Alabama Data Breach Notification Act
Alabama · Commercial Law and Consumer Protection · §§ 8-38-1 to 8-38-9 · 12 sections
Overview
This act governs how entities that hold sensitive personally identifying information must protect that data and what they must do when it is compromised. It requires covered entities to maintain and assess reasonable security measures, to securely dispose of records containing such information, and to investigate suspected security breaches. When a breach warrants notice, the act sets out who must be told — affected individuals, the state attorney general, consumer reporting agencies, and the entities on whose behalf data is held — and provides exemptions for entities already subject to comparable federal or state regimes, along with consequences for failing to give required notice.
Editorial summary generated from the text of this act. It is not part of the statute — read the sections below for the operative language.
Sections covered
- Ala. Code § 8-38-1Short Title.
- Ala. Code § 8-38-10Disposal of Records Containing Sensitive Personally Identifying Information.
- Ala. Code § 8-38-11Exemptions - Federal.
- Ala. Code § 8-38-12Exemptions - State.
- Ala. Code § 8-38-2Definitions.
- Ala. Code § 8-38-3Reasonable Security Measures; Assessment.
- Ala. Code § 8-38-4Investigation of Security Breach.
- Ala. Code § 8-38-5Notice of Security Breach - Individuals Affected.
- Ala. Code § 8-38-6Notice of Security Breach - Attorney General.
- Ala. Code § 8-38-7Notice of Security Breach - Consumer Reporting Agencies.
- Ala. Code § 8-38-8Notice of Security Breach - Covered Entity.
- Ala. Code § 8-38-9Violations of Notification Requirements.
Enacted in other states
Download
Copy
Embed on your site
Hover to preview · click to copy the code