State Guide
Alabama Privacy & Data Security Laws
Every statute below can apply to a business handling Alabama residents' data, depending on your revenue, the number of Alabama consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Newly enacted, not yet in force. No revenue-dollar threshold: applies if you process personal data of 25,000+ consumers (excluding payment-only data), or derive 25%+ of gross revenue from selling personal data regardless of consumer count. Nonprofit exemption is conditional (under 100 employees and no data sales), not automatic.
Data Security & Breach Notification · 1
Requires notifying affected residents (and often the state AG/regulator) after a breach of unencrypted personal information such as SSNs, driver's license/state ID numbers, or financial account numbers. Applies regardless of company size whenever you hold covered personal information about a resident of this state.
Children & Minors Online Safety · 1
Shifts age-verification and parental-consent duties to app stores; existing accounts must be categorized by Oct 1, 2027. Newly enacted — no litigation reported yet. Its eventual Code of Alabama 1975 chapter/section number is still not confirmed: the enrolled bill routes enforcement through the Deceptive Trade Practices Act (Title 8, Ch. 19, Ala. Code § 8-19-1 et seq.) rather than assigning the act's own substantive provisions a chapter, so there may be no separate codified cite to give. Signing date is triangulated, not primary — two independent legal-reference sources give Feb 17, 2026 while one contemporaneous news report gives Feb 18, 2026; the Alabama Secretary of State's act-detail record (arc-sos.state.al.us), which would settle both the date and the codification, has been unreachable at the host level, so the source link here is the Legislature's own enrolled text of HB 161 instead.