Law / United States / Florida

Florida Information Protection Act, data security and disposal duty

Fla. Stat. § 501.171(2), (8)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 1 July 2014.

A security baseline statutes rule binding public and private bodies.

As of 14 September 2026.

What it requires

  • This binds each covered entity (a sole proprietorship, partnership, corporation, trust, estate, cooperative, association, or other commercial entity that acquires, maintains, stores, or uses personal information), each governmental entity, and each third-party agent, for the data-security duty; the disposal duty binds a covered entity or third-party agent, and its own text does not separately name a governmental entity.
  • Take reasonable measures to protect and secure data in electronic form containing personal information. The statute states no further content for what 'reasonable' requires beyond this general standard.
  • Take all reasonable measures to dispose, or arrange for the disposal, of customer records containing personal information within your custody or control once the records are no longer to be retained, by shredding, erasing, or otherwise modifying the personal information to make it unreadable or undecipherable through any means.
  • A violation of either duty is enforced only by the Department of Legal Affairs, as an unfair or deceptive trade practice under Fla. Stat. 501.207; there is no private right of action. A willful violation draws a civil penalty of up to $10,000 under the Florida Deceptive and Unfair Trade Practices Act's general penalty provision, Fla. Stat. 501.2075; the $500,000-capped penalty Fla. Stat. 501.171(9)(b) sets applies only to a violation of the separate breach-notification duty in subsection (3) or (4).

If you get it wrong

Criminal exposureNo

Private right of actionNo

Penalty structure

Fla. Stat. 501.171 sets no penalty schedule of its own for a violation of the data-security duty (subsection (2)) or the disposal duty (subsection (8)); subsection (9)(a) deems any violation of the section an unfair or deceptive trade practice actionable under Fla. Stat. 501.207, and the Florida Deceptive and Unfair Trade Practices Act's own general civil penalty, Fla. Stat. 501.2075, caps a willful violation at $10,000, with no stated aggregate cap. This is distinct from the $500,000-capped, per-day-accruing penalty Fla. Stat. 501.171(9)(b) sets, which by its own terms reaches only a violation of the notice duty in subsection (3) or (4) and is recorded on this jurisdiction's privacy-topic row for that duty.

Rule
Per violation only
As of
14 September 2026
Currency
USD
Per violation unit
Violation
Per violation amount
10,000

Who enforces it

Enforcement body

The Department of Legal Affairs (the Florida Attorney General's office) is the sole enforcing authority. Under Fla. Stat. 501.171(9)(a), a violation of section 501.171 is treated as an unfair or deceptive trade practice actionable by the department under Fla. Stat. 501.207, which may bring a declaratory-judgment action, an action to enjoin the violation, or an action for actual damages on behalf of affected consumers or governmental entities.

What it reaches

Obligation class

Security, Retention

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Fla. Stat. 501.171(2) requires each covered entity, governmental entity, or third-party agent to take reasonable measures to protect and secure data in electronic form containing personal information; this duty explicitly names a governmental entity as a bound party in its own text.

Fla. Stat. 501.171(8) separately requires each covered entity or third-party agent, without naming a governmental entity, to take all reasonable measures to dispose of customer records containing personal information, by shredding, erasing, or otherwise rendering the information unreadable or undecipherable, once the records are no longer to be retained.

A covered entity is defined as a sole proprietorship, partnership, corporation, trust, estate, cooperative, association, or other commercial entity that acquires, maintains, stores, or uses personal information; that definition reaches a governmental entity only for the notice duty in subsections (3) through (6). Neither subsection states further content for what 'reasonable' requires beyond the general standard.

A violation of either duty is deemed an unfair or deceptive trade practice actionable only by the Department of Legal Affairs under Fla. Stat. 501.207; the section creates no private cause of action.

The $500,000-capped civil penalty Fla. Stat. 501.171(9)(b) sets applies only to a violation of the notice duty in subsection (3) or (4), so a willful violation of the data-security or disposal duty instead draws the Florida Deceptive and Unfair Trade Practices Act's general civil penalty of up to $10,000 per violation under Fla. Stat. 501.2075.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Official statute text, Florida Statutes, Consumer Protection chapter

Back to the example  ·  Lint your app