Skip to content
(888) 538-6881Client Portal
The Network Gurus

Blog

Florida's data breach law, explained for small businesses

The Florida Information Protection Act applies to almost every business in the state. Here's what it requires, the deadlines that matter, and what to do before you ever need it.

A business owner reviewing security settings on a laptop

October 10, 2026 · The Network Gurus

The short answer

The Florida Information Protection Act of 2014 (FIPA, Florida Statutes section 501.171) requires every business that keeps personal information about Florida residents to protect it with reasonable security, dispose of it properly, and give notice within 30 days if it's breached. Breaches affecting 500 or more Floridians must also be reported to the Florida Department of Legal Affairs, and breaches affecting more than 1,000 people require notice to the national credit reporting agencies. Late notice can cost up to $500,000 per breach.

There is no size exemption. A three-person insurance agency in Venice is covered the same way a hospital system is.

What counts as personal information

Under FIPA, personal information is a person's first name or first initial and last name combined with any of these:

  • Social Security number
  • Driver license, state ID, passport, or military ID number
  • Financial account, credit card, or debit card number together with any code or password needed to access the account
  • Medical history, condition, treatment, or diagnosis
  • Health insurance policy or subscriber number
  • Biometric data
  • Geolocation information

A username or email address combined with a password or security question answer for an online account also counts on its own, with no name required.

Two exclusions matter. Information that's publicly available from government records doesn't count, and neither does data that's encrypted or otherwise made unreadable. That second one is the closest thing FIPA has to a safe harbor.

Who has to comply

FIPA applies to any "covered entity": sole proprietorships, partnerships, corporations, associations, and other commercial entities that acquire, maintain, store, or use personal information. If you keep customer files, run payroll, take card payments, store patient records, or keep copies of driver licenses, you're covered.

It also applies to third-party agents, meaning vendors that handle personal information on your behalf. That includes your IT provider, your cloud backup company, and your payroll service.

The deadlines that matter

Who must be notifiedWhenThreshold
Affected Florida residentsNo later than 30 days after determining a breach occurredAny breach of personal information
Florida Department of Legal AffairsNo later than 30 days500 or more Floridians affected
Nationwide credit reporting agenciesWithout unreasonable delayMore than 1,000 individuals
Your business, from a vendorNo later than 10 days after the vendor discovers itAny breach at a third-party agent

The 30-day clock starts when you determine a breach occurred or have reason to believe one did. You don't get to wait until the forensic report is finished. An extra 15 days is available only if you give the Department good cause in writing inside the first 30 days. Law enforcement can also request a delay if notice would interfere with an investigation.

What the notices must say

Notice to individuals can go by mail or email to the address in your records and must include:

  • The date, estimated date, or date range of the breach
  • A description of the personal information involved
  • Contact information so the person can ask questions

Notice to the Department of Legal Affairs must include a synopsis of events, the number of Floridians affected, any free services offered (such as credit monitoring) and how to use them, a copy of the notice sent to individuals, and a named contact.

When you don't have to notify individuals

If, after an appropriate investigation and consultation with law enforcement, you reasonably determine the breach has not and will not likely result in identity theft or other financial harm, individual notice isn't required. You must put that determination in writing, keep it for five years, and send it to the Department within 30 days. This is not a shortcut to skip a hard conversation; it requires real investigation and documentation.

Penalties

Violations are treated as unfair or deceptive trade practices enforced by the Department of Legal Affairs. For failing to give required notice:

  • $1,000 per day for the first 30 days
  • $50,000 for each 30-day period after that, up to 180 days
  • Up to $500,000 per breach if the violation continues past 180 days

FIPA itself doesn't let customers sue, but a breach can still lead to claims under other laws, plus the very real cost of lost trust.

How FIPA overlaps with HIPAA and the FTC Safeguards Rule

Many Southwest Florida businesses answer to more than one rule. Medical and dental practices are also covered by HIPAA. Auto dealerships, CPA firms, and other financial institutions are covered by the FTC Safeguards Rule. FIPA says notice given under the rules of your primary or functional federal regulator is deemed to satisfy its individual notice requirement, as long as you also send a copy to the Department on time. The safe approach is to plan your incident response around the strictest deadline that applies to you and to confirm the details with your attorney.

What to do now, before anything happens

  1. Know where personal information lives. Email, file shares, the practice-management or dealer system, scanned driver licenses, spreadsheets on desktops. You can't protect or report on what you can't find.
  2. Encrypt laptops, phones, and backups. Encrypted data that's lost or stolen generally isn't a reportable breach under FIPA.
  3. Turn on multi-factor authentication everywhere, especially email. Compromised email accounts are the most common source of small business breaches.
  4. Get rid of what you don't need. FIPA requires reasonable disposal. Old scans, former-employee files, and closed-account records are liability with no upside.
  5. Check your vendors. Your IT provider and other third-party agents must tell you about a breach within 10 days. Make sure your contracts say so and that you know who to call.
  6. Write a one-page incident plan. Who decides a breach occurred, who calls the attorney, who calls the insurer, who drafts the notice. The 30-day clock goes fast when nobody knows whose job it is.

This article summarizes the statute for business owners and is not legal advice. Talk to your attorney about your specific situation.

How we help

Every Network Gurus managed plan includes enforced MFA, email security, endpoint detection and response, staff training, a managed firewall, and tested backups: the core of the "reasonable measures" FIPA expects. If you'd like to know where your business stands, start with a free IT and compliance assessment. It's a 60-minute on-site visit that ends with a written list of gaps and priorities.

Keep reading

More from the blog

Questions we hear

Frequently asked questions

Don’t see your question? Call us and a real person will answer.

Does the Florida Information Protection Act apply to small businesses?

Yes. It applies to any commercial entity, including sole proprietors, that acquires, maintains, stores, or uses personal information about Florida residents. There is no minimum size or revenue threshold.

How long do I have to notify customers after a data breach in Florida?

No later than 30 days after you determine a breach occurred or have reason to believe one did. You can get up to 15 more days if you give the Florida Department of Legal Affairs good cause in writing within the first 30 days, and law enforcement can request a delay.

When do I have to notify the Florida Attorney General?

When a breach affects 500 or more Florida residents. Notice goes to the Department of Legal Affairs within 30 days and must include a synopsis, the number of Floridians affected, any services offered, a copy of the notice, and a contact person.

What are the penalties for violating Florida's breach notification law?

Failing to give required notice is treated as an unfair or deceptive trade practice. Penalties are $1,000 per day for the first 30 days, then $50,000 for each additional 30-day period up to 180 days, capped at $500,000 per breach.

Can customers sue me under FIPA?

Not under FIPA itself. The statute says it does not create a private cause of action, and enforcement belongs to the Department of Legal Affairs. Customers may still bring claims under other laws.

Is encrypted data covered?

No. Data that is encrypted, secured, or modified so it is unreadable or unusable is excluded from the definition of personal information, which is why encrypting laptops and databases is one of the most valuable things a small business can do.

Free IT assessment

Know where you stand before something breaks

A plain-English review of your security, backups, and support experience. No cost, no obligation, and the report is yours to keep.