US Privacy Law Florida, USA

Florida Digital Bill of Rights: Who It Actually Covers

Florida's FDBR explained: the $1 billion revenue threshold, big-tech targeting, $50,000 penalties tripled for minors' violations, and the broader provisions that hit everyone.

Regulation

Florida Digital Bill of Rights (SB 262, 2023), Fla. Stat. 501.701 et seq., effective July 1, 2024

Max Penalty

Up to $50,000 per violation, trebled for violations involving known minors, failure to delete, or ignoring opt-outs after cure

Enforcing Authority

Florida Attorney General (Department of Legal Affairs)

Official Source

www.myfloridalegal.com

Executive Summary

  • The FDBR (effective July 1, 2024) is not a general privacy law: its core obligations apply only to for-profit businesses with over $1 billion in global gross annual revenue that also derive 50%+ of revenue from online ad sales, operate a qualifying app store or smart-speaker/virtual-assistant service.
  • For those covered 'controllers,' the rights set resembles Virginia's plus extras: opt-outs of targeted advertising, sale, and profiling, consent for sensitive data, and unique rights to opt out of voice and facial recognition data collection.
  • Two provisions reach far beyond big tech: any business selling sensitive data must post a prescribed notice, and the law's children's provisions (protections for known minors under 18 in online platforms) plus a separate social-media minor-access law apply broadly.
  • Penalties are the steepest structural numbers in state privacy law: up to $50,000 per violation, trebled for minor-related violations, with a discretionary 45-day cure.
  • Practical takeaway: most companies' Florida obligations come from the sensitive-data notice, the minors' rules, and Florida's separate data-broker and security statutes, not the billion-dollar core.

Florida passed the loudest and narrowest of the 2023 privacy laws: headline penalties and a name evoking constitutional rights, attached to a threshold, a billion dollars plus an ad-revenue or platform test, that excludes essentially everyone but the largest technology companies. Its real footprint for ordinary businesses is the parts that skipped the threshold: verbatim sensitive-data notices, minors’ protections with penalty trebling, and Florida’s fast-fuse breach statute.

LawFDBR, Fla. Stat. 501.701 et seq.
EffectiveJuly 1, 2024
Core scope$1B+ revenue AND ad/app-store/voice-assistant test
Max penalty$50,000 per violation; trebled for minors’ violations
RegulatorFlorida AG
StatuteSB 262 (2023)

Sorting your actual Florida obligations

Run the threshold test once, document it. If you are under $1B or fail the second prong, the controller/processor chapters do not bind you, keep the analysis on file for diligence and renew it if revenue or business model changes.

Check the notice triggers anyway. Selling sensitive or biometric data (broad definition, ad-tech included) requires the prescribed notices regardless of size, the same trap as Texas’s verbatim strings. If your data-flow inventory shows sensitive categories reaching third parties for consideration, post it or stop the flow.

Treat minors’ data as the enforcement magnet. Between FDBR trebling, HB 3’s contested social-media rules, and the national children’s privacy wave, Florida risk concentrates on under-18 users. Age-signal handling and teen ad-targeting settings should follow the strictest-state spec.

Comply with FIPA like it is the real law, because it is. 30-day breach notification, reasonable security, vendor obligations, and AG penalties, this is where Florida enforcement actually lands on mid-market companies. Wire it into your incident-response plan alongside the state breach-notification matrix.

For how Florida’s outlier design compares with the general-application states, see the state comparison. And verify what your site sells, shares, and discloses, the factual predicate for every Florida notice question, with a free scan.

Frequently Asked Questions

Does the FDBR apply to our company?

The full controller obligations almost certainly do not, unless you gross over $1 billion globally AND make half your revenue from online advertising, run an app store with 250,000+ apps, or operate smart-speaker/voice-assistant services. The law was drafted to cover a handful of large technology platforms. But narrower provisions, the sensitive-data sale notice, minors' protections, and Florida's pre-existing security and breach statutes, apply regardless of size, so 'FDBR doesn't apply to us' is only half true.

What is the sensitive-data notice everyone must post?

Any for-profit entity doing business in Florida that sells sensitive personal data must display, prominently: 'NOTICE: This website may sell your sensitive personal data.' (with a parallel notice for biometric data sales). This mirrors the Texas verbatim-notice technique and applies without the billion-dollar threshold. Sale uses a monetary-or-other-consideration definition, so ad-tech data flows can trigger it.

What do covered controllers owe consumers?

Access, correction, deletion, portability; opt-outs of targeted advertising, sale, and profiling for legal-effect decisions; opt-in consent for sensitive data (including known-child data); and FDBR-unique opt-outs from the collection of voice or facial recognition data and from collection via voice-activated features. Responses within 45 days, with authentication, and no discrimination for exercising rights.

How do the minors' provisions work?

The FDBR treats known under-18 data with heightened protection for covered platforms, and its companion social-media law (HB 3, 2024, litigated since) restricts accounts for young teens. Separately, penalty trebling attaches to any violation involving a known minor, so children's-data missteps by covered controllers carry up-to-$150,000-per-violation exposure. Teen-facing platforms should treat Florida as a children's privacy jurisdiction first and a general one second.

What Florida laws matter for non-billion-dollar companies?

The Florida Information Protection Act (FIPA, Fla. Stat. 501.171): breach notification within 30 days, among the fastest in the country, and reasonable security duties, enforced by the AG with penalties up to $500,000 per breach; the sensitive-data sale notices above; and Florida's active AG consumer-protection practice. FIPA is the statute mid-market companies actually get penalized under in Florida.

Regulatory Crosswalk

Virginia VCDPACCPAState children's privacy laws

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.