TL;DR:
- Alabama unanimously passed HB 351 on April 7, 2026: 104-0 in the House, 34-0 in the Senate. Not a single lawmaker voted no.[1]
- The lowest threshold in the country: Covers businesses processing data of just 25,000 Alabama residents. California's threshold is 100,000.[1]
- Businesses under 500 employees are exempt, unless they sell data. Most small businesses in Alabama won't feel this at all.[1]
- No private right of action. You can't sue. Only the Alabama Attorney General can enforce it, and violators get a 45-day "cure period" that never sunsets.[1]
- Takes effect May 1, 2027. Still awaiting Governor Ivey's signature. She's expected to sign it.[1]
- 29 states still have no comprehensive privacy law. And Congress hasn't passed a federal one. Don't hold your breath.
A Privacy Law Nobody Opposed
On April 7, 2026, something unusual happened in Montgomery. The Alabama House passed a comprehensive data privacy bill 104-0. The Senate had already cleared it 34-0. Not a single lawmaker in either chamber voted against the Personal Data Protection Act.[1]
That unanimity tells you something, not about bipartisan privacy conviction, but about how carefully the bill was written to avoid upsetting anyone with power. No private right of action. No universal opt-out requirement. A permanent 45-day cure period that gives companies a do-over every single time they violate the law. Exemptions for businesses under 500 employees.
Rep. Mike Shaw, who sponsored HB 351, described it as striking a "balance: Balancing Alabamians' rights with the burden of regulation." Translation: strong enough to put on a press release, gentle enough that the Business Council of Alabama didn't flinch.
What HB 351 Actually Does
Alabama's law grants residents five core rights:
- Access: You can ask a company what data it has on you
- Correction: You can demand they fix inaccuracies
- Deletion: You can tell them to delete your data
- Portability: You can get a copy of your data in a usable format
- Opt-out: You can stop them from using your data for targeted ads, data sales, or profiling
Companies have 45 days to respond. They can extend that to 90 if they claim complexity. Sensitive data (biometrics, health information, precise geolocation) requires explicit opt-in consent. Children under 13 get COPPA-level protections, and teens aged 13-15 need consent before companies can target them with ads or sell their data.
So far, so standard. This is the same basic framework that 20 other states have adopted, give or take a few details.
The 25,000-Person Threshold: Lowest in America
Here's where Alabama does something different. The law kicks in when a business processes personal data of 25,000 or more Alabama residents. That's the lowest numerical threshold of any state privacy law in the country.
For comparison:
- California, Colorado, Connecticut, Virginia: 100,000 consumers
- Texas: 500,000 consumers (or derives 50% of revenue from data sales)
- Utah: 100,000 consumers
- Alabama: 25,000 consumers, roughly 0.48% of the state's population
There's also a second trigger: any business that derives 25% or more of gross revenue from selling personal data is covered, regardless of how many people's data it handles. Alabama is the only state where this revenue test is completely untethered from consumer count.
In theory, this lower threshold catches mid-size companies that slip through other states' nets. In practice, the 500-employee exemption claws most of it back.
The Loopholes
The exemptions are where you see why no one voted against this bill.
Businesses under 500 employees are exempt, unless they sell data. Alabama has about 112,000 businesses. The vast majority have fewer than 500 employees. The exemption essentially limits the law to large corporations, most of which are already complying with California or Virginia's laws anyway.
Nonprofits under 100 employees are similarly carved out.
The "sale" definition is slippery. Alabama excludes transfers for analytics services and marketing services directed solely to the controller. That means a company can share your data with a third party for "analytics" purposes and argue it doesn't count as a sale. Other states have tighter definitions.
No data protection impact assessments required. Most state privacy laws require companies to evaluate risks when processing sensitive data. Alabama skipped that requirement entirely.
No universal opt-out signal recognition. In Colorado, Connecticut, and several other states, your browser's Global Privacy Control signal automatically opts you out of data sales. Alabama doesn't honor that. You'll need to go to each company individually.
The cure period never expires. Other states like Colorado and Connecticut included "sunset" provisions that eventually eliminated their cure periods, forcing companies to get it right the first time. Alabama's 45-day cure period is permanent. A company can violate the law, get caught, "cure" it, and face no penalties. Then do it again.
The 21-State Privacy Patchwork
Alabama joins a growing but inconsistent list. Here's where things stand as of April 2026:
States with comprehensive privacy laws (21): California, Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Tennessee, Montana, Texas, Oregon, Delaware, New Hampshire, New Jersey, Kentucky, Maryland, Minnesota, Nebraska, Rhode Island, Florida, and now Alabama.
States with nothing (29): Alaska, Arizona, Arkansas, Georgia, Hawaii, Idaho, Illinois, Kansas, Louisiana, Maine, Massachusetts, Michigan, Mississippi, Missouri, Nevada, New Mexico, New York, North Carolina, North Dakota, Ohio, Oklahoma, Pennsylvania, South Carolina, South Dakota, Vermont, Washington, West Virginia, Wisconsin, Wyoming.
Some of those "nothing" states will surprise you. New York, home to Wall Street and Silicon Valley East, has no comprehensive data privacy law. Neither does Massachusetts, Illinois (though it has the strong but narrow BIPA for biometrics), Pennsylvania, or Georgia.
Meanwhile, the laws that do exist vary wildly:
- Strongest: California (CCPA/CPRA), with a private right of action for breaches, broad definition of personal information, data broker registration
- Most business-friendly: Utah, Iowa, and now Alabama, with high exemption thresholds, no DPIA requirements, permanent cure periods
- Best for opt-out: Colorado, Connecticut, Minnesota, with mandatory universal opt-out signal recognition
- Weakest: Florida, with extremely narrow scope, a high revenue threshold ($1 billion), widely criticized as privacy law in name only
The Federal Law That's Never Coming
The American Data Privacy and Protection Act (ADPPA) came closest in 2022. It passed the House Energy and Commerce Committee 53-2. Bipartisan support. Real momentum. Then it died before reaching a floor vote. California killed it. Senator Cantwell and the state's delegation refused to let a federal law preempt California's stronger protections.
Since then: nothing. The 118th and 119th Congresses haven't even introduced a serious replacement. With FISA Section 702 expiring in 8 days and the current administration more interested in deregulation than consumer protection, a federal privacy law isn't on anyone's agenda in Washington.
That means the patchwork grows. Every new state law means another set of compliance requirements, another slightly different definition of "sale," another variation on consumer rights that companies need to navigate. It's a full-employment act for privacy lawyers and a maze for everyone else.
The EU passed GDPR in 2016 and it went into effect across 27 countries in 2018. One law. One standard. America has been debating this for over a decade and the best we've managed is 21 different laws that each protect different people in different ways.
Why This Matters (and Why It Doesn't)
Alabama's law matters because it's another signal that data privacy has bipartisan support at the state level. A deep-red state passing a privacy law 104-0 says something about where public opinion sits, even if the law itself is modest.
It matters because the 25,000-person threshold could catch companies that assumed they were too small for state privacy laws. If you run a mid-size business with an Alabama customer base, you need to check your numbers.
But it doesn't matter much for Alabamians who actually want protection right now. The law doesn't take effect until May 2027. When it does, only the AG can enforce it, and state AGs aren't exactly drowning in resources for privacy enforcement. The permanent cure period means companies face effectively zero consequences for a first violation. And the exemptions are wide enough to drive a data broker through.
What You Can Do
- Don't wait for state laws to protect you. Use browser privacy tools like Firefox with uBlock Origin, enable Global Privacy Control (even though Alabama doesn't honor it, 7 other states do), and limit what you share online.
- Exercise your rights where they exist. If you live in one of the 21 states with a privacy law, use it. Submit data deletion requests. Opt out of data sales. Make them do the paperwork.
- Push for stronger federal legislation. Call your representative. The ADPPA framework exists. It just needs political will. Tell them 21 different state laws aren't working for anyone except compliance consultants.
- Support organizations fighting for privacy. The EFF, EPIC, and the ACLU are the front lines of the federal privacy law fight.
Sources
Published: April 12, 2026