At a Glance
- Applies to businesses processing personal data of more than 25,000 Alabama consumers annually, or deriving more than 25 percent of gross revenue from data sales, with no revenue floor.
- Uses an opt-out model for targeted advertising, data sales, and qualifying profiling; requires affirmative, opt-in consent for sensitive data.
- Includes an explicit consent revocation right. Controllers must stop the relevant processing within 45 days of a request.
- Requires opt-in consent before using or selling data belonging to 13-to-15-year-olds for targeted advertising or sale.
- Enforced solely by the Alabama Attorney General, with no private right of action and a permanent 45-day cure period.
- Civil penalties can reach USD 15,000 per violation, double the ceiling in many comparable states.
The Alabama Personal Data Protection Act (APDPA) generally follows the same opt-out framework as Virginia’s VCDPA and the Oklahoma OCDPA: opt-out for most processing, affirmative consent for sensitive data, and enforcement handled solely by the Alabama Attorney General.
Where it departs is worth building into your configuration specifically. It has a low 25,000-consumer threshold, a broader “sale” definition that reaches some non-monetary exchanges, an explicit consent revocation right, and opt-in requirements for 13-to-15-year-olds that most peer states don’t include.
The Checklist
1: Determine If Your Company Must Comply
The APDPA applies if you conduct business in Alabama, or target Alabama residents, and meet either threshold below.
- Control or process the personal data of more than 25,000 Alabama consumers annually (excluding payment-transaction-only data), or
- Derive more than 25 percent of gross revenue from the sale of personal data, regardless of consumer volume
There is no minimum revenue floor. Businesses with fewer than 500 employees that don’t sell personal data are exempt, as are nonprofits with fewer than 100 employees that don’t sell personal data.
2: Update Your Privacy Notice
Your privacy notice needs to disclose data categories, processing purposes, third-party sharing, how consumers can exercise their rights, an active contact method, and a link to your opt-out method.
3: Inform Consumers of Their Rights
Alabama consumers can request access, correction, deletion, portability, and opt-out. They cannot be discriminated against for exercising any of them.
A parent, guardian, or conservator may exercise rights on behalf of a known child under 13 or another consumer, as applicable.
4: Provide a Clear and Conspicuous Opt-Out Method
Give consumers an easily accessible link to opt out of targeted advertising, data sales, and qualifying profiling directly, or up-to-date contact information for submitting a request.
Where an opt-out signal conflicts with an existing privacy setting or loyalty program, honor the signal. You may notify the consumer of the conflict.
5: Obtain Affirmative Consent for Sensitive Data
Get affirmative, opt-in consent before processing sensitive personal data.
This includes racial or ethnic origin, health data, biometric data, precise geolocation, sex life or sexual orientation data, citizenship or immigration status, and data from a known child.
6: Handle Teen Data (Ages 13–15) With Opt-In Consent
If you have actual knowledge a consumer is between 13 and 15, get their consent before processing their data for targeted advertising or sale.
This teen-specific opt-in requirement is absent from many comparable state laws.
7: Handle Children’s Data in Line With COPPA
Data from a known child under 13 is classified as sensitive data.
Controllers that meet the verifiable parental consent requirements of COPPA are deemed compliant with the APDPA’s parental consent obligation.
8: Build a Consent Revocation Mechanism
Revocation must be at least as easy as the method used to give consent.
Once a consumer revokes consent, stop the relevant processing as soon as practicable, and no later than 45 days after the request.
9: Build Consumer Rights Request Workflows
Provide a secure request intake, respond within 45 days. One 45-day extension is available, with notice.
Unlike most comprehensive state privacy laws, the APDPA does not require a formal appeal mechanism for denied requests. A documented internal review process is good practice, but not a legal obligation.
10: Review Data-Sharing Arrangements Against the APDPA’s “Sale” Definition
Alabama’s definition of “sale” is broader than several comparable state laws.
It covers exchanges for monetary or other valuable consideration, where the controller receives a material benefit and the recipient’s use of the data is unrestricted. Arrangements exempt elsewhere may qualify as a sale here.
Two disclosures are carved out regardless: sharing data with a third party solely to provide analytics services, and sharing data with a third party solely to provide marketing services to the controller itself. Neither counts as a “sale” under the APDPA, even where the broader “other valuable consideration” language might suggest otherwise.
11: Review and Update Processor Contracts
Put written contracts in place with processors covering instructions, data types, duration, and subprocessor obligations.
Unlike many peer states, the APDPA does not require a formal data protection assessment for high-risk processing. If you already run these for other states’ laws, there’s no APDPA-specific carve-out needed.
12: Audit Consent Interfaces for Dark Patterns
Review consent banners and opt-out flows for manipulative design.
The APDPA explicitly invalidates consent obtained through dark patterns.
Get the full picture in the Alabama Personal Data Protection Act overview.