Laws & Regulations

State Privacy Laws: Florida

A summary of privacy laws in Florida.

Overview

Florida enacted the Florida Digital Bill of Rights (FDBR) in June 2023, establishing consumer data privacy protections with a distinctive focus on large technology companies. Unlike most state privacy laws, the FDBR sets a high revenue threshold, limiting its applicability to organizations with annual global gross revenues exceeding $1 billion, making it one of the narrowest comprehensive privacy laws in the country.

Key Dates

  • Signed into law: June 2023
  • Effective date: July 1, 2024

Thresholds

The FDBR applies to for-profit entities that conduct business in Florida, collect personal data about consumers, and have annual global gross revenues exceeding $1 billion. In addition, the entity must meet at least one of the following:

  • Derive 50% or more of global annual revenue from the sale of online advertisements; or
  • Operate a consumer smart speaker and voice command component service with an integrated virtual assistant; or
  • Operate an app store or digital distribution platform that offers at least 250,000 software applications for download.

Consumer Rights

  • The right to confirm whether a controller is processing personal data and to access that data.
  • The right to correct inaccuracies in personal data.
  • The right to delete personal data provided by, or obtained about, the consumer.
  • The right to obtain a copy of personal data in a portable and readily usable format.
  • The right to opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, or profiling.
  • The right to opt out of the collection of sensitive data, including precise geolocation data, and the collection of data through voice or facial recognition features.

Sensitive Data

The law defines sensitive data as personal data revealing:

  • Racial or ethnic origin
  • Religious beliefs
  • A mental or physical health condition or diagnosis
  • Sexual orientation
  • Citizenship or immigration status
  • Genetic or biometric data processed for the purpose of uniquely identifying an individual
  • Personal data of a child under 18 years of age
  • Precise geolocation data

Penalties

Up to $50,000 per violation. Penalties of up to $150,000 per violation apply to violations involving a consumer under 18, failure to delete or correct personal data after a request, or continued sale or sharing of data after an opt-out request.

Regions are used to customize the behavior and experience based on an individual user’s location. As an example, this allows you to provide different experiences to users based on regional differences (like GDPR in the EU vs. FDBR in Florida). When a user visits your site, we will automatically determine their location and will match them to the most granular region rule that you have setup in Concord. This can go down to the state/province level, which allows for different experiences for different laws (like FDBR in Florida).

Based on the current laws, we recommend the following regional settings:

  • Consent Mode: Implied
  • Blocking Mode: Strict
  • Google Consent Mode V2: Advanced
  • Consent Duration: 12 months
  • Enable Limit Sensitive Information: Enabled
  • Enable Do Not Sell Consent: Enabled
  • Enable Global Privacy Control: Enabled

For step-by-step instruction on how to configure your consent banner for different geographical regions within the Concord app, see our help document Configure Your Consent Banner for Different Geographical Regions.

While you can get as granular as you want, we typically recommend a single global policy that meets the strictest guidelines across regions, or higher splits (like separate GDPR and United States regions, only adding additional regions for stricter states like California if needed). If you have any questions on how and why to configure your regions in certain ways, please reach out to our support team.