Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Adult content age verification (AV)
Requires a website on which more than one third of material is harmful to minors to perform reasonable age verification before granting access, using a standard method or an anonymous age verification service the visitor selects. A separate industry lawsuit challenging this provision was voluntarily dismissed in July 2025.
Note and primary source →
Breach notification
cite Fla. Stat. § 501.171
stage IMMINENT commencement not set
source official Florida statute text, Florida Statutes, Florida Legislature
A covered entity, defined broadly as any commercial entity that acquires, maintains, stores, or uses personal information, with no revenue gate of any kind, must provide notice to the Department of Legal Affairs of a breach affecting 500 or more individuals in Florida as expeditiously as practicable and no later than 30 days after determining a breach occurred or having reason to believe one occurred, and must give notice to each affected Florida individual on the same 30-day deadline, extendable by 15 days on a written good-cause showing.
This statute reaches far more entities than FDBR's $1 billion-plus controller duties and must not be conflated with FDBR. Originally enacted in 2014 (ch. 2014-189/190) and amended repeatedly since, including by the same 2023 bill that created FDBR and again by ch. 2026-52 in the 2026 session, the underlying research did not establish a dated original commencement from the codified text, so no effective_date is recorded here.
The statute expressly bars a private cause of action, so a breach violation does not reach a private plaintiff, through FDUTPA or otherwise.
What it asks of an app →
Comprehensive regime
FDBR binds only a 'controller': a for-profit entity conducting business in Florida that collects personal data and determines the purposes and means of processing, that also makes in excess of $1 billion in global gross annual revenue and additionally either derives 50 percent or more of its global gross annual revenue from online advertising, operates a consumer smart speaker and voice command service with an integrated virtual assistant, or operates an app store or digital distribution platform offering at least 250,000 applications.
This conjunctive-then-disjunctive threshold excludes essentially every business below $1 billion in global revenue, the overwhelming majority of controllers a peer state's comprehensive act would reach. Outside this narrow platform set, Florida imposes no state-law data-minimization, purpose-limitation, or consumer-rights duty on personal-data processing at all.
What it asks of an app →
Data subject rights
Against a qualifying controller, FDBR gives a Florida consumer confirmation and access, correction, deletion of data provided by or obtained about the consumer, data portability in a readily usable digital format, opt-out of processing for targeted advertising, sale, or profiling producing a legal or similarly significant effect, opt-out of collection or processing of sensitive data including precise geolocation, and opt-out of collection of personal data through a voice or facial recognition feature.
A controller must respond without undue delay and no later than 45 days after receipt, with one 15-day extension available, shorter than the 45-plus-45 model most peer states in this wave use, and must decide an appeal of a denial within 60 days. Rights are exercisable only against a narrowly defined controller and only by a Florida-resident consumer acting outside a commercial or employment context.
What it asks of an app →
Enforcement supervision
cite Fla. Stat. § 501.72
stage IN FORCE in force since 2024-07-01
source official Florida statute text, Florida Statutes, Florida Legislature
A violation of FDBR is an unfair and deceptive trade practice actionable solely by the Florida Department of Legal Affairs, with a civil penalty of up to $50,000 per violation, tripled for a known-child violation, a failure to delete or correct data after a valid request, or continuing to sell or share data after an opt-out.
After written notice of an alleged violation, the Department may, but is not required to, grant a 45-day cure period and issue a letter of guidance; that cure period does not apply to a known-child violation, and no sunset date for the cure provision appears anywhere in the text reviewed. FDBR creates no private right of action.
What it asks of an app →
Sensitive categories
For a qualifying controller, FDBR classifies data revealing racial or ethnic origin, religious beliefs, a mental or physical health diagnosis, sexual orientation, or citizenship or immigration status, genetic or biometric data processed to uniquely identify an individual, a known child's personal data, and precise geolocation data as sensitive data, which may not be processed without the consumer's prior consent.
'Biometric data' means data from automatic measurement of biological characteristics used to identify a person, including fingerprints, voiceprints, or eye retinas or irises, but the definition carries a blanket, unconditional exclusion for physical or digital photographs, video or audio recordings, or data generated from either, with no clawback for data generated to identify someone.
A voiceprint or faceprint extracted from a recording for identification purposes is therefore categorically outside biometric, and so sensitive, data here, the opposite posture from Connecticut's and Delaware's clawback structure. A controller may not sell sensitive personal data without prior consent and must display the notice "NOTICE: This website may sell your sensitive personal data" before doing so.
What it asks of an app →
Social media and minors
Bars minors under 14 from holding a social media account and requires verified parental consent for 14 and 15 year olds; covered platforms must terminate and permanently delete noncompliant minor accounts, including those a platform's own analytics flag as likely belonging to a minor.
Note and primary source →