Alabama Enacts Comprehensive Data Protection Law
On April 7, 2026, both houses of the Alabama legislature unanimously voted to pass the Alabama Personal Data Protection Act (“APDPA”). Governor Kay Ivey signed the bill into law on April 17, 2026, making Alabama the 21st state to adopt a comprehensive consumer privacy law. The law takes effect May 1, 2027, leaving applicable businesses a little less than a year to prepare to comply with the law’s obligations.
Scope and Exemptions
The APDPA applies to all (individuals or legal entities) who conduct business in Alabama or that target products or services to Alabama residents, provided they meet one or both of the following criteria:
- The person controls or processes the personal data of more than 25,000 Alabama consumers (excluding personal data processed solely to complete a payment or transaction); or
- The person derives more than 25% of its gross revenue from the sale of personal data, regardless of the number of consumers whose data the person controls or processes.
The APDPA’s threshold provisions are unique among other comprehensive state data privacy laws because they operate as independent, stand-alone provisions. Most states, such as Montana, enacting a similar 25% gross revenue threshold combine it with a requirement that the business also process the data of at least 25,000 individuals. Alabama’s approach separates those two requirements. No other state applies a stand-alone consumer processing threshold as low as Alabama’s, and no other state applies its data privacy law to persons deriving 25% of their revenue from the sale of personal data “regardless of the number of consumers whose data the person controls or processes.”
Despite its broad applicability, the APDPA contains a number of exemptions from coverage, including:
- State agencies and political subdivisions of the state of Alabama;
- Entities subject to the Gramm-Leach-Bliley Act (“GLBA”) or the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”);
- Higher education institutions and their affiliates;
- Small businesses with fewer than 500 employees that do not sell personal data; and
- Non-profit organizations with fewer than 100 employees that do not sell personal data.
In addition to these entity-level exemptions, the APDPA contains data-level exemptions, most notably for employee and job applicant data, business contact information, and data covered by HIPAA and/or the GLBA.
Consumer Rights
The APDPA contains the following consumer rights; to (1) correct inaccuracies in the consumer’s personal data; (2) delete the consumer’s personal ; (3) obtain a copy of the consumer’s personal data; and (4) the ability to opt out of targeted advertising, the sale of personal data, and profiling in furtherance of solely automated significant decisions concerning the consumer. The law also requires consumer consent for the processing of sensitive data, which is defined narrowly as: (1) personal data revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis, information about an individual’s sex life, sexual orientation, or citizenship or immigration status; (2) genetic or biometric data that is processed for the purpose of uniquely identifying an individual; (3) personal data collected from a known child; and (4) precise geolocation data.
Definition of Sale
Another aspect of the APDPA that is unique from other states’ data privacy laws, is its definition of “Sale”, which it defines as “an exchange of personal data for monetary consideration by a controller to a third party, or for other valuable consideration by a controller to a third party where the controller receives a material benefit and the third party is not restricted in its subsequent uses of the personal data.” The definition differs from other states’ Acts in that it tacks on an additional requirement that the third party be unrestricted in its use of the personal data before the transfer can be considered a “Sale.” The APDPA also contains novel exemptions from the definition of sale for the “disclosure or transfer of personal data to a third party for the purpose of providing analytics services” and the “disclosure or transfer of personal data to a third party for the purposes of providing marketing services solely to the controller.”
Business Obligations
The APDPA imposes the following obligations on applicable. First, businesses must ensure consumers are provided with meaningful privacy notice. Second, businesses must limit the collection of personal data to only what is “reasonably necessary” to accomplish the purpose for which the data is collected. Relatedly, the APDPA forbids controllers from processing sensitive data without first obtaining the consumer’s consent. Finally, businesses are also required to establish, implement, and maintain reasonable data security practices to protect the confidentiality, integrity, and accessibility of collected personal data. Unlike the majority of state comprehensive consumer privacy laws, however, the APDPA does not require controllers to conduct data protection.
Key Takeaways for your Business
While the APDPA largely follows the data privacy laws already enacted in other jurisdictions, its unique features warrant attention from any business collecting personal data of residents in the state. Among next steps, those businesses should consider the following:
- Assess applicability now. As noted above, the APDPA’s applicability thresholds are lower than those of other states’ laws, meaning that businesses exempt from other states’ laws may nonetheless fall within its scope.
- Evaluate the APDPA’s applicability exemptions carefully. Remember, small businesses with fewer than 500 employees and non-profit organizations with fewer than 100 employees are only exempt if they do not engage in the sale of personal data.
- Evaluate whether your business “Sells” personal data as defined by the Act. The key here is to remember that disclosures made solely for providing analytics or marketing services to the controller are not considered “Sales” under the APDPA.
- Update your privacy policy and ensure you are obtaining consent for sensitive data processing. The update should also ensure that your business does not collect more data than is reasonably necessary and ensure that your website provides consumers with a clear and conspicuous opportunity to opt out of targeted advertising and the sale of their personal data.
- Evaluate data security practices to ensure consumer’s personal data is protected.
Should you have any questions about the APDPA and its implications for your organization, please contact the author or any member of the Burr & Forman Digital Risk and Intelligence Protection team.