Privacy Law Library

Insurance Data Security Law

AL IDSL

Data security · Breach notification · Financial

Alabama's version of the NAIC Insurance Data Security Model Law. Insurance licensees must maintain a risk-based written information security program, oversee vendors, investigate cybersecurity events, and notify the Commissioner within three business days of qualifying events. They must also follow the state breach notification act for consumer notices.

Where
Alabama
Citation
Ala. Code §§ 27-62-1 to 27-62-11 (Act 2019-98, SB54)
Status
In force
In force since
2019-05-01
Enforced by
Alabama Commissioner of Insurance (Department of Insurance)
People can sue
No
Penalties
Producers may be penalized under Ala. Code § 27-7-19; other licensees may have their license or certificate of authority suspended or revoked or, at the Commissioner's discretion, be fined up to $10,000 per violation.
Applies to
  • Licensees of the Alabama Department of Insurance (insurers, producers, and other licensed persons)
  • Third-party service providers that maintain, process, store, or access licensees' nonpublic information (through contract requirements)
  • Licensees with fewer than 25 employees, under $5 million gross annual revenue, or under $10 million year-end assets are exempt from the information security program section; HIPAA- and GLBA-compliant programs are deemed compliant

Security duties

  • Develop, implement, and maintain a comprehensive written information security program based on a risk assessment and commensurate with size, complexity, and data sensitivity, including controls such as multi-factor authentication where appropriate.Ala. Code § 27-62-4(a)-(d) · Only if: Not exempt under § 27-62-9
  • Exercise due diligence in selecting third-party service providers and require them to implement appropriate administrative, technical, and physical safeguards.Ala. Code § 27-62-4(f)
  • Maintain a written incident response plan; domestic insurers must certify compliance to the Commissioner annually by February 15.Ala. Code § 27-62-4(h)-(i)

Breach duties

  • Promptly investigate any cybersecurity event, restore security, and keep records of all cybersecurity events for at least five years.Ala. Code § 27-62-5
  • Notify the Commissioner within three business days of determining a qualifying cybersecurity event occurred (Alabama-domiciled or home-state licensee with likely material harm, or 250+ Alabama consumers affected), and update the notice as facts change.Ala. Code § 27-62-6(a)-(c)
  • Comply with the Alabama Data Breach Notification Act for consumer notices and give the Commissioner a copy; insurers must notify producers of record of affected consumers.Ala. Code § 27-62-6(d), (g)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Effective date May 1, 2019 is from the ALISON bill record for SB54 (2019RS). Phased compliance dates in Act 2019-98 § 14 were not confirmed.

Research reference, not legal advice.