Florida's private-sector security law is a single reasonable-security-and-disposal duty carried inside the state's breach-notification statute, the Florida Information Protection Act (FIPA), Fla. Stat. 501.171, created by CS/CS/SB 1524 (ch. 2014-189), signed June 20, 2014 and effective July 1, 2014.
Subsection (2), Requirements for Data Security, requires each covered entity, governmental entity, or third-party agent to take reasonable measures to protect and secure data in electronic form containing personal information, and subsection (8), Requirements for Disposal of Customer Records, separately requires each covered entity or third-party agent to take all reasonable measures to dispose of customer records containing personal information, by shredding, erasing, or otherwise rendering them unreadable, once no longer retained; the disposal duty's own text does not name a governmental entity the way the data-security duty's does.
This is the same standalone-safeguards-and-disposal shape already seen in New York's SHIELD Act (899-bb), Delaware, Indiana, Louisiana, Maryland, Nebraska, and Illinois: the duty is split out of the breach-notification statute rather than living inside a comprehensive privacy regime, so it sits with this topic even though its trigger is that the entity holds personal information.
FIPA's own breach-notification duty, subsections (3) through (6), requiring notice to the Department of Legal Affairs and to affected individuals, and the Florida Digital Bill of Rights' (FDBR) own security-of-processing clause, Fla. Stat. 501.71(1)(b) (a controller must establish, implement, and maintain reasonable administrative, technical, and physical data security practices), the same Test 2 shape as the Texas Data Privacy and Security Act's section 541.101(a)(2), are already this jurisdiction's privacy-topic rows rather than repeated here.
No enacted Florida statute sets security requirements a connected device or software product must meet to be placed on the market, comparable to California's or Oregon's connected-device statutes or the Cyber Resilience Act, and no Florida statute imposes a general private-sector duty to report an exploited vulnerability or a security incident to an authority or to users; Fla. Stat. 282.3185 requires a local government, not a private business, to report a cybersecurity incident to the Cybersecurity Operations Center, and, like the government's-own-programme duties this profile carries with the Government Accountability wing, is outside this profile's private-sector scope rather than a row here.
Florida has twice come within one step of enacting a cybersecurity safe-harbor affirmative defense on the Utah, Ohio, Iowa, and Connecticut model, and both attempts failed: CS/CS/HB 473 (2024), the Cybersecurity Incident Liability Act, would have shielded a business with a framework-conforming written cybersecurity program from liability for a data-breach-related tort claim, passed the House 81-28 and the Senate 32-8 in March 2024, but never became law and carries no Chapter Law citation; its 2026 successor, CS/SB 692, reintroducing the identical Fla. Stat. 768.401 citation alongside a companion local-government cybersecurity provision, died in the Senate Appropriations Committee on March 13, 2026.
As of this visit, Fla. Stat. 768.401 does not exist in the Florida Statutes. Florida's insurance regulator separately administers an information-security-program rule for a licensee under the Insurance Code, Fla. Admin.
Code R. 69O-128.032 and 69O-128.033 (implementing Fla. Stat. 624.307(1) and 626.9651), a rule that predates the 2017 NAIC Insurance Data Security Model Law and binds an insurance licensee, a role no activity in the LexLint vocabulary can yet express; it is recorded here rather than flagged on a guess or filed as an instrument (#6740), the same deferred treatment this topic gives New York's 23 NYCRR Part 500.
The Florida Computer-Related Crime Act, Fla. Stat. 815.06, an offense against a computer's user committed by an unauthorized intruder, is a computer-misuse statute properly filed under this jurisdiction's scraping-topic row rather than a security-topic presence.
FIPA's data-security and disposal duty is enforced only by the Department of Legal Affairs (the Attorney General), which may bring a declaratory-judgment, injunctive, or consumer-damages action under Fla. Stat. 501.207 after a violation of section 501.171 is deemed an unfair or deceptive trade practice; the $500,000-capped civil penalty schedule that Fla. Stat. 501.171(9)(b) sets is expressly limited to a violation of the notice duty in subsection (3) or (4), so a violation of the data-security or disposal duty instead draws the Florida Deceptive and Unfair Trade Practices Act's general willful-violation civil penalty, Fla. Stat. 501.2075, of up to $10,000 per violation.
The statute creates no private right of action.