Reference Source

Florida

For Florida, statute citation is Fla. Stat. § 501.171; individual notice deadline is no later than 30 days after the determination of a breach or reason to believe a breach occurred; individual notice hard deadline (days) is 30; ag / regulator notice deadline is no later than 30 days after the determination of the breach or reason to believe a breach occurred; ag notice resident-count trigger is 500 or more individuals in this state, recorded from its source on 2026-08-18.

State
Florida
Statute citation
Fla. Stat. § 501.171
Individual notice deadline
no later than 30 days after the determination of a breach or reason to believe a breach occurred verified
Individual notice hard deadline (days)
30 our reading
AG / regulator notice deadline
no later than 30 days after the determination of the breach or reason to believe a breach occurred verified
AG notice resident-count trigger
500 or more individuals in this state verified
Consumer reporting agency notice trigger (residents)
more than 1,000 individuals at a single time
Encryption safe harbor
yes our reading
Notes
Notice goes to the 'department' (Florida Department of Legal Affairs), not the Attorney General by name. GLBA-regulated entities that comply with federal regulator notice procedures are deemed in compliance. CRA notice threshold of 1,000 is stated in subsection (5). our reading
Sourceflsenate.gov
Verified
Review by
DatasetUS state data breach notification deadlines by state

Values marked our reading are our classification of what the source says — the source does not print them in those words. The quote below is the evidence for each one; judge it yourself.

What the source says

(3)  NOTICE TO DEPARTMENT OF SECURITY BREACH. — (a)  A covered entity shall provide notice to the department of any breach of security affecting 500 or more individuals in this state. Such notice must be provided to the department as expeditiously as practicable, but no later than 30 days after the determination of the breach or reason to believe a breach occurred. A covered entity may receive 15 additional days to provide notice as required in subsection (4) if good cause for delay is provided in writing to the department within 30 days after determination of the breach or reason to believe a breach occurred. (b)  The written notice to the department must include: 1.  A synopsis of the events surrounding the breach at the time notice is provided. 2.  The number of individuals in this state who were or potentially have been affected by the breach. 3.  Any services related to the breach being offered or scheduled to be offered, without charge, by the covered entity to individuals, and instructions as to how to use such services. 4.  A copy of the notice required under subsection (4) or an explanation of the other actions taken pursuant to subsection (4). 5.  The name, address, telephone number, and e-mail address of the employee or agent of the covered entity from whom additional information may be obtained about the breach. (c)  The covered entity must provide the following information to the department upon its request: 1.  A police report, incident report, or computer forensics report. 2.  A copy of the policies in place regarding breaches. 3.  Steps that have been taken to rectify the breach. (d)  A covered entity may provide the department with supplemental information regarding a breach at any time. (e)  For a covered entity that is the judicial branch, the Executive Office of the Governor, the Department of Financial Services, or the Department of Agriculture and Consumer Services, in lieu of providing the written notice to the department, the covered entity may post the information described in subparagraphs (b)1.-4. on an agency-managed website. (4)  NOTICE TO INDIVIDUALS OF SECURITY BREACH. — (a)  A covered entity shall give notice to each individual in this state whose personal information was, or the covered entity reasonably believes to have been, accessed as a result of the breach. Notice to individuals shall be made as expeditiously as practicable and without unreasonable delay, taking into account the time necessary to allow the covered entity to determine the scope of the breach of security, to identify individuals affected by the breach, and to restore the reasonable integrity of the data system that was breached, but no later than 30 days after the determination of a breach or reason to believe a breach occurred unless subject to a delay authorized under paragraph (b) or waiver under paragraph (c).

flsenate.gov, retrieved 2026-08-18

Source

Last verified against source: . Due for re-check by . This page as Markdown · OKF bundle · full dataset as JSON.