Privacy Law Library

Florida Information Protection Act of 2014

FIPA

Breach notification · Data security · Biometric · Location

Florida's data breach and data security law. It requires businesses to reasonably secure electronic personal information and dispose of customer records securely, and to notify affected Floridians and, for breaches affecting 500 or more Floridians, the Attorney General, within 30 days. Personal information includes biometric data and geolocation (added by SB 262, effective July 1, 2024).

Where
Florida
Citation
Fla. Stat. 501.171
Status
In force
In force since
2014-07-01
Last amended
2026-04-23
Enforced by
Florida Department of Legal Affairs (Attorney General)
People can sue
No
Penalties
Violations are unfair or deceptive trade practices in department actions. Failure to give required breach notice adds a civil penalty of $1,000 per day for the first 30 days, $50,000 for each later 30-day period up to 180 days, and up to $500,000 beyond 180 days, per breach (501.171(9)). No private cause of action (501.171(10)).
Applies to
  • Covered entities: commercial entities that acquire, maintain, store, or use personal information; state governmental entities for notice purposes (501.171(1)(b), (f))
  • Third-party agents that maintain, store, or process personal information for a covered or governmental entity (501.171(1)(h))

What a privacy notice must say

  • Individual notices must include the date or estimated date range of the breach, the personal information involved, and contact information for inquiries.Fla. Stat. 501.171(4)(e)

Security duties

  • Dispose of customer records containing personal information, when no longer retained, by shredding, erasing, or otherwise making the information unreadable.Fla. Stat. 501.171(8)
  • Take reasonable measures to protect and secure electronic data containing personal information.Fla. Stat. 501.171(2)

Breach duties

  • Notify nationwide consumer reporting agencies without unreasonable delay when more than 1,000 individuals are notified at one time.Fla. Stat. 501.171(5) · Only if: More than 1,000 individuals notified
  • Notify affected Florida individuals by mail or e-mail as expeditiously as practicable and no later than 30 days after determining a breach, unless law enforcement delays notice or a documented no-harm determination is made (and sent to the department within 30 days).Fla. Stat. 501.171(4)(a)-(d)
  • Notify the Department of Legal Affairs within 30 days of any breach affecting 500 or more Floridians (15 more days for good cause), with a synopsis, number affected, services offered, a copy of the notice, and a contact.Fla. Stat. 501.171(3)(a)-(b) · Only if: Breaches affecting 500 or more individuals in Florida
  • Third-party agents must notify the covered entity within 10 days of determining a breach of their system.Fla. Stat. 501.171(6)(a)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: last_amended reflects ch. 2026-52 (a conforming public-records change effective April 23, 2026); the last substantive change was ch. 2023-201, effective July 1, 2024.

Research reference, not legal advice.