Florida cybersecurity laws sit in two main statutes: the Florida Information Protection Act (FIPA), which tells businesses, government entities, and their vendors how to safeguard personal data and notify people after a breach, and the State Cybersecurity Act along with its local-government counterpart, which sets security standards for public agencies. Together they impose 30-day breach notification deadlines, tiered civil penalties up to $500,000 per breach, mandatory annual training, and, through Chapter 815, criminal felonies of up to 30 years for the attackers themselves.
Who FIPA Applies To and What Counts as Personal Information
FIPA reaches any “covered entity” that acquires, maintains, stores, or uses personal information — businesses, government agencies, and nonprofits operating in Florida — and it extends to third-party agents handling that data on a covered entity’s behalf.1Online Sunshine. Florida Statutes 501.171 – Security of Confidential Personal Information
“Personal information” under FIPA means a first name or initial plus last name combined with any of the following: a Social Security, driver’s license, passport, or military ID number; a financial account, credit, or debit card number together with the security or access code needed to use it; medical history, condition, treatment, diagnosis, or health insurance information; biometric data such as fingerprints or retina scans; geolocation data; or an email address or username together with a password or security question and answer that would unlock an online account.1Online Sunshine. Florida Statutes 501.171 – Security of Confidential Personal Information
That last category catches many organizations off guard. If you store login credentials for any online platform, those qualify under FIPA whether or not they connect to money.
Breach Notification Deadlines Under FIPA
The clock starts the moment you determine a breach occurred, or have reason to believe one did. From that point:
- You must notify each affected Florida resident as quickly as practicable, and no later than 30 days after discovery. The Department of Legal Affairs can grant a 15-day extension for good cause if you request it in writing within that initial 30-day window.
- If the breach affects 500 or more individuals, you must also notify the Department of Legal Affairs within the same 30 days.2Florida Attorney General. How to Protect Yourself: Data Security
- If 1,000 or more individuals are affected, you must also notify all nationwide consumer credit reporting agencies.
- A third-party vendor holding personal data on your behalf must notify you within 10 days of a breach. Your own 30-day clock then begins running.1Online Sunshine. Florida Statutes 501.171 – Security of Confidential Personal Information
There is one narrow off-ramp. If, after investigating and consulting with law enforcement, you reasonably determine that no affected individual has suffered or is likely to suffer identity theft or financial harm, you can skip notifying individuals. You still cannot skip notifying the Department. You must provide a written explanation of that “no harm” determination within 30 days and keep the documentation on file for at least five years.1Online Sunshine. Florida Statutes 501.171 – Security of Confidential Personal Information
The Encryption Safe Harbor
FIPA’s most useful compliance lever is its treatment of encrypted data. If the compromised information was encrypted, secured, or otherwise modified in a way that removes the personally identifying elements or renders the data unusable, it falls outside the statute’s definition of personal information altogether. No notification obligation is triggered.1Online Sunshine. Florida Statutes 501.171 – Security of Confidential Personal Information
The catch is that the encryption has to be real, using current standards, with keys stored separately from the data they protect. If the keys were compromised along with the data, the safe harbor likely does not apply because the data is not truly rendered unusable. Encrypting personal information at rest and in transit is probably the single highest-return investment an organization can make in FIPA compliance.
FIPA Penalties and Who Enforces Them
Civil penalties for failing to meet the notification requirements are tiered by how long the violation continues:
- $1,000 per day for the first 30 days of violation
- $50,000 for each subsequent 30-day period, or portion of one, up to 180 days
- A total cap of $500,000 beyond 180 days
These figures apply per breach, not per affected individual. A breach touching 100,000 people carries the same maximum fine as one touching 500.1Online Sunshine. Florida Statutes 501.171 – Security of Confidential Personal Information
Enforcement runs through the Florida Department of Legal Affairs, which is the Attorney General’s office. A FIPA violation is treated as an unfair or deceptive trade practice under Florida’s Deceptive and Unfair Trade Practices Act, giving the Attorney General investigative and enforcement authority.1Online Sunshine. Florida Statutes 501.171 – Security of Confidential Personal Information
One point worth correcting because it is widely misunderstood: FIPA does not create a private right of action. Individuals whose data was exposed cannot sue under FIPA itself.1Online Sunshine. Florida Statutes 501.171 – Security of Confidential Personal Information That does not leave affected people without options. They can pursue negligence, breach of contract, or other claims through separate legal channels. FIPA simply is not the vehicle.
What the State Cybersecurity Act Requires of State Agencies
The State Cybersecurity Act, at Section 282.318, makes the Florida Digital Service the lead cybersecurity authority for state government. It houses the state chief information security officer, publishes an annually updated statewide cybersecurity strategic plan, and operates the Cybersecurity Operations Center.3Florida Senate. Florida Statutes 282.318 – Cybersecurity
Each state agency head must:
- Designate an information security manager in writing to the Department by January 1 each year
- Establish a cybersecurity response team in consultation with the Florida Digital Service and the Department of Law Enforcement’s Cybercrime Office
- Submit strategic and operational cybersecurity plans to the Department annually by July 31
- Conduct a comprehensive risk assessment and update it every three years
- Provide cybersecurity awareness training to all employees within 30 days of hire and annually thereafter
- Ensure IT contracts and service agreements meet standards at least as rigorous as the NIST Cybersecurity Framework
That final requirement matters for vendors. If you sell IT services to a Florida state agency, NIST alignment is not a nice-to-have. It is written into the statute.3Florida Senate. Florida Statutes 282.318 – Cybersecurity
Local Government Cybersecurity Rules
Local governments answer to a separate statute, Section 282.3185. The requirements resemble the state framework at a distance but differ in the specifics, so assuming they are the same will get details wrong.
Every county and municipality must adopt cybersecurity standards protecting the availability, confidentiality, and integrity of its data and systems, aligned with best practices including the NIST Cybersecurity Framework. Adoption deadlines were staggered by size. Counties with populations of 75,000 or more and municipalities of 25,000 or more had to comply by January 1, 2024; smaller ones had until January 1, 2025. Compliance must be reported to the Florida Digital Service.4Florida Senate. Florida Statutes 282.3185 – Local Government Cybersecurity
Training runs on two levels. All employees with network access must complete basic cybersecurity training within 30 days of starting and every year after. Technology professionals and employees handling highly sensitive information must complete advanced training on the same timeline.4Florida Senate. Florida Statutes 282.3185 – Local Government Cybersecurity
When a cybersecurity or ransomware incident occurs, a local government must notify three parties: the Cybersecurity Operations Center, the Department of Law Enforcement’s Cybercrime Office, and the sheriff with jurisdiction. The notice must include a summary of the incident, the date of the most recent data backup, the types of data compromised, and the estimated fiscal impact.
Within one week of remediation, the local government must also submit an after-action report to the Florida Digital Service summarizing what happened, how it was resolved, and lessons learned. That one-week follow-up is easy to overlook in the aftermath of a breach and adds compliance risk when missed.4Florida Senate. Florida Statutes 282.3185 – Local Government Cybersecurity
Criminal Penalties for Cyberattacks
Florida’s Computer Abuse and Data Recovery Act, in Chapter 815, targets attackers with penalties well beyond civil fines. Unauthorized access to a computer, network, or electronic device is a third-degree felony at baseline, carrying up to five years in prison. It escalates to a second-degree felony, up to 15 years, when any of the following applies:
- Damage or loss reaches $5,000 or more
- The offense was part of a fraud scheme
- The attack disrupts a governmental operation or a public service such as water, gas, transportation, or communication systems
- The attacker disrupts or gains unauthorized access to a public or private transit system
At the top of the scale, a cyberattack becomes a first-degree felony punishable by up to 30 years in prison if it endangers human life or disrupts a computer system affecting medical equipment used to treat patients.5Florida Senate. Florida Statutes 815.06 – Offenses Against Users of Computers, Computer Systems, Computer Networks, or Electronic Devices
A separate ransomware statute, Section 815.062, targets attacks against government entities specifically. Deploying ransomware that encrypts, modifies, or renders unavailable data belonging to a governmental computer system is treated as its own criminal offense with its own penalties.
Where Federal Law Overlaps
Meeting Florida’s requirements does not clear you at the federal level. Several federal regimes run in parallel.
The Federal Trade Commission enforces data security under Section 5 of the FTC Act. Companies that receive a Notice of Penalty Offenses and continue the prohibited conduct can face civil penalties of up to $50,120 per violation, a figure the FTC adjusts annually for inflation.6Federal Trade Commission. Notices of Penalty Offenses The same breach that draws a FIPA action from the Florida Attorney General can draw a separate FTC action.
Organizations in critical infrastructure sectors also face reporting duties under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA). Starting in 2026, covered entities must report significant cyber incidents to CISA within 72 hours and ransomware payments within 24 hours. Those deadlines run independently of FIPA’s 30-day window, so a Florida healthcare system or utility may need to meet both clocks at once.
NIST is not a separate federal obligation so much as a shared foundation. Both the State Cybersecurity Act and the local government statute require standards consistent with the NIST Cybersecurity Framework, so organizations aligned to NIST cover a substantial portion of Florida’s requirements by default.7NIST. NIST Cybersecurity Framework 2.0 – Resource and Overview Guide
Building Compliance Before a Breach
The 30-day FIPA clock does not pause while you figure out your response plan, and most organizations that miss the deadline miss it because they were still deciding who was in charge. A workable incident response plan pre-identifies who makes the notification decision, who drafts the language, who contacts the Department of Legal Affairs, and how affected individuals will be identified. Vendor contracts should lock in the 10-day notice from third-party agents so you keep the remaining 20 days to act.
Two other pieces of preparation pay off consistently. First, map where personal information actually lives in your systems, including the categories that surprise people — geolocation combined with a name, or credentials for social platforms. You cannot protect or report on data you have not located. Second, encrypt that data properly and store the keys separately, because encrypted data that is genuinely unusable to an attacker sits outside FIPA’s definition of personal information and outside its notification regime altogether.
Between FIPA on the private side, Sections 282.318 and 282.3185 on the public side, and Chapter 815 on the criminal side, Florida’s framework is layered but internally consistent: know the data you hold, protect it to a NIST-aligned standard, and be ready to notify quickly when something goes wrong.