Law / Florida

Florida

age

Florida's HB 3 (2024) bars minors under 14 from holding social media accounts without parental consent for 14 and 15 year olds, and separately requires age verification on websites where a substantial share of content is harmful to minors, both effective January 1, 2025.

The social media provision remains subject to First Amendment litigation but is currently enforceable after the Eleventh Circuit stayed a district court injunction pending Florida's appeal; a separate industry challenge to the adult content provision was voluntarily dropped in 2025.

Florida has not enacted an app store age verification or design code law; an App Store Accountability Act bill (SB 1722) filed for the 2026 session cleared one committee but died in Senate Judiciary on March 13, 2026.

privacy

The Florida Digital Bill of Rights (FDBR), Fla. Stat. §§ 501.701-501.718 (Part VI, Chapter 501), is not a comprehensive consumer-privacy statute.

It binds only a 'controller' that conducts business in Florida for profit, collects personal data, makes more than $1 billion in global gross annual revenue, and additionally derives 50 percent or more of that revenue from online advertising, operates a qualifying smart-speaker service, or operates an app store or digital distribution platform offering at least 250,000 applications.

Enacted as SB 262 (2023 Regular Session, Laws of Florida ch. 2023-201) and effective July 1, 2024, FDBR requires prior consent for sensitive data and gives a qualifying consumer access, correction, deletion, portability, and opt-out rights, but outside the tiny set of qualifying mega-platforms a Florida business faces no state-law data-minimization, purpose-limitation, or consumer-rights duty under Part VI at all.

FDBR's biometric data definition carries a blanket, unconditional exclusion for a photograph, video, or audio recording, or any data generated from either, with no clawback for data generated to identify someone, so a faceprint or voiceprint extracted from a recording falls outside biometric, and therefore sensitive, data even for a qualifying controller.

A separate, far more broadly reaching statute, the Florida Information Protection Act (Fla. Stat. § 501.171), governs breach notification for any commercial entity with no revenue gate. FDBR enforcement is exclusive to the Department of Legal Affairs, with no private right of action and a discretionary, not mandatory, cure period.

13 instruments named 7 researched in detail As of 2026-08-27

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Adult content age verification (AV)

HB 3 (2024), age verification for material harmful to minors

cite Fla. Stat. Secs. 501.1737, 501.1738 stage IN FORCE in force since 2025-01-01 source official Florida Statutes text

Requires a website on which more than one third of material is harmful to minors to perform reasonable age verification before granting access, using a standard method or an anonymous age verification service the visitor selects. A separate industry lawsuit challenging this provision was voluntarily dismissed in July 2025.

Note and primary source

Breach notification

Florida Information Protection Act, breach notification

cite Fla. Stat. § 501.171 stage IMMINENT commencement not set source official Florida statute text, Florida Statutes, Florida Legislature

A covered entity, defined broadly as any commercial entity that acquires, maintains, stores, or uses personal information, with no revenue gate of any kind, must provide notice to the Department of Legal Affairs of a breach affecting 500 or more individuals in Florida as expeditiously as practicable and no later than 30 days after determining a breach occurred or having reason to believe one occurred, and must give notice to each affected Florida individual on the same 30-day deadline, extendable by 15 days on a written good-cause showing.

This statute reaches far more entities than FDBR's $1 billion-plus controller duties and must not be conflated with FDBR. Originally enacted in 2014 (ch. 2014-189/190) and amended repeatedly since, including by the same 2023 bill that created FDBR and again by ch. 2026-52 in the 2026 session, the underlying research did not establish a dated original commencement from the codified text, so no effective_date is recorded here.

The statute expressly bars a private cause of action, so a breach violation does not reach a private plaintiff, through FDUTPA or otherwise.

What it asks of an app

Comprehensive regime

Florida Digital Bill of Rights, general applicability and large-platform threshold

cite Fla. Stat. §§ 501.701, 501.702(9) stage IN FORCE in force since 2024-07-01 source official Florida statute text, Florida Statutes, Florida Legislature

FDBR binds only a 'controller': a for-profit entity conducting business in Florida that collects personal data and determines the purposes and means of processing, that also makes in excess of $1 billion in global gross annual revenue and additionally either derives 50 percent or more of its global gross annual revenue from online advertising, operates a consumer smart speaker and voice command service with an integrated virtual assistant, or operates an app store or digital distribution platform offering at least 250,000 applications.

This conjunctive-then-disjunctive threshold excludes essentially every business below $1 billion in global revenue, the overwhelming majority of controllers a peer state's comprehensive act would reach. Outside this narrow platform set, Florida imposes no state-law data-minimization, purpose-limitation, or consumer-rights duty on personal-data processing at all.

What it asks of an app

Data subject rights

Florida Digital Bill of Rights, consumer rights

cite Fla. Stat. §§ 501.705, 501.706, 501.707 stage IN FORCE in force since 2024-07-01 source official Florida statute text, Florida Statutes, Florida Legislature

Against a qualifying controller, FDBR gives a Florida consumer confirmation and access, correction, deletion of data provided by or obtained about the consumer, data portability in a readily usable digital format, opt-out of processing for targeted advertising, sale, or profiling producing a legal or similarly significant effect, opt-out of collection or processing of sensitive data including precise geolocation, and opt-out of collection of personal data through a voice or facial recognition feature.

A controller must respond without undue delay and no later than 45 days after receipt, with one 15-day extension available, shorter than the 45-plus-45 model most peer states in this wave use, and must decide an appeal of a denial within 60 days. Rights are exercisable only against a narrowly defined controller and only by a Florida-resident consumer acting outside a commercial or employment context.

What it asks of an app

Enforcement supervision

Florida Digital Bill of Rights, Department of Legal Affairs enforcement

cite Fla. Stat. § 501.72 stage IN FORCE in force since 2024-07-01 source official Florida statute text, Florida Statutes, Florida Legislature

A violation of FDBR is an unfair and deceptive trade practice actionable solely by the Florida Department of Legal Affairs, with a civil penalty of up to $50,000 per violation, tripled for a known-child violation, a failure to delete or correct data after a valid request, or continuing to sell or share data after an opt-out.

After written notice of an alleged violation, the Department may, but is not required to, grant a 45-day cure period and issue a letter of guidance; that cure period does not apply to a known-child violation, and no sunset date for the cure provision appears anywhere in the text reviewed. FDBR creates no private right of action.

What it asks of an app

Sensitive categories

Florida Digital Bill of Rights, sensitive data and biometric data definitions

cite Fla. Stat. §§ 501.702(4), 501.702(31), 501.71(2)(d) stage IN FORCE in force since 2024-07-01 source official Florida statute text, Florida Statutes, Florida Legislature

For a qualifying controller, FDBR classifies data revealing racial or ethnic origin, religious beliefs, a mental or physical health diagnosis, sexual orientation, or citizenship or immigration status, genetic or biometric data processed to uniquely identify an individual, a known child's personal data, and precise geolocation data as sensitive data, which may not be processed without the consumer's prior consent.

'Biometric data' means data from automatic measurement of biological characteristics used to identify a person, including fingerprints, voiceprints, or eye retinas or irises, but the definition carries a blanket, unconditional exclusion for physical or digital photographs, video or audio recordings, or data generated from either, with no clawback for data generated to identify someone.

A voiceprint or faceprint extracted from a recording for identification purposes is therefore categorically outside biometric, and so sensitive, data here, the opposite posture from Connecticut's and Delaware's clawback structure. A controller may not sell sensitive personal data without prior consent and must display the notice "NOTICE: This website may sell your sensitive personal data" before doing so.

What it asks of an app

Social media and minors

HB 3 (2024), social media use for minors

cite Fla. Stat. Sec. 501.1736 stage IN FORCE in force since 2025-01-01 source official Florida Statutes text

Bars minors under 14 from holding a social media account and requires verified parental consent for 14 and 15 year olds; covered platforms must terminate and permanently delete noncompliant minor accounts, including those a platform's own analytics flag as likely belonging to a minor.

Note and primary source

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.