Law / United States / Alabama

Data Breach Notification Act, reasonable security measures and disposal of records

Ala. Code secs. 8-38-3, 8-38-10

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 1 June 2018.

A security baseline statutes rule binding public and private bodies.

As of 15 September 2026.

What it requires

  • This binds any covered entity (a person, sole proprietorship, partnership, government entity, corporation, nonprofit, trust, estate, cooperative association, or other business entity that acquires or uses sensitive personally identifying information of an Alabama resident) and any third-party agent it contracts with to maintain, store, process, or access that information. An entity already subject to and complying with a federal or state data-breach-notification regime at least as thorough as this chapter is exempt from the entire chapter.
  • Implement and maintain reasonable security measures to protect sensitive personally identifying information against a breach of security: designate an employee or employees to coordinate the effort, identify internal and external risks, adopt and assess information safeguards, contractually require any service providers to maintain appropriate safeguards, adjust the measures for changed circumstances, and keep management, including the board of directors where one exists, informed of the overall status of the measures.
  • Take reasonable measures to dispose, or arrange for the disposal, of records containing sensitive personally identifying information within its custody or control once the records are no longer to be retained, by shredding, erasing, or otherwise modifying the information to make it unreadable or undecipherable through any reasonable means consistent with industry standards.
  • There is no private right of action for a violation of either duty. Only the Attorney General may bring a civil action under the chapter, and the chapter's only stated civil-penalty amounts (up to $500,000 per breach, or $5,000 per day) are tied expressly to a violation of the chapter's separate notification provisions, not to this reasonable-security-measures or disposal duty; no distinct penalty figure or other enforcement mechanism is stated for either of these two duties.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Who enforces it

Enforcement body

The Attorney General has exclusive authority under Section 8-38-9(a) to bring a civil action under this chapter, but the only civil-penalty amounts the section states, up to $500,000 per breach under Section 8-19-11 or $5,000 per day under subsection (b)(1), are expressly tied to a violation of the chapter's notification provisions (Sections 8-38-4 through 8-38-8), not to this section's reasonable-security-measures duty or the disposal duty at Section 8-38-10; no separate enforcement mechanism or penalty figure is stated in the chapter for either of those two duties.

What it reaches

Obligation class

Security, Retention

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Each covered entity and third-party agent must implement and maintain reasonable security measures to protect sensitive personally identifying information against a breach of security, including designating an employee to coordinate the measures, identifying internal and external risks, adopting and assessing safeguards, requiring service providers to maintain appropriate safeguards by contract, adjusting the measures for changed circumstances, and keeping management informed of their overall status.

A covered entity or third-party agent must separately take reasonable measures to dispose, or arrange for the disposal, of records containing sensitive personally identifying information within its custody or control once the records are no longer to be retained, by shredding, erasing, or otherwise modifying the information to make it unreadable or undecipherable through any reasonable means consistent with industry standards.

"Covered entity" is defined to include a government entity as well as a private business. There is no private right of action for a violation of either duty, and the chapter's stated civil-penalty amounts apply only to a violation of the chapter's separate notification provisions, not to these two duties.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Official statute text, Code of Alabama, Title 8, Chapter 38 (Data Breach Notification Act of 2018)

Back to the example  ·  Lint your app