Law / United States / Alabama
Data Breach Notification Act, reasonable security measures and disposal of records
Ala. Code secs. 8-38-3, 8-38-10
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 1 June 2018.
A security baseline statutes rule binding public and private bodies.
As of 15 September 2026.
What it requires
- This binds any covered entity (a person, sole proprietorship, partnership, government entity, corporation, nonprofit, trust, estate, cooperative association, or other business entity that acquires or uses sensitive personally identifying information of an Alabama resident) and any third-party agent it contracts with to maintain, store, process, or access that information. An entity already subject to and complying with a federal or state data-breach-notification regime at least as thorough as this chapter is exempt from the entire chapter.
- Implement and maintain reasonable security measures to protect sensitive personally identifying information against a breach of security: designate an employee or employees to coordinate the effort, identify internal and external risks, adopt and assess information safeguards, contractually require any service providers to maintain appropriate safeguards, adjust the measures for changed circumstances, and keep management, including the board of directors where one exists, informed of the overall status of the measures.
- Take reasonable measures to dispose, or arrange for the disposal, of records containing sensitive personally identifying information within its custody or control once the records are no longer to be retained, by shredding, erasing, or otherwise modifying the information to make it unreadable or undecipherable through any reasonable means consistent with industry standards.
- There is no private right of action for a violation of either duty. Only the Attorney General may bring a civil action under the chapter, and the chapter's only stated civil-penalty amounts (up to $500,000 per breach, or $5,000 per day) are tied expressly to a violation of the chapter's separate notification provisions, not to this reasonable-security-measures or disposal duty; no distinct penalty figure or other enforcement mechanism is stated for either of these two duties.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Who enforces it
Enforcement body
The Attorney General has exclusive authority under Section 8-38-9(a) to bring a civil action under this chapter, but the only civil-penalty amounts the section states, up to $500,000 per breach under Section 8-19-11 or $5,000 per day under subsection (b)(1), are expressly tied to a violation of the chapter's notification provisions (Sections 8-38-4 through 8-38-8), not to this section's reasonable-security-measures duty or the disposal duty at Section 8-38-10; no separate enforcement mechanism or penalty figure is stated in the chapter for either of those two duties.
What it reaches
Obligation class
Security, Retention
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Each covered entity and third-party agent must implement and maintain reasonable security measures to protect sensitive personally identifying information against a breach of security, including designating an employee to coordinate the measures, identifying internal and external risks, adopting and assessing safeguards, requiring service providers to maintain appropriate safeguards by contract, adjusting the measures for changed circumstances, and keeping management informed of their overall status.
A covered entity or third-party agent must separately take reasonable measures to dispose, or arrange for the disposal, of records containing sensitive personally identifying information within its custody or control once the records are no longer to be retained, by shredding, erasing, or otherwise modifying the information to make it unreadable or undecipherable through any reasonable means consistent with industry standards.
"Covered entity" is defined to include a government entity as well as a private business. There is no private right of action for a violation of either duty, and the chapter's stated civil-penalty amounts apply only to a violation of the chapter's separate notification provisions, not to these two duties.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
Official statute text, Code of Alabama, Title 8, Chapter 38 (Data Breach Notification Act of 2018)