Summary
Alabama's new privacy law changes the answer for many Gulf Coast businesses. Here is whether your website needs a privacy policy now and what it needs to cover.
By: Jordan Gerheim, CEO – Outside Chief Legal LLC
Alabama’s new Personal Data Protection Act changes the privacy-policy question for many Gulf Coast businesses. Before the law passed, whether you needed a privacy policy on your website depended mostly on whether you collected data from California residents, whether you used third-party ad platforms with their own requirements, and whether your industry had specific federal rules. The answer is now more clear-cut for businesses operating in Alabama.
Who the Alabama Privacy Law Covers
The Alabama Personal Data Protection Act, signed in April 2026 and effective May 2027, applies to businesses that conduct business in Alabama or target products and services to Alabama residents and that meet at least one of two thresholds. The first threshold is processing or controlling the personal data of more than 25,000 Alabama consumers per year. The second is deriving more than 25 percent of gross revenue from selling personal data and processing the data of more than 10,000 Alabama consumers per year.
If either threshold applies, a privacy notice on your website is legally required.
The 25,000-consumer threshold is notably lower than what many other state privacy laws require. Several states set their floor at 100,000 consumers. Alabama set it at 25,000, which means businesses with a mid-size email list, an active website with tracking tools, or a customer loyalty program may cross it without realizing it. Payment-only data does not count toward the threshold, but names, email addresses, phone numbers, and IP addresses collected through your website do.
What the Privacy Policy Must Cover
The law requires covered businesses to provide a reasonably clear and accessible privacy notice. At minimum, that notice needs to explain what categories of personal data the business collects, the purposes for which the data is processed, whether the data is shared or sold to third parties and under what circumstances, and how consumers can exercise their rights under the law.
Consumer rights under the Alabama law include the right to access personal data the business holds about them, the right to correct inaccurate data, the right to delete their data in certain circumstances, and the right to opt out of the sale of their personal data. If your business runs targeted advertising or sells personal data, the law also requires a clear and visible opt-out link on your website. That link needs to lead to a functional opt-out page, not a general contact form or a privacy-policy page where the option is buried.
The privacy notice needs to be genuinely accessible, meaning easy for a consumer to find. A link in the footer is the standard approach, but the link itself needs to be labeled clearly enough that a reasonable person knows what they are clicking.
Here is what the gap looks like in practice: a Gulf Coast retailer with an e-commerce site and a loyalty program updates its privacy policy using a generic template downloaded from the internet. The template says the business does not sell personal data. The retailer’s actual advertising platform, however, shares customer purchase behavior with third-party advertisers under a data-sharing arrangement that qualifies as a sale under Alabama’s definition. The policy and the practice are now in direct conflict. When a consumer submits a deletion request and discovers the discrepancy, the retailer has a credibility problem on top of a compliance problem. The fix is not complicated, but it has to start with understanding what the website and its connected platforms actually do.
Businesses That Are Not Yet Covered But Should Still Have a Policy
Even if your business does not currently meet the Alabama law thresholds, there are other reasons to have a privacy policy in place.
If you use Google Analytics, Meta Pixel, or other third-party tracking tools on your website, those platforms have their own terms of service that require you to notify users that their data is being collected and used for tracking purposes. A missing or inaccurate privacy policy can put your access to those tools at risk, not just your legal standing.
If you collect email addresses for a newsletter or marketing list, most email service providers require a privacy policy as part of their terms of use. Mailchimp, Klaviyo, and similar platforms all include this requirement. A business that operates without one risks having its account suspended during an audit.
If you sell products or services to consumers in California, the California Consumer Privacy Act may apply independently of the Alabama law and carries its own set of requirements. For businesses that ship or sell across state lines, the compliance picture is broader than any one state law.
For any business with a functional website that collects user data in any form, having a privacy policy that accurately reflects actual practices is the cleaner position regardless of whether Alabama’s law currently requires it.
What a Useful Privacy Policy Actually Contains
A privacy policy that protects the business and informs users clearly covers the categories of data collected, how it is used, who it is shared with and why, the rights consumers have, and how to contact the business with privacy-related requests. It should be specific to your actual data practices, not a generic template that describes practices your website does not follow.
Generic templates are a starting point, not a finish line. A privacy policy that says you do not sell data when your advertising platform does share user data creates a credibility problem and a legal exposure. Getting the policy right means starting with a data map of what your website actually collects and where that data goes, then drafting language that matches that reality.
The businesses that handle this well are the ones that treat the privacy policy as a living document, not a one-time checkbox. When you add a new analytics tool, change email platforms, or launch a new feature that collects data, the policy needs to reflect that change.
A practical way to approach this is to review your privacy policy any time you onboard a new vendor or platform that touches customer data. That review does not need to be a legal project every time. It just needs to be a habit. The businesses that get caught with outdated policies are almost never the ones that ignored the issue entirely. They are the ones that wrote a policy once, published it, and assumed it would hold indefinitely while the tools they use kept changing around it.
Before May 2027
If your business meets the Alabama law coverage thresholds, getting a compliant privacy policy in place before the law takes effect is a straightforward project. Getting your vendor contracts updated to address data-handling obligations is the other key compliance step. The law requires written agreements with any outside company that processes personal data on your behalf, and many existing vendor arrangements do not include those terms.
Civil penalties for violations run up to $15,000 per violation, enforced by the Alabama Attorney General. The law includes a 45-day cure period, which gives covered businesses notice and an opportunity to fix a violation before enforcement proceeds. That provision helps businesses acting in good faith, but it does not help businesses that have not addressed the law at all by the time a complaint arrives.
A Risk-Free Strategy Session is a practical way to start that conversation. We look at your website, your data practices, and your vendor relationships and give you a clear read on where you stand and what a compliant policy actually needs to say.
No representation is made that the quality of the legal services to be performed is greater than the quality of legal services performed by other lawyers.
Our Corporate/Business Counsel Services
Outside Chief Legal LLC is a modern, forward-thinking law firm serving as fractional chief legal officers and outside general counsel for businesses and their owners. With over 200 years of combined litigation, in-house, general counsel, and administrative legal experience, the firm delivers approachable, comprehensive counsel that blends legal expertise with practical business insight to help clients navigate ownership complexities with confidence. OCL is a trusted partner for founders, business owners, and leadership teams nationwide. Learn more about our firm, meet our team, or schedule a Risk-Free Strategy Session to talk with an attorney about how we can help your company.