HB283 creates the Alabama Personal Data Protection Act, a comprehensive consumer privacy law governing how businesses collect, use, share, and sell personal data. It defines key terms such as personal data, sensitive data, targeted advertising, profiling, deidentified data, and artificial intelligence model, and applies to businesses operating in Alabama or targeting Alabama residents that meet specified data-volume or revenue thresholds. The bill gives consumers a set of rights over their data, including the right to confirm processing, access, correct, delete, and obtain a portable copy of their personal data, as well as the right to opt out of targeted advertising, the sale of personal data, and certain automated profiling used for significant decisions.
The bill also imposes duties on controllers and processors. Controllers must limit collection to what is reasonably necessary, maintain reasonable data security, provide clear privacy notices, and establish secure methods for consumers to submit requests. Processors must follow controller instructions, assist with consumer requests and security obligations, and operate under written contracts that set out processing terms and confidentiality requirements. The bill includes special rules for deidentified and pseudonymous data, restrictions on processing sensitive data, and an opt-out preference signal framework that must be supported by January 1, 2027. It also contains broad exemptions for many entities and data types, including small businesses under certain conditions, nonprofits under a size threshold, financial institutions, higher education institutions, HIPAA-covered information, FERPA-protected data, and certain research, law enforcement, and public health activities.
HB283 would amend Alabama law by creating a new statewide privacy framework and placing enforcement authority exclusively with the Attorney General. The Attorney General must give notice of a violation and allow a 60-day cure period before bringing an action, and civil penalties may reach $10,000 per violation if the violation is not corrected. The bill expressly states that it does not create a private right of action, meaning consumers could not sue directly under the act for violations. The act is scheduled to take effect on July 1, 2026.
The overall sentiment around the bill appears strongly favorable and noncontroversial in the House. The bill passed its House votes unanimously or nearly unanimously, including third reading passage with no recorded opposition. There is no committee transcript in the provided materials showing debate or opposition, and the voting history suggests broad bipartisan support for establishing consumer privacy protections and business compliance rules.
The main points of contention, as reflected in the text rather than recorded debate, are likely to involve the scope of exemptions, the compliance burden on businesses, and the balance between consumer rights and business flexibility. The bill exempts many sectors and smaller businesses, which may reduce opposition from regulated industries but could also limit the reach of the privacy protections. Another likely issue is enforcement design: the bill relies solely on Attorney General enforcement and does not allow private lawsuits, which may be seen as a compromise favoring businesses while still creating a state enforcement mechanism.
HB283 would add a new chapter of Alabama consumer privacy law governing the collection, processing, disclosure, sale, and deletion of personal data. It would impose compliance obligations on covered controllers and processors, establish consumer rights and opt-out mechanisms, regulate sensitive and deidentified data, and create a state enforcement regime led exclusively by the Attorney General. It would also leave many existing federal and state privacy regimes intact by carving out extensive exemptions for health, education, financial, research, and other regulated data categories, while expressly eliminating any private right of action under the act.
The bill appears to have broad support in the House, with unanimous or near-unanimous votes on the major motions and final passage. The absence of recorded committee testimony in the provided materials suggests no visible organized opposition in the available record. Overall, the sentiment is that of a consensus privacy measure aimed at modernizing consumer protections without triggering major partisan conflict.
The likely areas of contention are the breadth of exemptions, the compliance obligations placed on businesses, and the enforcement structure. Small businesses, nonprofits, financial institutions, higher education, and numerous categories of regulated data are excluded, which may be viewed either as necessary tailoring or as weakening the bill’s protections. Consumer advocates may also object to the lack of a private right of action, while businesses may still be concerned about the operational costs of notice, opt-out, deletion, and data-security requirements. The Attorney General-only enforcement model and the 60-day cure period also reflect a compromise that may draw mixed reactions.