Status: Enacted – Signed by Governor Kay Ivey on April 17, 2026 after unanimous passage in both chambers (House 104-0, Senate 34-0). Takes effect May 1, 2027.
Bill Number: AL HB 351 (2026 Regular Session) — Alabama Personal Data Protection Act ("ALDPA")
Jurisdiction: Alabama
Category: Consumer Data Privacy, Biometric Data Protections
Industries: All sectors that process personal data of Alabama residents at scale — including healthcare, retail, hospitality, manufacturing, K-12 and higher education vendors, and physical security solution providers.
Enacted Date: April 17, 2026
Effective Date: May 1, 2027
Summary: Alabama HB 351 establishes Alabama as the 21st U.S. state with a comprehensive consumer data privacy law. The act creates a baseline framework granting Alabama consumers the rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of the sale of personal data and certain targeted advertising or profiling practices. ALDPA classifies biometric data — including data used to uniquely identify an individual — as sensitive personal data, requiring affirmative opt-in consent before processing. The law applies to controllers that conduct business in Alabama or target Alabama residents and meet either of two thresholds: process the personal data of more than 100,000 Alabama consumers annually, or process the data of 25,000 consumers while deriving more than 25% of revenue from data sales. Enforced exclusively by the Alabama Attorney General with a notice-and-cure period and civil penalties up to $15,000 per violation.
Key Provisions:
- Consumer Rights: Access, correction, deletion, portability, and opt-out rights for sale of personal data, targeted advertising, and certain profiling.
- Biometric Data as Sensitive Data: Biometric identifiers and biometric information used to uniquely identify an individual are sensitive personal data requiring opt-in consent.
- Applicability Thresholds: 100,000 Alabama consumers OR 25,000 with majority of revenue from data sales.
- Enforcement: Exclusive enforcement by the Alabama Attorney General. Notice-and-cure period; civil penalties up to $15,000 per violation. No private right of action.
- Entity Exemptions: State agencies, nonprofits, higher education institutions, and certain entities regulated by HIPAA and GLBA are exempt at the entity or data level.
Affected Entities: Any business that conducts activity in Alabama or markets to Alabama residents and meets the applicability thresholds — including national retailers and quick-service chains operating Alabama stores, healthcare systems and hospital networks, hospitality and senior living operators, and physical security and surveillance technology vendors selling into Alabama buyers.
Funding/Compliance Outlook: Covered entities have approximately twelve months from the signing date to operationalize compliance. The biometric-as-sensitive classification is the most operationally significant element for the physical security industry: any solution that processes biometric identifiers in Alabama — including facial recognition, fingerprint readers, voice prints, and certain advanced video analytics — will need opt-in consent flows, sensitive-data documentation, and supplemental data protection assessments before deployment.
IntelliSee Relevance: High. The biometric-as-sensitive classification continues the multi-state pattern (Illinois BIPA, Texas CUBI, Washington HB 1493, Colorado SB 190, Maryland HB 4757) of treating biometric identifiers as a separately regulated data category. IntelliSee’s architecture is privacy-preserving by design: our AI gun detection and broader analytics suite process object and event data only, with no facial recognition, no biometric template extraction, and no identity-based matching. That posture sidesteps the highest-friction elements of ALDPA and equivalent state biometric statutes, and is a competitive differentiator against vendors who require biometric processing to function.