Florida FDBR vs comprehensive privacy regimes + federal preemption tracking. GDPR (EU Regulation 2016/679): FDBR is NARROWER (USD 1B big-tech threshold vs GDPR universal applicability) + DIFFERENT RIGHTS STRUCTURE (FDBR has voice/facial recognition opt-out + sensitive data opt-in vs GDPR Article 9 explicit consent + DPIA) + LIGHTER ENFORCEMENT (USD 50K-1.5M vs GDPR 2-4% turnover) + NO PRIVATE RIGHT OF ACTION (vs GDPR Article 79-80). CALIFORNIA CCPA/CPRA: FDBR + CCPA share rights (access + deletion + portability + opt-out) but CCPA includes BUSINESS-PURPOSE service-provider concept + sensitive personal information notice-at-collection + private right of action for breaches; CCPA covers MORE BUSINESSES (USD 25M threshold + 100K consumers + sale-of-data threshold) than FDBR. PRC PIPL (Personal Information Protection Law): completely different legal context + cross-border transfer focus + Chinese government-data-flow restrictions. AMERICAN PRIVACY RIGHTS ACT (APRA): proposed federal comprehensive privacy law (118th + 119th Congress 2024-2026); would PREEMPT state laws including FDBR for federally-covered data; status as of early 2026 - not enacted + may impact FDBR scope; federal preemption + state-AG enforcement coordination remain open. CRITICAL: organisations operating in Florida + other jurisdictions must maintain MULTI-REGIME COMPLIANCE + monitor federal preemption status + plan for APRA enactment + interpretation.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.