually demand from a covered controller

The FDBR allows a Florida consumer to submit a request to a controller specifying the rights they seek to exercise. Among these, a consumer is entitled to:

  • Confirm whether a controller is processing their personal data, and access that data;
  • Correct inaccuracies within their personal data;
  • Delete any or all personal data provided by or obtained about them;
  • Obtain a copy of their personal data in a portable, readily usable format, to the extent technically feasible, if it exists in digital form;
  • Opt out of processing for purposes of sale, targeted advertising, or profiling;
  • Opt out of the collection or processing of sensitive data, including precise geolocation; and
  • Opt out of personal data collected through a voice recognition or facial recognition feature.

The act separately prohibits using a device’s voice recognition, facial recognition, or other data-collecting feature for surveillance purposes when the consumer has not affirmatively activated those features.

Controllers must respond to authenticated consumer requests within 45 days (extendable), and must provide an internal appeal mechanism if a request is denied. As a matter of public policy, these rights are non-waivable — a business cannot use its terms of service to contract around them.

Controller & Processor Duties

Consent, minimization, and two mandatory sale disclosures

The act imposes duties on controllers in how they collect and disseminate personal data, which includes any information linked or reasonably linkable to a consumer — potentially including racial or ethnic origin, religious beliefs, immigration status, biometric data, and geolocation data, among others.

To protect the confidentiality of this data, controllers must develop and maintain a reasonable administrative system proportionate to the volume and nature of the data they handle. They must limit collection to what is reasonable and relevant for disclosed processing purposes, and may not process the data without consent, nor discriminate against a consumer for exercising any FDBR right. Consent itself must be a clear, unambiguous affirmative act — it cannot be inferred from hovering over or pausing content, and it cannot be buried inside broad, general terms of use.

Privacy notices must be clear and reasonably accessible, describing the purpose and categories of personal data processed and shared with third parties, and how consumers may exercise their rights. A business selling this data must post two distinct notices, in the statute’s prescribed language: one disclosing that sensitive data may be sold, and a separate one disclosing that biometric data may be sold.

Processors, as the name suggests, process personal data on behalf of a controller. Their main duties are to help controllers meet their FDBR obligations and to execute data-processing contracts that meet the statute’s requirements, including detailed terms describing how the data will be processed.

While these duties bind only a narrow slice of large businesses, companies that fall outside the FDBR’s revenue thresholds should still consider voluntary compliance with at least the consent standard — that specific obligation applies more broadly to any for-profit entity conducting business in Florida that processes this type of data, not just the largest players, reaching a considerably wider swath of businesses than the rest of the statute.

Enforcement: Regulatory Risk, Not Litigation Risk

No private plaintiff — only the Attorney General

While the act aims to strengthen consumer protection, it does not create a private cause of action. It functions instead as a regulatory tool enforced exclusively by the Florida Department of Legal Affairs. A Florida consumer whose FDBR rights are violated cannot sue the controller directly under the statute — the consumer’s only avenue is to file a complaint with the Department, which then decides, in its own discretion, whether to investigate and bring an action.

The Department has discretion to give a controller 45 days to cure a violation before initiating action, though that cure period is unavailable for violations involving a child. Once the Department does act, it may collect a civil penalty of up to $50,000 per violation, and penalties may be tripled where the violation involves a Florida consumer who is a child, where a controller fails to honor a deletion or correction request, or for continuing to sell or share personal data after a consumer has opted out.

In all, FDBR exposure is entirely regulatory. Florida’s deliberate choice to steer away from a private litigation model distinguishes its approach as considerably more business-friendly than jurisdictions like Illinois, where a private right of action has driven enormous class-action exposure under the Biometric Information Privacy Act (BIPA).

FDBR’s Impact on Florida: The Data

What the Attorney General’s own enforcement reports show

The FDBR requires the Attorney General to publish an annual enforcement report, and two years of real data are now on the record. In the law’s first six months in effect, the Department received nearly 800 consumer complaints. The second full-year report, covering all of calendar year 2025, shows the program has grown substantially:

1,496

Consumer complaints/inquiries received by the Florida AG in 2025.

186

Notices of Alleged Violation issued to controllers in 2025.

$0

Civil penalties actually collected by the Department in 2025.

Of the 1,496 complaints received in 2025, 685 were closed as outside the FDBR’s scope and 811 were placed under active review. The categories consumers most frequently invoked break down as follows (some complaints alleged more than one category):

Right Exercised Complaints Alleging It (Jan–Dec 2025)
Confirm processing & access personal data 730
Delete personal data 97
Correct inaccuracies 74
Obtain a portable copy of personal data 60
Opt out of processing (sale/targeted ads/profiling) 53
Opt out of sensitive data collection/processing 35
Opt out of voice/facial recognition data collection 15

On the enforcement side, the Department made 60 initial inquiries to determine whether a business even qualifies as a covered controller, issued 186 Notices of Alleged Violation, resolved 64 of those without litigation, and had 1 matter in active litigation as of the reporting date — with no civil penalties yet collected. The takeaway for Florida businesses: real regulatory activity is underway, complaint volume is climbing, and requests to access and delete personal data dominate what consumers are actually asking for — but enforcement so far has emphasized negotiated resolution over collected penalties, at least in the program’s first eighteen months.

FDBR vs. FIPA: Two Different Florida Privacy Statutes

The law that covers Big Tech, and the law that covers almost everyone else

It is crucial to distinguish the FDBR from the Florida Information Protection Act (FIPA), a data-breach-notification law enacted in 2014 that applies broadly to essentially any entity that processes personal data, regardless of size. In practice, FIPA is the statute that actually reaches most Florida businesses, since the FDBR’s thresholds really only capture Big Tech.

FDBR FIPA
Citation Fla. Stat. § 501.701 et seq. Fla. Stat. § 501.171
Enacted 2023 (SB 262) 2014 (SB 1524)
Who is covered Only “controllers” meeting the $1B+ global revenue threshold and an ad-revenue, app-store, or smart-speaker test Virtually any entity handling a Florida resident’s personal data, regardless of size
Core focus Ongoing consumer rights: access, correction, deletion, portability, and opt-outs Data security safeguards and breach notification
What triggers an obligation Routine data processing activity Occurrence of a data security breach
Enforcement Florida Department of Legal Affairs, as an unfair or deceptive trade practice Florida Department of Legal Affairs, as an unfair or deceptive trade practice
Civil penalty Up to $50,000 per violation (treble in certain circumstances) Up to $500,000 for continued violations
Private right of action None None
Practical reach in Florida A narrow slice of Big Tech Nearly every Florida business that processes personal data

Practical Takeaways

What most Florida businesses actually need to do

  • Businesses that make less than $1 billion in global revenue will not be affected by most of the FDBR’s duties and obligations.
  • Regardless of size, businesses should independently confirm compliance with the FDBR’s consent requirement if they process personal data, since that piece is not limited to the $1 billion threshold.
  • There is no private lawsuit exposure under the FDBR or FIPA. The real, and growing, risk under the FDBR is regulatory — as the Attorney General’s own 2025 numbers now confirm.

Full Capability

Our Florida Digital Bill of Rights Services Include

Controller-status threshold analysis
Privacy notice & consent-flow compliance review
Data processing agreements (controller/processor)
Sensitive & biometric data sale disclosures
Attorney General Notice of Alleged Violation response
FDBR vs. FIPA applicability analysis
Data protection assessments
Children’s online privacy compliance (§ 501.1736)
Cross-statute coordination with Brooke’s Law/FDUTPA
Voluntary compliance counseling for non-covered businesses

Get In Touch

rthornburg@allendyer.com