Florida Information Protection Act of 2014
FIPA
Breach notification · Data security · Biometric · Location
Florida's data breach and data security law. It requires businesses to reasonably secure electronic personal information and dispose of customer records securely, and to notify affected Floridians and, for breaches affecting 500 or more Floridians, the Attorney General, within 30 days. Personal information includes biometric data and geolocation (added by SB 262, effective July 1, 2024).
- Where
- Florida
- Citation
- Fla. Stat. 501.171
- Status
- In force
- In force since
- 2014-07-01
- Last amended
- 2026-04-23
- Enforced by
- Florida Department of Legal Affairs (Attorney General)
- People can sue
- No
- Penalties
- Violations are unfair or deceptive trade practices in department actions. Failure to give required breach notice adds a civil penalty of $1,000 per day for the first 30 days, $50,000 for each later 30-day period up to 180 days, and up to $500,000 beyond 180 days, per breach (501.171(9)). No private cause of action (501.171(10)).
- Applies to
- Covered entities: commercial entities that acquire, maintain, store, or use personal information; state governmental entities for notice purposes (501.171(1)(b), (f))
- Third-party agents that maintain, store, or process personal information for a covered or governmental entity (501.171(1)(h))
What a privacy notice must say
- Individual notices must include the date or estimated date range of the breach, the personal information involved, and contact information for inquiries.Fla. Stat. 501.171(4)(e)
Security duties
- Dispose of customer records containing personal information, when no longer retained, by shredding, erasing, or otherwise making the information unreadable.Fla. Stat. 501.171(8)
- Take reasonable measures to protect and secure electronic data containing personal information.Fla. Stat. 501.171(2)
Breach duties
- Notify nationwide consumer reporting agencies without unreasonable delay when more than 1,000 individuals are notified at one time.Fla. Stat. 501.171(5) · Only if: More than 1,000 individuals notified
- Notify affected Florida individuals by mail or e-mail as expeditiously as practicable and no later than 30 days after determining a breach, unless law enforcement delays notice or a documented no-harm determination is made (and sent to the department within 30 days).Fla. Stat. 501.171(4)(a)-(d)
- Notify the Department of Legal Affairs within 30 days of any breach affecting 500 or more Floridians (15 more days for good cause), with a synopsis, number affected, services offered, a copy of the notice, and a contact.Fla. Stat. 501.171(3)(a)-(b) · Only if: Breaches affecting 500 or more individuals in Florida
- Third-party agents must notify the covered entity within 10 days of determining a breach of their system.Fla. Stat. 501.171(6)(a)
Sources
- Official text
- Fla. Stat. 501.171 (2026 Florida Statutes, Online Sunshine)
- Laws of Florida ch. 2023-201 (SB 262), s. 25 (adds biometric data and geolocation to personal information)
- Laws of Florida ch. 2026-52 (SB 7026), conforming amendment to s. 501.171(11)
- Laws of Florida ch. 2014-189 (effective July 1, 2014)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: last_amended reflects ch. 2026-52 (a conforming public-records change effective April 23, 2026); the last substantive change was ch. 2023-201, effective July 1, 2024.
Research reference, not legal advice.