Florida · verified through August 25, 2026

Florida: law status and evidence context.

Law status, direct attached-library attribution, and public enforcement context are shown separately. A zero direct total does not mean no enforcement exists.

FL · 6 requirements mapped / control outcomes supported

Law status

Verified comprehensive law

Yes - Florida Digital Bill of Rights

Official name / citation
Fla. Stat. §§ 501.701-501.722
Status / effective date
Codified; effective July 1, 2024 per the 2023 statutes copy
Principal enforcer
Florida Attorney General (Department of Legal Affairs)

Direct attached-library attribution

0 cases · $0

These totals are assigned solely by the attachment’s state heading. Shared multistate totals are not allocated in full to every state.

The attached library does not enumerate participant-level allocations for every multistate matter; shared settlement totals are presented once at the national level and are not duplicated into state totals.

Official law sources

Other generally applicable PII law

Also relevant: Fla. Stat. § 501.171, 'Security of confidential personal information' - https://www.flsenate.gov/laws/statutes/2025/501.171

Public enforcement context

Tier 1*

Blackbaud, Inc.

$49.5 million total payment to the states (do not infer a state share unless quoted below) · October 5, 2023

The AGs alleged Blackbaud failed to implement reasonable data security and to remediate known gaps before a 2020 ransomware incident, and failed to give customers timely, complete or accurate breach information. Florida is named among the participating jurisdictions on the Illinois AG page; the Florida share is not stated there.

Legal basis: State consumer protection laws, state breach-notification laws and HIPAA (as alleged by the AGs)

Official case source (opens in a new tab)

Mapped control outcomes

1 personal data inventory/data map; 2 sensitive-data discovery; 3 downstream copy tracking; 8 breach blast-radius analysis; 9 retention/minimization; 10 regulator audit evidence

Kestryl can evidence where regulated personal data actually resides across structured stores and unstructured attachments/images, produce audit rows and evidence packs showing when each location was discovered and reviewed, and apply structured-data remediation modes (mask, vault, strip) to reduce exposure. It does not alter source attachments or documents, and its output is technical evidence supporting controls, not proof of legal compliance.