Florida FDBR coordination with sectoral federal privacy + data protection laws. COPPA (Children Online Privacy Protection Act, 15 USC 6501 + 16 CFR Part 312): FTC-administered; covers online services collecting from children under 13; FDBR is MORE PROTECTIVE (under 18) + may apply in parallel; the 2024 FTC COPPA Rule Update + the pending COPPA 2.0 (Markey-Cassidy Senate bill) would extend to teens 13-16 aligning with FDBR. FERPA (Family Educational Rights and Privacy Act, 20 USC 1232g + 34 CFR Part 99): EXEMPT data covered by FERPA at the dataset level - educational records remain FERPA-governed; ed-tech vendors may be subject to FDBR for non-educational records. HIPAA: EXEMPT data covered by HIPAA at the dataset level - health records remain HIPAA-governed; non-health-record consumer data of healthcare entities may be subject to FDBR. GLBA (Gramm-Leach-Bliley Act + 16 CFR Part 314 Safeguards Rule): EXEMPT data covered by GLBA at the dataset level - financial records remain GLBA-governed. FCRA (Fair Credit Reporting Act + 15 USC 1681 et seq): EXEMPT data covered by FCRA at the dataset level - consumer credit records remain FCRA-governed. DPPA (Drivers Privacy Protection Act): EXEMPT data subject to DPPA. CRITICAL INFRASTRUCTURE: critical-infrastructure entities subject to CIRCIA + sector-specific cybersecurity requirements - FDBR applies to consumer-data layer; cybersecurity-incident layer may be reported per CIRCIA + FBI/CISA. INTERPLAY: the FDBR's NARROW APPLICABILITY (USD 1B threshold) means most sectoral entities won't trigger it - it primarily catches big-tech platforms + sector-cross-cutting digital advertising + voice/facial recognition vendors.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.