Alabama recently passed its comprehensive consumer privacy law. Governor Kay Ivey signed Alabama HB 351 […]
The post Guide to Alabama Personal Data Protection Act appeared first on CookieYes.
Alabama recently passed its comprehensive consumer privacy law. Governor Kay Ivey signed Alabama HB 351 into law, establishing the Alabama Personal Data Protection Act (APDPA) effective from May 1, 2027. This means that handling personal data of Alabama residents is not the same anymore. This guide preps businesses to comply with the new Alabama law, from applicability thresholds to enforcement mechanisms in plain, actionable terms.
What is Alabama data privacy law?The Alabama Personal Data Protection Act is Alabama’s comprehensive state privacy law. It grants consumers specific rights over their personal data and imposes obligations on businesses that collect, process, or sell that data. Enacted through HB 351, the APDPA establishes a regulatory framework for how businesses must handle the personal data of Alabama residents.
Structurally, the APDPA draws most directly from the Virginia Consumer Data Protection Act (VCDPA): distinct roles for data controllers and data processors, enumerated consumer rights, and enforcement through the state attorney general rather than private litigation.
The APDPA takes effect on May 1, 2027. Enforcement authority rests with the Alabama Attorney General.
Who does the Alabama privacy law apply to?The APDPA applies to persons that conduct business in Alabama or produce products or services targeted to Alabama residents and meet specific data processing thresholds.
Your business falls under the APDPA if it meets either of two thresholds during a calendar year:
There is no standalone revenue-based threshold here. A business with $50 million in annual revenue still falls outside the law’s scope if it processes data from fewer than 25,000 Alabama consumers and does not meet the second threshold. That’s a meaningful structural difference from the California Consumer Privacy Act (CCPA), which includes an annual gross revenue threshold of $25 million as one of its three criteria.
Who is exempt?Alabama privacy law exempts specific entities and data types, such as:
Exempt data types include protected health information under HIPAA, Education records governed by the Family Educational Rights and Privacy Act (FERPA), employee and job applicant data processed in an employment context, and data processed for certain approved research purposes.
What is personal data under Alabama privacy law?Personal data is defined as any information that is linked or reasonably linkable to an identified or identifiable individual.
This includes common data points such as:
The definition is broad, covering both direct identifiers and data that, when combined with other information, can indirectly identify a person.
However, the Alabama Data Protection Act excludes:
Employee data and data processed in a commercial or employment context are also outside the scope of this law.
In practice, if your business can reasonably connect data to a specific individual, it will be treated as personal data under this Alabama privacy law.
What is sensitive data under Alabama privacy law?Under the Alabama Personal Data Protection Act, sensitive data is a specific category of personal data that requires higher protection and explicit consent before processing.
Sensitive data includes:
The Alabama Data Protection Act requires businesses to obtain clear opt-in consent before processing any of these categories.
For children under 13, businesses must comply with COPPA requirements, including verifiable parental consent. Alabama law provides no further clarification regarding children’s data, unlike states such as Colorado, which have amended their laws on this.
Under the Alabama Personal Data Protection Act, consent must meet a clear legal standard. It must be a freely given, specific, informed, and unambiguous indication of the consumer’s agreement to process their personal data.
Valid consent requires a clear affirmative act, such as actively selecting an option or confirming agreement. It cannot be inferred from silence, inactivity, pre-ticked boxes, or acceptance of broad terms (dark patterns).
Consent is specifically required when:
In addition, businesses must provide a simple way for users to withdraw consent, and must stop processing the data once consent is revoked.
Opt-out requirements under Alabama privacy lawThe Alabama Data Protection Act gives consumers the right to opt out of certain types of data processing.
Consumers can opt out of:
Businesses must provide a clear and conspicuous link on their website or another accessible method for consumers to opt out.
Example of a cookie banner with an opt-out link
Unlike other US privacy laws, Alabama law doesn’t explicitly require recognizing global opt-out signals. However, if a consumer’s opt-out signal conflicts with privacy settings or loyalty program participation, the controller must honor the signal and may notify the consumer, offering a chance to confirm settings.
Once a valid opt-out request is received, the business must stop the relevant processing without delay and cannot discriminate against the user for exercising this right.
Sign up to CookieYes, connect your site, and deploy the banner today!
14-day free trialCancel anytime
The Alabama Personal Data Protection Act requires businesses to provide a clear, accurate, and meaningful privacy notice to consumers.
The privacy notice must include:
Use our privacy policy generator to create and manage your privacy policy easily
Generate instantlyNo signup required
The Alabama Personal Data Protection Act places clear obligations on businesses that process personal data. These requirements focus on transparency, data minimisation, security, and consumer rights.
Businesses must:
Provide a clear privacy noticeDisclose the categories of personal data collected, purposes of processing, consumer rights, categories of third parties, and how users can exercise their rights.
Data minimisation and purpose limitationCollect only data that is adequate, relevant, and reasonably necessary for the stated purpose. Businesses must not process personal data for purposes that are incompatible with the disclosed purpose.
Implement data security measuresMaintain reasonable administrative, technical, and physical safeguards to protect personal data.
Enable consumer rightsProvide secure and reliable methods for consumers to access, correct, delete, or obtain their data, and respond within the required timelines. Controllers must respond to authenticated consumer requests within 45 days, with a possible 45-day extension when reasonably necessary.
Offer opt-out mechanismsAllow consumers to opt out of targeted advertising and sale of personal data through a clear and accessible method.
Obtain consent where requiredSecure opt-in consent before processing sensitive data and comply with parental consent rules for children.
Maintain processor contractsEnsure contracts with processors clearly define processing instructions, data types, duration, and responsibilities.
Allow consent withdrawalProvide an easy way for users to withdraw consent. Businesses must stop processing the data as soon as practicable and no later than 45 days after consent is withdrawn.
Non-discriminationBusinesses must not deny goods or services, charge different prices, or provide a different level of quality solely because a consumer exercises their rights, except in limited cases such as voluntary loyalty programs.
Alabama law does not explicitly require a Data Protection Impact Assessment, unlike other state privacy laws such as the CCPA.
The Alabama privacy law grants five core rights to consumers whose personal data is processed by covered businesses.
Right to access and confirmConsumers have the right to confirm whether a controller is processing their personal data and to access that data.
Right to correction and deletionConsumers may request correction of inaccuracies in their personal data. They may also request deletion of personal data provided by or obtained about them.
Right to data portabilityConsumers can obtain a copy of their personal data in a readily usable, portable format that allows transmission to another controller without hindrance.
Right to opt out of sale and targeted advertisingConsumers may opt out of the processing of personal data for:
Enforcement authority rests exclusively with the Alabama Attorney General. There is no private right of action under the APDPA, which means consumers cannot sue businesses directly for violations.
Before initiating enforcement, the Attorney General must issue a notice of violation and allow a 45-day cure period. If the violation is not cured, the Attorney General may bring an action. Courts may impose civil penalties of up to $15,000 per violation.
No private right of action reduces litigation risk compared to the CCPA. But state-level enforcement is a credible compliance driver. So, don’t read the absence of class action exposure as a reason to deprioritize this.
Alabama privacy law checklistWhat rights do consumers have under Alabama privacy law?
Consumers have five core rights: the right to access and confirm, correct, delete, obtain a portable copy of their personal data, and opt out of its sale, use for targeted advertising, and certain profiling. Businesses must respond to requests within 45 days.
What are the penalties for violating Alabama data privacy law?
The Alabama Attorney General enforces the law exclusively. There is no private right of action. Civil penalties reach up to $15,000 per violation. Businesses receive a 45-day cure period after written notice before enforcement action may proceed.
What should companies do to prepare for the Alabama Personal Data Protection Act?
Confirm whether your business meets the applicability thresholds, conduct a data inventory, update your privacy notice, implement consumer rights request workflows, audit vendor contracts for data processing agreements, and deploy a consent management solution to handle sensitive data opt-in and targeted advertising opt-out.
Does Alabama have a privacy law?
Yes. Alabama has a comprehensive privacy law called the Alabama Personal Data Protection Act (APDPA). Enacted through HB 351, this Alabama privacy law gives consumers rights over their personal data and imposes obligations on businesses that collect, process, or sell that data. It applies to companies that meet specific data processing thresholds and is enforced by the Alabama Attorney General. The law will take effect on May 1, 2027.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Louisiana Moves Closer to Becoming the 22nd US State With a Privacy Law | 0 | 7 | 26-05-2026 |
| 2 | SECURE Data Act: What This Federal Privacy Law Means for Your Business | 0 | 5.52 | 15-05-2026 |
| 3 | GDPR and AI Act: Similarities, Differences, and Overlaps | 0 | 7.94 | 29-04-2026 |
| 4 | Canada’s Biggest Privacy Reform in 25 Years: What Bill C-36 Means for Your Business | 0 | 9.3 | 17-06-2026 |
| 5 | AL HB352 | 0 | 5 | 29-01-2026 |
| 6 | Do I Need a Cookie Policy on My Website: Country-by-Country Guide | 0 | 10.28 | 20-05-2026 |
| 7 | Privacy Policy for Google Analytics Users: Free Template and Examples 2026 | 0 | 8.94 | 08-06-2026 |
| 8 | GDPR Best Practices for Businesses: 10 Steps to Stay Compliant in 2026 | 0 | 10.92 | 09-06-2026 |
| 9 | AL HB219 | -1 | 10 | 03-12-2001 |
| 10 | IL SB0340 | 0 | 8 | 31-05-2026 |