Alabama's product-security and cyber-resilience posture, for a private-sector operator, rests on one enacted state statute reaching a covered entity's general security posture: the Alabama Data Breach Notification Act of 2018 (Act 2018-396, effective June 1, 2018), whose Section 8-38-3 requires each covered entity and third-party agent to implement and maintain reasonable security measures to protect sensitive personally identifying information against a breach of security, and whose Section 8-38-10 separately requires a covered entity or third-party agent to take reasonable measures to dispose of records containing that information, by shredding, erasing, or otherwise rendering it unreadable, once the records are no longer to be retained.
"Covered entity" is defined broadly to include a government entity as well as a private business, so both duties bind the state and its political subdivisions alongside private operators.
Enforcement of these two duties is narrower than the chapter's heading suggests: Section 8-38-9, titled "Violations of Notification Requirements," gives the Attorney General exclusive authority to bring a civil action under the chapter, but the only civil-penalty amounts the section actually states, up to $500,000 per breach under Section 8-19-11, or $5,000 per day under subsection (b)(1), are tied expressly to a violation of "the notification provisions of this chapter" and "the notice provisions of this chapter," the separate duties at Sections 8-38-4 through 8-38-8, not to the reasonable-security or disposal duties recorded here; no other enforcement mechanism or penalty figure is stated in the chapter for a violation of Section 8-38-3 or Section 8-38-10 specifically.
The chapter forecloses a private cause of action for a violation of any of its provisions, while preserving whatever right a person may separately have at common law, by statute, or otherwise. No enacted Alabama statute was located that sets security requirements a connected device or software product must meet before or after it reaches the market, comparable to California's or Oregon's connected-device statutes or the Cyber Resilience Act; this is a researched absence.
Alabama has adopted the NAIC Insurance Data Security Model Law as its own Insurance Data Security Law, Ala. Code sections 27-62-1 to 27-62-11 (Act 2019-98), which requires each "licensee," defined at Section 27-62-3 as a person licensed, authorized to operate, or registered pursuant to the insurance laws of the state, to develop, implement, and maintain a written information security program and to investigate and notify the Commissioner of a cybersecurity event.
Because "licensee" is a role the LexLint activity vocabulary cannot yet express, the same gap already recorded for South Carolina's, North Carolina's, Kentucky's, New Hampshire's, and Pennsylvania's insurance data security statutes, no instrument is filed for it here, and it is recorded in this summary so a reader knows it exists.
Alabama has no general private-sector duty to report an exploited vulnerability or a security incident to an authority: the Insurance Data Security Law's own incident-notification duty, Section 27-62-6, reaches only that same licensee population, and the state's Office of Information Technology operates a cyber-incident-reporting channel that is a state-agency program rather than a status-based duty on a private operator.
Alabama's breach-notification duty, the Data Breach Notification Act's Sections 8-38-4 through 8-38-8, is already this jurisdiction's privacy row rather than repeated here.
The Alabama Personal Data Protection Act (HB 351, 2026), Ala. Code Title 8, Chapter 44, effective May 1, 2027, layers a comprehensive privacy regime's own security-of-processing clause onto any controller it reaches, Section 7(a)(2), requiring a controller to establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal data at issue; this belongs to the privacy topic rather than here, on the same reasoning Texas's Data Privacy and Security Act's Section 541.101(a)(2) does, because it is one subsection of a comprehensive regime addressed to a controller and the chapter's other controller duties are already researched there.