Alabama Personal Data Protection Act What Businesses Should Know

Alabama business owners reviewing data privacy compliance documents

Alabama businesses that collect information about customers are facing an important new privacy requirement. The Alabama Personal Data Protection Act creates consumer rights involving personal information and establishes duties for certain companies that control or process that data.

Alabama enacted the law through House Bill 351, which became Act 2026-552. The law takes effect on May 1, 2027. That date gives affected businesses time to examine their websites, privacy notices, advertising practices, customer databases, vendor relationships, and information security procedures.

The new law does not apply to every Alabama organization. Coverage depends on factors such as the amount of consumer data processed, revenue from data sales, business size, and statutory exemptions. Companies should evaluate their operations carefully rather than assuming they fall inside or outside the statute.

What Is the Alabama Personal Data Protection Act?

The Alabama Personal Data Protection Act is a comprehensive state privacy statute governing certain uses of personal data.

Its basic purpose is to give Alabama consumers greater control over information connected with them. It also establishes responsibilities for businesses that decide why and how personal data is processed.

The Alabama Secretary of State identifies House Bill 351 as Act 2026-552 and describes the legislation as regulating personal data processing and consumer actions involving that data.

The law uses the term “controller” for a person or entity that determines the purposes and means of processing personal data. A processor generally handles information on behalf of a controller.

Business data inventory and privacy compliance records in Alabama

What Counts as Personal Data?

The statute broadly defines personal data as information linked or reasonably linkable to an identified or identifiable person. Publicly available information and qualifying deidentified data fall outside that definition.

Personal data can include names, account information, online identifiers, purchase histories, location information, contact details, and other records connected with an individual.

Businesses should begin by determining what information they collect and why they collect it. This review may include websites, customer relationship systems, advertising platforms, mobile applications, payment systems, email marketing tools, and third party vendors.

Companies already reviewing electronic information can also read our article on digital assets and online information for broader discussion of digital records and account management.

Which Alabama Businesses May Be Covered?

The statute generally applies to persons conducting business in Alabama or offering products or services targeted to Alabama residents when specified thresholds are met.

One threshold applies when an organization controls or processes personal information involving more than 25,000 consumers. Personal data processed only to complete payment transactions is excluded from that calculation.

Another threshold applies when a person derives more than 25 percent of gross revenue from selling personal data. This threshold does not depend on a minimum consumer count.

However, the law contains numerous exemptions. Businesses with fewer than 500 employees are exempt when they do not sell personal data. Certain nonprofits with fewer than 100 employees receive a similar exemption.

The statute also contains exemptions affecting financial institutions, certain health care organizations, higher education institutions, political organizations, and specific categories of federally regulated information.

What Rights Do Alabama Consumers Receive?

The new privacy law gives qualifying Alabama consumers several ways to control their personal information.

  • Confirm whether a business is processing their personal data and obtain access when applicable.
  • Request correction of inaccurate personal information.
  • Request deletion of personal data.
  • Obtain certain information in a portable and usable format.
  • Opt out of targeted advertising.
  • Opt out of qualifying sales of personal data.
  • Opt out of profiling used for solely automated significant decisions.

Controllers generally have 45 days to respond to authenticated requests. The statute permits an additional 45 days when reasonably necessary because of complexity or request volume.

A business needs a secure and reliable method for consumers to exercise these rights. The method should also appear in the company’s privacy notice.

Businesses May Need Clearer Privacy Notices

A privacy policy should not exist solely because a website template includes one. Covered businesses need to review whether their notices accurately describe actual data practices.

The Alabama statute requires a reasonably accurate, clear, and meaningful privacy notice. The notice must address categories of personal data processed, processing purposes, third party sharing, and methods for exercising consumer rights.

Businesses involved in targeted advertising or qualifying data sales also need clear disclosures about those activities and available opt out procedures.

If your organization maintains a website privacy page, compare its statements with actual technology use. Analytics software, advertising pixels, customer databases, plugins, and marketing platforms may collect more information than company managers realize.

Anderson Law Group’s privacy policy page provides an example of the types of website practices that may require explanation, although every business needs language matching its own operations.

Opt Out Requests Deserve Special Attention

The law provides consumers with the ability to opt out of certain targeted advertising, personal data sales, and qualifying automated profiling.

Controllers need a clear method that allows consumers to submit applicable opt out requests. Businesses should test this process before the effective date.

A privacy link that leads to a broken page or an inbox nobody monitors may create operational problems. Companies should identify who receives requests, how identities are verified when necessary, and how changes reach internal systems and vendors.

Marketing teams should also understand the difference between contextual advertising and targeted advertising. The statute defines targeted advertising using activity across nonaffiliated websites or applications to predict interests or preferences.

Sensitive Personal Data Receives Additional Protection

The Alabama Personal Data Protection Act identifies several categories of information as sensitive data.

These categories include information revealing racial or ethnic origin, religious beliefs, health conditions, citizenship status, immigration status, sex life, or sexual orientation. Certain genetic, biometric, child, and precise geolocation data also receive sensitive status.

A covered controller generally needs consumer consent before processing sensitive data. Information collected from known children under 13 must follow federal children’s privacy requirements.

The Federal Trade Commission provides information about the Children’s Online Privacy Protection Rule for businesses collecting information from children online.

The Alabama statute also addresses consumers between ages 13 and 15. Businesses with actual knowledge of a consumer’s age need to examine consent rules involving targeted advertising and personal data sales.

Data Collection Should Have a Clear Purpose

The law requires covered controllers to limit personal data collection to information that is adequate, relevant, and reasonably necessary for the disclosed processing purpose.

This requirement provides businesses with a practical reason to examine old databases. A company may have information collected years ago that no longer serves an active business purpose.

Businesses can review what they collect, where the data sits, who can access it, which vendors receive it, and how long the company keeps it.

This process is often called data mapping or creating a data inventory. It can reveal unnecessary duplication and forgotten third party connections.

Reasonable Data Security Becomes Part of Compliance

The Alabama statute requires covered controllers to establish reasonable administrative, technical, and physical security practices appropriate to the volume and nature of the information involved.

The Federal Trade Commission’s data security resources provide practical guidance about protecting customer information, managing access, securing systems, and addressing cybersecurity risks.

The Cybersecurity and Infrastructure Security Agency also provides cybersecurity resources for small and medium sized companies.

Businesses may consider reviewing password policies, multi factor authentication, employee permissions, backups, encryption, system updates, vendor access, and incident response procedures.

Privacy compliance and cybersecurity are closely related. A detailed privacy notice provides limited protection if an organization does not maintain reasonable safeguards around the information described in that notice.

Vendor Contracts Should Be Reviewed

Many companies do not process customer data entirely inside their own systems. They use payment processors, cloud providers, marketing platforms, customer relationship tools, analytics services, payroll companies, and outside consultants.

The Alabama law addresses relationships between controllers and processors and requires contracts covering certain processing responsibilities.

A business preparing for compliance should identify vendors receiving personal information and review existing agreements. The contract should accurately describe processing activities and responsibilities.

This review also connects with broader business governance. Our article on Alabama business law changes in 2026 discusses why company documents, contracts, records, and management procedures should reflect actual operations.

Health and Financial Data May Involve Other Laws

Some entities and categories of information receive exemptions under Alabama’s privacy statute because other regulatory systems already apply.

For example, the statute contains provisions involving certain information governed by HIPAA. The U.S. Department of Health and Human Services maintains guidance covering HIPAA privacy requirements.

Certain financial institutions and information regulated under federal financial privacy laws also receive statutory treatment.

An exemption should be analyzed carefully. A business may have one category of exempt information while collecting other consumer information that receives different treatment.

Business data inventory and privacy compliance records in Alabama

The Alabama Attorney General Has Enforcement Authority

The statute gives enforcement authority to the Alabama Attorney General. Before initiating an enforcement action, the Attorney General must provide notice of an alleged violation.

A controller generally receives 45 days to correct the noticed violation. If the violation remains uncorrected, a court may impose a civil penalty of up to $15,000 per violation.

The Alabama Attorney General’s Consumer Interest Division handles consumer protection matters and currently provides resources concerning data breaches and related issues.

Businesses should also remember that privacy compliance and breach notification involve separate questions. The Attorney General maintains information about Alabama’s existing Data Breach Notification Act.

What Alabama Businesses Can Do Before May 2027

The effective date may seem distant, but privacy projects can require coordination across legal, marketing, technology, operations, and vendor management teams.

Businesses can begin by identifying personal data, reviewing applicability, checking exemptions, updating privacy notices, and documenting consumer request procedures.

Companies can also examine targeted advertising, data sales, sensitive data, vendor contracts, security controls, retention practices, and online opt out mechanisms.

Organizations should document decisions about why the statute applies or why an exemption appears relevant. That documentation can help when business practices change later.

The broader Anderson Law Group legal blog provides additional Alabama legal updates affecting businesses, property owners, families, and estates.

Final Thoughts

The Alabama Personal Data Protection Act represents a significant change in the state’s approach to consumer privacy. Act 2026-552 takes effect on May 1, 2027.

Covered businesses need to understand consumer rights, privacy notice requirements, opt out procedures, sensitive data rules, security duties, and processor relationships.

Preparing early gives organizations time to identify their data practices and address gaps before the effective date. Businesses with uncertain coverage can seek legal guidance based on their size, data volume, revenue sources, and technology practices.

This article provides general educational information and does not constitute legal, cybersecurity, or compliance advice for a particular organization.