#
A comprehensive framework exists on paper (HB 351) but is not yet legally operative; current in-force coverage is limited to breach notification and sectoral rules.
Sub-modules (5)
Regulator And AuthorityGreen
The Alabama AG (currently Steve Marshall) enforces the breach notification act and will hold exclusive enforcement authority under the incoming PDPA; there is no dedicated data-protection authority (DPA).
Claims (2):
- The Alabama Attorney General has authority to issue penalties for violations of the Alabama Data Breach Notification Act of 2018.
- The Alabama Personal Data Protection Act grants residents various data rights and sets obligations for data controllers and processors, with enforcement by the Attorney General.
Act And InstrumentsAmber
Two primary instruments identified: the 2018 Data Breach Notification Act (in force) and the 2026-signed Personal Data Protection Act (enacted_not_yet_effective).
Claims (2):
- Governor Kay Ivey signed the Alabama Data Breach Notification Act of 2018, following passage by the Alabama House and Senate (SB 318).
- Governor Kay Ivey signed House Bill 351, the Alabama Personal Data Protection Act, into law on 16 April 2026; the law takes effect 1 May 2027.
Material ScopeAmber
The PDPA's applicability thresholds (25,000+ AL residents, or any-volume data sales generating 25% of revenue) and exemptions are documented; the breach act's scope is defined by its notification triggers rather than a general material-scope clause.
Claims (2):
- The Alabama Personal Data Protection Act generally applies to businesses that control or process the data of more than 25,000 Alabama residents, or that derive 25% of their revenue from data sales involving any number of data subjects.
- The Alabama Personal Data Protection Act exempts small businesses with fewer than 500 employees and nonprofits with fewer than 100 employees, unless they sell personal data, and also exempts defined political organizations.
Territorial ScopeRed
No source located specifying an extraterritorial-application clause beyond the resident-count/revenue thresholds used to define 'controller' status.
Absence provenance: unavailable. Searched: unavailable.
Regulator Registration And FilingRed
No controller/processor registration or filing regime (e.g., data-broker registry) was found for Alabama's breach act or the PDPA; this differs from states like California and Vermont.
Absence provenance: unavailable. Searched: unavailable.
Key findings (1)
- Alabama's first comprehensive consumer-privacy statute, effective 2027-05-01, enforced by the AG only. — source on file
Regulator & Framework
Alabama enacted its first comprehensive consumer data privacy statute in the 2026 legislative session, the Alabama Personal Data Protection Act, through HB351. The Act designates the Alabama Attorney General as the exclusive enforcement authority, with no private right of action available to consumers, a structural choice consistent with the AG-enforcement-only model already adopted by most comprehensive US state privacy laws. The Act's material scope threshold applies to entities that control or process the personal data of more than 25,000 Alabama consumers, with payment-transaction data excluded from that count, or that derive more than 25 percent of their gross revenue from the sale of personal data. This threshold is comparatively higher than some peer-state laws, meaning a narrower population of businesses will fall within its direct scope than under, for example, statutes with lower consumer-count thresholds.
The Act was enacted but is not yet effective, with the effective date set for 1 May 2027, giving covered businesses just over a year from enactment to build out compliance programs. This gap between enactment and effect is typical of the comprehensive state privacy law model, which generally allows substantial lead time for businesses to adjust internal data-handling practices, update privacy notices, and build consumer-rights request-handling processes before the statute becomes enforceable.
Outlook
The 1 May 2027 effective date is the central marker for this module going forward. Between now and then, the key open question is whether the Alabama Attorney General's office issues any implementing guidance or rulemaking to clarify application of the Act's material scope threshold, particularly around how the payment-transaction data exclusion interacts with the 25,000-consumer count. No such guidance has been identified this cycle, and this remains an area to watch as the effective date approaches.
1 further periodic run re-emitted the standing brief unchanged and is not shown.
Sources and claims (6)
- ConfirmedDataGuidance (reporting AG announcement) — The Alabama Attorney General has authority to issue penalties for violations of the Alabama Data Breach Notification Act of 2018.observed
- ConfirmedDataGuidance — The Alabama Personal Data Protection Act grants residents various data rights and sets obligations for data controllers and processors, with enforcement by the Attorney General.observed
- ConfirmedDataGuidance (reporting AG announcement) — Governor Kay Ivey signed the Alabama Data Breach Notification Act of 2018, following passage by the Alabama House and Senate (SB 318).observed
- ConfirmedIAPP — Governor Kay Ivey signed House Bill 351, the Alabama Personal Data Protection Act, into law on 16 April 2026; the law takes effect 1 May 2027.observed
- ConfirmedIAPP — The Alabama Personal Data Protection Act generally applies to businesses that control or process the data of more than 25,000 Alabama residents, or that derive 25% of their revenue from data sales involving any number of data subjects.observed
- ProbableIAPP — The Alabama Personal Data Protection Act exempts small businesses with fewer than 500 employees and nonprofits with fewer than 100 employees, unless they sell personal data, and also exempts defined political organizations.observed