Florida Digital Bill of Rights (FDBR)
The Florida Digital Bill of Rights (SB 262, 2023, codified as F.S. 501.701-501.721) is Florida's comprehensive consumer data privacy law. Unlike most US state privacy laws, it applies only to businesses with global gross annual revenues exceeding $1 billion. Includes specific provisions for children's data, social media platforms, and search engine transparency. Effective July 1, 2024.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (19)
Children
| Code | Title |
|---|---|
| FL-DBR-008 | Children's Personal Data (Under 18) |
Children and Online Safety
| Code | Title |
|---|---|
| FDBR-1735 | Children's Online Protection (§501.1735) |
Consumer Rights
| Code | Title |
|---|---|
| CPA-CR-1 | Right to Access |
| CPA-CR-2 | Right to Correction |
| CPA-CR-3 | Right to Deletion |
| CPA-CR-4 | Right to Data Portability |
| CPA-CR-5 | Right to Opt Out |
| CTDPA-3 | Right to Access (Section 4) |
| CTDPA-4 | Right to Correction and Deletion |
| CTDPA-5 | Right to Portability |
| CTDPA-6 | Right to Opt Out |
| FDBR-705 | Consumer Rights (§501.705) |
| FDBR-706 | Controller Response Requirements (§501.706) |
| RIDTPPA-6 | Right to Confirm and Access |
| RIDTPPA-7 | Right to Correct and Delete |
| RIDTPPA-8 | Right to Opt Out |
| TIPA-3 | Right to Access and Confirm |
| TIPA-4 | Right to Delete |
| TIPA-5 | Right to Opt Out |
| WDPA-3 | Right to Access and Confirm |
| WDPA-4 | Right to Portability |
| WDPA-5 | Right to Correction and Deletion |
| WDPA-6 | Right to Opt Out |
| s.6(1) | Right to Deletion |
| s.6(2) | Deletion Request Processing |
| s.6(3) | Right to Withdraw Consent |
| s.7(1) | Data Security Obligations |
Controller and Processor Obligations
| Code | Title |
|---|---|
| FDBR-709 | Consumer Request Methods (§501.709) |
| FDBR-710 | Controller Requirements (§501.71) |
| FDBR-711 | Privacy Notice Requirements (§501.711) |
| FDBR-712 | Processor Contracts (§501.712) |
| FDBR-713 | Data Protection Assessments (§501.713) |
Definitions and Applicability
| Code | Title |
|---|---|
| FDBR-701 | Short Title (§501.701) |
| FDBR-702 | Definitions (§501.702) |
| FDBR-703 | Applicability (§501.703) |
| FDBR-704 | Exemptions (§501.704) |
| RIDTPPA-1 | Definitions |
| RIDTPPA-2 | Applicability Thresholds |
| WDPA-1 | Definitions |
| WDPA-2 | Applicability Thresholds |
Enforcement
| Code | Title |
|---|---|
| CTDPA-13 | AG Enforcement Authority |
| CTDPA-14 | Cure Period |
| FDBR-720 | Enforcement and Penalties (§501.72) |
| FL-DBR-021 | Enforcement by the Department of Legal Affairs |
| FL-DBR-022 | Cure Period and Remediation Records |
| MMCL-Ch13-1 | Penalties |
| MMCL-Ch14-1 | Appeal Procedures |
| PY-11 | Supervisory Authority |
| PY-12 | Penalties |
| TIPA-12 | Profiling with Significant Effects |
| TIPA-13 | Children's and Teen Data Considerations |
Enforcement
| Code | Title |
|---|---|
| CTDPA-13 | AG Enforcement Authority |
| CTDPA-14 | Cure Period |
| FDBR-720 | Enforcement and Penalties (§501.72) |
| FL-DBR-021 | Enforcement by the Department of Legal Affairs |
| FL-DBR-022 | Cure Period and Remediation Records |
| MMCL-Ch13-1 | Penalties |
| MMCL-Ch14-1 | Appeal Procedures |
| PY-11 | Supervisory Authority |
| PY-12 | Penalties |
| TIPA-12 | Profiling with Significant Effects |
| TIPA-13 | Children's and Teen Data Considerations |
Government Coordination
| Code | Title |
|---|---|
| FL-DBR-020 | Government-Moderated Social Media Restriction |
Opt-Out
| Code | Title |
|---|---|
| FL-DBR-005 | Right to Opt Out of Sale, Targeted Advertising, Profiling |
| FL-DBR-006 | Right to Opt Out of Voice or Facial Recognition Collection |
Pricing
| Code | Title |
|---|---|
| FL-DBR-018 | Loyalty and Bona Fide Programs |
Principles
| Code | Title |
|---|---|
| FL-DBR-015 | Data Minimisation and Purpose Limitation |
Rights
| Code | Title |
|---|---|
| FL-DBR-002 | Consumer Right to Confirm and Access |
| FL-DBR-003 | Right to Correct Personal Data |
| FL-DBR-004 | Right to Delete Personal Data |
| FL-DBR-011 | Authentication of Consumer Requests |
| FL-DBR-012 | Response Timelines and Appeals |
| FL-DBR-017 | Non-Discrimination for Exercising Rights |
Risk Assessment
| Code | Title |
|---|---|
| FL-DBR-013 | Data Protection Assessments |
Scope
| Code | Title |
|---|---|
| FL-DBR-001 | Applicability Threshold Determination |
Search Engines
| Code | Title |
|---|---|
| FL-DBR-019 | Search Engine Disclosure of Political Bias |
Security
| Code | Title |
|---|---|
| FL-DBR-016 | Security of Personal Data |
Sensitive Data
| Code | Title |
|---|---|
| FL-DBR-007 | Sensitive Data Opt-In Consent |
Transparency
| Code | Title |
|---|---|
| FL-DBR-009 | Privacy Notice Disclosure |
| FL-DBR-010 | Sale of Sensitive Data Disclosure |
Vendor
| Code | Title |
|---|---|
| FL-DBR-014 | Processor Contracts and Duties |
Your Compliance Coverage
If you comply with Florida Digital Bill of Rights (FDBR), you already cover:
FAA Cybersecurity Framework for Aviation
20%
14 controls mapped
Compare →Australia Consumer Data Right - Banking (CDR)
19%
13 controls mapped
Compare →Australia My Health Records Act 2012
19%
13 controls mapped
Compare →+ 635 more: EU Clinical Trials Regulation (CTR 536/2014) (19%), Connecticut Data Privacy Act (CTDPA) (19%)
See all 638 mapped frameworks ↓Maps to 638 other frameworks
Frequently Asked Questions
What is Florida Digital Bill of Rights (FDBR)?
Florida Digital Bill of Rights (FDBR) is a compliance framework from United States with 19 domains and 70 controls. The Florida Digital Bill of Rights (SB 262, 2023, codified as F.S. 501.701-501.721) is Florida's comprehensive consumer data privacy law. Unlike most US state privacy laws, it applies only to businesses with global gross annual revenues exceeding $1 billion. Includes specific provisions for children's data, social media platforms, and search engine transparency. Effective July 1, 2024. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Florida Digital Bill of Rights (FDBR) have?
Florida Digital Bill of Rights (FDBR) has 70 controls organised across 19 domains. The largest domains are Consumer Rights (25 controls), Enforcement (9 controls), Definitions and Applicability (8 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Florida Digital Bill of Rights (FDBR) map to?
Florida Digital Bill of Rights (FDBR) maps to 638 other compliance frameworks. The top mapping partners are FAA Cybersecurity Framework for Aviation (20% coverage), Australia Consumer Data Right - Banking (CDR) (19% coverage), Australia My Health Records Act 2012 (19% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Florida Digital Bill of Rights (FDBR) compliance?
Start your Florida Digital Bill of Rights (FDBR) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Florida Digital Bill of Rights (FDBR) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 70 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required