Alabama Personal Data Protection Act: 2027 Compliance Guide
ON THIS PAGE
- What Is the Alabama Personal Data Protection Act?
- Who Must Comply With the Alabama Personal Data Protection Act in 2027?
- What Consumer Privacy Rights Does the Alabama Personal Data Protection Act Provide?
- Alabama Personal Data Protection Act Penalties and Compliance Risks
- Alabama Personal Data Protection Act Requirements for Businesses
- Rules for Selling, Sharing, and Using Personal Data for Targeted Advertising
- Alabama Personal Data Protection Act Compliance Checklist in 2027
- How Can CookieScript Help to Comply with the APDPA?
- Frequently Asked Questions
On April 7, 2026, the Alabama legislature passed House Bill 351, the Alabama personal data Protection Act (APDLA) that will take effect on May 1, 2027.
Alabama becomes the 21st state to enact a broad consumer data privacy law, one of the more business-friendly laws passed to date.
The new business-friendly law is similar to other state laws. Companies that comply with other state consumer data privacy laws will most probably comply with the APDLA as well.
However, the new Alabama law contains several Alabama-specific provisions. Notably, it has relatively low applicability thresholds, provides a permanent 45-day opportunity to cure violations before enforcement, and allows civil penalties of up to $15,000 per violation.
Read this compliance guide to get ready before the 2027 effective date. It will help reduce regulatory risk and make consumer privacy requests easier to manage.
What Is the Alabama Personal Data Protection Act?
The Alabama personal data Protection Act is a comprehensive state consumer privacy law that protects Alabama residents' privacy rights by governing how organizations collect, use, process, disclose, and protect residents’ personal data.
Effective date: May 1, 2027.
The law provides data privacy rights for Alabama residents. It focuses primarily on individuals acting in a personal or household capacity. People acting solely in an employment or commercial context, such as employees, contractors, business owners, officers, and directors, generally are not covered by the APDPA.
Under the Alabama personal data Protection Act, personal data is defined as any information that is linked or reasonably linkable to an identified or identifiable individual. It includes common identifiers like names, home addresses, email addresses, phone numbers, and IP addresses. Deidentified data and publicly available information are not considered personal data.
The APDPA establishes several core privacy obligations for organizations operating in Alabama. Organizations must limit personal data collection to information that is adequate, relevant, and reasonably necessary for the disclosed purpose. They must also implement reasonable administrative, technical, and physical security practices appropriate to the nature and volume of personal data they process.
Businesses must provide consumers with a clear privacy notice explaining what personal data they collect, why they collect and process it, the categories of information disclosed to third parties, the types of third parties receiving it, and how consumers can contact the business and exercise their APDPA rights.
The APDPA also regulates targeted advertising, sales of personal data, automated profiling associated with significant decisions, processor relationships, and deidentified information.
Unlike several other comprehensive state privacy laws, the APDPA does not require formal data protection assessments for high-risk processing activities.
Who Must Comply With the Alabama Personal Data Protection Act in 2027?
The APDPA applies to organizations that conduct business in Alabama or produce products or services targeted to Alabama residents and meet at least one of the following criteria:
- Control or process the personal data of more than 25,000 consumers, excluding information processed solely for completing payment transactions.
- Derives more than 25% of its gross revenue from the sale of personal data, regardless of how much consumers' data it controls or processes.
The APDPA therefore has a low applicability threshold and can potentially apply to organizations that would fall below the consumer-volume requirements of some other state comprehensive privacy laws.
Exemptions to the APDPA
However, meeting a numerical threshold does not automatically mean that an organization is covered. The APDPA includes several entity-level and data-level exemptions, including:
- Businesses with fewer than 500 employees that do not sell personal data.
- Nonprofit organizations with fewer than 100 employees that do not sell personal data.
- Certain Alabama governmental entities.
- Institutions of higher education.
- Financial institutions governed by the Gramm-Leach-Bliley Act.
- HIPAA covered entities and business associates.
Some exemptions also apply to particular types of information, including specified information regulated by laws such as HIPAA, the Fair Credit Reporting Act, the Family Educational Rights and Privacy Act, and the Driver's Privacy Protection Act.
Because APDPA coverage depends on the number of employees, the organization's activities, and the type of information involved, companies shouldn’t rely solely on revenue or employees’ number thresholds. Company’s size, number of consumers, whether personal data is sold, the organization's industry, and whether particular statutory exemptions apply should also be evaluated.
What Consumer Privacy Rights Does the Alabama Personal Data Protection Act Provide?
The Alabama Personal Data Protection Act (APDPA) grants Alabama residents these core consumer privacy rights:
- Right to access and portability: Individuals have the right to confirm whether a business processes their personal data, obtain a copy of it, and request a portable, readily usable format.
- Right to correction: Individuals have the right to request correction of inaccuracies in their personal data.
- Right to deletion: Individuals have the right to request the deletion of personal data about the consumer.
- Right to opt-out: Individuals have the right to object to and stop the processing of their data for targeted advertising, the sale of personal data, or profiling that produces legal or similarly significant effects.
Businesses that sell Personal Information or process it for targeted advertising must clearly disclose those practices and explain how consumers can opt out. They must provide a clear website link that either allows consumers to opt out directly or provides current contact information through which they can make an opt-out request.
Notably, the APDPA does not contain a right to appeal.
All rights, except the opt-out rights, are subject to authentication.
Consumers must obtain information free of charge once during each 12-month period. The APDPA permits a controller to charge a reasonable administrative fee or decline certain requests when they are manifestly unfounded, excessive, technically infeasible, or repetitive.
Sensitive Personal Information
The law requires controllers to obtain consumer consent to process sensitive data.
Under the Alabama law, sensitive data is defined as:
- Racial or ethnic origin, or religious beliefs.
- Mental or physical health condition or diagnosis.
- Information about an individual’s sex life or sexual orientation, or gender identity.
- Citizenship or immigration status.
- Genetic or biometric data processed to uniquely identify a person.
- Precise geolocation data (within a radius of 1,750 feet).
- Personal data collected from a known child under 13.
Biometric data
The APDPA defines biometric data as data “generated by automatic measurements of an individual’s biological characteristics, such as a fingerprint, voiceprint, retina, or iris, that are used to identify a specific individual.”
The definition expressly excludes digital or physical photographs, audio or video recordings, and data generated from photographs or recordings, unless the data is used to identify a specific individual.
Children’s privacy rights
Controllers cannot process the children’s personal data for the purpose of targeted advertising or sell a consumer’s personal data without the consumer’s consent when a controller has actual knowledge that a consumer is between 13 and 16 years of age.
Opt-out preference signals
The law does not require controllers to recognize opt-out preference signals.
Originally passed by the House, HB 351 would have required controllers to recognize universal opt-out preference signals. A Senate amendment removed that requirement. This is a significant departure from state data privacy laws that mandate recognition of Global Privacy Control and other opt-out preference signals.
Alabama Personal Data Protection Act Penalties and Compliance Risks
The Alabama Attorney General is responsible solely for enforcing the APDPA.
The law does not create a private right of action that allows consumers to sue solely for an APDPA violation.
Before bringing an enforcement action, the Attorney General must notify the controller of an alleged violation. The business then has 45 days to correct the violation.
If the organization cures the violation during a 45-day period and provides an express written statement confirming that the problem has been corrected and that the violation will not recur, the Attorney General may not initiate an action against the violation.
If a controller fails to correct the violation within the 45-day period, the Attorney General may impose a civil penalty of up to $15,000 per violation.
The per-violation penalty structure may create substantial regulatory exposure when they affect large numbers of consumers or occur repeatedly. For example, non-compliance problems in privacy notices, opt-out mechanisms, consumer-request workflows, consent collection, or security controls could affect thousands of consumers.
Beyond direct penalties, privacy violations can trigger regulatory investigations, remediation expenses, vendor disputes, reputational damage, and additional cost under other state or federal laws.
Alabama Personal Data Protection Act Requirements for Businesses
Beginning May 1, 2027, controllers must comply with requirements governing how they collect, use, disclose, and protect Alabama consumers’ personal data, follow data minimization principles, obtain consent for certain sensitive-data processing, provide appropriate opt-out mechanisms, maintain transparent privacy notices, and implement reasonable data security safeguards.
Controllers must respond to a consumer’s request within 45 days of receipt. Where reasonably necessary, the response period may be extended by a further 45 days, provided the consumer is informed of the extension and its reason within the initial 45-day period.
Controllers must provide responses free of charge once per 12-month period per consumer. If requests are manifestly unfounded, excessive, technically infeasible, or repetitive, the controller may charge a reasonable fee or decline to act.
Controllers must also establish an appeal process for consumers whose requests are denied. If the controller denies an appeal, it must direct the consumer to the Alabama Attorney General.
The law sets several requirements for businesses:
Data minimization principle
The APDPA requires controllers to limit personal data collection to information that is adequate, relevant, and reasonably necessary for the purposes for which it is processed. Do not use personal data for purposes that are incompatible with the purposes disclosed to consumers, except where another provision of the law permits the processing.
Consent requirements for processing sensitive personal data in Alabama
The APDPA requires affirmative, prior consent before controllers process sensitive personal data.
Valid consent must involve a clear affirmative act demonstrating a freely given, specific, informed, and unambiguous agreement to the processing. Solely accepting broad terms of use that combine privacy disclosures with unrelated provisions does not qualify as consent. Dark patterns are also prohibited for obtaining consent.
When processing the personal data of a known child under 13, the business must process the information in accordance with the federal Children’s Online Privacy Protection Act (COPPA).
Businesses must also provide an effective way for consumers to revoke their consent. The revocation method must be at least as easy to use as the method used to provide consent.
Upon revocation, the controller must cease processing “as soon as practicable, but no later than 45 days” after the opt-out is received.
Privacy notice requirements
Section 7(d) of the APDPA requires controllers to provide a reasonably accurate, clear, and meaningful privacy notice that includes:
- Categories of personal data processed by the controller.
- The purpose for processing personal data.
- Categories of personal data shared with third parties, if any.
- Categories of third parties with whom personal data is shared, if any.
- An active email address or other contact mechanism for the controller.
- How consumers may exercise their rights, including a link to the opt-out method.
Security requirements
The ADPDA requires controllers to “establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data appropriate to the volume and nature of the personal data at issue.”
The law doesn’t specifically describe data security practices. Businesses should adopt safeguards proportionate to their data-processing risks. Depending on the organization, appropriate measures may include access controls, encryption, authentication controls, employee security training, vulnerability management, incident-response procedures, secure data disposal, and vendor oversight.
Processor contract requirements
Section 8 of the APDPA requires businesses to sign a written contract between controllers and processors. A valid data processing agreement must set out instructions for processing, the nature and purpose of data processing, type of data, duration of keeping consumers’ data, and rights and obligations of both parties.
Data Protection Impact Assessments (DPIAs)
APDPA does not generally require data protection impact assessments (DPIAs) for standard data processing activities.
However, controllers must conduct DPIAs before undertaking processing activities having heightened risk. These activities include targeted advertising, data sales, certain profiling, and processing sensitive data. Assessments apply only to processing commencing on or after May 1, 2027, and are not retroactive.
Data deidentification
Section 9 requires controllers that have deidentified data to take measures to prevent re-identification, refrain from re-identifying it, and contractually require recipients to follow these obligations regarding data deidentification.
Rules for Selling, Sharing, and Using Personal Data for Targeted Advertising
The APDPA gives Alabama consumers the right to opt out of the sale of their personal data and the processing of personal data for targeted advertising. Consumers may also opt out of profiling used solely for automated significant decisions.
Businesses that sell personal data to third parties or process personal information for targeted advertising must clearly disclose those practices and explain how consumers can exercise their opt-out rights.
Controllers must provide a clear and conspicuous link on their website that allows consumers to opt out directly or provides current contact information through which consumers can submit an opt-out request.
Unlike certain access, correction, or deletion requests, consumers do not need to authenticate for opt-out requests, although a controller may reject a request when it has a reasonable and documented belief that the request is fraudulent or unauthorized.
Businesses should distinguish between selling personal data and other forms of data sharing. The APDPA specifically grants an opt-out right for sales and targeted advertising, but it does not characterize every disclosure to a vendor, processor, affiliate, or other third-party recipient as a sale. Nevertheless, the law requires businesses to disclose in their privacy notices both the categories of personal data they share with third parties and the categories of third parties receiving that information.
Alabama Personal Data Protection Act Compliance Checklist in 2027
Use this practical compliance checklist for complying with the Alabama Personal Data Protection Act:
- Assess applicability
Review your Alabama operations, number of consumers whose personal data you control or process, percentage of revenue derived from personal data sales, and employee count to determine whether your business is covered by the APDPA. Also assess whether the small business exemption (fewer than 500 employees, no data sales) applies. - Create personal data inventory
Identify what Alabama consumer information you collect, where it comes from, where it is stored, why it is processed, how long it is retained, and which third parties receive it. - Identify sensitive personal data
Identify whether you collect Alabama residents’ sensitive personal data, including precise geolocation, biometric or genetic information, sex-related information, protected demographic characteristics, certain health information, children's data, and other sensitive categories. - Review consent mechanisms
Obtain consent before processing sensitive personal data and before certain targeted advertising or data sales involving consumers aged 13 to 15. Also implement a consent revocation mechanism, ensuring revocation is as easy as providing consent, and that systems can cease processing within 45 days of revocation. - Apply data minimization principles
Limit personal data collection to information that is adequate, relevant, and reasonably necessary for disclosed processing purposes. - Update your privacy notice
Clearly explain the categories of personal data processed, processing purposes, third-party disclosures, contact methods, consumer rights, and available opt-out procedures. - Provide clear opt-out mechanisms and Implement consumer request workflows
If your businesses is engaged in targeted advertising or personal data sales, provide a clear opt-out mechanism on your websites. Create procedures for receiving, authenticating, tracking, and fulfilling access, correction, deletion, portability, and opt-out requests within 45 days. - Review automated profiling practices
Determine whether automated systems make significant decisions in your business and provide a mechanism for consumers to exercise their opt-out rights. - Implement reasonable data security safeguards
Implement administrative, technical, and physical controls appropriate to the quantity and sensitivity of the personal data processed. - Review processor and vendor contracts
Sign binding contracts with data processors that include required instructions, purposes, data types, processing duration, confidentiality obligations, responsibilities, and appropriate subcontractor provisions. - Review data retention and deletion practices
Ensure personal information is not retained longer than necessary and implement a mechanism for authenticated deletion requests across relevant systems and processors. - Audit sales and targeted advertising activities
Identify advertising technologies, analytics providers, data brokers, marketing vendors, and other third parties to determine whether disclosures constitute regulated sales or targeted advertising. - Train employees on privacy and security protocols
Train privacy, legal, marketing, IT, security, customer support, and procurement teams to comply with the APDPA based on their role. - Document compliance decisions
Keep records showing how the organization assessed applicability, exemptions, consumer requests, consent, vendor relationships, and security practices. - Implement a CMP
Use a Consent Management Platform (CMP) for privacy notices, consent management, opt-out mechanisms, and automated proof of consent.
How Can CookieScript Help to Comply with the APDPA?
Use a professional Consent Management Platform (CMP) to comply with the APDPA and other data privacy laws.
CookieScript Consent Management Platform (CMP) comes with a Cookie Banner, Cookie Scanner, Privacy Policy Generator, script manager, and user consent manager. It recognizes a Global Privacy Controls signal, detects and categorizes cookies, local storage, session storage, and other trackers, and automatically blocks Third-Party Cookies, so you can be sure your website is compliant with the APDPA and other privacy regulations 100%!
In 2024, CookieScript CMP was ranked by users as the best CMP on a peer-review site G2.
It also received a GOLD Tier in the New Google Tiering System.
Try a free 14-day trial of CookieScript CMP.
Frequently Asked Questions
What is personal data under the Alabama Personal Data Protection Act?
Under the Alabama Personal Data Protection Act, personal data is defined as any information that is linked or reasonably linkable to an identified or identifiable individual. It includes common identifiers like names, home addresses, email addresses, phone numbers, and IP addresses. Deidentified data and publicly available information are not considered personal data. CookieScript CMP can help manage user consent when collecting personal data.
When does the Alabama Personal Data Protection Act take effect?
The Alabama Personal Data Protection Act (APDPA) will take effect on May 1, 2027. Use CookieScript CMP to comply with the APDPA and avoid risks for non-compliance.
What businesses are exempt from Alabama’s data privacy law?
The APDPA includes several entity-level and data-level exemptions, including businesses with fewer than 500 employees that do not sell personal data, nonprofit organizations with fewer than 100 employees that do not sell personal data, certain Alabama governmental entities, institutions of higher education, financial institutions governed by the Gramm-Leach-Bliley Act, and HIPAA covered entities and business associates.
What are consent requirements for processing sensitive personal data in Alabama?
The APDPA requires freely given, specific, informed, and unambiguous consent before processing sensitive personal data. Consent must be obtained before any data collection or processing takes place. Businesses must obtain consent before any data collection or processing. Use CookieScript CMP to manage user consent and comply with the APDPA.
Are data processing agreements required by the APDPA?
APDPA does not generally require data protection impact assessments (DPIAs) for standard data processing activities. However, controllers must conduct DPIAs before undertaking processing activities having heightened risk, such as targeted advertising, data sales, certain profiling, and sensitive data processing.
How to comply with the Alabama Personal Data Protection Act?
To comply with the APDPA, create a personal data inventory, identify sensitive personal data, review consent mechanisms, apply data minimization principles, update the privacy notice, implement consumer request workflows, provide clear opt-out mechanisms, implement reasonable data security safeguards, and implement a CMP like CookieScript for consent management.