Skip to Main Content
U.S. Consumer Data Privacy Law Guide: Alabama

This state-specific guide covers data privacy law, rules, and regulations that professionals and clients often encounter or have questions about in Alabama.

Overview


Last updated: August 2026

Please note this is a highlighted overview and not a complete overview of privacy laws for this state. If you would like a complete review of this state's privacy laws or a multi-state privacy compliance cheat sheet on specific topics, please contact Vivien Peaden at vpeaden@bakerdonelson.com.

Disclaimer: These materials do not constitute legal advice and should not be substituted for the advice of legal counsel.

The Alabama Personal Data Protection Act (APDPA)

Effective Date: May 1, 2027 (Ala. HB351, § 12).

1. Applicability Thresholds:

Subject to entity-level and data-level exemptions, the APDPA applies to any person doing business in Alabama or producing products or services targeted to Alabama residents that meets at least one of the following criteria:

  • Controls or processes personal data of more than 25,000 Alabama consumers (excluding data processed solely to complete a payment transaction);
  • Derives 25 percent or more of gross revenue from the sale of personal data, regardless of the number of consumers.

2. Exemptions and Key Definitions:

  • Entity-level Exemptions: State government entities; certain state political action committees; institutions of higher education; certain entities subject to the Gramm-Leach-Bliley Act (GLBA) or HIPAA; certain small municipal corporations or non-profits with low employee headcounts that do not sell personal data; among others.
     
  • Data-level Exemptions: Certain data are exempt, including data collected in a commercial (B2B), employment, or benefits context; data covered by HIPAA and other health care-related or clinical research statutes; and data governed by the Family Educational Rights and Privacy Act (FERPA), the Fair Credit Reporting Act (FCRA), and the Driver's Privacy Protection Act (DPPA), among other exemptions.
     
  • Sales of Personal Data: Similar to California, "sales of personal data" is broadly defined as "the exchange of personal data for monetary consideration, or for other valuable consideration when the Controller receives a material benefit and the third party is not restricted in subsequent uses."
     
  • Sensitive Data: "Sensitive data" is defined broadly in the APDPA, including:
    • Data revealing racial or ethnic origin, religious belief, health data, sex life, sexual orientation, or immigration status;
    • Genetic or biometric data processed to uniquely identify an individual;
    • Personal data of children under the age of 13; and
    • Precise geolocation data (i.e., within a radius of 1,750 feet or less).

The APDPA requires Controllers to obtain consumer consent before processing sensitive data. For a known child, the data must be processed in accordance with the federal Children's Online Privacy Protection Act (COPPA).

3. Controller Obligations:

In addition to responding to various Consumer rights, a Controller must comply with the following responsibilities:

  • Data Processing Agreement (DPA): A written DPA between the Controller and Processor must govern the Processor's processing activities. The DPA must include clear processing instructions, the nature and duration of processing, and the types of data processed, among other requirements.
     
  • Data Protection Assessment: No. The APDPA does not contain an explicit data protection assessment requirement, a key distinction from other state privacy laws.
     
  • Privacy Notice: A Controller must provide consumers with a privacy notice that includes the purposes for processing; the categories of personal data shared with third parties; the categories of third parties with which data is shared; an active email address or other contact method; and how consumers may exercise their rights, including how to opt out.
     
  • Data Minimization and Purpose Limitation: The APDPA requires Controllers to limit collection of personal data to what is adequate, relevant, and reasonably necessary for the purposes of processing. Controllers may process personal data only for purposes that are reasonably necessary to or compatible with the disclosed purposes.

4. Consumer Rights:

Subject to certain exceptions, Alabama consumers have the following rights under the APDPA:

  • Confirm whether a Controller (including its agent) is processing their personal data and access the personal data, unless confirmation or access would require the Controller to reveal a trade secret;
  • Correct inaccuracies in the consumer's personal data;
  • Delete such consumer's personal data;
  • Obtain a copy of the personal data previously provided by the consumer to the Controller in a digital format (known as Data Portability), unless providing the data would require the Controller to reveal a trade secret; and
  • Opt out of processing of the consumer's personal data for targeted advertising, the sale of personal data, and profiling in furtherance of "solely automated significant decisions concerning the consumer."

5. Enforcement and Penalties:

Private Right of Action: None

Penalties: Up to $15,000 per violation.

Cure Period: 45-day cure period after the Controller receives a notice of violation from the Alabama Attorney General.

Email Disclaimer

NOTICE: The mailing of this email is not intended to create, and receipt of it does not constitute an attorney-client relationship. Anything that you send to anyone at our Firm will not be confidential or privileged unless we have agreed to represent you. If you send this email, you confirm that you have read and understand this notice.
Cancel Accept