The Letter About Your Information
Fla. Stat. 501.171 — notice within 30 days, and the Department of Legal Affairs at 500
In Florida, a covered entity gives notice to each individual whose personal information was or is reasonably believed to have been accessed, as expeditiously as practicable and without unreasonable delay, and no later than 30 days after determining a breach occurred or having reason to believe one did.
| Who is told | When, as the section puts it |
|---|---|
| Who is toldEach affected individual | When, as the section puts itNo later than 30 days after the breach is determined, with 15 additional days for good cause given in writing |
| Who is toldThe Department of Legal Affairs, for a breach affecting 500 or more individuals in this state | When, as the section puts itNo later than 30 days after the breach is determined |
| Who is toldConsumer reporting agencies, if more than 1,000 individuals are notified at a single time | When, as the section puts itWithout unreasonable delay |
| Who is toldA third party agent that maintains the data | When, as the section puts itTells the covered entity no later than 10 days after determining the breach |
- A covered entity that fails the notice requirements is liable for a civil penalty of $1,000 for each day up to the first 30 days, then $50,000 for each further 30-day period for up to 180 days, and not more than $500,000 in all.
What counts as personal information, the forms notice may take, and the exceptions for encrypted data are in the section and are not reproduced in full here. Whether a notice was required or on time is a question for the attorney general, a court, and a licensed Florida attorney.
Sources for this section (1)
- Fla. Stat. 501.171 — Security of confidential personal information
Legal information, not legal advice. Verified as of September 2026. Applying it to a particular situation is the work of a licensed Florida attorney.