Skip to content

Evidence request lists

Florida Digital Bill of Rights (FDBR)

Evidence request list. 19 controls, 19 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Florida FDBR: Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)

FDBR-ConsumerRights
Consumer Rights (Fla. Stat. 501.705, 501.706, 501.707)

Florida Statutes 501.705 consumer rights + 501.706 controller response + 501.707 controller responsibilities. CONSUMER RIGHTS: (1) RIGHT TO CONFIRM + ACCESS the personal data the controller is processing about the consumer; (2) RIGHT TO CORRECT inaccuracies in personal data; (3) RIGHT TO DELETE personal data provided by or obtained about the consumer; (4) RIGHT TO DATA PORTABILITY - obtain in portable + commonly used + technically feasible format if processing is automated; (5) RIGHT TO OPT OUT of (a) SALE of personal data; (b) TARGETED ADVERTISING; (c) PROFILING in furtherance of solely automated decisions producing legal or similarly significant effects; (6) RIGHT TO OPT-OUT OF COLLECTION OF VOICE OR FACIAL RECOGNITION DATA (UNIQUE to Florida + not in other state laws). CONTROLLER RESPONSE (501.706): 45 DAYS to respond + may extend by 15 days for complex requests; must confirm receipt

Artefacts an auditor will ask for
  • Rights request procedure + log
  • Voice/facial recognition opt-out mechanism
  • Identity verification policy
  • Appeals procedure documented
Where this commonly fails
  • Voice/facial recognition opt-out missing (UNIQUE Florida requirement)
  • 45-day SLA missed
  • Identity verification too weak or too strong
  • Appeals procedure unclear

Florida FDBR: Controller and Processor Obligations, DPA, Privacy Notice

FDBR-ControllerObligations-DPA-Notice
Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)

Florida Statutes 501.707-711. CONTROLLER RESPONSIBILITIES (501.707): (a) PURPOSE LIMITATION - limit personal data collection + retention to what is adequate + relevant + reasonably necessary for the specified purpose; (b) DATA MINIMISATION; (c) PROHIBITION on processing personal data for purposes neither reasonably necessary to + compatible with the disclosed purposes; (d) AVOID PROCESSING in violation of FDBR + state + federal anti-discrimination laws; (e) IMPLEMENT REASONABLE administrative + technical + physical safeguards. DATA PROTECTION ASSESSMENTS (501.708): controllers MUST CONDUCT DPAs for processing activities involving (a) sale of personal data; (b) targeted advertising; (c) profiling presenting reasonably foreseeable risk of unfair or deceptive treatment / unlawful disparate impact / financial / physical / reputational injury / intrusion on private affairs / other substantial

Artefacts an auditor will ask for
  • DPA template + records
  • Processor agreement template
  • Privacy notice published + accurate
  • Search bias disclosure if applicable
Where this commonly fails
  • DPA skipped for risk categories
  • Processor agreements weak
  • Privacy notice generic or stale
  • Search bias disclosure missing if applicable

Florida FDBR: Coordination with US State Privacy Laws, COPPA, FOSA and Status

FDBR-Compliance-Crosswalk-NIST-ISO-SOC
FDBR Crosswalk to NIST CSF, ISO 27001, SOC 2 and Federal/Sectoral Frameworks

Florida FDBR crosswalk to comprehensive security + privacy frameworks. NIST CSF 2.0 mapping: GOVERN (FDBR controller responsibilities + DPAs + privacy notice) + IDENTIFY (sensitive data inventory + minors data + voice/facial recognition data) + PROTECT (opt-in + opt-out + access controls + safeguards under 501.707) + DETECT (rights-request monitoring + breach detection) + RESPOND (45-day rights SLA + cure-period response + breach response) + RECOVER (data restoration + rights remediation). NIST PRIVACY FRAMEWORK + NIST AI RISK MANAGEMENT FRAMEWORK (NIST AI 600-1) coordination for AI + profiling + automated decision-making + voice/facial recognition. ISO/IEC 27001:2022 + ISO/IEC 27701:2019 mapping: ISO 27001 ISMS + ISO 27701 PIMS provide ISMS + PIMS structure for FDBR program implementation. SOC 2 (Service Organization Control 2): privacy + confidentiality + security trust service criteri

Artefacts an auditor will ask for
  • NIST CSF 2.0 crosswalk
  • ISO 27001/27701 alignment evidence
  • SOC 2 report + AICPA assessment
  • Sectoral exemption documentation
Where this commonly fails
  • Crosswalk to NIST/ISO/SOC 2 not maintained
  • Sectoral exemption mapping incomplete
  • AICPA + IAPP guidance not integrated
FDBR-Coord-CCPA-CPRA-State-Privacy
Coordination with US State Privacy Laws (CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, ICDPA, TIPA, RIDTPPA, WDPA, MMCL, OCPA, NHDPA, MDPA, TDPSA, KCDPA, NJDPA, DPDPA, INCDPA)

Florida FDBR coordination with the rapidly-growing US state privacy law ecosystem. COMPARABLE STATE LAWS (as of 2026 - approximately 20 comprehensive state privacy laws): California (CCPA + CPRA + 2018/2020) + Virginia VCDPA (2021) + Colorado CPA (2021) + Connecticut CTDPA (2022) + Utah UCPA (2022) + Iowa ICDPA (2023) + Indiana INCDPA (2023) + Tennessee TIPA (2023) + Montana MCDPA (2023) + Oregon OCPA (2023) + Texas TDPSA (2023) + Delaware DPDPA (2023) + New Jersey NJDPA (2024) + New Hampshire NHDPA (2024) + Kentucky KCDPA (2024) + Maryland MDPA (2024) + Minnesota MCDPA (2024) + Nebraska NDPA (2024) + Rhode Island RIDTPPA (2024) + Washington WDPA (2025) + Florida FDBR. KEY DIFFERENTIATORS for FDBR: (a) NARROWEST APPLICABILITY (USD 1B threshold + big-tech-specific) - most other states are USD 25M-100M + business volume + consumer thresholds; (b) UNIQUE VOICE/FACIAL RECOGNITION OPT-OUT not

Artefacts an auditor will ask for
  • Multi-state privacy compliance program
  • Florida-specific feature implementation evidence
  • Federal preemption tracking (APRA + others)
Where this commonly fails
  • State privacy laws confused with each other
  • Florida-unique features missed
  • Federal preemption not tracked
FDBR-Coord-COPPA-FERPA-HIPAA-Sectoral
Coordination with COPPA, FERPA, HIPAA, GLBA, FCRA and Sectoral Federal Laws

Florida FDBR coordination with sectoral federal privacy + data protection laws. COPPA (Children Online Privacy Protection Act, 15 USC 6501 + 16 CFR Part 312): FTC-administered; covers online services collecting from children under 13; FDBR is MORE PROTECTIVE (under 18) + may apply in parallel; the 2024 FTC COPPA Rule Update + the pending COPPA 2.0 (Markey-Cassidy Senate bill) would extend to teens 13-16 aligning with FDBR. FERPA (Family Educational Rights and Privacy Act, 20 USC 1232g + 34 CFR Part 99): EXEMPT data covered by FERPA at the dataset level - educational records remain FERPA-governed; ed-tech vendors may be subject to FDBR for non-educational records. HIPAA: EXEMPT data covered by HIPAA at the dataset level - health records remain HIPAA-governed; non-health-record consumer data of healthcare entities may be subject to FDBR. GLBA (Gramm-Leach-Bliley Act + 16 CFR Part 314 Safeg

Artefacts an auditor will ask for
  • Exemption documentation + dataset-level classification
  • Sectoral compliance program (where applicable)
  • CIRCIA + critical-infrastructure coordination
Where this commonly fails
  • Exemption claims overbroad
  • Sectoral compliance program missing
  • CIRCIA coordination skipped
FDBR-PIPL-Comparison
Comparison with GDPR + Comprehensive Privacy Laws + APRA Federal Preemption Tracking

Florida FDBR vs comprehensive privacy regimes + federal preemption tracking. GDPR (EU Regulation 2016/679): FDBR is NARROWER (USD 1B big-tech threshold vs GDPR universal applicability) + DIFFERENT RIGHTS STRUCTURE (FDBR has voice/facial recognition opt-out + sensitive data opt-in vs GDPR Article 9 explicit consent + DPIA) + LIGHTER ENFORCEMENT (USD 50K-1.5M vs GDPR 2-4% turnover) + NO PRIVATE RIGHT OF ACTION (vs GDPR Article 79-80). CALIFORNIA CCPA/CPRA: FDBR + CCPA share rights (access + deletion + portability + opt-out) but CCPA includes BUSINESS-PURPOSE service-provider concept + sensitive personal information notice-at-collection + private right of action for breaches; CCPA covers MORE BUSINESSES (USD 25M threshold + 100K consumers + sale-of-data threshold) than FDBR. PRC PIPL (Personal Information Protection Law): completely different legal context + cross-border transfer focus + Ch

Artefacts an auditor will ask for
  • Multi-regime compliance program
  • Cross-border data flow assessment
  • APRA + federal preemption tracking
Where this commonly fails
  • Cross-regime compliance program ad-hoc
  • APRA + federal preemption not tracked
  • Florida-only program ignores multi-state + federal interplay
FDBR-Status-Implementation-Org
FDBR Compliance Program Implementation - Organizational Roles and Operational Controls

FDBR compliance program implementation roadmap. ORGANIZATIONAL ROLES: (a) PRIVACY COUNSEL or CHIEF PRIVACY OFFICER (CPO) - FDBR coordination + AG engagement + cross-state privacy program; (b) DATA PROTECTION ASSESSMENT OWNER - conducting + maintaining DPAs for sale + targeted advertising + profiling + sensitive data + minors; (c) CONSUMER RIGHTS MANAGER - 45-day SLA + identity verification + appeals; (d) VENDOR + PROCESSOR CONTRACT OWNER - Florida-FDBR-specific contract clauses; (e) CHILDREN PROTECTION LEAD - under-18 protections + parental consent + targeted-advertising-to-minors prohibition; (f) AI/VOICE/FACIAL RECOGNITION TECHNICAL LEAD - opt-out mechanism implementation + technical scope. OPERATIONAL CONTROLS: (a) consumer rights portal + identity verification; (b) DPA process + documentation; (c) sensitive-data opt-in flows; (d) voice/facial recognition opt-out flows; (e) privacy no

Artefacts an auditor will ask for
  • CPO appointment + privacy program charter
  • DPA ownership + records
  • Consumer rights metrics + SLA tracking
  • Operational metrics dashboard
Where this commonly fails
  • CPO not designated
  • DPA ownership unclear
  • Consumer rights SLA not measured
  • Operational metrics absent
FDBR-Status-Pipeline-Litigation
FDBR Implementation Status, 2024-2025 Amendments, Litigation and Pipeline

FDBR implementation status + 2024-2025 amendments + litigation. STATUS: FDBR effective 1 July 2024; amended by 2024 SB 472 (surveillance exemption clarifications + cure period refinements) + 2025 legislative session amendments (anticipated); Florida House Bill 3 (2024 social-media-minor restriction) struck down in part by federal court (Florida appealing). FLORIDA DEPARTMENT OF LEGAL AFFAIRS: published initial enforcement priorities + FAQs + cure-period guidance; 2024-2025 enforcement actions against major tech platforms (specific case dockets via FloridaAttorneyGeneral.com); FloridaDigitalBillofRights.com regulator portal. INTERPRETIVE GUIDANCE: Attorney General opinions on (a) USD 1B threshold calculation (worldwide vs Florida-specific); (b) voice/facial recognition opt-out implementation; (c) DPAs for processing minors; (d) government content moderation prohibition scope. LITIGATION:

Artefacts an auditor will ask for
  • FDBR amendment tracking
  • AG enforcement priorities + FAQ adoption
  • Litigation status tracking + adaptation
Where this commonly fails
  • FDBR amendments not tracked
  • AG priorities not adopted
  • Litigation outcomes not anticipated

Florida FDBR: Enforcement, Penalties, Cure Period and Florida AG / Department of Legal Affairs

FDBR-Enforcement-AG-CurePeriod
Enforcement by Florida Department of Legal Affairs + Penalties + 45-Day Cure (Fla. Stat. 501.72, 501.721, 501.722)

Florida Statutes 501.72-722. ENFORCEMENT AUTHORITY: the FLORIDA DEPARTMENT OF LEGAL AFFAIRS (within the Office of the Attorney General) has exclusive enforcement authority + may investigate + bring civil actions in state court. PENALTIES (501.72): (a) CIVIL PENALTY UP TO USD 50,000 PER VIOLATION; (b) UP TO USD 150,000 PER VIOLATION for INTENTIONAL VIOLATIONS or violations involving CHILDREN; (c) UP TO USD 1.5 MILLION PER YEAR or per ACT of non-compliance for repeated + intentional violations; (d) INJUNCTIVE relief + RESTITUTION to consumers + ATTORNEY FEES. NO PRIVATE RIGHT OF ACTION (501.722): the FDBR does NOT create a private right of action - consumers may not sue under the FDBR but may file complaints with the Department of Legal Affairs; this distinguishes the FDBR from CCPA (limited private right for data breaches) + Illinois BIPA (full private right for biometric). 45-DAY CURE PE

Artefacts an auditor will ask for
  • AG engagement procedure
  • Penalty calculation framework
  • Cure-period response procedure
  • Complaint-not-suit policy
Where this commonly fails
  • AG notification missed or slow
  • Cure window expired without remediation
  • Cure rejected for intentional violation
  • Misunderstanding FDBR creates private right of action

Florida FDBR: Florida-Specific Provisions (Search Engine Bias + Government Content Moderation)

FDBR-Section112.23-Government-Moderation
Government-Directed Content Moderation Prohibition (Fla. Stat. 112.23)

Florida Statutes 112.23 - Prohibition on government-directed content moderation (added by SB 262 alongside the FDBR). PROVISIONS: (1) PROHIBITION on Florida state + local government entities + officers + employees from: (a) DIRECTING + REQUESTING social media platforms or other online platforms to MODERATE specific content or accounts; (b) ENTERING INTO AGREEMENTS with platforms providing for moderation; (c) DIRECTLY OR INDIRECTLY communicating moderation requests outside of statutory notice channels. (2) EXCEPTIONS: (a) law enforcement responding to imminent threats to life or property; (b) emergency communications; (c) statutorily authorised public health communications; (d) intellectual-property enforcement notices; (e) statutory criminal-investigation requests under valid legal process. (3) ENFORCEMENT: violations may be enjoined by court + civil penalties + private right of action f

Artefacts an auditor will ask for
  • Online platform government-communication policy + log
  • Permitted-exception documentation
  • Litigation tracking + adaptation plan
Where this commonly fails
  • Government communications routed outside permitted exceptions
  • Documentation missing
  • Litigation status not tracked

Florida FDBR: Scope, Applicability Thresholds (USD 1B Big Tech) and Definitions

FDBR-Scope-Defs
Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)

Florida Statutes 501.701 short title + 501.702 definitions + 501.703 applicability + 501.704 exemptions. APPLICABILITY THRESHOLDS (NARROW + BIG TECH-FOCUSED): controllers that (a) conduct business in Florida + collect or process Florida consumer personal data + (b) make in excess of USD 1 BILLION in GLOBAL gross annual revenue + (c) satisfy AT LEAST ONE of: (i) derive 50% or more of global gross annual revenue from sale of advertisements ONLINE; OR (ii) operate a consumer SMART SPEAKER AND VOICE COMMAND COMPONENT SERVICE with integrated virtual assistant connected to a cloud computing service; OR (iii) operate an APP STORE or DIGITAL DISTRIBUTION PLATFORM offering at least 250,000 different software applications. KEY DEFINITIONS: CONSUMER = Florida resident acting in individual / household capacity (excluding employee + B2B contexts); CONTROLLER + PROCESSOR per GDPR-style roles; PERSONAL

Artefacts an auditor will ask for
  • Applicability assessment + threshold calculation
  • Sensitive data inventory
  • Child data identification (under 18)
Where this commonly fails
  • Wrongly assumed in-scope (USD 1B threshold not met)
  • Child threshold confused with COPPA under-13
  • Sensitive data definition narrower than FDBR

Florida FDBR: Sensitive Data, Children, Voice/Facial Recognition Opt-Out

FDBR-SensitiveData-Children-VoiceFacial
Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735)

Florida Statutes 501.711 sensitive data + 501.1735 Protection of Children Online. SENSITIVE DATA: includes race + ethnicity + religion + mental/physical health diagnosis + sex life + sexual orientation + citizenship status + genetic data + biometric data used for unique identification + precise geolocation + children data (under 18). PROCESSING REQUIRES (a) AFFIRMATIVE OPT-IN CONSENT from the consumer + clear notice + ability to withdraw; OR (b) for children under 18 + parental consent per the federal COPPA 16 CFR Part 312 + the more-protective Florida age threshold; OR (c) the controller is allowed to process under another statutory exception (e.g. HIPAA + healthcare delivery + court order). VOICE + FACIAL RECOGNITION DATA: an OPT-OUT right separate from sensitive-data opt-in - the consumer may opt out of collection of voice or facial recognition data (501.705(1)(e)); applies to smart s

Artefacts an auditor will ask for
  • Sensitive data opt-in records
  • Voice/facial opt-out mechanism
  • Children-under-18 processing controls
  • Florida HB 3 coordination + litigation tracking
Where this commonly fails
  • Sensitive data processed without opt-in (PROHIBITED)
  • Voice/facial opt-out not implemented
  • Children protections aligned only with COPPA-13 (FDBR uses under-18)
  • Florida HB 3 status not tracked

Statute Sections 501.701 to 501.72

FDBR-701
Short Title (§501.701)

Establishes the short title as the Florida Digital Bill of Rights

Artefacts an auditor will ask for
  • RI DTPPA short title reference card
  • Statutory citation register
  • Internal policy cross reference
  • Regulatory inventory entry
Where this commonly fails
  • Policy references generic privacy law not RI DTPPA
  • Citation register omits RI statute
  • Cross reference to other state laws missing
  • Effective date (1 Jan 2026) not flagged
FDBR-702
Definitions (§501.702)

Defines key terms including consumer, controller, processor, personal data, and sensitive data

Artefacts an auditor will ask for
  • Defined terms glossary aligned to RI DTPPA
  • Personal data taxonomy
  • Sensitive data category list
  • Sale and targeted advertising definitions reference
Where this commonly fails
  • Glossary not aligned to RI specific definitions
  • Sensitive data list missing RI categories
  • Sale definition copied from CCPA without RI adjustment
  • Targeted advertising definition not documented
FDBR-703
Applicability (§501.703)

Sets applicability thresholds for large businesses providing products or services in Florida

Artefacts an auditor will ask for
  • Applicability threshold assessment
  • RI resident count methodology
  • Revenue from sale calculation
  • Annual scoping review record
Where this commonly fails
  • Threshold assessment not refreshed annually
  • RI resident count estimated rather than measured
  • Revenue from sale not tracked discretely
  • Scoping review not signed off by counsel
FDBR-704
Exemptions (§501.704)

Lists exempted entities and data types including HIPAA, GLBA, and nonprofit organizations

Artefacts an auditor will ask for
  • Exemption applicability decision tree
  • Entity-level exemption evidence file (GLBA, HIPAA, FCRA)
  • Data-level exemption mapping
  • Exemption review log
Where this commonly fails
  • Exemption claimed at entity level when only data exempt
  • No evidence supporting GLBA or HIPAA exemption
  • Exemption mapping not refreshed
  • Overly broad reliance on employee data exemption
FDBR-705
Consumer Rights (§501.705)

Establishes consumer rights to access, delete, correct, and port personal data; includes opt-out rights

Artefacts an auditor will ask for
  • Consumer rights menu
  • Rights exercise portal
  • Plain language rights description
  • Rights audit log
Where this commonly fails
  • Rights menu hidden in lengthy privacy notice
  • Portal not accessible without account creation
  • Plain language test not performed
  • Rights log not retained for audit
FDBR-706
Controller Response Requirements (§501.706)

Sets timeframes for controller responses to consumer requests and notice requirements

Artefacts an auditor will ask for
  • Controller response SLA dashboard
  • Extension notification template
  • Denial reason library
  • Appeal handling procedure
Where this commonly fails
  • SLA dashboard not monitored weekly
  • Extension notifications not sent within window
  • Denial reasons inconsistent or unsupported
  • Appeal route absent or undocumented
FDBR-720
Enforcement and Penalties (§501.72)

Establishes enforcement mechanisms and penalty provisions by the Florida AG

Artefacts an auditor will ask for
  • AG inquiry response playbook (10-business-day acknowledgement target)
  • Cure period tracker (60-day cure window, sunset 31 Dec 2024 per § 42-525)
  • Penalty exposure model up to USD 5,000 per willful violation
  • Restitution and disgorgement reserve calculation
  • Post-cure-sunset escalation procedure to AG settlement counsel
Where this commonly fails
  • Cure tracker still relied on after sunset date
  • AG inquiry triage owner undefined
  • No coordination between privacy, security incident response, and legal hold
  • Penalty model not refreshed against latest AG enforcement reports
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Florida Digital Bill of Rights (FDBR) framework page.