Law / United States / Florida

Florida

United States law applies in Florida Florida is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Florida, described on this page below, applies here too.

14 of 15 named instruments researched to a stage, across five of the six areas of law we track: 13 in force and 1 enacted but not yet in force. As of 14 September 2026.

When they take effect12 of 14 carry a date, 2 do not.
2014: 1 instrument (1 in force) ’14 2015: 0 instruments 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 1 instrument (1 in force) 2020: 0 instruments ’20 2021: 0 instruments 2022: 2 instruments (2 in force) 2023: 0 instruments 2024: 6 instruments (6 in force) 2025: 2 instruments (2 in force) 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 3
  2. Privacy law 5
  3. Scraping law 3
  4. Cybersecurity law 1
  5. Age gating law 2
  6. News aggregation law none researched

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law3 instruments, 3 in force

Research summary (254 words)

Florida has no general statute requiring a consumer-facing generative AI product to disclose its non-human status. A comprehensive Artificial Intelligence Bill of Rights that would have added a chatbot-disclosure duty, parental-consent requirements for companion chatbot use by minors, and government AI-contracting restrictions, Senate Bill 482 (2026), passed the Senate 35 to 2 on March 4, 2026 but died in House Messages on March 13, 2026 without a House floor vote.

Florida's enacted AI-transparency duty is narrow: a political advertisement or other advertisement of a political nature that uses generative AI to depict a real person doing something that did not happen, created to injure a candidate or deceive on a ballot issue, must carry a prominent AI-use disclaimer.

Separately, Florida bans the willful generation, solicitation, or malicious promotion of an altered sexual depiction of an identifiable person without consent, arms the depicted person with a civil action, and, since a 2025 amendment cited as Brooke's Law, requires a covered platform to remove such a depiction within 48 hours of a valid request.

Florida's child sexual abuse material statute independently reaches any image created, altered, adapted, or modified by electronic, mechanical, or other means to portray an identifiable minor engaged in sexual conduct, the same as an unaltered photograph.

A 2026 study bill directing the Florida Digital Service to study state agencies' own procurement and use of AI, SB 146, remained in committee at the close of the 2026 session and would bind only state agencies, so it is not catalogued as an instrument here.

AI prohibited practices

Child Sexual Abuse Material Including AI-Altered Images of a Minor

Fla. Stat. § 827.071Florida Statutes, official code text, Online Sunshine

In force since 1 October 2022. Binds public and private bodies.

What this law does

Florida's child sexual abuse material statute defines the term to include any image that has been created, altered, adapted, or modified by electronic, mechanical, or other means to portray an identifiable minor engaged in sexual conduct, reaching an AI-generated or AI-altered depiction the same as an unaltered photograph.

Using or inducing a child in a sexual performance is a first-degree felony with a 15-year mandatory minimum, or 25 years in aggravated circumstances; promoting such a performance is a second-degree felony with a 5-year mandatory minimum; and possessing with intent to promote, or knowingly soliciting, possessing, controlling, or intentionally viewing such material, is a second-degree felony.

This AI-covering definition took effect October 1, 2022, and the surrounding evidentiary criteria were further amended in 2025.

What it requires

Promotion of an Altered Sexual Depiction; Brooke's Law platform takedown duty

Fla. Stat. § 836.13Florida Statutes, official code text, Online Sunshine

In force since 1 October 2022. Binds public and private bodies.

What this law does

It is a third-degree felony to willfully generate, solicit, or maliciously promote a digitally, electronically, or mechanically altered sexual depiction of an identifiable person without that person's consent, and an aggrieved person may bring a civil action for injunctive relief and at least $10,000 in damages plus attorney's fees.

A 2025 amendment cited as Brooke's Law added a duty for a covered platform, one that primarily hosts user-generated content or that in the regular course of business makes such depictions available, to establish a notice-and-removal process and to remove a validly requested depiction, and known identical copies, within 48 hours; a platform's unreasonable failure to comply is treated as an unfair or deceptive trade practice under part II of chapter 501. Florida created this prohibition in 2022. Its criminal provisions were further amended in 2025.

What it requires

AI transparency

AI Use in Political Advertising Disclosure Requirement (HB 919, 2024)

Fla. Stat. § 106.145Florida Statutes, official code text, Online Sunshine

In force since 1 July 2024. Binds public and private bodies.

What this law does

A political advertisement, an electioneering communication, or another advertisement of a political nature that contains images, video, audio, or graphics created in whole or in part with generative AI, that appears to depict a real person performing an action that did not occur, and that was created to injure a candidate or deceive regarding a ballot issue, must carry a prominent disclaimer stating that generative AI was used.

The disclaimer's format varies by medium, and failing to include it is a first-degree misdemeanor; any person may file a complaint with the Florida Elections Commission. Chaptered as 2024-126 and signed April 29, 2024.

What it requires

Privacy law5 instruments, 4 in force, 1 enacted but not yet in force

Research summary (240 words)

The Florida Digital Bill of Rights (FDBR), Fla. Stat. §§ 501.701-501.718 (Part VI, Chapter 501), is not a comprehensive consumer-privacy statute.

It binds only a 'controller' that conducts business in Florida for profit, collects personal data, makes more than $1 billion in global gross annual revenue, and additionally derives 50 percent or more of that revenue from online advertising, operates a qualifying smart-speaker service, or operates an app store or digital distribution platform offering at least 250,000 applications.

Enacted as SB 262 (2023 Regular Session, Laws of Florida ch. 2023-201) and effective July 1, 2024, FDBR requires prior consent for sensitive data and gives a qualifying consumer access, correction, deletion, portability, and opt-out rights, but outside the tiny set of qualifying mega-platforms a Florida business faces no state-law data-minimization, purpose-limitation, or consumer-rights duty under Part VI at all.

FDBR's biometric data definition carries a blanket, unconditional exclusion for a photograph, video, or audio recording, or any data generated from either, with no clawback for data generated to identify someone, so a faceprint or voiceprint extracted from a recording falls outside biometric, and therefore sensitive, data even for a qualifying controller.

A separate, far more broadly reaching statute, the Florida Information Protection Act (Fla. Stat. § 501.171), governs breach notification for any commercial entity with no revenue gate. FDBR enforcement is exclusive to the Department of Legal Affairs, with no private right of action and a discretionary, not mandatory, cure period.

Breach notification

Florida Information Protection Act, breach notification

Fla. Stat. § 501.171official Florida statute text, Florida Statutes, Florida Legislature

Commencement not set. Binds private bodies.

What this law does

A covered entity, defined broadly as any commercial entity that acquires, maintains, stores, or uses personal information, with no revenue gate of any kind, must provide notice to the Department of Legal Affairs of a breach affecting 500 or more individuals in Florida as expeditiously as practicable and no later than 30 days after determining a breach occurred or having reason to believe one occurred, and must give notice to each affected Florida individual on the same 30-day deadline, extendable by 15 days on a written good-cause showing.

This statute reaches far more entities than FDBR's $1 billion-plus controller duties and must not be conflated with FDBR. Originally enacted in 2014 (ch. 2014-189/190) and amended repeatedly since, including by the same 2023 bill that created FDBR and again by ch. 2026-52 in the 2026 session; no dated original commencement is established from the codified text, so no effective date is recorded here.

The statute expressly bars a private cause of action, so a breach violation does not reach a private plaintiff, through FDUTPA or otherwise.

What it requires

Comprehensive regime

Florida Digital Bill of Rights, general applicability and large-platform threshold

Fla. Stat. §§ 501.701, 501.702(9)official Florida statute text, Florida Statutes, Florida Legislature

In force since 1 July 2024. Binds private bodies.

What this law does

FDBR binds only a 'controller': a for-profit entity conducting business in Florida that collects personal data and determines the purposes and means of processing, that also makes in excess of $1 billion in global gross annual revenue and additionally either derives 50 percent or more of its global gross annual revenue from online advertising, operates a consumer smart speaker and voice command service with an integrated virtual assistant, or operates an app store or digital distribution platform offering at least 250,000 applications.

This conjunctive-then-disjunctive threshold excludes essentially every business below $1 billion in global revenue, the overwhelming majority of controllers a peer state's comprehensive act would reach. Outside this narrow platform set, Florida imposes no state-law data-minimization, purpose-limitation, or consumer-rights duty on personal-data processing at all.

What it requires

Data subject rights

Florida Digital Bill of Rights, consumer rights

Fla. Stat. §§ 501.705, 501.706, 501.707official Florida statute text, Florida Statutes, Florida Legislature

In force since 1 July 2024. Binds private bodies.

What this law does

Against a qualifying controller, FDBR gives a Florida consumer confirmation and access, correction, deletion of data provided by or obtained about the consumer, data portability in a readily usable digital format, opt-out of processing for targeted advertising, sale, or profiling producing a legal or similarly significant effect, opt-out of collection or processing of sensitive data including precise geolocation, and opt-out of collection of personal data through a voice or facial recognition feature.

A controller must respond without undue delay and no later than 45 days after receipt, with one 15-day extension available, shorter than the 45-plus-45 model most peer states use, and must decide an appeal of a denial within 60 days. Rights are exercisable only against a narrowly defined controller and only by a Florida-resident consumer acting outside a commercial or employment context.

What it requires

Enforcement supervision

Florida Digital Bill of Rights, Department of Legal Affairs enforcement

Fla. Stat. § 501.72official Florida statute text, Florida Statutes, Florida Legislature

In force since 1 July 2024. Binds private bodies.

What this law does

A violation of FDBR is an unfair and deceptive trade practice actionable solely by the Florida Department of Legal Affairs, with a civil penalty of up to $50,000 per violation, tripled for a known-child violation, a failure to delete or correct data after a valid request, or continuing to sell or share data after an opt-out.

After written notice of an alleged violation, the Department may, but is not required to, grant a 45-day cure period and issue a letter of guidance; that cure period does not apply to a known-child violation, and no sunset date for the cure provision appears anywhere in the text reviewed. FDBR creates no private right of action.

What it requires

Sensitive categories

Florida Digital Bill of Rights, sensitive data and biometric data definitions

Fla. Stat. §§ 501.702(4), 501.702(31), 501.71(2)(d)official Florida statute text, Florida Statutes, Florida Legislature

In force since 1 July 2024. Binds private bodies.

What this law does

For a qualifying controller, FDBR classifies data revealing racial or ethnic origin, religious beliefs, a mental or physical health diagnosis, sexual orientation, or citizenship or immigration status, genetic or biometric data processed to uniquely identify an individual, a known child's personal data, and precise geolocation data as sensitive data, which may not be processed without the consumer's prior consent.

'Biometric data' means data from automatic measurement of biological characteristics used to identify a person, including fingerprints, voiceprints, or eye retinas or irises, but the definition carries a blanket, unconditional exclusion for physical or digital photographs, video or audio recordings, or data generated from either, with no clawback for data generated to identify someone.

A voiceprint or faceprint extracted from a recording for identification purposes is therefore categorically outside biometric, and so sensitive, data here, the opposite posture from Connecticut's and Delaware's clawback structure. A controller may not sell sensitive personal data without prior consent and must display the notice "NOTICE: This website may sell your sensitive personal data" before doing so.

What it requires

Scraping law3 instruments, 3 in force

Research summary (172 words)

Florida diverges from federal scraping law in the computer_misuse, personal_data, and unfair_competition families. Its computer-crime statute explicitly names both the without authorization and exceeding authorization prongs the federal Computer Fraud and Abuse Act (CFAA) uses, and because Van Buren v. United States construed only the federal statute, Florida's own exceeding-authorization prong is not automatically narrowed by that federal reading.

The Florida Digital Bill of Rights (FDBR) is the narrowest of its kind among the states researched: it reaches only for-profit entities making more than $1 billion in global gross annual revenue and meeting an additional online-advertising, smart-speaker, or app-store criterion, so it binds essentially no ordinary scraper's target and no ordinary scraping actor.

The Florida Deceptive and Unfair Trade Practices Act (FDUTPA) is Florida's general backstop against deceptive scraping-adjacent conduct, with both Attorney General enforcement and a private right of action. Copyright, text-and-data-mining, and database rights add nothing beyond the federal position. ToS enforceability rests on general contract law with no Florida-specific rule, so it earns no instrument here. robots.txt carries no independent legal weight in Florida.

Computer misuse

Florida Computer-Related Crime Act (dual without-authorization and exceeding-authorization prongs)

Fla. Stat. § 815.06official text, Florida Legislature (leg.state.fl.us)

In force since 1 October 2019. Binds public and private bodies.

What this law does

Section 815.06(2) provides that a person commits an offense if he or she willfully, knowingly, and without authorization or exceeding authorization accesses or causes access to any computer, computer system, computer network, or electronic device with knowledge that such access is unauthorized or the manner of use exceeds authorization, among other prohibited acts such as denial of service, destruction of data, and introduction of malware.

Unlike a single-prong without authorization statute, section 815.06 explicitly names both prongs the Computer Fraud and Abuse Act (CFAA) is built on, the exact wording Van Buren v. United States (593 U.S. 374, 2021) narrowed for the federal statute; that holding construes the federal CFAA and does not bind a Florida court's reading of its own statute, so Florida's exceeding-authorization prong is not automatically read narrowly simply because the federal one now is.

Section 815.06(5)(a) also creates a civil remedy for the owner or lessee of the computer harmed by a violation. No Florida appellate decision squarely addresses public-page scraping under this section. The section originates in ch. 78-92 (1978), but the exceeding-authorization prong quoted above was not yet present as of the 2018 codification; it was added by section 40 of ch. 2019-167, so the section dates to that amendment's commencement rather than to the 1978 original.

What it requires

Personal data

Florida Digital Bill of Rights (FDBR), publicly available information exemption and narrow applicability

Fla. Stat. § 501.702 (SB 262, 2023 session)official text, Florida Senate (flsenate.gov)

In force since 1 July 2024. Binds private bodies.

What this law does

Section 501.702(19) excludes publicly available information from the FDBR's definition of personal data, and section 501.702(28) defines publicly available information as information lawfully made available through government records, or information that a business has a reasonable basis for believing is lawfully made available to the general public through widely distributed media, by a consumer, or by a person to whom a consumer has disclosed the information, unless the consumer has restricted the information to a specific audience.

That added restriction clause is narrower than Connecticut's or Delaware's equivalent definitions, which carry no comparable restriction-based carve-back.

The FDBR's applicability is far narrower than its peers: section 501.702's controller definition reaches only a for-profit entity conducting business in Florida that collects or determines the purposes and means of processing personal data, makes more than $1 billion in global gross annual revenue, and additionally either derives 50% or more of global gross annual revenue from online advertising sales, operates a consumer smart speaker and voice-command service with an integrated virtual assistant, or operates an app store with 250,000 or more digital applications.

This combination reaches essentially no ordinary scraper's target and no ordinary scraping actor, only a handful of the largest technology platforms; government agencies and non-profits are separately exempt under section 501.703(2). The FDBR was created by Senate Bill 262 of the 2023 Regular Session (ch. 2023-201) and took effect July 1, 2024.

What it requires

Unfair competition

Florida Deceptive and Unfair Trade Practices Act (FDUTPA)

Fla. Stat. §§ 501.201-501.213official text, Florida Senate (flsenate.gov)

In force. Binds private bodies.

What this law does

FDUTPA prohibits unfair methods of competition and unfair or deceptive acts or practices in trade or commerce, enforceable by the Florida Attorney General and by private right of action for actual damages plus attorney's fees.

In the absence of a Florida bot-disclosure or scraping-specific statute, FDUTPA is the plausible vehicle for a claim against a scraper or a scraped-data reseller whose conduct is deceptive as to origin or authenticity, though no FDUTPA decision addressing scraping specifically was located.

FDUTPA's short title and core prohibition were both enacted by ch. 73-124, Laws of Florida (1973), confirmed against flsenate.gov's own History note to section 501.201; that note, like the Florida Senate's statute pages generally for chapters this old, does not carry the day of the year, and no located session-law or secondary source supplies it, so the commencement date is left unset rather than assumed from either Florida's constitutional 60-day-after-adjournment default or a period-typical October 1 date.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (703 words)

Florida's private-sector security law is a single reasonable-security-and-disposal duty carried inside the state's breach-notification statute, the Florida Information Protection Act (FIPA), Fla. Stat. 501.171, created by CS/CS/SB 1524 (ch. 2014-189), signed June 20, 2014 and effective July 1, 2014.

Subsection (2), Requirements for Data Security, requires each covered entity, governmental entity, or third-party agent to take reasonable measures to protect and secure data in electronic form containing personal information, and subsection (8), Requirements for Disposal of Customer Records, separately requires each covered entity or third-party agent to take all reasonable measures to dispose of customer records containing personal information, by shredding, erasing, or otherwise rendering them unreadable, once no longer retained; the disposal duty's own text does not name a governmental entity the way the data-security duty's does.

This is the same standalone-safeguards-and-disposal shape already seen in New York's SHIELD Act (899-bb), Delaware, Indiana, Louisiana, Maryland, Nebraska, and Illinois: the duty is split out of the breach-notification statute rather than living inside a comprehensive privacy regime, so it sits with this topic even though its trigger is that the entity holds personal information.

FIPA's own breach-notification duty, subsections (3) through (6), requiring notice to the Department of Legal Affairs and to affected individuals, and the Florida Digital Bill of Rights' (FDBR) own security-of-processing clause, Fla. Stat. 501.71(1)(b) (a controller must establish, implement, and maintain reasonable administrative, technical, and physical data security practices), the same Test 2 shape as the Texas Data Privacy and Security Act's section 541.101(a)(2), are already this jurisdiction's privacy-topic rows rather than repeated here.

No enacted Florida statute sets security requirements a connected device or software product must meet to be placed on the market, comparable to California's or Oregon's connected-device statutes or the Cyber Resilience Act, and no Florida statute imposes a general private-sector duty to report an exploited vulnerability or a security incident to an authority or to users; Fla. Stat. 282.3185 requires a local government, not a private business, to report a cybersecurity incident to the Cybersecurity Operations Center, and, like the government's-own-programme duties this profile carries with the Government Accountability wing, is outside this profile's private-sector scope rather than a row here.

Florida has twice come within one step of enacting a cybersecurity safe-harbor affirmative defense on the Utah, Ohio, Iowa, and Connecticut model, and both attempts failed: CS/CS/HB 473 (2024), the Cybersecurity Incident Liability Act, would have shielded a business with a framework-conforming written cybersecurity program from liability for a data-breach-related tort claim, passed the House 81-28 and the Senate 32-8 in March 2024, but never became law and carries no Chapter Law citation; its 2026 successor, CS/SB 692, reintroducing the identical Fla. Stat. 768.401 citation alongside a companion local-government cybersecurity provision, died in the Senate Appropriations Committee on March 13, 2026.

As of this visit, Fla. Stat. 768.401 does not exist in the Florida Statutes. Florida's insurance regulator separately administers an information-security-program rule for a licensee under the Insurance Code, Fla. Admin.

Code R. 69O-128.032 and 69O-128.033 (implementing Fla. Stat. 624.307(1) and 626.9651), a rule that predates the 2017 NAIC Insurance Data Security Model Law and binds an insurance licensee, a role no activity in the LexLint vocabulary can yet express; it is recorded here rather than flagged on a guess or filed as an instrument (#6740), the same deferred treatment this topic gives New York's 23 NYCRR Part 500.

The Florida Computer-Related Crime Act, Fla. Stat. 815.06, an offense against a computer's user committed by an unauthorized intruder, is a computer-misuse statute properly filed under this jurisdiction's scraping-topic row rather than a security-topic presence.

FIPA's data-security and disposal duty is enforced only by the Department of Legal Affairs (the Attorney General), which may bring a declaratory-judgment, injunctive, or consumer-damages action under Fla. Stat. 501.207 after a violation of section 501.171 is deemed an unfair or deceptive trade practice; the $500,000-capped civil penalty schedule that Fla. Stat. 501.171(9)(b) sets is expressly limited to a violation of the notice duty in subsection (3) or (4), so a violation of the data-security or disposal duty instead draws the Florida Deceptive and Unfair Trade Practices Act's general willful-violation civil penalty, Fla. Stat. 501.2075, of up to $10,000 per violation.

The statute creates no private right of action.

Security baseline statutes

Florida Information Protection Act, data security and disposal duty

Fla. Stat. § 501.171(2), (8)Official statute text, Florida Statutes, Consumer Protection chapter

In force since 1 July 2014. Binds public and private bodies.

What this law does

Fla. Stat. 501.171(2) requires each covered entity, governmental entity, or third-party agent to take reasonable measures to protect and secure data in electronic form containing personal information; this duty explicitly names a governmental entity as a bound party in its own text.

Fla. Stat. 501.171(8) separately requires each covered entity or third-party agent, without naming a governmental entity, to take all reasonable measures to dispose of customer records containing personal information, by shredding, erasing, or otherwise rendering the information unreadable or undecipherable, once the records are no longer to be retained.

A covered entity is defined as a sole proprietorship, partnership, corporation, trust, estate, cooperative, association, or other commercial entity that acquires, maintains, stores, or uses personal information; that definition reaches a governmental entity only for the notice duty in subsections (3) through (6). Neither subsection states further content for what 'reasonable' requires beyond the general standard.

A violation of either duty is deemed an unfair or deceptive trade practice actionable only by the Department of Legal Affairs under Fla. Stat. 501.207; the section creates no private cause of action.

The $500,000-capped civil penalty Fla. Stat. 501.171(9)(b) sets applies only to a violation of the notice duty in subsection (3) or (4), so a willful violation of the data-security or disposal duty instead draws the Florida Deceptive and Unfair Trade Practices Act's general civil penalty of up to $10,000 per violation under Fla. Stat. 501.2075.

What it requires

Age gating law2 instruments, 2 in force

Research summary (122 words)

Florida's HB 3 (2024) bars minors under 14 from holding social media accounts without parental consent for 14 and 15 year olds, and separately requires age verification on websites where a substantial share of content is harmful to minors, both effective January 1, 2025.

The social media provision remains subject to First Amendment litigation but is currently enforceable after the Eleventh Circuit stayed a district court injunction pending Florida's appeal; a separate industry challenge to the adult content provision was voluntarily dropped in 2025.

Florida has not enacted an app store age verification or design code law; an App Store Accountability Act bill (SB 1722) filed for the 2026 session cleared one committee but died in Senate Judiciary on March 13, 2026.

Adult content age verification (AV)

HB 3 (2024), age verification for material harmful to minors

Fla. Stat. Secs. 501.1737, 501.1738official Florida Statutes text

In force since 1 January 2025. Binds private bodies.

What this law does

Requires a website on which more than one third of material is harmful to minors to perform reasonable age verification before granting access, using a standard method or an anonymous age verification service the visitor selects. A separate industry lawsuit challenging this provision was voluntarily dismissed in July 2025.

Note and primary source

Social media and minors

HB 3 (2024), social media use for minors

Fla. Stat. Sec. 501.1736official Florida Statutes text

In force since 1 January 2025. Binds private bodies.

What this law does

Bars minors under 14 from holding a social media account and requires verified parental consent for 14 and 15 year olds; covered platforms must terminate and permanently delete noncompliant minor accounts, including those a platform's own analytics flag as likely belonging to a minor.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.