Florida Digital Bill of Rights (FDBR)
Evidence request list. 19 controls, 19 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Florida FDBR: Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)
Florida Statutes 501.705 consumer rights + 501.706 controller response + 501.707 controller responsibilities. CONSUMER RIGHTS: (1) RIGHT TO CONFIRM + ACCESS the personal data the controller is processing about the consumer; (2) RIGHT TO CORRECT inaccuracies in personal data; (3) RIGHT TO DELETE personal data provided by or obtained about the consumer; (4) RIGHT TO DATA PORTABILITY - obtain in portable + commonly used + technically feasible format if processing is automated; (5) RIGHT TO OPT OUT of (a) SALE of personal data; (b) TARGETED ADVERTISING; (c) PROFILING in furtherance of solely automated decisions producing legal or similarly significant effects; (6) RIGHT TO OPT-OUT OF COLLECTION OF VOICE OR FACIAL RECOGNITION DATA (UNIQUE to Florida + not in other state laws). CONTROLLER RESPONSE (501.706): 45 DAYS to respond + may extend by 15 days for complex requests; must confirm receipt
- Rights request procedure + log
- Voice/facial recognition opt-out mechanism
- Identity verification policy
- Appeals procedure documented
- Voice/facial recognition opt-out missing (UNIQUE Florida requirement)
- 45-day SLA missed
- Identity verification too weak or too strong
- Appeals procedure unclear
Florida FDBR: Controller and Processor Obligations, DPA, Privacy Notice
Florida Statutes 501.707-711. CONTROLLER RESPONSIBILITIES (501.707): (a) PURPOSE LIMITATION - limit personal data collection + retention to what is adequate + relevant + reasonably necessary for the specified purpose; (b) DATA MINIMISATION; (c) PROHIBITION on processing personal data for purposes neither reasonably necessary to + compatible with the disclosed purposes; (d) AVOID PROCESSING in violation of FDBR + state + federal anti-discrimination laws; (e) IMPLEMENT REASONABLE administrative + technical + physical safeguards. DATA PROTECTION ASSESSMENTS (501.708): controllers MUST CONDUCT DPAs for processing activities involving (a) sale of personal data; (b) targeted advertising; (c) profiling presenting reasonably foreseeable risk of unfair or deceptive treatment / unlawful disparate impact / financial / physical / reputational injury / intrusion on private affairs / other substantial
- DPA template + records
- Processor agreement template
- Privacy notice published + accurate
- Search bias disclosure if applicable
- DPA skipped for risk categories
- Processor agreements weak
- Privacy notice generic or stale
- Search bias disclosure missing if applicable
Florida FDBR: Coordination with US State Privacy Laws, COPPA, FOSA and Status
Florida FDBR crosswalk to comprehensive security + privacy frameworks. NIST CSF 2.0 mapping: GOVERN (FDBR controller responsibilities + DPAs + privacy notice) + IDENTIFY (sensitive data inventory + minors data + voice/facial recognition data) + PROTECT (opt-in + opt-out + access controls + safeguards under 501.707) + DETECT (rights-request monitoring + breach detection) + RESPOND (45-day rights SLA + cure-period response + breach response) + RECOVER (data restoration + rights remediation). NIST PRIVACY FRAMEWORK + NIST AI RISK MANAGEMENT FRAMEWORK (NIST AI 600-1) coordination for AI + profiling + automated decision-making + voice/facial recognition. ISO/IEC 27001:2022 + ISO/IEC 27701:2019 mapping: ISO 27001 ISMS + ISO 27701 PIMS provide ISMS + PIMS structure for FDBR program implementation. SOC 2 (Service Organization Control 2): privacy + confidentiality + security trust service criteri
- NIST CSF 2.0 crosswalk
- ISO 27001/27701 alignment evidence
- SOC 2 report + AICPA assessment
- Sectoral exemption documentation
- Crosswalk to NIST/ISO/SOC 2 not maintained
- Sectoral exemption mapping incomplete
- AICPA + IAPP guidance not integrated
Florida FDBR coordination with the rapidly-growing US state privacy law ecosystem. COMPARABLE STATE LAWS (as of 2026 - approximately 20 comprehensive state privacy laws): California (CCPA + CPRA + 2018/2020) + Virginia VCDPA (2021) + Colorado CPA (2021) + Connecticut CTDPA (2022) + Utah UCPA (2022) + Iowa ICDPA (2023) + Indiana INCDPA (2023) + Tennessee TIPA (2023) + Montana MCDPA (2023) + Oregon OCPA (2023) + Texas TDPSA (2023) + Delaware DPDPA (2023) + New Jersey NJDPA (2024) + New Hampshire NHDPA (2024) + Kentucky KCDPA (2024) + Maryland MDPA (2024) + Minnesota MCDPA (2024) + Nebraska NDPA (2024) + Rhode Island RIDTPPA (2024) + Washington WDPA (2025) + Florida FDBR. KEY DIFFERENTIATORS for FDBR: (a) NARROWEST APPLICABILITY (USD 1B threshold + big-tech-specific) - most other states are USD 25M-100M + business volume + consumer thresholds; (b) UNIQUE VOICE/FACIAL RECOGNITION OPT-OUT not
- Multi-state privacy compliance program
- Florida-specific feature implementation evidence
- Federal preemption tracking (APRA + others)
- State privacy laws confused with each other
- Florida-unique features missed
- Federal preemption not tracked
Florida FDBR coordination with sectoral federal privacy + data protection laws. COPPA (Children Online Privacy Protection Act, 15 USC 6501 + 16 CFR Part 312): FTC-administered; covers online services collecting from children under 13; FDBR is MORE PROTECTIVE (under 18) + may apply in parallel; the 2024 FTC COPPA Rule Update + the pending COPPA 2.0 (Markey-Cassidy Senate bill) would extend to teens 13-16 aligning with FDBR. FERPA (Family Educational Rights and Privacy Act, 20 USC 1232g + 34 CFR Part 99): EXEMPT data covered by FERPA at the dataset level - educational records remain FERPA-governed; ed-tech vendors may be subject to FDBR for non-educational records. HIPAA: EXEMPT data covered by HIPAA at the dataset level - health records remain HIPAA-governed; non-health-record consumer data of healthcare entities may be subject to FDBR. GLBA (Gramm-Leach-Bliley Act + 16 CFR Part 314 Safeg
- Exemption documentation + dataset-level classification
- Sectoral compliance program (where applicable)
- CIRCIA + critical-infrastructure coordination
- Exemption claims overbroad
- Sectoral compliance program missing
- CIRCIA coordination skipped
Florida FDBR vs comprehensive privacy regimes + federal preemption tracking. GDPR (EU Regulation 2016/679): FDBR is NARROWER (USD 1B big-tech threshold vs GDPR universal applicability) + DIFFERENT RIGHTS STRUCTURE (FDBR has voice/facial recognition opt-out + sensitive data opt-in vs GDPR Article 9 explicit consent + DPIA) + LIGHTER ENFORCEMENT (USD 50K-1.5M vs GDPR 2-4% turnover) + NO PRIVATE RIGHT OF ACTION (vs GDPR Article 79-80). CALIFORNIA CCPA/CPRA: FDBR + CCPA share rights (access + deletion + portability + opt-out) but CCPA includes BUSINESS-PURPOSE service-provider concept + sensitive personal information notice-at-collection + private right of action for breaches; CCPA covers MORE BUSINESSES (USD 25M threshold + 100K consumers + sale-of-data threshold) than FDBR. PRC PIPL (Personal Information Protection Law): completely different legal context + cross-border transfer focus + Ch
- Multi-regime compliance program
- Cross-border data flow assessment
- APRA + federal preemption tracking
- Cross-regime compliance program ad-hoc
- APRA + federal preemption not tracked
- Florida-only program ignores multi-state + federal interplay
FDBR compliance program implementation roadmap. ORGANIZATIONAL ROLES: (a) PRIVACY COUNSEL or CHIEF PRIVACY OFFICER (CPO) - FDBR coordination + AG engagement + cross-state privacy program; (b) DATA PROTECTION ASSESSMENT OWNER - conducting + maintaining DPAs for sale + targeted advertising + profiling + sensitive data + minors; (c) CONSUMER RIGHTS MANAGER - 45-day SLA + identity verification + appeals; (d) VENDOR + PROCESSOR CONTRACT OWNER - Florida-FDBR-specific contract clauses; (e) CHILDREN PROTECTION LEAD - under-18 protections + parental consent + targeted-advertising-to-minors prohibition; (f) AI/VOICE/FACIAL RECOGNITION TECHNICAL LEAD - opt-out mechanism implementation + technical scope. OPERATIONAL CONTROLS: (a) consumer rights portal + identity verification; (b) DPA process + documentation; (c) sensitive-data opt-in flows; (d) voice/facial recognition opt-out flows; (e) privacy no
- CPO appointment + privacy program charter
- DPA ownership + records
- Consumer rights metrics + SLA tracking
- Operational metrics dashboard
- CPO not designated
- DPA ownership unclear
- Consumer rights SLA not measured
- Operational metrics absent
FDBR implementation status + 2024-2025 amendments + litigation. STATUS: FDBR effective 1 July 2024; amended by 2024 SB 472 (surveillance exemption clarifications + cure period refinements) + 2025 legislative session amendments (anticipated); Florida House Bill 3 (2024 social-media-minor restriction) struck down in part by federal court (Florida appealing). FLORIDA DEPARTMENT OF LEGAL AFFAIRS: published initial enforcement priorities + FAQs + cure-period guidance; 2024-2025 enforcement actions against major tech platforms (specific case dockets via FloridaAttorneyGeneral.com); FloridaDigitalBillofRights.com regulator portal. INTERPRETIVE GUIDANCE: Attorney General opinions on (a) USD 1B threshold calculation (worldwide vs Florida-specific); (b) voice/facial recognition opt-out implementation; (c) DPAs for processing minors; (d) government content moderation prohibition scope. LITIGATION:
- FDBR amendment tracking
- AG enforcement priorities + FAQ adoption
- Litigation status tracking + adaptation
- FDBR amendments not tracked
- AG priorities not adopted
- Litigation outcomes not anticipated
Florida FDBR: Enforcement, Penalties, Cure Period and Florida AG / Department of Legal Affairs
Florida Statutes 501.72-722. ENFORCEMENT AUTHORITY: the FLORIDA DEPARTMENT OF LEGAL AFFAIRS (within the Office of the Attorney General) has exclusive enforcement authority + may investigate + bring civil actions in state court. PENALTIES (501.72): (a) CIVIL PENALTY UP TO USD 50,000 PER VIOLATION; (b) UP TO USD 150,000 PER VIOLATION for INTENTIONAL VIOLATIONS or violations involving CHILDREN; (c) UP TO USD 1.5 MILLION PER YEAR or per ACT of non-compliance for repeated + intentional violations; (d) INJUNCTIVE relief + RESTITUTION to consumers + ATTORNEY FEES. NO PRIVATE RIGHT OF ACTION (501.722): the FDBR does NOT create a private right of action - consumers may not sue under the FDBR but may file complaints with the Department of Legal Affairs; this distinguishes the FDBR from CCPA (limited private right for data breaches) + Illinois BIPA (full private right for biometric). 45-DAY CURE PE
- AG engagement procedure
- Penalty calculation framework
- Cure-period response procedure
- Complaint-not-suit policy
- AG notification missed or slow
- Cure window expired without remediation
- Cure rejected for intentional violation
- Misunderstanding FDBR creates private right of action
Florida FDBR: Florida-Specific Provisions (Search Engine Bias + Government Content Moderation)
Florida Statutes 112.23 - Prohibition on government-directed content moderation (added by SB 262 alongside the FDBR). PROVISIONS: (1) PROHIBITION on Florida state + local government entities + officers + employees from: (a) DIRECTING + REQUESTING social media platforms or other online platforms to MODERATE specific content or accounts; (b) ENTERING INTO AGREEMENTS with platforms providing for moderation; (c) DIRECTLY OR INDIRECTLY communicating moderation requests outside of statutory notice channels. (2) EXCEPTIONS: (a) law enforcement responding to imminent threats to life or property; (b) emergency communications; (c) statutorily authorised public health communications; (d) intellectual-property enforcement notices; (e) statutory criminal-investigation requests under valid legal process. (3) ENFORCEMENT: violations may be enjoined by court + civil penalties + private right of action f
- Online platform government-communication policy + log
- Permitted-exception documentation
- Litigation tracking + adaptation plan
- Government communications routed outside permitted exceptions
- Documentation missing
- Litigation status not tracked
Florida FDBR: Scope, Applicability Thresholds (USD 1B Big Tech) and Definitions
Florida Statutes 501.701 short title + 501.702 definitions + 501.703 applicability + 501.704 exemptions. APPLICABILITY THRESHOLDS (NARROW + BIG TECH-FOCUSED): controllers that (a) conduct business in Florida + collect or process Florida consumer personal data + (b) make in excess of USD 1 BILLION in GLOBAL gross annual revenue + (c) satisfy AT LEAST ONE of: (i) derive 50% or more of global gross annual revenue from sale of advertisements ONLINE; OR (ii) operate a consumer SMART SPEAKER AND VOICE COMMAND COMPONENT SERVICE with integrated virtual assistant connected to a cloud computing service; OR (iii) operate an APP STORE or DIGITAL DISTRIBUTION PLATFORM offering at least 250,000 different software applications. KEY DEFINITIONS: CONSUMER = Florida resident acting in individual / household capacity (excluding employee + B2B contexts); CONTROLLER + PROCESSOR per GDPR-style roles; PERSONAL
- Applicability assessment + threshold calculation
- Sensitive data inventory
- Child data identification (under 18)
- Wrongly assumed in-scope (USD 1B threshold not met)
- Child threshold confused with COPPA under-13
- Sensitive data definition narrower than FDBR
Florida FDBR: Sensitive Data, Children, Voice/Facial Recognition Opt-Out
Florida Statutes 501.711 sensitive data + 501.1735 Protection of Children Online. SENSITIVE DATA: includes race + ethnicity + religion + mental/physical health diagnosis + sex life + sexual orientation + citizenship status + genetic data + biometric data used for unique identification + precise geolocation + children data (under 18). PROCESSING REQUIRES (a) AFFIRMATIVE OPT-IN CONSENT from the consumer + clear notice + ability to withdraw; OR (b) for children under 18 + parental consent per the federal COPPA 16 CFR Part 312 + the more-protective Florida age threshold; OR (c) the controller is allowed to process under another statutory exception (e.g. HIPAA + healthcare delivery + court order). VOICE + FACIAL RECOGNITION DATA: an OPT-OUT right separate from sensitive-data opt-in - the consumer may opt out of collection of voice or facial recognition data (501.705(1)(e)); applies to smart s
- Sensitive data opt-in records
- Voice/facial opt-out mechanism
- Children-under-18 processing controls
- Florida HB 3 coordination + litigation tracking
- Sensitive data processed without opt-in (PROHIBITED)
- Voice/facial opt-out not implemented
- Children protections aligned only with COPPA-13 (FDBR uses under-18)
- Florida HB 3 status not tracked
Statute Sections 501.701 to 501.72
Establishes the short title as the Florida Digital Bill of Rights
- RI DTPPA short title reference card
- Statutory citation register
- Internal policy cross reference
- Regulatory inventory entry
- Policy references generic privacy law not RI DTPPA
- Citation register omits RI statute
- Cross reference to other state laws missing
- Effective date (1 Jan 2026) not flagged
Defines key terms including consumer, controller, processor, personal data, and sensitive data
- Defined terms glossary aligned to RI DTPPA
- Personal data taxonomy
- Sensitive data category list
- Sale and targeted advertising definitions reference
- Glossary not aligned to RI specific definitions
- Sensitive data list missing RI categories
- Sale definition copied from CCPA without RI adjustment
- Targeted advertising definition not documented
Sets applicability thresholds for large businesses providing products or services in Florida
- Applicability threshold assessment
- RI resident count methodology
- Revenue from sale calculation
- Annual scoping review record
- Threshold assessment not refreshed annually
- RI resident count estimated rather than measured
- Revenue from sale not tracked discretely
- Scoping review not signed off by counsel
Lists exempted entities and data types including HIPAA, GLBA, and nonprofit organizations
- Exemption applicability decision tree
- Entity-level exemption evidence file (GLBA, HIPAA, FCRA)
- Data-level exemption mapping
- Exemption review log
- Exemption claimed at entity level when only data exempt
- No evidence supporting GLBA or HIPAA exemption
- Exemption mapping not refreshed
- Overly broad reliance on employee data exemption
Establishes consumer rights to access, delete, correct, and port personal data; includes opt-out rights
- Consumer rights menu
- Rights exercise portal
- Plain language rights description
- Rights audit log
- Rights menu hidden in lengthy privacy notice
- Portal not accessible without account creation
- Plain language test not performed
- Rights log not retained for audit
Sets timeframes for controller responses to consumer requests and notice requirements
- Controller response SLA dashboard
- Extension notification template
- Denial reason library
- Appeal handling procedure
- SLA dashboard not monitored weekly
- Extension notifications not sent within window
- Denial reasons inconsistent or unsupported
- Appeal route absent or undocumented
Establishes enforcement mechanisms and penalty provisions by the Florida AG
- AG inquiry response playbook (10-business-day acknowledgement target)
- Cure period tracker (60-day cure window, sunset 31 Dec 2024 per § 42-525)
- Penalty exposure model up to USD 5,000 per willful violation
- Restitution and disgorgement reserve calculation
- Post-cure-sunset escalation procedure to AG settlement counsel
- Cure tracker still relied on after sunset date
- AG inquiry triage owner undefined
- No coordination between privacy, security incident response, and legal hold
- Penalty model not refreshed against latest AG enforcement reports
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Florida Digital Bill of Rights (FDBR) framework page.