Florida Privacy Law (FDBR): Compliance Guide
The Florida Digital Bill of Rights, effective July 1, 2024, is an outlier in nearly every dimension. Its $1 billion revenue prong takes direct aim at Big Tech, and it carries the country's only broad opt-IN requirement for processing sensitive data — health, financial, precise geolocation, and biometric information all need affirmative consent before processing. Do not assume the huge revenue number means you are exempt: the separate 100,000-consumer prong catches ordinary businesses too.
- Effective
- July 1, 2024
- GPC / universal opt-out
- Not required
- Required link text
- “Your Privacy Choices”
Last reviewed July 19, 2026 · Florida Digital Bill of Rights (FDBR)
Applicability
Who must comply with the FDBR
The Florida Digital Bill of Rights applies to businesses that meet the following criteria:
- Conducts business in Florida, and:
- Has annual gross revenue above $1 billion, or
- Processes the personal data of 100,000 or more Florida consumers
Consumer rights
What Florida consumers can demand
- Right to access personal data
- Right to correct inaccuracies
- Right to delete personal data
- Right to data portability
- Right to opt out of targeted advertising and the sale of personal data
Opt-out mechanics
Florida opt-out & GPC requirements
Like every US state privacy law, the FDBR uses an opt-out model: you do not need a GDPR-style cookie banner, but you must provide a clear and conspicuous opt-out link. The accepted text for Florida is “Your Privacy Choices”.
Global Privacy Control: Not required
The FDBR does not require honoring universal opt-out signals such as Global Privacy Control. The opt-out link remains the required mechanism for targeted advertising and sale opt-outs.
Enforcement
FDBR penalties & enforcement
- Enforced by the Florida Attorney General
Cure period: Our reference lists no specific cure period for Florida; enforcement runs through the Florida Attorney General.
State quirks
What makes Florida different
Florida is the only state that flips the default for sensitive data. Everywhere else, sensitive personal information follows an opt-out model or a narrow consent duty; in Florida, health, financial, precise geolocation, and biometric data cannot be processed without opt-in consent at all. That demands a genuinely different consent flow for those categories — not just a link. The dual threshold structure is equally unusual: a $1 billion revenue prong for the largest platforms, and a separate 100,000-consumer prong that works like other states' volume tests.
Sensitive data requires opt-IN
Processing sensitive personal information — health, financial, precise geolocation, and biometric data — requires explicit opt-in consent. This is unique among the 20 state laws, which otherwise use opt-out for all categories.
$1 billion revenue prong
A revenue threshold aimed squarely at Big Tech — though the separate 100,000-consumer prong catches ordinary mid-size businesses too.
Automation
How ConsentKit handles Florida
- ConsentKit's widget is served from Cloudflare's edge and receives the visitor's US state server-side, so Florida visitors are identified before any consent UI renders — no client-side geo-lookup delay.
- Florida visitors see a persistent “Your Privacy Choices” link — the exact statutory text — available to new and returning visitors alike.
- Florida does not legally require honoring Global Privacy Control. ConsentKit applies automatic GPC honoring in the 12 states that mandate it; in Florida the opt-out link remains the visitor's control.
- Every opt-out is recorded server-side with a timestamp and jurisdiction metadata, reviewable and exportable (CSV) from the dashboard — the audit trail regulators ask for.
- Google Consent Mode v2 stays in sync: analytics and advertising tags update the moment a Florida visitor makes a choice.
Florida's sensitive-data opt-in is a consent-flow problem, not just a link problem — ConsentKit's per-category consent records give you the audit trail for opt-ins and opt-outs alike.
FAQ
Florida FDBR FAQ
Who does the Florida Digital Bill of Rights actually cover?
Mainly large companies: it applies to businesses operating in Florida with annual revenue above $1 billion, or that process the personal data of 100,000 or more Florida consumers. The $1 billion prong was designed with Big Tech in mind — but the 100,000-consumer prong catches ordinary mid-size businesses too.
What is Florida's sensitive-data opt-in rule?
Florida is the only state that requires opt-in consent before processing sensitive personal information — health, financial, precise geolocation, and biometric data. Everywhere else, those categories follow an opt-out model or narrower consent duties, so Florida needs a genuinely different consent flow.
Is Global Privacy Control required in Florida?
No. The FDBR does not require honoring universal opt-out signals. The “Your Privacy Choices” opt-out link remains the required mechanism for targeted advertising and sale opt-outs.
When did the FDBR take effect, and who enforces it?
The law took effect July 1, 2024 and is enforced by the Florida Attorney General. Our reference lists no specific per-violation dollar figure or cure period for Florida.
This guide is for informational purposes and is not legal advice. Work with qualified counsel to confirm your obligations under the FDBR.
Comply with Florida's FDBR — and the other 19 state laws
ConsentKit detects each visitor's state at the Cloudflare edge, renders the exact opt-out link their law requires, honors GPC automatically where mandated, and records every choice for your audit trail.