Florida’s data governance laws sit in four main places: the Florida Information Protection Act (FIPA) governs breach notification and data security for businesses and agencies; the Florida Digital Bill of Rights adds consumer privacy rights against the largest technology companies; Chapter 282 imposes a detailed cybersecurity framework on state agencies; and Chapter 119, the Public Records Law, controls how government data is retained and destroyed. Federal laws like HIPAA and FERPA layer on top for health and education data. Penalties range from $1,000 a day up to $500,000 per breach under FIPA, with HIPAA fines reaching more than $2.1 million a year.
FIPA: The Core Data Breach Law
FIPA, at Section 501.171 of the Florida Statutes, is the backbone. It applies to any commercial entity that acquires, maintains, stores, or uses personal information, and to government entities as well. Every covered entity has to take reasonable measures to protect personal information held in electronic form.1Florida Senate. Florida Code 501.171 – Security of Confidential Personal Information
“Personal information” under FIPA means a person’s name combined with at least one sensitive identifier: a Social Security number, driver’s license or state ID number, a financial account number paired with the credentials to access it, medical history or treatment information, a health insurance identifier, or an email address paired with a password or security question that unlocks an online account. Encrypted or otherwise unreadable data falls outside the definition.
Breach Notification Deadlines
When a breach affects 500 or more Florida residents, the entity must notify the Department of Legal Affairs within 30 days of discovering the breach or having reason to believe one occurred. A 15-day extension is available if the entity provides a written explanation within that initial 30-day window.1Florida Senate. Florida Code 501.171 – Security of Confidential Personal Information
Every affected Florida resident must also be notified individually within 30 days. Law enforcement can request a written delay if notification would interfere with a criminal investigation.2The Florida Legislature. Florida Code 501.171 – Security of Confidential Personal Information
Third parties handling data on behalf of a covered entity carry their own duty to report breaches back to the entity they serve, which then handles the outward notifications.
The Florida Digital Bill of Rights
Effective July 1, 2024, the Florida Digital Bill of Rights (Sections 501.701 through 501.721) added consumer privacy protections, but only against a narrow set of very large technology companies.3Florida Senate. Florida Senate Bill 262 (2023) – Florida Digital Bill of Rights It applies only to entities with more than $1 billion in global gross annual revenue that also meet one of these criteria: at least half their revenue from online advertising, operation of a consumer smart speaker with a cloud-connected virtual assistant, or operation of an app store with at least 250,000 apps.
Consumers can submit requests to controllers to access or delete their personal data. The Department of Legal Affairs enforces the law. Its first annual enforcement report, covering the period through early 2026, showed no penalties issued or collected.4Florida Department of Legal Affairs. Florida Digital Bill of Rights Annual Enforcement Report
If your business doesn’t clear that revenue threshold, this law doesn’t touch you. FIPA still does.
Cybersecurity Requirements for State Agencies
Section 282.318 imposes a much more prescriptive framework on state agencies. The Florida Digital Service, operating under the Department of Management Services, sets statewide cybersecurity standards aligned with the NIST Cybersecurity Framework.5Florida Senate. Florida Code 282.318 – Enterprise Security of Data and Information Technology
Each agency head must, at minimum:
- Designate an information security manager to run the cybersecurity program, reported in writing to the department by January 1 each year.
- Submit an annual cybersecurity plan by July 31 covering a three-year strategic outlook and a current-year operational plan with measurable objectives.
- Conduct a comprehensive risk assessment every three years using the department’s methodology. A private vendor may do the assessment but must attest to the findings.
- Establish a cybersecurity response team that convenes immediately upon discovery of an incident.
- Provide cybersecurity awareness training to every new employee within 30 days of their start date.
- Conduct periodic internal audits of the cybersecurity program.
Incident Reporting Clocks
The reporting deadlines are strict and vary by incident type. Ransomware incidents must be reported to both the Cybersecurity Operations Center and the Florida Department of Law Enforcement within 12 hours of discovery. Other incidents rated severity level 3 or higher must be reported within 48 hours. Lower-severity incidents must be reported “as soon as possible.” Once an incident is remediated, the agency has one week to file an after-action report.6The Florida Legislature. Florida Code 282.318 – Enterprise Security of Data and Information Technology
Data governance strategy above the agency level flows through a single state chief data officer, designated by the state chief information officer under Section 282.0051. Florida does not require each agency to appoint its own CDO.
Public Records: Retention and Destruction
Florida’s Public Records Law (Chapter 119) defines public records broadly to cover any document, photograph, recording, data file, or other material made or received in connection with official government business, in any format.7Florida Department of State. Division of Library and Information Services – Records Management FAQ State agencies follow general records schedules setting minimum retention periods. Agencies can keep records longer than the schedule requires. They cannot shorten retention.
Approved Destruction Methods
When records containing confidential or exempt information reach the end of their retention period, the destruction method must make the data unrecoverable. What’s approved depends on the format:
- Paper records: burning in an industrial facility, pulping, pulverizing, shredding, or macerating. Water-repellent or high-wet-strength papers cannot be destroyed by pulping alone and require shredding or burning.
- Electronic records: physical destruction of storage media by shredding, crushing, or incineration; high-level overwriting that renders data unrecoverable; or degaussing.
- Non-paper media such as audio tape, video tape, or microfilm: pulverizing, shredding, or chemical decomposition.
Burying records is explicitly prohibited because it does not guarantee complete destruction.8Florida Department of State. Approved Methods of Destruction
Penalties for Non-Compliance
FIPA Fines
Failing to provide required breach notifications triggers escalating civil penalties: $1,000 per day for the first 30 days, then $50,000 for each subsequent 30-day period up to 180 days. Beyond 180 days, the total penalty can reach $500,000. These penalties apply per breach, not per affected individual. The Department of Legal Affairs may also treat violations as unfair or deceptive trade practices, opening additional remedies.1Florida Senate. Florida Code 501.171 – Security of Confidential Personal Information
HIPAA
Entities handling protected health information also face federal penalties under HIPAA. The four-tier structure is based on fault, with amounts adjusted annually for inflation. For 2026:
- No knowledge of the violation: $145 to $73,011 per violation, with a calendar-year cap of $2,190,294.
- Reasonable cause, not willful neglect: $1,461 to $73,011 per violation, same annual cap.
- Willful neglect, corrected within 30 days: $14,602 to $73,011 per violation, same annual cap.
- Willful neglect, not corrected within 30 days: $73,011 to $2,190,294 per violation, with a calendar-year cap of $2,190,294.
The original statutory amounts ran from $100 to $50,000 per violation, so any Florida entity handling health data should budget against the current inflation-adjusted numbers.9Federal Register. Annual Civil Monetary Penalties Inflation Adjustment (2026)
FERPA
Florida’s public schools and universities also comply with the Family Educational Rights and Privacy Act, which protects student education records at institutions receiving federal funding.10Student Privacy Policy Office. 34 CFR Part 99 – Family Educational Rights and Privacy FERPA’s enforcement mechanism is potential loss of federal funding rather than per-violation fines, which raises the stakes for institutions dependent on those dollars.
What’s Changing in 2026
Two pending proposals could reshape the framework. Senate Bill 480 would transfer the Florida Digital Service’s duties, and the state chief information officer position, to a new Division of Integrated Government Innovation and Technology (DIGIT).11Florida Senate. Florida Senate Bill 480 – Information Technology If enacted, DIGIT would become the enterprise body for IT governance, standards, strategy, and statewide reporting.
SPB 7024 would carve out several categories of cybersecurity information from public records requests, including insurance coverage limits and deductibles for IT systems, critical infrastructure information, incident reports filed under Sections 282.318 and 282.3185, network diagrams and encryption details, detection and response practices, portions of risk assessments and audit reports where disclosure could enable unauthorized access, and login credentials, IP addresses, and geolocation data from public-facing portals. Portions of public meetings that would reveal exempt cybersecurity information could be closed, though recordings and transcripts would still be required and would themselves be confidential.12Florida Senate. SPB 7024 – Agency Cybersecurity Information
Neither is law yet. Until they pass, the framework above is what applies.