FDBR · Opt-out (opt-in for sensitive data) model

Florida Privacy Law (FDBR): Compliance Guide

The Florida Digital Bill of Rights, effective July 1, 2024, is an outlier in nearly every dimension. Its $1 billion revenue prong takes direct aim at Big Tech, and it carries the country's only broad opt-IN requirement for processing sensitive data — health, financial, precise geolocation, and biometric information all need affirmative consent before processing. Do not assume the huge revenue number means you are exempt: the separate 100,000-consumer prong catches ordinary businesses too.

Effective
July 1, 2024
GPC / universal opt-out
Not required
Required link text
Your Privacy Choices
Handle FDBR compliance free

Last reviewed July 19, 2026 · Florida Digital Bill of Rights (FDBR)

Applicability

Who must comply with the FDBR

The Florida Digital Bill of Rights applies to businesses that meet the following criteria:

  • Conducts business in Florida, and:
  • Has annual gross revenue above $1 billion, or
  • Processes the personal data of 100,000 or more Florida consumers

Consumer rights

What Florida consumers can demand

  • Right to access personal data
  • Right to correct inaccuracies
  • Right to delete personal data
  • Right to data portability
  • Right to opt out of targeted advertising and the sale of personal data

Opt-out mechanics

Florida opt-out & GPC requirements

Like every US state privacy law, the FDBR uses an opt-out model: you do not need a GDPR-style cookie banner, but you must provide a clear and conspicuous opt-out link. The accepted text for Florida is Your Privacy Choices.

Global Privacy Control: Not required

The FDBR does not require honoring universal opt-out signals such as Global Privacy Control. The opt-out link remains the required mechanism for targeted advertising and sale opt-outs.

Enforcement

FDBR penalties & enforcement

  • Enforced by the Florida Attorney General

Cure period: Our reference lists no specific cure period for Florida; enforcement runs through the Florida Attorney General.

State quirks

What makes Florida different

Florida is the only state that flips the default for sensitive data. Everywhere else, sensitive personal information follows an opt-out model or a narrow consent duty; in Florida, health, financial, precise geolocation, and biometric data cannot be processed without opt-in consent at all. That demands a genuinely different consent flow for those categories — not just a link. The dual threshold structure is equally unusual: a $1 billion revenue prong for the largest platforms, and a separate 100,000-consumer prong that works like other states' volume tests.

Sensitive data requires opt-IN

Processing sensitive personal information — health, financial, precise geolocation, and biometric data — requires explicit opt-in consent. This is unique among the 20 state laws, which otherwise use opt-out for all categories.

$1 billion revenue prong

A revenue threshold aimed squarely at Big Tech — though the separate 100,000-consumer prong catches ordinary mid-size businesses too.

Automation

How ConsentKit handles Florida

  • ConsentKit's widget is served from Cloudflare's edge and receives the visitor's US state server-side, so Florida visitors are identified before any consent UI renders — no client-side geo-lookup delay.
  • Florida visitors see a persistent Your Privacy Choices link — the exact statutory text — available to new and returning visitors alike.
  • Florida does not legally require honoring Global Privacy Control. ConsentKit applies automatic GPC honoring in the 12 states that mandate it; in Florida the opt-out link remains the visitor's control.
  • Every opt-out is recorded server-side with a timestamp and jurisdiction metadata, reviewable and exportable (CSV) from the dashboard — the audit trail regulators ask for.
  • Google Consent Mode v2 stays in sync: analytics and advertising tags update the moment a Florida visitor makes a choice.

Florida's sensitive-data opt-in is a consent-flow problem, not just a link problem — ConsentKit's per-category consent records give you the audit trail for opt-ins and opt-outs alike.

FAQ

Florida FDBR FAQ

Who does the Florida Digital Bill of Rights actually cover?

Mainly large companies: it applies to businesses operating in Florida with annual revenue above $1 billion, or that process the personal data of 100,000 or more Florida consumers. The $1 billion prong was designed with Big Tech in mind — but the 100,000-consumer prong catches ordinary mid-size businesses too.

What is Florida's sensitive-data opt-in rule?

Florida is the only state that requires opt-in consent before processing sensitive personal information — health, financial, precise geolocation, and biometric data. Everywhere else, those categories follow an opt-out model or narrower consent duties, so Florida needs a genuinely different consent flow.

Is Global Privacy Control required in Florida?

No. The FDBR does not require honoring universal opt-out signals. The “Your Privacy Choices” opt-out link remains the required mechanism for targeted advertising and sale opt-outs.

When did the FDBR take effect, and who enforces it?

The law took effect July 1, 2024 and is enforced by the Florida Attorney General. Our reference lists no specific per-violation dollar figure or cure period for Florida.

This guide is for informational purposes and is not legal advice. Work with qualified counsel to confirm your obligations under the FDBR.

Comply with Florida's FDBR — and the other 19 state laws

ConsentKit detects each visitor's state at the Cloudflare edge, renders the exact opt-out link their law requires, honors GPC automatically where mandated, and records every choice for your audit trail.