🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
US-AL v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing9 sources retrieved model claude-sonnet-5 · 2026-08-05

Alabama, USA

US-AL schema gdpri-v2 trajectory: not yet assessedregulated (sectoral)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 25 claims · 30 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
25Claimsbaseline..claims[]
1Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Alabama enacted its first comprehensive consumer data privacy statute in the 2026 legislative session, the Alabama Personal Data Protection Act (APDPA, enacted as HB351), alongside a separate and equally significant child-safety measure, the App Store Accountability Act (HB161). The APDPA vests exclusive enforcement authority in the Alabama Attorney General and does not provide a private right of action, a structural choice that places Alabama firmly within the AG-enforcement-only model already common among comprehensive US state privacy laws. The Act applies to entities controlling or processing personal data of more than 25,000 Alabama consumers, excluding payment-transaction data, or deriving more than 25 percent of gross revenue from the sale of personal data, becomes effective 1 May 2027, and carries civil penalties of up to $15,000 per violation together with a mandatory, non-sunsetting 45-day right-to-cure period before the Attorney General may pursue enforcement.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A comprehensive framework exists on paper (HB 351) but is not yet legally operative; current in-force coverage is limited to breach notification and sectoral rules.

Primary frameworkAlabama Data Breach Notification Act of 2018 (in force); Alabama Personal Data Protection Act, HB 351 (enacted, not yet effective 2027-05-01)
Traffic-light rationale — AmberA comprehensive framework exists on paper (HB 351) but is not yet legally operative; current in-force coverage is limited to breach notification and sectoral rules.

Sub-modules (5)

Regulator And AuthorityGreen

The Alabama AG (currently Steve Marshall) enforces the breach notification act and will hold exclusive enforcement authority under the incoming PDPA; there is no dedicated data-protection authority (DPA).

Claims (2):

  • The Alabama Attorney General has authority to issue penalties for violations of the Alabama Data Breach Notification Act of 2018.
  • The Alabama Personal Data Protection Act grants residents various data rights and sets obligations for data controllers and processors, with enforcement by the Attorney General.

Act And InstrumentsAmber

Two primary instruments identified: the 2018 Data Breach Notification Act (in force) and the 2026-signed Personal Data Protection Act (enacted_not_yet_effective).

Claims (2):

  • Governor Kay Ivey signed the Alabama Data Breach Notification Act of 2018, following passage by the Alabama House and Senate (SB 318).
  • Governor Kay Ivey signed House Bill 351, the Alabama Personal Data Protection Act, into law on 16 April 2026; the law takes effect 1 May 2027.

Material ScopeAmber

The PDPA's applicability thresholds (25,000+ AL residents, or any-volume data sales generating 25% of revenue) and exemptions are documented; the breach act's scope is defined by its notification triggers rather than a general material-scope clause.

Claims (2):

  • The Alabama Personal Data Protection Act generally applies to businesses that control or process the data of more than 25,000 Alabama residents, or that derive 25% of their revenue from data sales involving any number of data subjects.
  • The Alabama Personal Data Protection Act exempts small businesses with fewer than 500 employees and nonprofits with fewer than 100 employees, unless they sell personal data, and also exempts defined political organizations.

Territorial ScopeRed

No source located specifying an extraterritorial-application clause beyond the resident-count/revenue thresholds used to define 'controller' status.

Absence provenance: unavailable. Searched: unavailable.

Regulator Registration And FilingRed

No controller/processor registration or filing regime (e.g., data-broker registry) was found for Alabama's breach act or the PDPA; this differs from states like California and Vermont.

Absence provenance: unavailable. Searched: unavailable.

Key findings (1)

  • Alabama's first comprehensive consumer-privacy statute, effective 2027-05-01, enforced by the AG only. — source on file
Category narrative59 words

Alabama currently has no operative comprehensive data-protection statute; the field is governed by the Alabama Data Breach Notification Act of 2018 (in force) plus the newly enacted but not-yet-effective Alabama Personal Data Protection Act (HB 351, effective 1 May 2027) and a scatter of sectoral statutes. The Alabama Attorney General is the consistent enforcement authority across all instruments identified.

Periodic update · new data 2026-09-28

Regulator & Framework

Alabama enacted its first comprehensive consumer data privacy statute in the 2026 legislative session, the Alabama Personal Data Protection Act, through HB351. The Act designates the Alabama Attorney General as the exclusive enforcement authority, with no private right of action available to consumers, a structural choice consistent with the AG-enforcement-only model already adopted by most comprehensive US state privacy laws. The Act's material scope threshold applies to entities that control or process the personal data of more than 25,000 Alabama consumers, with payment-transaction data excluded from that count, or that derive more than 25 percent of their gross revenue from the sale of personal data. This threshold is comparatively higher than some peer-state laws, meaning a narrower population of businesses will fall within its direct scope than under, for example, statutes with lower consumer-count thresholds.

The Act was enacted but is not yet effective, with the effective date set for 1 May 2027, giving covered businesses just over a year from enactment to build out compliance programs. This gap between enactment and effect is typical of the comprehensive state privacy law model, which generally allows substantial lead time for businesses to adjust internal data-handling practices, update privacy notices, and build consumer-rights request-handling processes before the statute becomes enforceable.

Outlook

The 1 May 2027 effective date is the central marker for this module going forward. Between now and then, the key open question is whether the Alabama Attorney General's office issues any implementing guidance or rulemaking to clarify application of the Act's material scope threshold, particularly around how the payment-transaction data exclusion interacts with the 25,000-consumer count. No such guidance has been identified this cycle, and this remains an area to watch as the effective date approaches.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (6)
  1. ConfirmedDataGuidance (reporting AG announcement) — The Alabama Attorney General has authority to issue penalties for violations of the Alabama Data Breach Notification Act of 2018.observed
  2. ConfirmedDataGuidance — The Alabama Personal Data Protection Act grants residents various data rights and sets obligations for data controllers and processors, with enforcement by the Attorney General.observed
  3. ConfirmedDataGuidance (reporting AG announcement) — Governor Kay Ivey signed the Alabama Data Breach Notification Act of 2018, following passage by the Alabama House and Senate (SB 318).observed
  4. ConfirmedIAPP — Governor Kay Ivey signed House Bill 351, the Alabama Personal Data Protection Act, into law on 16 April 2026; the law takes effect 1 May 2027.observed
  5. ConfirmedIAPP — The Alabama Personal Data Protection Act generally applies to businesses that control or process the data of more than 25,000 Alabama residents, or that derive 25% of their revenue from data sales involving any number of data subjects.observed
  6. ProbableIAPP — The Alabama Personal Data Protection Act exempts small businesses with fewer than 500 employees and nonprofits with fewer than 100 employees, unless they sell personal data, and also exempts defined political organizations.observed

#

No in-force lawful-basis regime exists; the incoming PDPA's granular consent/special-category text could not be confirmed from available secondary sources.

Primary frameworkAlabama Personal Data Protection Act, HB 351 (enacted, not yet effective); House Bill 263 (biological/neural data, status unconfirmed)
Traffic-light rationale — RedNo in-force lawful-basis regime exists; the incoming PDPA's granular consent/special-category text could not be confirmed from available secondary sources.

Sub-modules (4)

Lawful BasesRed

No enumerated lawful-basis list (analogous to GDPR Art. 6) was confirmed for the PDPA in the sources reviewed.

Absence provenance: unavailable. Searched: unavailable.

Special CategoriesAmber

HB 263 proposes consumer protections for biological and neural data, requiring consent for transfer and prohibiting marketing based on such data; the PDPA aligns its definition of 'child' with COPPA (under 13), implying heightened treatment of children's data as a sensitive category.

Claims (2):

  • House Bill 263 introduces consumer protections for biological and neural data, requiring consent for data transfer and prohibiting marketing based on such data.
  • The Alabama Personal Data Protection Act's children's privacy provisions follow the Children's Online Privacy Protection Act definition of a child, and the bill's definition of minors for PDPA purposes covers children under age 13.

Pseudonymisation And AnonymisationRed

No pseudonymisation/anonymisation safe-harbour provisions specific to Alabama statutes were identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative65 words

Alabama has no enacted, operative lawful-basis or consent framework analogous to GDPR Art. 6/7. The forthcoming PDPA's consent architecture and enumerated lawful bases were not directly retrievable from bill text via secondary sources. Sensitive/special data protections are emerging piecemeal, notably via a proposed bill (HB 263) targeting biological and neural data, and via the PDPA's COPPA-aligned treatment of children under 13 as a sensitive population.

Periodic update · new data 2026-09-28

Lawful Processing & Special Data

The Alabama Personal Data Protection Act adopts a consent-centric model for the processing of sensitive data categories. Sensitive data under the Act is defined to include racial or ethnic origin, citizenship or immigration status, religious beliefs, health condition, sexual orientation, genetic or biometric identifying data, precise geolocation, and known children's data. A controller must obtain consumer consent before processing any personal data falling into these categories, placing Alabama within the consent-gated model for special-category data that is common across US comprehensive privacy statutes, as distinct from a strict prohibition or licensing-based model.

The breadth of the sensitive-data definition, spanning immigration status and precise geolocation alongside more familiar categories like health and genetic data, reflects an increasingly standardized approach among newer state privacy statutes to capturing the categories of data most likely to cause concrete harm to consumers if mishandled or breached. Because the Act is not yet effective, having been enacted but not yet in force pending its 1 May 2027 effective date, this consent requirement is not yet operative, but businesses collecting Alabama consumer data that falls into these categories should anticipate needing consent mechanisms in place well ahead of that date.

Outlook

As the 1 May 2027 effective date approaches, the practical question for this module is how businesses operationalize consent capture for the Act's sensitive-data categories, particularly for categories like precise geolocation that may be collected through mechanisms, such as mobile app permissions, not traditionally designed around a discrete consent-capture moment. No Alabama-specific guidance on implementation mechanics has been identified this cycle.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (2)
  1. UncertainDataGuidance — House Bill 263 introduces consumer protections for biological and neural data, requiring consent for data transfer and prohibiting marketing based on such data.observed
  2. ProbableIAPP — The Alabama Personal Data Protection Act's children's privacy provisions follow the Children's Online Privacy Protection Act definition of a child, and the bill's definition of minors for PDPA purposes covers children under age 13.observed

#

A rights regime is legislated but not yet effective, and its granular contours are not independently confirmed in the sources gathered.

Primary frameworkAlabama Personal Data Protection Act, HB 351 (enacted, not yet effective 2027-05-01)
Traffic-light rationale — AmberA rights regime is legislated but not yet effective, and its granular contours are not independently confirmed in the sources gathered.

Sub-modules (5)

Access RightAmber

General grant of 'data rights' confirmed; a specific right-of-access provision was not independently verified.

Claims (1):

  • The Alabama Personal Data Protection Act grants Alabama residents various consumer data rights, enforceable exclusively by the Attorney General.

Rectification And ErasureRed

Not independently confirmed from bill text; typical of comparable 2020s-era state comprehensive laws but unverified for Alabama specifically.

Absence provenance: unavailable. Searched: unavailable.

Restriction And ObjectionRed

Not independently confirmed.

Absence provenance: unavailable. Searched: unavailable.

Data PortabilityRed

Not independently confirmed.

Absence provenance: unavailable. Searched: unavailable.

Deadlines And Response WindowsRed

No confirmed statutory response-window deadlines for consumer rights requests under the PDPA were located.

Absence provenance: unavailable. Searched: unavailable.

Category narrative45 words

Sources confirm the Alabama Personal Data Protection Act grants residents 'various data rights' with AG enforcement, but granular right-by-right text (access, rectification/erasure, restriction/objection, portability, and specific response-window deadlines) was not retrievable from the secondary reporting reviewed. This module is assessed conservatively pending primary bill-text confirmation.

Periodic update · new data 2026-09-28

Data Subject Rights

The Alabama Personal Data Protection Act grants consumers the right to confirm whether a controller is processing their personal data and to access that data, forming part of a rights suite that is standard across US comprehensive privacy statutes and generally understood to also include correction, deletion, and portability rights alongside the confirmation and access rights specifically identified this cycle. A notable feature of Alabama's approach, however, is a narrower opt-out right than found in most peer states: the Act does not require an opt-out for targeted advertising based on pseudonymous data, such as alphanumeric device identifiers, where that data is stored separately from directly identifiable information. This carve-out is shared with only Kentucky, Iowa, and Tennessee among US comprehensive state privacy laws, placing Alabama in a small minority of states that take this more permissive approach to pseudonymous-data-based advertising.

The practical effect of this carve-out is that businesses engaged in targeted advertising in Alabama using device identifiers or similar pseudonymous data, kept separately from identifiable consumer records, are not required to offer Alabama consumers an opt-out mechanism for that specific advertising use case, even though most other state comprehensive privacy laws would require one. This is a meaningful compliance-scoping distinction for any business operating a multi-state consumer-facing advertising compliance program, since an opt-out mechanism built for stricter peer states will likely already satisfy Alabama, but a program calibrated only to Alabama's narrower requirement would fall short elsewhere.

Outlook

As the Act's 1 May 2027 effective date approaches, businesses should expect that the pseudonymous-data advertising carve-out will likely draw continued commentary and possible legislative attention, given that it was already noted as a point of controversy at the time of the Act's passage. Whether Alabama's legislature revisits this carve-out before the effective date, either narrowing it to align with the broader peer-state model or leaving it as enacted, is an open question this cycle's research did not resolve.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (1)
  1. ConfirmedDataGuidance — The Alabama Personal Data Protection Act grants Alabama residents various consumer data rights, enforceable exclusively by the Attorney General.observed

#

Breach-notification duties are well-evidenced and in force; DPIA/DPO/ROPA/retention duties under the incoming PDPA remain unconfirmed.

Primary frameworkAlabama Data Breach Notification Act of 2018 (in force); Insurance Data Security Law, Ala. Code Title 27, Ch. 62 (in force, insurance sector); Alabama Personal Data Protection Act (enacted, not yet effective)
Traffic-light rationale — AmberBreach-notification duties are well-evidenced and in force; DPIA/DPO/ROPA/retention duties under the incoming PDPA remain unconfirmed.

Sub-modules (7)

Accountability And DpiaRed

No DPIA trigger or accountability-principle text specific to the PDPA was confirmed.

Absence provenance: unavailable. Searched: unavailable.

Dpo RequirementsRed

No DPO-appointment threshold specific to Alabama was confirmed.

Absence provenance: unavailable. Searched: unavailable.

Ropa RequirementsRed

No records-of-processing obligation specific to Alabama was confirmed.

Absence provenance: unavailable. Searched: unavailable.

Joint Controller ArrangementsRed

No joint-controller provision specific to Alabama was confirmed.

Absence provenance: unavailable. Searched: unavailable.

Security MeasuresAmber

Insurance licensees must implement an information security program to protect personal information under the Insurance Data Security Law; a general (non-insurance) security-of-processing mandate under the PDPA was not confirmed.

Claims (1):

  • Under the Insurance Data Security Law, insurance licensees are required to protect personal information and to investigate and respond to breaches of security.

Breach NotificationGreen

The 2018 Act requires notice to affected Alabama residents within 45 days of discovery, notice to the AG within 45 days (and to nationwide consumer reporting agencies) if a breach affects more than 1,000 individuals, and notice from third-party agents to covered entities within 10 days. Insurance licensees separately must notify the Alabama Department of Insurance within three business days of determining a breach occurred.

Claims (2):

  • The Alabama Data Breach Notification Act of 2018 requires entities to notify Alabama residents of a breach within 45 days of its discovery, and to notify the Attorney General within 45 days if the breach affects more than 1,000 individuals, as well as all nationwide consumer reporting agencies; third-party agents must notify the covered entity within ten days of discovering a breach.
  • Under the Insurance Data Security Law, insurance licensees must notify the Alabama Department of Insurance within three business days of determining that a security breach has occurred.

Retention And DisposalRed

No general retention-limitation or disposal-duty statute specific to Alabama personal data was confirmed.

Absence provenance: unavailable. Searched: unavailable.

Category narrative52 words

The clearest, currently in-force controller duty in Alabama is breach notification under the 2018 Act (45-day consumer/AG notice, 10-day third-party-agent notice). Sector-specific security-of-processing duties exist for insurance licensees under the Insurance Data Security Law. DPIA, DPO, ROPA, joint-controller and retention/disposal duties under the incoming PDPA were not confirmed from available secondary sources.

Periodic update · new data 2026-09-28

Controller/Processor Duties

The Alabama Personal Data Protection Act imposes a general duty on controllers to implement reasonable data security practices appropriate to the volume and nature of the personal data they process, a standard accountability obligation consistent with the broad, flexible security-duty language found across US comprehensive privacy statutes. Notably, however, the Act does not require data protection assessments, sometimes called data protection impact assessments or DPIAs, for high-risk processing activities. This is a material departure from the approach taken by California, Colorado, Connecticut, and Virginia, all of which require some form of risk assessment for high-risk processing under their respective comprehensive privacy laws. Alabama's decision not to include this requirement represents a lighter-touch accountability model relative to those peer states, reducing the documentary and procedural burden on controllers even as they remain subject to the Act's substantive consent and rights obligations.

Separately, Alabama's existing Data Breach Notification Act of 2018 continues to operate independently of, and unaffected by, the new APDPA. That pre-existing sectoral statute requires covered entities to notify affected residents within 45 days of a breach, with penalties of up to $500,000 per breach. The breach-notification regime and the new comprehensive privacy Act therefore operate as two separate compliance obligations for Alabama-facing businesses, one addressing breach response specifically and the other addressing the broader data-handling lifecycle.

Outlook

The absence of a DPIA requirement under the APDPA means Alabama-facing businesses that already operate DPIA programs to satisfy other states' comprehensive privacy laws will likely find their existing programs more than sufficient for Alabama, but businesses whose only comprehensive privacy exposure is Alabama should not expect to need to build a DPIA process specifically for this statute. The pre-existing 2018 breach notification law remains a separate and unaffected compliance track to monitor alongside the APDPA's 1 May 2027 effective date.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (3)
  1. ConfirmedDataGuidance — Under the Insurance Data Security Law, insurance licensees are required to protect personal information and to investigate and respond to breaches of security.observed
  2. ConfirmedDataGuidance (reporting AG announcement) — The Alabama Data Breach Notification Act of 2018 requires entities to notify Alabama residents of a breach within 45 days of its discovery, and to notify the Attorney General within 45 days if the breach affects more than 1,000 individuals, as well as all nationwide consumer reporting agencies; third-party agents must notify the covered entity within ten days of discovering a breach.observed
  3. ConfirmedDataGuidance — Under the Insurance Data Security Law, insurance licensees must notify the Alabama Department of Insurance within three business days of determining that a security breach has occurred.observed

#

No comprehensive cross-border transfer regime exists at the Alabama state level; this is an explicit and legitimate gap finding rather than a silent omission.

Traffic-light rationale — RedNo comprehensive cross-border transfer regime exists at the Alabama state level; this is an explicit and legitimate gap finding rather than a silent omission.

Sub-modules (6)

Transfer MechanismsRed

No Alabama-specific transfer-mechanism statute was located.

Absence provenance: unavailable. Searched: unavailable.

Adequacy ReceivedRed

Not applicable at US sub-federal level; no adequacy-receipt mechanism exists for Alabama.

Absence provenance: unavailable. Searched: unavailable.

Adequacy GrantedRed

Not applicable; Alabama grants no adequacy decisions.

Absence provenance: unavailable. Searched: unavailable.

Sccs And BcrsRed

No Alabama-specific SCC/BCR framework was located.

Absence provenance: unavailable. Searched: unavailable.

Transfer Impact AssessmentRed

No Alabama-specific TIA requirement was located.

Absence provenance: unavailable. Searched: unavailable.

Data LocalisationRed

No Alabama data-localisation mandate was located.

Absence provenance: unavailable. Searched: unavailable.

Category narrative43 words

Alabama, as a US state, has no adequacy-decision framework, SCC/BCR regime, or data-localisation mandate of its own; cross-border personal-data transfer questions touching Alabama residents are governed by general U.S. federal law rather than a state-specific transfer mechanism. No Alabama-specific data-localisation statute was identified.

Sources and claims (1)
  1. UncertainDataGuidance — Alabama has no comprehensive privacy law establishing a cross-border data-transfer mechanism; general U.S. federal frameworks apply instead of a state-specific regime.observed

#

Insurance overlay is well-evidenced and in force; health, financial, telecoms, employment, credit-scoring and education overlays are only generically referenced without confirmed Alabama-specific statutory text.

Primary frameworkInsurance Data Security Law, Ala. Code Title 27, Ch. 62 (in force)
Supervisory authorityAlabama Department of Insurance
Traffic-light rationale — AmberInsurance overlay is well-evidenced and in force; health, financial, telecoms, employment, credit-scoring and education overlays are only generically referenced without confirmed Alabama-specific statutory text.

Sub-modules (7)

Financial Sector OverlayAmber

Alabama statutes are noted to regulate 'financial information' generally, implying reliance on federal GLBA overlay rather than a dedicated state financial-privacy statute.

Claims (1):

  • There are other Alabama statutes that regulate patient and medical records, financial information, and telemarketing and telephone communications.

Health Sector OverlayAmber

Alabama statutes regulate patient and medical records generally, implying reliance on federal HIPAA overlay; recent breach reports (e.g., Aesto Health, Norwood Clinic) were filed under HIPAA/HHS OCR channels.

Claims (1):

  • There are other Alabama statutes that regulate patient and medical records, financial information, and telemarketing and telephone communications.

Telecoms And EprivacyAmber

Alabama statutes regulate telemarketing and telephone communications generally; no dedicated ePrivacy/cookie-consent statute was identified.

Claims (1):

  • There are other Alabama statutes that regulate patient and medical records, financial information, and telemarketing and telephone communications.

Employment DataRed

No Alabama-specific employment-data privacy statute was located.

Absence provenance: unavailable. Searched: unavailable.

Credit And ScoringRed

No Alabama-specific credit-scoring privacy statute was located beyond reliance on federal FCRA.

Absence provenance: unavailable. Searched: unavailable.

EducationRed

No Alabama-specific education-sector data-privacy statute was located.

Absence provenance: unavailable. Searched: unavailable.

InsuranceGreen

Insurance licensees are required to protect personal information and to notify the Alabama Department of Insurance within three business days of determining a breach occurred.

Claims (1):

  • Under the Insurance Data Security Law, insurance licensees must notify the Alabama Department of Insurance within three business days of determining that a security breach has occurred.
Category narrative49 words

Alabama layers several sector-specific statutes atop the general breach-notification baseline: the Insurance Data Security Law (Title 27, Ch. 62) for insurance licensees, and general references to statutes governing patient/medical records, financial information, and telemarketing/telephone communications (implying reliance on federal HIPAA/GLBA/TCPA overlays rather than dedicated Alabama enactments in those areas).

Periodic update · new data 2026-09-28

Sectoral Watch

The Alabama Personal Data Protection Act follows the now-standard US comprehensive privacy statute pattern of broad sectoral carve-outs. The Act exempts protected health information regulated under HIPAA, consumer report data governed by the FCRA, driver data under the DPPA, FERPA-regulated educational records, Farm Credit Act data, and Airline Deregulation Act data, removing entire categories of already-regulated data from the APDPA's scope on the theory that existing federal sectoral regimes already provide adequate protection. Alabama's Act also specifically exempts persons regulated under the state's own Title 8, Chapter 7A, its Monetary Transmission Act, from APDPA coverage, a state-specific carve-out that reflects the existing money-transmission licensing and oversight regime already covering that sector.

A second significant carve-out excludes individuals acting in a commercial or employment context from the Act's definition of consumer, meaning most human-resources data and business-to-business data relationships fall outside the APDPA's primary obligations. This employment and B2B exclusion is a standard feature of the US comprehensive privacy statute model and generally reflects a legislative judgment that employment relationships and business dealings are sufficiently different from consumer relationships to warrant separate treatment, often left to other employment or contract law frameworks instead.

Outlook

The money-transmission sectoral carve-out is of particular cross-monitor interest given Alabama's concurrent activity in stablecoin and crypto-kiosk regulation, since entities operating under the Title 8 Chapter 7A money transmission licensing regime, including certain crypto-facing businesses, fall outside the APDPA for data processed in that capacity. As the 1 May 2027 effective date approaches, clarifying exactly how this carve-out interacts with businesses that operate both a money-transmission-licensed line of business and other consumer-facing lines not covered by that licensing regime will be a practical compliance question worth monitoring.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (1)
  1. UncertainDataGuidance — There are other Alabama statutes that regulate patient and medical records, financial information, and telemarketing and telephone communications.observed

#

Only the PDPA's sale-threshold provision is confirmed as enacted (not yet effective); dark-pattern and marketing-restriction bills have uncertain enactment status.

Primary frameworkAlabama Personal Data Protection Act, HB 351 (enacted, not yet effective)
Traffic-light rationale — AmberOnly the PDPA's sale-threshold provision is confirmed as enacted (not yet effective); dark-pattern and marketing-restriction bills have uncertain enactment status.

Sub-modules (6)

Cookies And TrackersRed

No Alabama-specific cookie/tracker consent statute was located.

Absence provenance: unavailable. Searched: unavailable.

Dark PatternsAmber

House Bill 283 is reported to empower consumers to control their personal data and to address manipulative user interfaces (dark patterns), but its enactment status was not independently confirmed.

Claims (1):

  • Alabama's House Bill 283 empowers consumers to control their personal data and addresses manipulative user interfaces.

Opt Out SignalsRed

No universal opt-out signal (e.g., Global Privacy Control) recognition requirement was located for Alabama.

Absence provenance: unavailable. Searched: unavailable.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rule specific to Alabama was located.

Absence provenance: unavailable. Searched: unavailable.

Cross Context AdvertisingAmber

The PDPA's 'sale' threshold is unusual in applying regardless of data volume where 25% of revenue derives from data sales, a novelty compared with most other state comprehensive laws.

Claims (1):

  • The Alabama Personal Data Protection Act's sale-related applicability threshold is unique in applying when any number of individuals' data is sold in combination with the 25%-of-revenue test, unlike most other states which pair the 25% revenue test with a 25,000-individual threshold.

Direct MarketingAmber

House Bill 263, if enacted, would prohibit marketing based on biological/neural data; no general direct-marketing consent/suppression statute for Alabama was otherwise confirmed.

Claims (1):

  • House Bill 263 introduces consumer protections for biological and neural data, requiring consent for data transfer and prohibiting marketing based on such data.
Category narrative57 words

Commercial/adtech-specific privacy rules in Alabama are emergent and largely tied to the not-yet-effective PDPA and several 2026 bills of uncertain enactment status: House Bill 283 (dark patterns / consumer control over personal data) and the PDPA's unusual 'sale' threshold (any-volume data sales generating 25% of revenue). No dedicated cookie-consent, opt-out-signal (e.g., GPC), or clean-room statute was identified.

Periodic update · new data 2026-09-28

AdTech & Commercial Privacy

The Alabama Personal Data Protection Act provides consumers with an opt-out right for targeted advertising, but the practical reach of that right is narrowed by a specific carve-out for advertising based on pseudonymous data, such as alphanumeric device identifiers, where that data is stored separately from directly identifiable consumer information. Under this carve-out, businesses conducting targeted advertising in Alabama using such pseudonymous identifiers are not required to offer consumers an opt-out for that specific use case, a position shared with only Kentucky, Iowa, and Tennessee among US states with comprehensive privacy laws. The Act does not establish a universal opt-out signal mandate, meaning there is no statutory requirement in Alabama analogous to the universal opt-out mechanisms, such as the Global Privacy Control, that some other states have begun to require businesses to honor.

This combination, an opt-out right that exists in name but is substantially narrowed by the pseudonymous-data carve-out, and no universal opt-out signal requirement, places Alabama toward the more permissive end of the US state comprehensive privacy law spectrum on commercial advertising practices specifically. For businesses running multi-state targeted advertising compliance programs, Alabama's requirements are likely to be satisfied by compliance frameworks built to meet the requirements of stricter peer states, but a program built to Alabama's specific requirements alone would not meet the higher bar set by states requiring opt-outs for pseudonymous-data-based advertising or universal opt-out signal honoring.

Outlook

Given that the pseudonymous-data carve-out was already a point of legislative controversy at the time the APDPA was passed, continued advocacy or subsequent legislative attention to narrowing this carve-out before the Act's 1 May 2027 effective date is plausible, though this cycle's research found no confirmed legislative activity to that effect. The absence of a universal opt-out signal mandate is likewise worth monitoring as other states continue to adopt such requirements, potentially creating pressure for Alabama to follow suit in a future session.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (2)
  1. UncertainDataGuidance — Alabama's House Bill 283 empowers consumers to control their personal data and addresses manipulative user interfaces.observed
  2. ProbableIAPP — The Alabama Personal Data Protection Act's sale-related applicability threshold is unique in applying when any number of individuals' data is sold in combination with the 25%-of-revenue test, unlike most other states which pair the 25% revenue test with a 25,000-individual threshold.observed

#

Several AI-specific bills are documented but enactment status and full scope are only partially confirmed; core ADM/profiling/biometric rights are unconfirmed.

Primary frameworkSenate Bill 129 (AI-generated content transparency); House Bills 324/325 (AI chatbot regulation) — enactment status not fully confirmed
Traffic-light rationale — AmberSeveral AI-specific bills are documented but enactment status and full scope are only partially confirmed; core ADM/profiling/biometric rights are unconfirmed.

Sub-modules (6)

Profiling RestrictionsRed

No confirmed profiling-restriction provision analogous to GDPR Art. 22 was located for Alabama.

Absence provenance: unavailable. Searched: unavailable.

Automated Decision Making TransparencyRed

No confirmed ADM transparency/explanation right was located for Alabama.

Absence provenance: unavailable. Searched: unavailable.

Ai Risk AssessmentsAmber

Senate Bill 129 mandates transparency for AI-generated content, requiring clear disclosures and metadata marking, with enforcement starting 1 October 2026; House Bills 324/325 mandate age verification, emergency protocols, and data-collection limits for AI chatbots, enforced by the AG.

Claims (2):

  • Senate Bill 129 mandates transparency for AI-generated content in Alabama, requiring clear disclosures and metadata marking, with enforcement starting 1 October 2026.
  • House Bill 324 mandates age verification, emergency protocols, and data-collection limits for AI chatbots, with enforcement by the Attorney General of Alabama; House Bill 325 regulates AI chatbot use, requiring consumer notification and establishing penalties for violations.

Biometric RegimeAmber

House Bill 263's biological data provisions are the closest analogue to a biometric regime identified, but its enactment status is unconfirmed; no dedicated facial-recognition/fingerprint statute was located.

Claims (1):

  • House Bill 263 introduces consumer protections for biological and neural data, requiring consent for data transfer and prohibiting marketing based on such data.

Genetic DataRed

No dedicated Alabama genetic-data statute distinct from HB 263's biological-data language was located.

Absence provenance: unavailable. Searched: unavailable.

State Surveillance CarveoutsRed

No Alabama-specific state-surveillance/national-security carveout provision was located.

Absence provenance: unavailable. Searched: unavailable.

Category narrative67 words

Alabama's algorithmic/biometric governance activity in 2026 clusters around AI-specific bills: Senate Bill 129 (AI-generated content transparency, disclosures and metadata marking, enforcement from 1 October 2026) and House Bills 324/325 (AI chatbot regulation, age verification, emergency protocols, data-collection limits, AG enforcement). House Bill 263's biological/neural data protections also touch this module. No confirmed Art. 22-style profiling restriction, ADM transparency right, or dedicated biometric/genetic-data statute was located for Alabama.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (2)
  1. ProbableDataGuidance — Senate Bill 129 mandates transparency for AI-generated content in Alabama, requiring clear disclosures and metadata marking, with enforcement starting 1 October 2026.observed
  2. UncertainDataGuidance — House Bill 324 mandates age verification, emergency protocols, and data-collection limits for AI chatbots, with enforcement by the Attorney General of Alabama; House Bill 325 regulates AI chatbot use, requiring consumer notification and establishing penalties for violations.observed

#

Multiple children's-privacy instruments are documented, but a material date conflict (HB 161 effective date) and uncertain enactment status of related bills prevent a green rating.

Primary frameworkAlabama App Store Accountability Act, HB 161 (age/effective-date conflict unresolved); Alabama Personal Data Protection Act, HB 351 (enacted, not yet effective)
Traffic-light rationale — AmberMultiple children's-privacy instruments are documented, but a material date conflict (HB 161 effective date) and uncertain enactment status of related bills prevent a green rating.

Sub-modules (5)

Age VerificationAmber

The App Store Accountability Act (HB 161) requires age verification for minors under 18 using app stores; reported effective dates conflict between 1 October 2026 and 1 January 2027 across sources.

Claims (1):

  • Alabama's App Store Accountability Act (House Bill 161) mandates age verification for minors using app stores; secondary sources report conflicting effective dates of 1 October 2026 and 1 January 2027, which remains unresolved.

Minor Profiling BansAmber

No dedicated minor-profiling ban was located; the PDPA's COPPA-aligned 'child' definition (under 13) is the closest analogue for heightened protection of minors' data.

Claims (1):

  • The Alabama Personal Data Protection Act's children's privacy provisions follow the Children's Online Privacy Protection Act definition of a child, and the bill's definition of minors for PDPA purposes covers children under age 13.

Education SettingsRed

No education-setting-specific children's data statute was located for Alabama.

Absence provenance: unavailable. Searched: unavailable.

Dependent AdultsRed

No dependent-adult (elderly/incapacitated) data-protection statute was located for Alabama.

Absence provenance: unavailable. Searched: unavailable.

Category narrative96 words

Alabama has the most active children's-privacy legislative track of any module reviewed: the App Store Accountability Act (HB 161) mandates age verification and verifiable parental consent for minors under 18 using app stores, though its effective date is reported inconsistently (1 October 2026 in one summary vs. 1 January 2027 in another — flagged as an open question). The PDPA separately defines 'minor' by reference to COPPA (under 13) for its own sensitive-data purposes. House Bill 276 requires social media platforms to protect minors and cooperate with law enforcement. No education-setting-specific or dependent-adult-specific protection was located.

Periodic update · new data 2026-09-28

Children & Vulnerable Groups

Alabama enacted the App Store Accountability Act, HB161, addressing app-store age verification and parental consent for minors, in the same 2026 legislative session as the broader Alabama Personal Data Protection Act. HB161 establishes four discrete age categories: under 13, 13 to 15, 16 to 17, and 18 and over. App-store providers are required to request age-category information from users at account creation and to affiliate a minor's account with a verified parent account, obtaining verifiable parental consent before a minor under 18 may download an app. This parental-consent mechanism is the core substantive requirement of the statute and represents a significant compliance obligation for app-store providers and, by extension, app developers whose products are distributed through those stores in Alabama.

A retroactive compliance element applies to existing accounts: accounts created before 2 October 2026 must be categorized by age and verified by 1 October 2027, giving app-store providers roughly a year to work through their existing Alabama user base rather than requiring immediate retroactive compliance. Secondary reporting on HB161's general effective date is inconsistent, with some sources indicating 1 October 2026 and others indicating 1 January 2027; this discrepancy has not been resolved against primary Alabama legislature text this cycle and should be treated as an open sourcing question rather than a settled fact.

HB161 was enacted alongside the APDPA within the same session, and both statutes reflect a broader Alabama legislative focus in 2026 on strengthening consumer and child data protections, even though HB161 addresses a narrower, age-verification-specific concern rather than the general data-processing landscape covered by the APDPA.

Outlook

Resolving the disputed general effective date, either 1 October 2026 or 1 January 2027, against primary Alabama statute text is the immediate research priority for this module. Separately, the 1 October 2027 deadline for retroactive verification of pre-existing accounts is a further compliance milestone that app-store providers operating in Alabama will need to track regardless of which general effective date proves correct.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (2)
  1. UncertainDataGuidance — Alabama's App Store Accountability Act (House Bill 161) mandates age verification for minors using app stores; secondary sources report conflicting effective dates of 1 October 2026 and 1 January 2027, which remains unresolved.observed
  2. ProbableIAPP — Alabama's App Store Accountability Act, which requires verifiable parental consent in addition to age verification, applies to minors under age 18.observed

#

Enforcement powers and penalty structures are clearly documented and the AG has a track record of active, recent enforcement (multistate settlements) even absent a comprehensive law currently in force.

Primary frameworkAlabama Data Breach Notification Act of 2018 (in force); Alabama Personal Data Protection Act, HB 351 (enacted, not yet effective)
Traffic-light rationale — GreenEnforcement powers and penalty structures are clearly documented and the AG has a track record of active, recent enforcement (multistate settlements) even absent a comprehensive law currently in force.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The AG can impose penalties up to $500,000 per breach for knowing violations of the 2018 Act's notice provisions, and up to $5,000/day for continuing non-compliance; the PDPA is exclusively AG-enforced.

Claims (2):

  • Covered entities or third-party agents who knowingly violate the Alabama Data Breach Notification Act's notification provisions can be subject to a penalty not exceeding $500,000 per breach, and covered entities can be liable for a civil penalty of not more than $5,000 per day for each consecutive day of continued non-compliance.
  • The Alabama Personal Data Protection Act includes a non-sunsetting 45-day cure provision together with exclusive Attorney General enforcement.

Enforcement Activity IndexGreen

Alabama reached a $12.2 million settlement with Roblox Corporation to enhance child-safety measures on the platform, and joined a 42-state AG coalition settlement with 23andMe's bankruptcy trustee over a 2023 breach affecting 6.9 million customers.

Claims (2):

  • Alabama reached a $12.2 million settlement with Roblox Corporation to enhance child-safety measures on the platform.
  • A coalition of 42 attorneys general, including Alabama, reached a settlement with 23andMe's bankruptcy trustee over a 2023 data breach affecting 6.9 million customers.

Regulator Funding And CapacityRed

No specific funding or headcount data for the AG's Consumer Protection Division's privacy enforcement function was located.

Absence provenance: unavailable. Searched: unavailable.

Collective Redress And Class ActionsAmber

No Alabama-specific consumer class-action mechanism for data-privacy claims was located; the 23andMe matter was a multistate AG settlement rather than a private class action.

Claims (1):

  • A coalition of 42 attorneys general, including Alabama, reached a settlement with 23andMe's bankruptcy trustee over a 2023 data breach affecting 6.9 million customers.

Private Right Of ActionAmber

The PDPA provides for exclusive Attorney General enforcement together with a non-sunsetting 45-day cure provision, indicating the absence of a private right of action.

Claims (1):

  • The Alabama Personal Data Protection Act's exclusive Attorney General enforcement model, combined with its 45-day cure provision, indicates the statute does not create a private right of action for consumers.

Recent Developments 180DAmber

Within the last 180 days, the most significant development is the Governor's 16 April 2026 signature enacting the Alabama Personal Data Protection Act (HB 351), alongside a wave of related 2026-session bills (App Store Accountability Act, AI-transparency and AI-chatbot bills, data-broker and dark-pattern bills) of varying enactment status.

Claims (1):

  • Governor Kay Ivey signed House Bill 351, the Alabama Personal Data Protection Act, into law on 16 April 2026; the law takes effect 1 May 2027.
Category narrative72 words

Enforcement is centralized in the Alabama Attorney General across all identified instruments. The 2018 breach act carries defined civil penalties ($500,000 per breach for knowing violations; $5,000/day for continuing non-compliance). The PDPA (not yet effective) provides a non-sunsetting 45-day cure period and exclusive AG enforcement, implying no private right of action. Recent multistate AG enforcement activity involving Alabama includes the 23andMe bankruptcy-trustee settlement and a $12.2 million Roblox settlement on child-safety grounds.

Periodic update · new data 2026-09-28

Enforcement & Redress

Both of Alabama's major 2026 privacy statutes, the Alabama Personal Data Protection Act and the App Store Accountability Act, structure enforcement identically: exclusive authority rests with the Alabama Attorney General, and neither statute provides consumers with a private right of action. Under the APDPA specifically, civil penalties can reach up to $15,000 per violation, and the Act includes a mandatory, non-sunsetting 45-day right-to-cure period, meaning the Attorney General must provide covered entities with 45 days to cure an alleged violation before pursuing enforcement, and this cure right does not expire or sunset over time as some other states' cure provisions have been designed to do.

The AG-exclusive enforcement model, combined with the absence of a private right of action, is now the dominant pattern among US comprehensive state privacy statutes, and Alabama's adoption of this model for both its general privacy statute and its child-safety-focused app-store statute reflects consistency in the state's approach to enforcement design across its 2026 privacy legislative package. The practical consequence is that the pace and rigor of enforcement under both statutes will depend substantially on how the Attorney General's office chooses to allocate resources and prioritize privacy enforcement once both laws become operative, since there is no parallel private litigation track to supplement regulatory enforcement.

Outlook

As both statutes approach their respective effective dates, the concrete signal to watch for is whether the Alabama Attorney General's office issues any public enforcement priorities, guidance, or staffing announcements specific to either the APDPA or HB161. No such announcements have been identified this cycle. The mandatory 45-day cure period under the APDPA means that even once the Act becomes effective on 1 May 2027, the first wave of any enforcement actions would likely not become public until at least 45 days after an initial violation notice, a timing consideration for tracking the regime's practical rollout.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. ConfirmedDataGuidance (reporting AG announcement) — Covered entities or third-party agents who knowingly violate the Alabama Data Breach Notification Act's notification provisions can be subject to a penalty not exceeding $500,000 per breach, and covered entities can be liable for a civil penalty of not more than $5,000 per day for each consecutive day of continued non-compliance.observed
  2. ProbableIAPP — The Alabama Personal Data Protection Act includes a non-sunsetting 45-day cure provision together with exclusive Attorney General enforcement.observed
  3. ConfirmedDataGuidance — Alabama reached a $12.2 million settlement with Roblox Corporation to enhance child-safety measures on the platform.observed
  4. ConfirmedDataGuidance — A coalition of 42 attorneys general, including Alabama, reached a settlement with 23andMe's bankruptcy trustee over a 2023 data breach affecting 6.9 million customers.observed
  5. ProbableIAPP — The Alabama Personal Data Protection Act's exclusive Attorney General enforcement model, combined with its 45-day cure provision, indicates the statute does not create a private right of action for consumers.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metpass
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct11.11
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Alabama, USA
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 25 claim(s) (25 category placement(s)), 30 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Breach-notification duties, AG enforcement powers/penalties, and the Insurance Data Security Law overlay are grounded in T2 (AG-announcement-derived) sources and are high-confidence. The Alabama Personal Data Protection Act's existence, signing date, effective date, applicability thresholds, exemptions, and cure/enforcement model are grounded in T3 (IAPP/DataGuidance) analysis and are Probable-to-Confirmed. Granular PDPA provisions (enumerated lawful bases, DPIA/DPO/ROPA duties, itemized consumer rights, response-window deadlines) and the enactment status of several 2026-session bills (HB 263, HB 283, SB 213, HB 324/325, HB 276, HB 171/173/219) could not be verified against primary bill text and are marked Uncertain/Speculative with absent_field_provenance. cross_border_and_adequacy is legitimately near-empty, reflecting the absence of any state-level transfer regime.

Unresolved questions (7):

  • What is the correct effective date for the App Store Accountability Act (HB 161) — 1 October 2026 or 1 January 2027 — given conflicting statements in the same secondary source?
  • Has House Bill 263 (biological/neural data) been signed into law, and if so, on what date and with what effective date?
  • Has House Bill 283 (dark patterns / consumer control) been signed into law?
  • Has Senate Bill 213 (data broker obligations) been enacted, and what obligations does it impose?
  • Have House Bills 324/325 (AI chatbot regulation) and House Bill 276 (social media minor protections) been signed into law?
  • Does the Alabama Personal Data Protection Act include a GDPR-style enumerated lawful-bases list, DPIA triggers, DPO thresholds, or ROPA obligations, and what are the exact consumer-rights response deadlines?
  • What is the exact statutory citation and effective date for the Alabama Data Breach Notification Act of 2018 (Ala. Code Title 8, Chapter 38) beyond its 28 March 2018 signing?

Escalate to primary-source review: yes