{"id":403,"date":"2023-07-28T13:54:37","date_gmt":"2023-07-28T11:54:37","guid":{"rendered":"https:\/\/stage.usercentrics.com\/?post_type=knowledge&#038;p=31532"},"modified":"2025-06-26T13:08:09","modified_gmt":"2025-06-26T11:08:09","slug":"florida-digital-bill-of-rights-fdbr","status":"publish","type":"knowledge","link":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/florida-digital-bill-of-rights-fdbr\/","title":{"rendered":"Understanding the Florida Digital Bill of Rights (FDBR): A complete overview"},"content":{"rendered":"\n\n<h2 class=\"wp-block-heading\">Introduction to the Florida Digital Bill of Rights<\/h2>\n<p>Florida was the tenth state in the United States to pass a consumer privacy bill, <a href=\"https:\/\/www.flsenate.gov\/Session\/Bill\/2023\/262\/BillText\/er\/HTML\" target=\"_blank\" rel=\"noopener\">SB 262<\/a>, with an effective date of July 1, 2024. It\u2019s the fifth of six states to pass a privacy law in 2023. As of June 6, 2023, when the bill was passed, organizations have just over a year to prepare for FDBR compliance.<\/p>\n<p>Passage of comprehensive state-level privacy laws is gaining momentum in the United States in 2023, with Iowa, Indiana, Tennessee, Montana, Florida, and Texas all passing laws between March and June.<\/p>\n<p>The data privacy law passed in Florida differs in a number of respects from the other comprehensive state privacy laws passed in the US, with a focus on child protection, social media, and technology regulation. Several aspects, including compliance thresholds, appear to particularly target big tech companies. A federal data privacy law in the US has not been passed to date.<\/p>\n\n\n<h2 class=\"wp-block-heading\">What is the Florida data privacy act?<\/h2>\n<p>The <a href=\"https:\/\/www.flsenate.gov\/Session\/Bill\/2023\/262\/BillText\/er\/HTML\" target=\"_blank\" rel=\"noopener\">Florida Digital Bill of Rights (FDBR)<\/a> protects the digital privacy and personal data rights of Florida\u2019s more than 21 million residents, and establishes data privacy responsibilities for companies doing business in the state or providing goods or services targeting Florida residents. In the course of doing business these organizations process consumers\u2019 personal information. This law is a bit different from others passed in the US to date, however, with its focus on large tech companies, newer consumer technologies, and online social media platforms.<\/p>\n<p>Like other states with data privacy laws, Florida defines a consumer as a resident of or person living in the state who is acting in an individual or household context and not in a commercial or employment context.<\/p>\n<p>Like all the other comprehensive data privacy regulations passed in the US to date, the FDBR uses an opt-out model. Data subject consent is not required prior to data collection or processing in many cases. Businesses that are required to comply with the Florida privacy law must inform consumers about what data collection and processing they perform, what consumers\u2019 rights are, and how to exercise them.<\/p>\n<p>Notifications need to include what data is collected, for what purposes, third parties with whom the data is shared, etc. Businesses must provide consumers with ways to opt out of data collection and processing for several purposes: sale, targeted advertising, or profiling. Organizations (controllers) and any third parties they engage for data processing (processors) must also implement reasonable security and protections.<\/p>\n<p>For a few personal data uses, consumer consent does have to be obtained before data collection or processing. This includes personal data categorized as sensitive or data belonging to a known child. The Florida law differs from other states\u2019 laws in that the definition of a child applies to anyone under age 18, not under age 13, which is more common.<\/p>\n<h4>Definitions in the Florida Digital Bill of Rights<\/h4>\n<p><strong>Personal information \/ personal data<\/strong><\/p>\n<p>The FDBR includes definitions of both personal information and personal data. The definition of personal data has a specific purpose referencing children: \u201c<em>information that is linked or reasonably linkable to an identified or identifiable child, including biometric information and unique identifiers to the child<\/em>\u201d.<\/p>\n<p>The definition of personal data is a bit more detailed than in other US privacy laws: \u201c<em>any information, including sensitive data, which is linked or reasonably linkable to an identified or identifiable individual. The term includes pseudonymous data when the data is used by a controller or processor in conjunction with additional information that reasonably links the data to an identified or identifiable individual. The term does not include deidentified data or publicly available information.<\/em>\u201d<\/p>\n<p>The detail about use of <a href=\"https:\/\/usercentrics-poc.psapp.devknowledge-hub\/data-anonymization\/\">pseudonymous or anonymized data<\/a> in conjunction with other information to identify someone is interesting to note, especially as the definition also mentions that deidentified data \u2014 presumably which cannot be used to identify anyone \u2014 is not included.<\/p>\n<p><strong>Extension of the Florida Information Protection Act<\/strong><\/p>\n<p>Florida has had the <a href=\"http:\/\/www.leg.state.fl.us\/Statutes\/index.cfm?App_mode=Display_Statute&amp;URL=0500-0599\/0501\/Sections\/0501.171.html\" target=\"_blank\" rel=\"noopener\">Florida Information Protection Act (FIPA)<\/a> in effect since 2014, which defines and covers various kinds of data, including electronic information that commercial entities may store. That Act\u2019s requirements are fairly standard compared to the newer comprehensive data privacy laws in requirements for reasonable data protection, breach reporting, etc.<\/p>\n<p>The FDBR expands FIPA\u2019s definition of personal information, which already included standard examples like Social Security numbers, financial information, and personal contact information, to include newer technologies like biometric or geolocation data.<\/p>\n<p><strong>Consent<\/strong><\/p>\n<p>The European Union\u2019s <a href=\"https:\/\/usercentrics-poc.psapp.devgdpr\/\" target=\"_blank\" rel=\"noopener\">General Data Protection Regulation (GDPR)<\/a> set the standard for defining consent, which has been followed by many regulations passed since.<\/p>\n<p>Under the FDBR, consent is defined as: \u201c<em>a clear affirmative act signifying a consumer\u2019s freely given, specific, informed, and unambiguous agreement to process personal data relating to the consumer. The term includes a written statement, including a statement written by electronic means, or any other unambiguous affirmative act.<\/em>\u201d<\/p>\n<p>The Florida law, like<a href=\"https:\/\/usercentrics-poc.psapp.devknowledge-hub\/montana-consumer-data-privacy-act-mtcdpa\/\"> Montana\u2019s Consumer Data Privacy Act (MTCDPA)<\/a>, explicitly excludes these conditions from validly obtained consent, which are all in line with GDPR and other laws\u2019 requirements for consent to be \u201cfreely given, specific, informed and unambiguous\u201d:<\/p>\n<ul>\n<li>acceptance of a general or broad terms of use or similar document that contains descriptions of personal data processing along with other, unrelated information<\/li>\n<li>hovering over, muting, pausing, or closing a given piece of content<\/li>\n<li>agreement obtained through the use of <a href=\"https:\/\/usercentrics-poc.psapp.devknowledge-hub\/dark-patterns-and-how-they-affect-consent\/\">dark patterns<\/a><\/li>\n<\/ul>\n<p>Florida\u2019s privacy law, like <a href=\"https:\/\/usercentrics-poc.psapp.devknowledge-hub\/connecticut-data-privacy-act-ctdpa\/\">Connecticut\u2019s CTDPA<\/a> and Montana\u2019s MTCDPA, includes a requirement for consumers to be able to revoke their consent at any time.<\/p>\n<p><strong>Sensitive data \/ sensitive personal information<\/strong><\/p>\n<p>This definition covers more specific categories of personal information, particularly that which could cause harm if misused, including any of the following revealing:<\/p>\n<ul>\n<li>racial or ethnic origin<\/li>\n<li>religious beliefs<\/li>\n<li>mental or physical health diagnosis<\/li>\n<li>sexual orientation<\/li>\n<li>citizenship or immigration status<\/li>\n<li>genetic or biometric data processed for the purpose of uniquely identifying an individual<\/li>\n<li>from a known child (under 18 years of age)<\/li>\n<li>precise geolocation data (to within 1,750 feet \/ 533.4 meters)<\/li>\n<\/ul>\n<p><strong>Controller<\/strong><\/p>\n<p>The definition of controller is considerably longer and more detailed in Florida\u2019s law than in most. This is due to the number of requirements, and also because elements like compliance thresholds are built into the definition, which is unusual.<\/p>\n<p>To be defined as a controller an entity must meet the following requirements:<\/p>\n<ul>\n<li>a sole proprietorship, partnership, limited liability company, corporation, association, or legal entity that meets the following requirements:\n<ul>\n<li style=\"list-style-type: none\">\n<ul>\n<li>organized or operated for the profit or financial benefit of its shareholders or owners<\/li>\n<li>conducts business in Florida<\/li>\n<li>collects personal data about consumers, or is the entity on behalf of which such information is collected<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<li>determines the purposes and means of processing personal data about consumers alone or jointly with others<\/li>\n<li>makes in excess of $1 billion in global gross annual revenues<\/li>\n<li style=\"list-style-type: none\"><\/li>\n<\/ul>\n<p>The entity must also satisfy at least one of the following:<\/p>\n<ul>\n<li>derives 50 percent or more of its global gross annual revenues from the sale of advertisements online\n<ul>\n<li>including providing targeted advertising or the sale of ads online<\/li>\n<\/ul>\n<\/li>\n<li>operates a consumer smart speaker and voice command component service with an integrated virtual assistant connected to a cloud computing service that uses hands-free verbal activation\n<ul>\n<li>a consumer smart speaker and voice command component service does not include a motor vehicle or speaker or device associated with or connected to a vehicle which is operated by a motor vehicle manufacturer or a subsidiary or affiliate thereof<\/li>\n<\/ul>\n<\/li>\n<li>operates an app store or a digital distribution platform that offers at least 250,000 different software applications for consumers to download and install<\/li>\n<\/ul>\n<p><strong>Processor<\/strong><\/p>\n<p>For businesses that share personal data for processing purposes, the business will be the controller and the third-party entity will be the processor, defined in the Florida privacy bill as \u201c<em>a person who processes personal data on behalf of a controller.<\/em>\u201d<\/p>\n<p><strong>Sale of personal data<\/strong><\/p>\n<p>This is defined as \u201c<em>the sharing, disclosing, or transferring of personal data for monetary or other valuable consideration by the controller to a third party<\/em>.\u201d<\/p>\n<p>Disclosure of personal data to any of the following is not considered a sale:<\/p>\n<ul>\n<li>a processor who processes the personal data on the controller\u2019s behalf<\/li>\n<li>a third party for purposes of providing a product or service requested by the consumer<\/li>\n<li>information that the consumer:\n<ul>\n<li>intentionally made available to the general public through a mass media channel and did not restrict to a specific audience<\/li>\n<li>disclosed or transferred personal data to a third party as an asset that is part of a merger or an acquisition<\/li>\n<\/ul>\n<p>&nbsp;<\/li>\n<\/ul>\n<p><strong>Targeted advertising<\/strong><\/p>\n<p>Refers to \u201c<em>displaying to a consumer an advertisement selected based on personal data obtained from that consumer\u2019s activities over time across affiliated or unaffiliated websites and online applications used to predict the consumer\u2019s preferences or interests.<\/em>\u201d<\/p>\n<p>The term does not include ads that are \u201c<em>based on the context of a consumer\u2019s current search query on the controller\u2019s own website or online application, or directed to a consumer search query on the controller\u2019s own website or online application in response to the consumer\u2019s request for information or feedback.<\/em>\u201d<\/p>\n<p><strong>Surveillance<\/strong><\/p>\n<p>Surveillance is referenced regarding the use of assorted technologies, specifically: \u201c<em>a device that has a voice recognition feature, a facial recognition feature, a video recording feature, an audio recording feature, or any other electronic, visual, thermal, or olfactory feature that collects data may not use those features <strong>for the purpose of surveillance<\/strong> by the controller, processor, or affiliate of a controller or processor when such features are not in active use by the consumer, unless otherwise expressly authorized by the consumer.<\/em>\u201d<\/p>\n<p>However, the FDBR does not specifically include a definition of \u201csurveillance\u201d. This may be legally tricky for tech companies with products using these increasingly common \u201csmart\u201d technologies if and when they need to draft consumer privacy and consent notices.<\/p>\n\n\n<h2 class=\"wp-block-heading\">What is covered in the Florida data privacy law?<\/h2>\n<h4>Who has to comply with the Florida Digital Bill of Rights?<\/h4>\n<p>The FDBR applies to organizations conducting business in Florida, and any business that offers products or services targeted to Florida residents. As noted under the \u201ccontroller\u201d definition, the compliance requirements are a bit different and in some ways more targeted than many other US data privacy laws.<\/p>\n<p>Organizations have to comply with the FDBR if they:<\/p>\n<ul>\n<li>make more than US $1 billion in global gross annual revenue<\/li>\n<\/ul>\n<p>and at least one of:<\/p>\n<ul>\n<li>derives 50 percent or more of its global gross annual revenues from the sale of advertisements online, including providing targeted advertising or the sale of ads online<\/li>\n<li>operate a consumer smart speaker and voice command component service with an integrated virtual assistant connected to a cloud computing service that uses hands-free verbal activation\n<ul>\n<li>except that a consumer smart speaker and voice command component service does not include a motor vehicle or speaker or device associated with or connected to a vehicle which is operated by a motor vehicle manufacturer or a subsidiary or affiliate thereof<\/li>\n<\/ul>\n<\/li>\n<li>operates an app store or a digital distribution platform that offers at least 250,000 different software applications for consumers to download and install<\/li>\n<\/ul>\n<p>Of particular note here is the inclusion of US $1 billion in gross annual revenue as a threshold. This clearly targets larger companies, as other states\u2019 data privacy laws that include a revenue threshold, like the <a href=\"https:\/\/usercentrics-poc.psapp.devccpa\/\">California Privacy Rights Act (CPRA)<\/a>, set the threshold at only US $25 million. A number of the more recently passed laws, like <a href=\"https:\/\/usercentrics-poc.psapp.devknowledge-hub\/tennessee-information-protection-act-tips\/\">Tennessee\u2019s Information Protection Act (TIPA)<\/a>, have no revenue-only threshold for compliance.<\/p>\n<p>There are currently fewer than 6,000 businesses operating in Florida that meet the more than US $1 billion revenue threshold. Add in any of the other criteria and the number of organizations needing to comply would shrink even further.<\/p>\n<p>Other line items also appear to target certain large tech companies that earn their revenue from ad sales, operate smart speakers or tech incorporating voice commands, and operate app stores or other digital distribution platforms. These requirements are not included in any other US state privacy law, and would apply to companies like Apple and Google that offer those technologies and run popular app stores.<\/p>\n<h4>Exemptions to Florida Digital Bill of Rights compliance<\/h4>\n<p>The exemptions in the Florida data protection law are fairly consistent with the other existing US data privacy laws, deferring mainly to existing federal laws, including:<\/p>\n<ul>\n<li>Health Insurance Portability and Accountability Act (HIPAA)<\/li>\n<li>Health Information Technology for Economic and Clinical Health Act<\/li>\n<li>Patient Safety and Quality Improvement Act<\/li>\n<li>Fair Credit Reporting Act (FCRA)<\/li>\n<li>Children\u2019s Online Privacy Protection Act (COPPA)<\/li>\n<li>Family Educational Rights and Privacy Act (FERPA)<\/li>\n<li>Driver\u2019s Privacy Protection Act<\/li>\n<li>Farm Credit Act (FCA)<\/li>\n<li>Airline Deregulation Act<\/li>\n<\/ul>\n<p>Other exemptions include HR data, health records, data for providing financial services, research data for human subjects that are covered by other federal laws or standards, and data that is processed or maintained for employment-related purposes.<\/p>\n<p>Exempted institutions include:<\/p>\n<ul>\n<li style=\"list-style-type: none\">\n<ul>\n<li>state government agencies<\/li>\n<li>financial institutions (also entities and affiliates subject to the Gramm-Leach-Bliley Act)<\/li>\n<li>insurance companies<\/li>\n<li>postsecondary education institutions<\/li>\n<li>nonprofit organizations<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n<h2 class=\"wp-block-heading\">Consumers\u2019 rights under the Florida Digital Bill of Rights<\/h2>\n<p>Consumers have a number of rights under the new digital bill:<\/p>\n<ul>\n<li><strong>Right to access<\/strong>: confirmation if the controller is processing the consumer\u2019s personal information and access to that data, with some exceptions<\/li>\n<li><strong>Right to correction<\/strong>: any inaccurate or outdated information the controller has that was provided by the consumer<\/li>\n<li><strong>Right to delete<\/strong>: any personal data the controller has about or from the consumer, with some exceptions<\/li>\n<li><strong>Right to portability<\/strong>: obtain a copy of the consumer\u2019s personal data that the consumer previously provided to the controller, in a readily usable format, with some exceptions<\/li>\n<li><strong>Right not to be discriminated against<\/strong>: controllers cannot unlawfully discriminate against consumers, including for exercising their rights<\/li>\n<li><strong>Right to opt out<\/strong>:\n<ul>\n<li>sale of personal data<\/li>\n<li>targeted advertising<\/li>\n<li>certain profiling \u201c<em>in furtherance of a decision that produces a legal or similarly significant effect concerning a consumer<\/em>\u201d<\/li>\n<li>collection or processing of sensitive data<\/li>\n<li>collection of personal data through the operation of a voice recognition or facial recognition feature<\/li>\n<\/ul>\n<p>&nbsp;<\/li>\n<\/ul>\n<p>Parents or guardians can exercise these rights on behalf of children. Like all other US data privacy laws except California\u2019s, the Florida Digital Bill of Rights does not enable private right of action, which would allow consumers to sue violators. Interestingly, a previous data privacy bill in Florida that failed in 2021 did include private right of action.<\/p>\n\n\n<h2 class=\"wp-block-heading\">How does the new Florida data protection act affect businesses?<\/h2>\n<h4>How to comply with the Florida data privacy law<\/h4>\n<p>Controllers must notify consumers of their rights and ways that consumers can exercise those rights by submitting a verifiable request to the company. Controllers must supply at least two means of contact that are secure and consistent with normal ways in which consumers would contact the organization. The controller must also include clear information on how to exercise consumer rights in their privacy notice or policy page on their website.<\/p>\n<p>After a consumer\u2019s authenticated request is received, the controller has 45 days to respond. There are some limited reasons that they can decline to act on the request, including if the consumer\u2019s identity cannot be reasonably verified or if the consumer submits an excessive number of requests in a 12-month period.<\/p>\n<p>If there are extenuating circumstances preventing fulfilling a consumer request, once the consumer has been notified that response period can be extended by 15 days if reasonably necessary. Controllers must inform consumers within 60 days of receiving a request to notify them that it has been fulfilled.<\/p>\n<p>If a controller denies a request, the consumer can appeal such a decision, and the controller has to provide information on how to do so. The controller has 60 days to respond to appeals.<\/p>\n<p><strong>Purpose limitation<\/strong><\/p>\n<p>Controllers can process personal data for the purpose(s) that they have communicated, as long as the processing is \u201c<em>adequate, relevant, and reasonably necessary<\/em>\u201d and proportional to those purposes.<\/p>\n<p><strong>Data security<\/strong><\/p>\n<p>Controllers must protect personal data by establishing, implementing and maintaining reasonable administrative, technical, and physical security measures. These measures should be appropriate to the nature and volume of personal information being processed.<\/p>\n<p><strong>Data protection assessments (DPA)<\/strong><\/p>\n<p>Controllers must conduct and document data protection assessments when they process information:<\/p>\n<ul>\n<li>for the purposes of targeted advertising<\/li>\n<li>to sell the personal data<\/li>\n<li>categorized as sensitive personal data<\/li>\n<li>for the purposes of profiling if there is a reasonably foreseeable or heightened risk of harm to consumers<\/li>\n<\/ul>\n<p>The Attorney General can request a DPA from a controller, typically for the purposes of investigating an alleged violation.<\/p>\n<p><strong>Consent requirements<\/strong><\/p>\n<p>Like other US states that have passed privacy laws, Florida uses an opt-out model, so user consent is not required before collecting and processing personal data in many cases. The exception is that consent must be obtained before collecting or processing sensitive personal data. Consumers must be given clear notice about processing and be able to opt out of sale, targeted advertising, profiling, or data collection via face or voice recognition.<\/p>\n<p>Where children are concerned, the FDBR follows the federal <a href=\"\/knowledge-hub\/childrens-online-privacy-protection-act-coppa\/\">Children\u2019s Online Privacy Protection Act (COPPA)<\/a>. Consent from any known child\u2019s parent or guardian must be obtained before processing any personal data of any user known to be a child. This would include all children\u2019s personal data, as under Florida\u2019s data privacy regulation data of children under 18 is classified as sensitive by default. The FDBR pays particular attention to the protection of children, so has expanded the age range up to when children become legal adults.<\/p>\n<p><strong>Nondiscrimination<\/strong><\/p>\n<p>Controllers are prohibited from unlawful discrimination against consumers, and from processing personal data if doing so is in violation of state or federal laws governing discrimination. Controllers cannot discriminate against consumers for exercising their rights. For example, a consumer cannot be blocked from accessing a website if they opt out of allowing personal information collection.<\/p>\n<p>However, there are often website features or functions that will not work without certain trackers being active, so if a consumer does not opt in to their use because they collect personal information, the site may not work optimally. This is not discriminatory.<\/p>\n<p>Controllers can offer voluntary incentives like discounts for consumers\u2019 voluntary participation in operations like an organization\u2019s loyalty program or signing up for a newsletter, where these operations collect and process personal data. Such offers have to be reasonable, as data protection authorities tend to frown on disproportionate incentives as they start to look like bribes.<\/p>\n<p><strong>Transparency<\/strong><\/p>\n<p>Controllers must provide consumers with clear and accessible information about data processing. Commonly this appears on the company\u2019s website in a privacy notice or policy. Under the FDBR, this information must include:<\/p>\n<ul>\n<li>categories of personal data processed by the controller, including sensitive data, if any<\/li>\n<li>purpose(s) for processing personal data\n<ul>\n<li>a controller may not collect different or additional categories of personal data, or use personal data collected for different or additional purposes than those stated, without notifying the consumer<\/li>\n<\/ul>\n<\/li>\n<li>how consumers may contact the controller, exercise their rights and\/or appeal a controller&#8217;s decision (e.g. if a request for access is denied)<\/li>\n<li>categories of personal data that the controller sells to or shares with third parties, if any\n<ul>\n<li>if a controller sells sensitive data, they must post the following: \u201c<em>NOTICE: This website may sell your sensitive personal data.<\/em>\u201d<\/li>\n<li>if a controller sells biometric data, they must post the following: \u201c<em>NOTICE: This website may sell your biometric personal data.<\/em>\u201d<\/li>\n<li>if a controller sells personal data to third parties or processes personal data for targeted advertising, the controller must clearly and conspicuously disclose that process<\/li>\n<\/ul>\n<\/li>\n<li>categories of third parties to whom the controller sells to or shares personal data, if any<\/li>\n<li>the right to opt out of the sale of personal data to third parties or processing personal data for targeted advertising or profiling and how to exercise it, including contact methods<\/li>\n<\/ul>\n<p><strong>Third party contracts<\/strong><\/p>\n<p>Controllers must have contracts in place with third-party processors (service providers) with clear information about:<\/p>\n<ul>\n<li>duty of confidentiality<\/li>\n<li>instructions for processing data<\/li>\n<li>nature and purpose of processing<\/li>\n<li>type of data subject to processing<\/li>\n<li>duration of processing<\/li>\n<li>rights and obligations of both parties<\/li>\n<\/ul>\n<p><strong>Universal opt-out signal<\/strong><\/p>\n<p>The Florida Digital Bill of Rights, like some other state-level data privacy laws, including <a href=\"https:\/\/usercentrics-poc.psapp.devknowledge-hub\/indiana-consumer-data-protection-act-cdpa\/\">Indiana\u2019s Consumer Data Protection Act (Indiana CDPA)<\/a> and Tennessee\u2019s, does not reference the <a href=\"https:\/\/usercentrics-poc.psapp.devccpa\/\">Global Privacy Control<\/a> (GPC) \u201cuniversal opt-out\u201d or similar mechanism.<\/p>\n<p>The GPC is intended to standardize user consent online. Using it enables consumers to create a single set of their own personal data privacy consent preferences. These settings can then be communicated to all websites or apps that consumers visit, so users don\u2019t have to set new preferences on every site. Use of this mechanism also helps ensure compliance with consumer privacy laws relevant to each user.<\/p>\n\n\n<h2 class=\"wp-block-heading\">What happens if you break the Florida data protection law?<\/h2>\n<h4>Enforcement<\/h4>\n<p>In Florida, the Attorney General and the Department of Legal Affairs have exclusive enforcement authority for the FDBR. As noted, the law does not provide consumers with private right of action, but they can report alleged violations or complaints about denial of requests to the Attorney General\u2019s office. The Attorney General must provide parties with alleged violations against them with written notice that lists the violations.<\/p>\n<p>As with the <a href=\"https:\/\/usercentrics-poc.psapp.devknowledge-hub\/colorado-privacy-act\/\">Colorado Privacy Act (CPA)<\/a>, violations of the FDBR are considered deceptive trade practices.<\/p>\n<h4>Cure period and controller actions<\/h4>\n<p>After being notified by the Attorney General in writing, a 45-day cure period may be granted when organizations can fix issues and take steps to prevent recurrence, without suffering penalties. If the organization does \u201ccure\u201d issues to the Attorney General\u2019s satisfaction and provides written notification, while they may not be financially penalized, they may receive a letter of guidance stating that they will not receive a cure period for any future violation.<\/p>\n<p>If a violation involves a known child, the cure period does not apply. The Department of Legal Affairs will also consider conditions like the number and severity of violations before deciding if a cure period will be allowed.<\/p>\n<p>Cure periods in other state-level data privacy laws range from 30 to 90 days. The Florida Digital Bill of Rights does not include any provision to sunset the cure period after a year or two, as some other states\u2019 data privacy laws do.<\/p>\n<h4>Fines and penalties<\/h4>\n<p>If the controller or any of their data processors are still in violation after the cure period, or after submitting their statement, the Attorney General can initiate investigative actions and levy penalties of up to US $50,000 per violation. Penalties can be tripled if:<\/p>\n<ul>\n<li>the violation is against a known child<\/li>\n<li>a controller fails to delete personal data after receiving an authenticated consumer request (or a processor receives instructions to do so from a controller)<\/li>\n<li>a controller continues to sell or share a consumer\u2019s personal data after the consumer has opted out<\/li>\n<\/ul>\n\n\n<h2 class=\"wp-block-heading\">Prohibition of government censorship under Florida\u2019s Digital Bill of Rights<\/h2>\n<p>Under the new section of the statutes, the FDBR is also a social media law, dictating that no government entity can request that a social media platform remove content or user accounts unless the content or account is used to commit a crime or otherwise violates Florida public records law.<\/p>\n<p>This prohibition could make it possible to use online social media platforms to promote content that could be considered to violate other state-level content restriction laws like the <a href=\"https:\/\/laws.flrules.org\/2023\/105\" target=\"_blank\" rel=\"noopener\">Parental Rights in Education Law<\/a>.<\/p>\n<p>The definition of \u201csocial media platform\u201d is also quite broad: \u201c<em>a form of electronic communication through which users create online communities or groups to share information, ideas, personal messages, and other content.<\/em>\u201d This could also create some legal quandaries in practice.<\/p>\n\n\n<h2 class=\"wp-block-heading\">Protection of children under the Florida Digital Bill of Rights<\/h2>\n<p>The FDBR includes more specific information about children and requirements for protecting them, particularly online, than other US data privacy laws. In addition to defining children as anyone up to age 18, the law triples the potential financial penalties for violations affecting known children.<\/p>\n<p>The definitions section of the law also has an extensive entry for \u201c<em>substantial harm or privacy risk to children\u201d, with many examples of types of harm outlined, ways children\u2019s data cannot be collected or used, and prohibitions specifically for any \u201conline platform that provides an online service, product, game, or feature likely to be predominantly accessed by children\u201d<\/em>.<\/p>\n\n\n<h2 class=\"wp-block-heading\">The Florida Digital Bill of Rights and consent management<\/h2>\n<p>Florida\u2019s consumer privacy law only requires prior consent where sensitive personal data and children\u2019s data are concerned. Penalties for knowingly processing children\u2019s data without consent are triple the baseline penalty for data privacy violations under the law.<\/p>\n<p>Consumers do have to be provided with the option of opting out of collection and processing of their personal data for sale, targeted advertising, or profiling at any point. Information about that must be provided on the website, typically under the privacy notice\/policy page. Penalties for not complying with consumer\u2019s valid opt-out requests can also be tripled from the standard fine.<\/p>\n<p>The mechanism to enable users to opt out of data processing can be presented in a banner and displayed, most commonly as a link or button. A consent management platform (CMP) like Usercentrics\u2019 also helps to automate detection of the cookies and other tracking technologies in use on websites and apps. Use of a CMP streamlines collecting and providing the information to users about categories of data and specific services in use by the controller and\/or processor(s), and third parties with whom data is shared. Florida\u2019s privacy law, and most data privacy regulations around the world, require this notification.<\/p>\n<p>Because the United States does not have a single federal data privacy law, companies doing business across the country and\/or with other countries may need to comply with multiple consumer privacy laws to protect data. (Learn more: <a href=\"https:\/\/usercentrics-poc.psapp.devknowledge-hub\/comparison-guide-to-us-state-level-data-privacy-laws\/\">Comparing US state-level data privacy laws<\/a>) A CMP can make this easier by enabling banner customization and geotargeting. Data processing, consent information and choices for specific regulations can be presented based on specific user location. Geotargeting can also improve clarity and user experience by presenting this information in the user\u2019s preferred language.<\/p>\n\n\n<div class=\"uc-notice\">\n    <div class=\"uc-notice__icon\">\n        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M10.8177 17.0093H12.8177V11.0093H10.8177V17.0093ZM11.8177 9.00928C12.1011 9.00928 12.3386 8.91344 12.5302 8.72178C12.7219 8.53011 12.8177 8.29261 12.8177 8.00928C12.8177 7.72594 12.7219 7.48844 12.5302 7.29678C12.3386 7.10511 12.1011 7.00928 11.8177 7.00928C11.5344 7.00928 11.2969 7.10511 11.1052 7.29678C10.9136 7.48844 10.8177 7.72594 10.8177 8.00928C10.8177 8.29261 10.9136 8.53011 11.1052 8.72178C11.2969 8.91344 11.5344 9.00928 11.8177 9.00928ZM11.8177 22.0093C10.4344 22.0093 9.13442 21.7468 7.91775 21.2218C6.70108 20.6968 5.64275 19.9843 4.74275 19.0843C3.84275 18.1843 3.13025 17.1259 2.60525 15.9093C2.08025 14.6926 1.81775 13.3926 1.81775 12.0093C1.81775 10.6259 2.08025 9.32594 2.60525 8.10928C3.13025 6.89261 3.84275 5.83428 4.74275 4.93428C5.64275 4.03428 6.70108 3.32178 7.91775 2.79678C9.13442 2.27178 10.4344 2.00928 11.8177 2.00928C13.2011 2.00928 14.5011 2.27178 15.7177 2.79678C16.9344 3.32178 17.9928 4.03428 18.8927 4.93428C19.7927 5.83428 20.5052 6.89261 21.0302 8.10928C21.5552 9.32594 21.8177 10.6259 21.8177 12.0093C21.8177 13.3926 21.5552 14.6926 21.0302 15.9093C20.5052 17.1259 19.7927 18.1843 18.8927 19.0843C17.9928 19.9843 16.9344 20.6968 15.7177 21.2218C14.5011 21.7468 13.2011 22.0093 11.8177 22.0093Z\" fill=\"black\"\/>\n<\/svg>\n    <\/div>\n    <div class=\"uc-notice__content\">\n                <p><strong>Check out our on-demand webinar:<\/strong> <a href=\"https:\/\/usercentrics-poc.psapp.devwebinar\/us-data-privacy-legislations\/\">US Data Privacy Legislations<\/a><\/p>\n            <\/div>\n<\/div>\n\n\n\n\n<p>This will enable companies to achieve FDBR compliance, as well as other current and upcoming regulations across the United States. For companies doing business internationally, using a consent management platform also enables compliance with regulations like the European Union\u2019s <a href=\"https:\/\/usercentrics-poc.psapp.devknowledge-hub\/the-eu-general-data-protection-regulation\/\">GDPR<\/a>, which has more strict consent management requirements than the laws in the US.<\/p>\n\n\n<h2 class=\"wp-block-heading\">Preparing for the Florida Digital Bill of Rights<\/h2>\n<p>Organizations doing business in Florida have until July 1, 2024 to prepare for compliance with the FDBR. If they have already achieved compliance with other state-level data privacy laws in the US, like Connecticut\u2019s, a good portion of the work is already done. However, special attention should be paid to the differences with Florida\u2019s law, especially as they pertain to protection of children, government censorship, and compliance thresholds.<\/p>\n<p>As always, a <a href=\"https:\/\/usercentrics-poc.psapp.devknowledge-hub\/what-is-privacy-by-design\/\">privacy by design<\/a> approach will benefit all operations in an organization, whether specifically for regulatory compliance or not.<\/p>\n<p>Achieving FDBR compliance will mainly be a matter of confirming the Florida privacy law\u2019s specific requirements and having a solution in place to provide users with the necessary notifications and opt-out options. The Usercentrics Consent Management Platform (CMP) can help with cookie and tracking notification and management.<\/p>\n<p>Updates to the FDBR are likely over time, as these US regulations are all in their first version, and both technology and consumer expectations are rapidly changing. The FDBR does not include private right of action, so consumer class-actions lawsuits will not be a potential influence on future amendments to Florida\u2019s privacy law as they may be in California.<\/p>\n<p>Eventual case law may also clarify some of the law\u2019s requirements or prohibitions, especially as they pertain to newer technologies for facial or voice recognition or audio recording, or operation of social media platforms.<\/p>\n<p>Consulting qualified legal counsel and\/or your organization\u2019s data privacy expert, like a Data Protection Officer, is recommended to ensure responsibilities are met.<\/p>\n<p>Beyond just meeting requirements, being proactive about protecting user privacy is a valuable business effort. It builds user trust and engagement, provides better user experiences, and strengthens customer relationships long-term.<\/p>\n<p>If you have questions or interest in implementing a consent management platform to help achieve compliance with privacy laws in the United States and around the world, <a href=\"https:\/\/usercentrics-poc.psapp.devbook-a-consultation\/\">talk to one of our experts<\/a>.<\/p>\n<p><em>Usercentrics does not provide legal advice, and information is provided for educational purposes only. We always recommend engaging qualified legal counsel or privacy specialists regarding data privacy and protection issues and operations.<\/em><\/p>\n\n\n","protected":false},"excerpt":{"rendered":"<p>The Florida Digital Bill of Rights is the tenth state-level data privacy law passed in the United States, with a critical focus on online social media platforms and the protection of children.<\/p>\n","protected":false},"featured_media":2156,"template":"","meta":{"_acf_changed":false,"editor_notices":[],"footnotes":""},"tags":[],"magazine_issue":[],"magazine_tag":[],"resource_tag":[14,13],"class_list":["post-403","knowledge","type-knowledge","status-publish","has-post-thumbnail","hentry","resource_tag-privacy","resource_tag-regulations"],"acf":[],"yoast_head":"<title>Understanding the Florida Digital Bill of Rights: Key Protections for Consumer Privacy | Usercentrics<\/title>\n<meta name=\"description\" content=\"Discover the Florida Digital Bill of Rights, a law giving residents privacy rights, data access, and opt-out options to manage their digital information.\" \/>\n<meta name=\"robots\" content=\"noindex, follow\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The Florida Digital Bill of Rights - Usercentrics\" \/>\n<meta property=\"og:description\" content=\"Usercentrics explains the Florida Digital Bill of Rights (FDBR) and what the Florida privacy law means for consumers and companies. Find out more today.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/florida-digital-bill-of-rights-fdbr\/\" \/>\n<meta property=\"og:site_name\" content=\"Usercentrics - US\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/usercentrics\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-26T11:08:09+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/usercentrics-poc.psapp.devwp-content\/uploads\/2023\/07\/florida_consumer.png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"The Florida Digital Bill of Rights - Usercentrics\" \/>\n<meta name=\"twitter:description\" content=\"Usercentrics explains the Florida Digital Bill of Rights (FDBR) and what the Florida privacy law means for consumers and companies. Find out more today.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/usercentrics-poc.psapp.devwp-content\/uploads\/2023\/07\/florida_consumer.png\" \/>\n<meta name=\"twitter:site\" content=\"@usercentrics\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"21 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/florida-digital-bill-of-rights-fdbr\/\",\"url\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/florida-digital-bill-of-rights-fdbr\/\",\"name\":\"Understanding the Florida Digital Bill of Rights: Key Protections for Consumer Privacy | Usercentrics\",\"isPartOf\":{\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/florida-digital-bill-of-rights-fdbr\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/florida-digital-bill-of-rights-fdbr\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2023\/07\/florida_consumer.svg?v=1776852039\",\"datePublished\":\"2023-07-28T11:54:37+00:00\",\"dateModified\":\"2025-06-26T11:08:09+00:00\",\"description\":\"Discover the Florida Digital Bill of Rights, a law giving residents privacy rights, data access, and opt-out options to manage their digital information.\",\"breadcrumb\":{\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/florida-digital-bill-of-rights-fdbr\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/florida-digital-bill-of-rights-fdbr\/\"}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/florida-digital-bill-of-rights-fdbr\/#primaryimage\",\"url\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2023\/07\/florida_consumer.svg?v=1776852039\",\"contentUrl\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2023\/07\/florida_consumer.svg?v=1776852039\",\"copyrightNotice\":\"\u00a9 Copyright 2026 Usercentrics GmbH\",\"creator\":{\"@type\":\"Organization\",\"name\":\"Usercentrics GmbH\"},\"creditText\":\"Image: Usercentrics GmbH\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/florida-digital-bill-of-rights-fdbr\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Resources\",\"item\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/resources\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Blog\",\"item\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Understanding the Florida Digital Bill of Rights (FDBR): A complete overview\",\"item\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/florida-digital-bill-of-rights-fdbr\/\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/#website\",\"url\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/\",\"name\":\"Usercentrics - US\",\"description\":\"Consent Management Platform (CMP) Usercentrics\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/?s={search_term_string}\"}}],\"inLanguage\":\"en-US\"}]}<\/script>","yoast_head_json":{"title":"Understanding the Florida Digital Bill of Rights: Key Protections for Consumer Privacy | Usercentrics","description":"Discover the Florida Digital Bill of Rights, a law giving residents privacy rights, data access, and opt-out options to manage their digital information.","robots":{"index":"noindex","follow":"follow"},"og_locale":"en_US","og_type":"article","og_title":"The Florida Digital Bill of Rights - Usercentrics","og_description":"Usercentrics explains the Florida Digital Bill of Rights (FDBR) and what the Florida privacy law means for consumers and companies. Find out more today.","og_url":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/florida-digital-bill-of-rights-fdbr\/","og_site_name":"Usercentrics - US","article_publisher":"https:\/\/www.facebook.com\/usercentrics","article_modified_time":"2025-06-26T11:08:09+00:00","og_image":[{"url":"https:\/\/usercentrics-poc.psapp.devwp-content\/uploads\/2023\/07\/florida_consumer.png","type":"","width":"","height":""}],"twitter_card":"summary_large_image","twitter_title":"The Florida Digital Bill of Rights - Usercentrics","twitter_description":"Usercentrics explains the Florida Digital Bill of Rights (FDBR) and what the Florida privacy law means for consumers and companies. Find out more today.","twitter_image":"https:\/\/usercentrics-poc.psapp.devwp-content\/uploads\/2023\/07\/florida_consumer.png","twitter_site":"@usercentrics","twitter_misc":{"Est. reading time":"21 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/florida-digital-bill-of-rights-fdbr\/","url":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/florida-digital-bill-of-rights-fdbr\/","name":"Understanding the Florida Digital Bill of Rights: Key Protections for Consumer Privacy | Usercentrics","isPartOf":{"@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/#website"},"primaryImageOfPage":{"@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/florida-digital-bill-of-rights-fdbr\/#primaryimage"},"image":{"@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/florida-digital-bill-of-rights-fdbr\/#primaryimage"},"thumbnailUrl":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2023\/07\/florida_consumer.svg?v=1776852039","datePublished":"2023-07-28T11:54:37+00:00","dateModified":"2025-06-26T11:08:09+00:00","description":"Discover the Florida Digital Bill of Rights, a law giving residents privacy rights, data access, and opt-out options to manage their digital information.","breadcrumb":{"@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/florida-digital-bill-of-rights-fdbr\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/florida-digital-bill-of-rights-fdbr\/"}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/florida-digital-bill-of-rights-fdbr\/#primaryimage","url":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2023\/07\/florida_consumer.svg?v=1776852039","contentUrl":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2023\/07\/florida_consumer.svg?v=1776852039","copyrightNotice":"\u00a9 Copyright 2026 Usercentrics GmbH","creator":{"@type":"Organization","name":"Usercentrics GmbH"},"creditText":"Image: Usercentrics GmbH"},{"@type":"BreadcrumbList","@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/florida-digital-bill-of-rights-fdbr\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https:\/\/usercentrics-poc.psapp.dev\/us\/resources\/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/"},{"@type":"ListItem","position":3,"name":"Understanding the Florida Digital Bill of Rights (FDBR): A complete overview","item":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/florida-digital-bill-of-rights-fdbr\/"}]},{"@type":"WebSite","@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/#website","url":"https:\/\/usercentrics-poc.psapp.dev\/us\/","name":"Usercentrics - US","description":"Consent Management Platform (CMP) Usercentrics","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/usercentrics-poc.psapp.dev\/us\/?s={search_term_string}"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/knowledge\/403","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/knowledge"}],"about":[{"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/types\/knowledge"}],"version-history":[{"count":0,"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/knowledge\/403\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/media\/2156"}],"wp:attachment":[{"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/media?parent=403"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/tags?post=403"},{"taxonomy":"magazine_issue","embeddable":true,"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/magazine_issue?post=403"},{"taxonomy":"magazine_tag","embeddable":true,"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/magazine_tag?post=403"},{"taxonomy":"resource_tag","embeddable":true,"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/resource_tag?post=403"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}