ConsentPixel – Privacy · Verified

HomeRegulations › APDPA
🇺🇸United States · Alabama State Privacy Law

APDPA Compliance for Websites in Alabama

The Alabama Personal Data Protection Act (APDPA) is Alabama's comprehensive consumer privacy law — a business-friendly, Virginia-style opt-out framework, but with the lowest consumer threshold in the nation and a permanent cure period. It takes effect May 1, 2027. ConsentPixel — Privacy · Verified already supports it, so you can be ready ahead of the deadline.

Enacted April 16, 2026Effective May 1, 2027Virginia/VCDPA-styleLowest US thresholdSupported in ConsentPixel now
Enacted
April 16, 2026
Effective
May 1, 2027
Enforcer
Alabama AG only
Private suits
None

Key facts verified July 2026 against analyses from Mayer Brown, WilmerHale, Davis Wright Tremaine, Freshfields, and Burr & Forman. This page is educational and is not legal advice.

Alabama became one of the newest US states to enact a comprehensive consumer privacy law when Governor Kay Ivey signed House Bill 351 into law on April 16, 2026. The Alabama Personal Data Protection Act largely follows the Virginia Consumer Data Protection Act (VCDPA) template that has become the dominant model for state privacy laws outside California — but it stands out for unusually low applicability thresholds and a notably business-friendly enforcement structure. The law takes effect May 1, 2027.

What is the APDPA?

The Alabama Personal Data Protection Act is a comprehensive consumer privacy law that grants Alabama residents rights over their personal data and imposes duties on the businesses — controllers and processors — that handle it. It closely follows the Virginia-style framework already familiar from laws in Virginia, Texas, and other states, so organizations with an existing state-privacy compliance program will find much of it recognizable.

Where the APDPA departs from the template is worth attention. It carries the lowest consumer threshold of any state privacy law in the country, a revenue-based threshold with no consumer minimum at all, a novel definition of "sale," no data protection assessment requirement, and a permanent cure period that — unlike most states — never sunsets. The result is a law that reaches a lot of businesses, but is comparatively gentle in how it enforces.

📉

The lowest threshold in the nation means the APDPA catches more businesses

No other state applies a stand-alone consumer-processing threshold as low as Alabama's 25,000, and no other state applies its privacy law purely on a revenue basis — 25% of gross revenue from data sales — regardless of how few consumers are involved. Businesses that are exempt from other states' laws may nonetheless fall within the APDPA's scope, so it's worth checking applicability even if you've cleared other state thresholds.

Does the APDPA apply to your website?

The APDPA applies to any person or business that conducts business in Alabama, or targets products or services to Alabama residents, and meets either of these thresholds:

  • 25,000+ Alabama consumers whose personal data you control or process (excluding data processed solely to complete a payment transaction), or
  • 25%+ of gross revenue derived from the sale of personal data — regardless of the number of consumers whose data you process.

That second threshold is unique: most states pair a revenue test with a consumer minimum, but Alabama's revenue trigger has none, so a data-driven business could be in scope on revenue alone. The APDPA does include exemptions — HIPAA-covered entities and protected health information, financial institutions subject to the GLBA, government entities, higher-education institutions, and small businesses with fewer than 500 employees that do not sell personal data are all excluded from some or all obligations.

Consumer rights under APDPA

The APDPA gives Alabama residents the standard set of Virginia-style consumer rights. Businesses must provide a way to exercise each and generally respond within 45 days, with one 45-day extension available where reasonably necessary.

1

Access

Confirm whether you process their data and access that data.

2

Correct

Correct inaccuracies in the personal data you hold about them.

3

Delete

Request deletion of the personal data you have collected.

4

Portability

Obtain a portable copy of their data in a usable format.

5

Opt out of sale

Opt out of the sale of their personal data.

6

Opt out of targeted ads

Opt out of processing for targeted advertising.

7

Opt out of profiling

Opt out of profiling in furtherance of decisions with legal or similarly significant effects.

8

Appeal

Appeal a business's refusal to act on a rights request within a reasonable time.

What APDPA requires of your website

On the website side, APDPA compliance is a familiar Virginia-style checklist: transparency, honoring opt-outs, and reasonable data practices. Here are the areas your site needs to address.

Signals

Honor opt-out choices

Provide a clear way for Alabama consumers to opt out of the sale of their data, targeted advertising, and significant profiling — and honor those choices reliably.

Notice

Clear privacy notice

A reasonably accessible, clear privacy notice covering the categories of data processed, the purposes, categories shared with third parties, and how consumers exercise their rights.

Consent

Opt-in for sensitive data

Like the Virginia model, processing sensitive data requires the consumer's consent — an opt-in step before that data is processed.

Minimization

Reasonable data practices

Limit collection to what is adequate, relevant, and reasonably necessary for the disclosed purposes, and process data consistently with those purposes.

Security

Reasonable safeguards

Establish and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the data.

Contracts

Processor agreements

Bind processors with contracts that set out processing instructions, confidentiality, and the required data-protection duties.

Non-discrimination

No penalizing rights use

Do not discriminate against consumers for exercising their rights, such as by denying goods or services or charging different prices.

Trackers

Block before consent

Prevent non-essential trackers from firing before a visitor has had the chance to exercise their opt-out — the practical front-line of the whole framework.

🚫

Opt-out is the model — but pre-consent tracking is still the risk

The APDPA follows the opt-out model, so standard personal data can be processed by default subject to the consumer's right to opt out. But the real-world website exposure is identical to every other state law and the CIPA wiretapping wave: analytics and advertising pixels that fire on page load, before a visitor can act on any opt-out. Sensitive data requires opt-in consent regardless. Blocking non-essential trackers until the visitor has a genuine choice is the reliable way to satisfy both.

What a compliant setup looks like

✕ Non-compliant

  • Trackers firing on page load before any consent or opt-out
  • No opt-out mechanism for sale or targeted advertising
  • Sensitive-data processing with no opt-in consent
  • Privacy notice missing or incomplete
  • No consumer-rights request process or appeal path
  • No record of consent or opt-out decisions

✓ Compliant

  • Non-essential trackers blocked until the visitor consents
  • Clear opt-out of sale, targeted ads, and significant profiling
  • Opt-in captured before any sensitive-data processing
  • Reasonably accessible, complete privacy notice published
  • Consumer-rights request process with a 45-day response
  • Consent and opt-out decisions logged for accountability

See what fires before consent on your site

The APDPA is an opt-out law — but the first thing that gives you away is a tracker firing before the visitor could opt out. See which trackers fire before consent on your site, in about 10 seconds — no signup, no install.

Scan your site free →

Enforcement and penalties

The APDPA is enforced exclusively by the Alabama Attorney General — there is no private right of action, so consumers cannot sue directly. What makes Alabama notably business-friendly is its cure period: unlike most states, where the right to cure sunsets after a fixed period, the APDPA's cure period is permanent and does not expire.

Enforcement authority
Alabama AG
Exclusive enforcement by the Office of the Attorney General. No private right of action for consumers.
Cure period
Permanent
A right-to-cure period applies before enforcement — and unlike most state laws, it does not sunset. This is one of the APDPA's most business-friendly features.

Because enforcement runs solely through the Attorney General and the cure period is permanent, the APDPA is among the more forgiving state privacy laws on paper. That said, the low thresholds mean more businesses are in scope than under comparable laws — so the practical exposure comes less from harsh penalties and more from simply being covered when you didn't expect to be.

Live compliance check — fresh session
Meta Pixel (connect.facebook.net)BLOCKED
Google Analytics / GA4 (gtag)BLOCKED
TikTok Pixel (analytics.tiktok.com)BLOCKED
Targeted-ad retargeting tagBLOCKED
Consent banner✓ DISPLAYED
Opt-out signal (GPC)✓ HONORED
Consent log entry✓ PENDING CHOICE
With ConsentPixel, non-essential trackers stay blocked until the visitor makes a choice, opt-out signals are honored automatically, and every decision is logged — the evidence that demonstrates you handled Alabama consumers' choices properly.

How to comply with APDPA

APDPA readiness is operational infrastructure, not a one-time task — and with a May 1, 2027 effective date, you have time to get it right now. Because the APDPA is Virginia-style, most of this overlaps with compliance you may already have for other states. These are the steps, ordered by impact.

01

Install a consent platform that blocks before consent

The foundation. A CMP technically blocks non-essential trackers until the visitor has a choice, honors opt-out signals for sale and targeted advertising, captures opt-in for sensitive data, and logs every decision. ConsentPixel — Privacy · Verified does all of this from one script tag, with APDPA support already built in.

02

Provide clear opt-out mechanisms

Give Alabama consumers an easy, accessible way to opt out of the sale of their data, targeted advertising, and significant profiling — and make sure your site actually honors those choices, including universal opt-out signals like Global Privacy Control.

03

Gate sensitive data behind opt-in

Identify any sensitive-data processing and require the consumer's consent before processing it, consistent with the Virginia-style model the APDPA follows.

04

Publish a complete privacy notice

Your privacy notice must cover the categories of data processed, the purposes, the categories shared with third parties, and how consumers exercise their rights and appeal a refusal. ConsentPixel's privacy policy generator produces an APDPA-aligned notice as part of setup.

05

Set up a consumer-rights request process

Provide a way for Alabama residents to submit access, correction, deletion, portability, and opt-out requests, with a 45-day response window and an appeal path. ConsentPixel includes a DSAR request flow with deadline tracking.

06

Keep records of consent and opt-outs

Log consent and opt-out decisions with timestamps so you can demonstrate compliance if the Attorney General inquires — and take advantage of the permanent cure period by fixing any gap promptly.

APDPA compliance checklist

Use this to assess where your website stands today, ahead of the May 1, 2027 effective date.

Consent platform installed — non-essential trackers blocked until consent
Opt-out of sale and targeted advertising offered and honored
Global Privacy Control / universal opt-out signal recognized
Sensitive-data processing gated behind opt-in consent
Reasonably accessible, complete privacy notice published
Consumer-rights request process in place — 45-day response
Appeal path available when a rights request is refused
Processor contracts include required data-protection terms
Reasonable data security practices documented
Consent and opt-out decisions logged with timestamp
Applicability re-checked against the low 25,000 / 25%-revenue thresholds

Being ready before 2027 is the easy win

The APDPA doesn't take effect until May 1, 2027 — and because it's a Virginia-style opt-out law, most of what it requires is compliance infrastructure you either already have for other states or can stand up quickly. The one thing to watch is scope: Alabama's thresholds are the lowest in the nation, so you may be covered even if you're exempt elsewhere.

ConsentPixel already supports APDPA today. You can switch it on now, be verifiably ready well ahead of the deadline, and cover Alabama alongside the rest of your US state-law exposure from a single script tag — rather than treating each new state law as a fresh fire drill.

APDPA frequently asked questions

When does the APDPA take effect?

The Alabama Personal Data Protection Act (House Bill 351) was signed into law by Governor Kay Ivey on April 16, 2026, and takes legal effect on May 1, 2027. The runway is intended to give businesses time to prepare. Because the APDPA follows the Virginia-style model already in force in several states, much of the required infrastructure — opt-out handling, prior tracker blocking, a clear privacy notice, and a consumer-rights process — overlaps with compliance you may already have. ConsentPixel already includes APDPA support, so you can be ready well ahead of the effective date.

Does the APDPA apply to my business?

It applies if you conduct business in Alabama or target products or services to Alabama residents and meet either of two thresholds: controlling or processing the personal data of more than 25,000 Alabama consumers (excluding data used solely to complete a payment transaction), or deriving more than 25% of gross revenue from the sale of personal data regardless of the number of consumers involved. The 25,000 threshold is the lowest of any state privacy law, and the revenue threshold uniquely requires no consumer minimum — so businesses exempt from other states' laws may still be covered here. Exemptions exist for HIPAA and GLBA-regulated entities, government bodies, higher education, and small businesses under 500 employees that don't sell data.

How is the APDPA different from other state privacy laws?

The APDPA closely tracks the Virginia Consumer Data Protection Act, so its consumer rights and controller duties will look familiar. Its distinguishing features are mostly about scope and enforcement: the lowest consumer threshold in the country (25,000), a revenue-based threshold with no consumer minimum, a novel definition of "sale," the absence of a data protection assessment requirement, and — most notably — a permanent cure period that, unlike most states, never sunsets. In short, it reaches more businesses than comparable laws but enforces more gently.

Does the APDPA require opt-in consent?

For most personal data, no — the APDPA follows the opt-out model, meaning you can process standard personal data by default subject to the consumer's right to opt out of sale, targeted advertising, and significant profiling. However, processing sensitive data requires the consumer's consent, which is an opt-in step. In practice your website needs both: reliable opt-out mechanisms (including recognition of universal opt-out signals) for standard data, and an opt-in gate before any sensitive-data processing.

Is there a private right of action under the APDPA?

No. The APDPA is enforced exclusively by the Alabama Attorney General, and there is no private right of action, so individual consumers cannot sue businesses directly for violations. The APDPA is also notably business-friendly in its enforcement: it provides a cure period before enforcement that, unlike most state privacy laws, is permanent and does not expire. This means a business given notice of a violation generally has the opportunity to fix it — though relying on the cure period is no substitute for being compliant in the first place.

What should my website do to prepare for the APDPA?

Because the APDPA is Virginia-style, the website steps are the familiar ones: install a consent platform that blocks non-essential trackers until the visitor has a choice; offer clear opt-outs of sale, targeted advertising, and profiling, and honor universal opt-out signals like Global Privacy Control; gate sensitive data behind opt-in consent; publish a complete, accessible privacy notice; set up a consumer-rights request process with a 45-day response and appeal path; and log consent and opt-out decisions. ConsentPixel handles all of this from one script tag and already includes APDPA support, so you can be ready before the May 2027 deadline.

Be APDPA-ready before Alabama's 2027 deadline

ConsentPixel — Privacy · Verified handles prior tracker blocking, opt-out signal recognition, sensitive-data opt-in, an APDPA-aligned privacy notice, consumer-rights requests, and consent logging — for Alabama and every other US state law, from one script tag.

No credit card required · from $8.99/domain/mo · cancel any time
Scroll to Top