Home About Who We Are Team Services Startups Businesses Enterprise Case Studies Industries Commercial Real Estate Blog Guides Contact Connect with Us
Back to Guides
Enterprise Software 13 min read

Does the Florida Digital Bill of Rights Apply to My Small Business?

Does the Florida Digital Bill of Rights Apply to My Small Business?

No. If your business has 5 to 50 employees, the Florida Digital Bill of Rights almost certainly does not apply to you. The law’s core obligations only reach companies with more than $1 billion in global annual revenue that also meet one of three additional conditions, and a small Florida employer using ChatGPT or Claude for internal drafting work is nowhere near that line. That said, two narrow rules in the same statute apply to every business in the state regardless of size, and this guide covers exactly what those are so you aren’t left with a false sense of total exemption.

What the Florida Digital Bill of Rights actually regulates

The Florida Digital Bill of Rights, codified at Fla. Stat. §§ 501.701–501.722, took effect on July 1, 2024. It gives Florida residents rights over their personal data: the right to know what a company collects, the right to correct or delete it, and the right to opt out of targeted advertising, the sale of personal data, and certain kinds of automated profiling. Those rights sound sweeping, and press coverage at the time treated the bill as Florida joining the wave of state privacy laws that started with California’s CCPA.

What that coverage usually skipped is who the rights run against. The law defines a “controller” as a for-profit entity doing business in Florida that collects Florida residents’ personal data and decides how that data gets processed. So far, that description could apply to almost any company. The statute then adds a revenue floor that changes everything: a business only qualifies as a controller if it makes more than $1 billion in global annual revenue. Below that line, the law’s main duties (data access requests, opt-out rights, deletion requests) simply do not attach.

The exact threshold: $1 billion in revenue, plus one more condition

Passing the $1 billion mark is necessary but not sufficient. Fla. Stat. § 501.702(9) requires a controller to clear the revenue floor and satisfy at least one of three additional conditions:

Condition What it means
Advertising revenue Derives 50% or more of global gross annual revenue from selling online advertising, including targeted ads
Smart speaker or voice service Operates a consumer smart speaker or voice-command service with a built-in virtual assistant activated hands-free through a cloud service
App store scale Runs an app store or digital distribution platform offering at least 250,000 different apps for consumers to download

This is a narrower test than most state privacy laws use. California’s CCPA, for comparison, pulls in any business with $25 million or more in annual revenue, no matter what it sells or how it makes money. Florida’s law was written with three specific business models in mind: large ad-funded platforms, smart-speaker makers, and app-store operators. A law firm, a dental practice, a roofing contractor, or a CPA office doesn’t fit any of those three categories regardless of revenue, which means the second half of the test would exclude most mid-size Florida companies even in the unlikely event they somehow crossed $1 billion in revenue.

Two other details matter for accuracy. First, a parent or subsidiary of a qualifying controller is also treated as a controller under the statute, so a small Florida subsidiary of a billion-dollar ad-tech company wouldn’t get to claim exemption on its own numbers. Second, the Florida Attorney General has exclusive enforcement authority. There’s no private right of action, meaning individual consumers can’t sue a business directly under this law; only the state can bring an enforcement action, with penalties up to $50,000 per violation, tripled for certain repeat or willful conduct.

Where this leaves a 5–50 person Florida business

Run the numbers for a typical reader of this article: a 20-person property management office in Tampa, a 12-person law firm in Fort Lauderdale, a 40-person medical practice in Jacksonville. None of these clear $1 billion in revenue by a wide margin, and none operate a smart-speaker product, an app store, or an ad-sales business. On the controller test, every one of them is out of scope, full stop.

This isn’t a close call the way some state privacy thresholds are. California’s CCPA revenue bar, for reference, sits around $25 million, low enough that a genuinely small business can trip it. Florida picked a number specifically designed to catch a handful of the largest technology companies operating in the state and leave everyone else alone, then narrowed the pool further by requiring one of the three business-model conditions on top.

The two rules that apply to you anyway

Here’s the part most small-business coverage of this law leaves out, and it’s worth naming plainly: two provisions in the same statute apply to all commercial entities doing business in Florida, with no revenue threshold at all.

The first covers sensitive data. Any business, regardless of size, needs a consumer’s prior consent before selling sensitive personal data: race, ethnicity, religion, health status, sexual orientation, immigration status, genetic or biometric data, or precise geolocation. Selling a minor’s data requires “affirmative authorization” rather than ordinary consent. This matters if your business ever sells lead lists, health-adjacent data, or location data to a third party, something that has nothing to do with running AI tools internally but is worth knowing if data brokering is any part of your revenue.

The second amends the Florida Information Protection Act, the state’s existing data-breach and data-security law, to add biometric and geolocation data to the definition of protected personal information. Every business holding that kind of data now has to apply “reasonable measures” to secure it, the same standard that already applied to Social Security numbers and financial account data. A dental practice storing biometric access-control logs or a logistics company tracking driver geolocation falls under this duty even though it will never come close to the $1 billion controller threshold.

Neither of these two rules requires the data-subject-rights infrastructure (deletion requests, opt-out mechanisms, data portability) that makes the CCPA and similar laws expensive to implement. They’re closer to ordinary data-hygiene obligations than a full privacy-compliance program, and most small businesses that already handle sensitive data carefully are effectively compliant without doing anything new.

How this differs from the CCPA and other state privacy laws

If you’ve read anything about California, Colorado, or Virginia’s privacy laws, the Florida approach reads as an outlier. The table below lines up the headline revenue threshold across the states most often confused with each other:

State Law Revenue threshold
California CCPA / CPRA $25 million annual revenue, or data-volume/revenue-mix alternatives
Colorado Colorado Privacy Act No revenue threshold; based on number of consumers processed
Virginia Virginia CDPA No revenue threshold; based on number of consumers processed
Florida Digital Bill of Rights $1 billion global revenue, plus one of three business-model conditions

Florida’s is the narrowest controller test of any state comprehensive privacy law on the books. Practically, that means a Florida business confirmed exempt from the FDBR still needs to separately check its exposure under any other state’s law if it sells to or collects data from residents of California, Colorado, or elsewhere. Being under Florida’s radar doesn’t mean being under every state’s radar.

What this means for using ChatGPT, Claude, or Gemini at work

The practical question behind this search is usually some version of “can I roll out AI tools to my team without worrying about Florida law first.” The honest answer: yes, on the compliance side, you’re clear. Nothing in the FDBR creates new obligations for a small business using consumer AI assistants for internal drafting, client correspondence, or document review.

The real risk sits somewhere else entirely, and it has nothing to do with Florida’s statute. It’s what happens when an employee pastes client records, patient information, or a signed contract into a personal, free-tier chatbot account. Most consumer-tier AI accounts don’t carry the same data-handling terms as business or enterprise plans, and that’s a policy your firm needs regardless of what any state privacy law requires. If your business handles anything that would qualify as sensitive data under the FDBR’s all-entity rule (health status, biometric data, precise location), that’s the more relevant reason to standardize on business-tier AI accounts before training staff, not the exempt $1 billion controller test.

Training your team while the law sits on the shelf

Since compliance risk isn’t the blocker here, the more useful next question for a Florida small business is how to get a team using AI tools well, and whether there’s help paying for it. CareerSource Florida’s Incumbent Worker Training grant reimburses 50% of direct training costs for most eligible employers, rising to 75% for firms with 25 or fewer employees or those in a rural, distressed, brownfield, or HUBZone area, capped at $100,000 per company for the current funding year. That program, covered in full in the state’s corporate AI training playbook, runs through 21 regional CareerSource boards and is a separate track entirely from privacy compliance.

Market rates for a hands-on AI workshop built around your team’s own documents run $2,000 to $15,000 depending on group size and session count, before any CareerSource reimbursement lowers the net cost. Firms in Florida’s larger metros, including Miami, apply through their county’s regional board rather than a single statewide office, which is worth knowing before assuming the process works the same way everywhere in the state.

Frequently asked questions

Does the Florida Digital Bill of Rights apply to my small business?

Almost certainly not. The law’s controller test requires more than $1 billion in global annual revenue plus at least one of three additional conditions (deriving half or more of revenue from online ad sales, running a smart-speaker service, or operating an app store with 250,000-plus apps). A 5–50 person business doesn’t come close to the revenue floor, so the law’s data-access, deletion, and opt-out obligations don’t attach to it.

What is the exact revenue threshold, and what are the three additional conditions?

More than $1 billion in global gross annual revenue, per Fla. Stat. § 501.702(9), plus at least one of: deriving 50% or more of global revenue from selling online advertising, operating a consumer smart speaker or voice-command service with a built-in assistant, or operating an app store offering at least 250,000 apps. All three conditions target specific large-platform business models, not general-purpose small businesses.

Are there any FDBR duties that apply to my business even though I’m under $1 billion in revenue?

Yes, two. Every commercial entity in Florida, regardless of revenue, needs a consumer’s prior consent before selling sensitive personal data (health, biometric, genetic, immigration status, precise geolocation, and similar categories), and every business holding biometric or geolocation data now has to apply reasonable security measures to it under the amended Florida Information Protection Act. Neither requires the full data-subject-rights apparatus the $1 billion controller test triggers.

When did the Florida Digital Bill of Rights take effect, and who enforces it?

It took effect July 1, 2024. The Florida Attorney General has exclusive enforcement authority, with no private right of action for individual consumers. Penalties run up to $50,000 per violation, tripled under certain repeat or willful circumstances, and only the state can bring a case.

How is the FDBR different from the CCPA or other state privacy laws?

Florida’s revenue threshold ($1 billion, plus a business-model condition) is far higher than California’s CCPA ($25 million, no business-model condition required) and higher than Colorado or Virginia’s laws, which use consumer-volume thresholds instead of revenue at all. Florida’s is the narrowest controller test among state comprehensive privacy laws, meaning a business exempt in Florida could still be covered elsewhere if it operates in other states.

Does being exempt from the FDBR mean I don’t need to think about data privacy at all?

No. Exemption from the FDBR’s controller obligations doesn’t erase ordinary data-handling risk. Client and patient records still deserve care regardless of which law technically applies, and the two all-entity FDBR duties (sensitive data consent, biometric and geolocation security) apply no matter your size. Most small businesses that already handle sensitive information carefully meet these two duties without changing anything.

Do my software vendors’ privacy obligations under the FDBR flow down to my business as a customer?

Generally no, not as a direct FDBR liability. If a vendor happens to be a covered $1 billion controller, that vendor’s obligations run to its own consumers and to the state, not automatically to a small business customer. Any obligations a small business does take on typically come through a contract (a data processing addendum, for example), not from the statute reaching down to reach smaller companies.

Should FDBR exemption change how my team uses ChatGPT, Claude, or Gemini with client data?

Not directly, since the law doesn’t create AI-specific obligations for a business this size. The relevant precaution is unrelated to the FDBR: use business-tier AI accounts rather than personal free-tier ones for anything involving client, patient, or sensitive data, because consumer accounts typically carry different data-handling terms than business plans. That’s a sound policy with or without any state privacy law on the books.

Key takeaways

  • The Florida Digital Bill of Rights applies only to “controllers”: businesses over $1 billion in global annual revenue that also derive 50%+ of revenue from online ads, run a smart-speaker service, or operate a 250,000-plus-app app store. A 5–50 person business meets none of this.
  • Two narrow duties apply to every Florida business regardless of size: consent before selling sensitive or biometric data, and reasonable security measures for biometric and geolocation data under the amended Florida Information Protection Act.
  • The law took effect July 1, 2024, is enforced only by the Florida Attorney General, and carries no private right of action for consumers.
  • Florida’s $1 billion threshold is far higher than California’s CCPA ($25 million) or Colorado and Virginia’s consumer-volume tests, making it the narrowest controller test among current state privacy laws.
  • FDBR exemption doesn’t remove the real risk small businesses face with AI tools: pasting client or patient data into personal free-tier chatbot accounts. That’s a policy question, not a compliance one, and it’s worth settling before rolling training out to a full team.
  • Florida businesses that want to move ahead with AI training can apply through CareerSource Florida’s Incumbent Worker Training grant, which is unrelated to FDBR compliance and can offset 50–75% of the training cost.

Confirming FDBR exemption clears the compliance objection that sometimes stalls an AI rollout, but it isn’t the whole data-handling picture, and it isn’t a funding answer either. For the full funding and delivery details for Florida, see the state’s AI training playbook, or book a free AI-readiness call to see whether your firm qualifies for the CareerSource reimbursement path.

Last Updated: Sep 15, 2026

DJ

Dirk Jan van Veen, PhD

SFAI Labs helps companies build AI-powered products that work. We focus on practical solutions, not hype.

Make your team fluent in AI — then automate what proves out

  • Hands-on training applied to your own documents and workflows
  • Reimbursable for many Florida small businesses through Incumbent Worker Training
  • Built for 5–50 person firms with no IT department

Related articles