---
title: Alabama Breach Notification Law - SCA Security
description: Breach Notification Guide in Alabama Alabama S.B. 318 was put into law March 28, 2018 and became effective June 1 that year. Breach laws for Alabama apply to individuals or commercial entities pertaining to sensitive PI. A breach in Alabama is the unauthorized acquisition of such data electronically. Legal Requirements When it comes to a
image: https://blog.scasecurity.com/hubfs/Imported_Blog_Media/alabama-breach-notification-law.jpg
---

[727-571-1141 Talk to an Expert](tel:727-571-1141) [info@scasecurity.com Email Us](mailto:info@scasecurity.com) <https://www.facebook.com/Security-Compliance-Associates-170070577097300/?ref=br_rs> <https://twitter.com/scasecurity> <https://www.linkedin.com/company/security-compliance-associates/>

[![sca-logo-r](https://blog.scasecurity.com/hs-fs/hubfs/sca-logo-r.png?length=190&name=sca-logo-r.png)](https://scasecurity.com/)

☰

- [Home](https://scasecurity.com/)
- [Security](https://scasecurity.com/security/) 
    - [Email Phishing & Employee Training](https://scasecurity.com/anti-phishing-training-with-phished-io/)
    - [Vulnerability Assessments](https://scasecurity.com/security/vulnerability-assessments/)
    - [Penetration Testing](https://scasecurity.com/security/penetration-testing/)
    - [Applications](https://scasecurity.com/security/applications/)
    - [Controls](https://scasecurity.com/security/controls/)
    - [Centurion ESO](https://scasecurity.com/executive-security-officer/)
    - [Consulting](https://scasecurity.com/security/consulting/)
- [Risk & Compliance](https://scasecurity.com/compliance/) 
    - [CMMC](https://scasecurity.com/cybersecurity-maturity-model-certification/)
    - [HITRUST](https://scasecurity.com/hitrust/)
    - [Federal](https://scasecurity.com/compliance/federal/)
    - [State](https://scasecurity.com/compliance/state/)
    - [Industry](https://scasecurity.com/compliance/industry/)
    - [Cybersecurity Risk Assessment](https://scasecurity.com/security/risk-assessment/)
    - [NIST Cybersecurity Framework Assessment](https://scasecurity.com/compliance/nist-framework/)
    - [AI Risk Management Services](https://scasecurity.com/ai-risk-management-services/)
- [Governance](https://scasecurity.com/compliance/governance/)
- [Industries](https://scasecurity.com/industries/) 
    - [Financial Services](https://scasecurity.com/industries/financial-services/)
    - [Healthcare](https://scasecurity.com/industries/healthcare/)
    - [Government/Public Sector](https://scasecurity.com/industries/government-public-sector/)
    - [Title/Real Estate](https://scasecurity.com/industries/title-real-estate/)
    - [Technology](https://scasecurity.com/industries/technology/)
    - [Manufacturing](https://scasecurity.com/industries/manufacturing/)
    - [Professional Services](https://scasecurity.com/industries/professional-services/)
    - [Automotive](https://scasecurity.com/automotive/)
    - [Higher Education](https://scasecurity.com/higher-education/)
- News & Resources 
    - [Blog](https://blog.scasecurity.com)
    - [Events](https://scasecurity.com/event/)
    - [Case Studies](https://scasecurity.com/case-studies/)
    - [Recorded Webinars](https://scasecurity.com/recorded-webinars/)
    - [SCA Breach Notification Guide](https://scasecurity.com/breach-notification-guide/)
    - [HIPAA Security Audit Checklist](https://info.scasecurity.com/hipaa-audit-checklist)
    - [Cybersecurity Checklist for Insurance Providers](https://info.scasecurity.com/cybersecurity-checklist-for-insurance-providers)
- Company 
    - [About Us](https://scasecurity.com/about-us/)
    - [Leadership](https://scasecurity.com/leadership/)
    - [Affiliates](https://scasecurity.com/affiliates/)
    - [Career Opportunities](https://scasecurity.com/career-opportunities/)
    - [Testimonials](https://scasecurity.com/testimonials/)
- [Contact Us](https://scasecurity.com/contact-us/)

#### Menu

 Home

 Security ›

 Email Phishing & Employee Training

 Vulnerability Assessments

 Penetration Testing

 Applications

 Controls

 Centurion ESO

 Consulting

 Risk & Compliance ›

 CMMC

 HITRUST

 Federal

 State

 Industry

 Cybersecurity Risk Assessment

 NIST Cybersecurity Framework Assessment

 AI Risk Management Services

 Governance

 Industries ›

 Financial Services

 Healthcare

 Government/Public Sector

 Title/Real Estate

 Technology

 Manufacturing

 Professional Services

 Automotive

 Higher Education

 News & Resources ›

 Blog

 Events

 Case Studies

 Recorded Webinars

 SCA Breach Notification Guide

 HIPAA Security Audit Checklist

 Cybersecurity Checklist for Insurance Providers

 Company ›

 About Us

 Leadership

 Affiliates

 Career Opportunities

 Testimonials

 Contact Us

[727-571-1141 Talk to an Expert](tel:727-571-1141)

[info@scasecurity.com Email Us](mailto:info@scasecurity.com)

<https://www.facebook.com/Security-Compliance-Associates-170070577097300/?ref=br_rs>

<https://twitter.com/scasecurity>

<https://www.linkedin.com/company/security-compliance-associates/>

 October 18, 2019

# Alabama Breach Notification Law

 By: SCA Editor

![](https://blog.scasecurity.com/hubfs/Imported_Blog_Media/alabama-breach-notification-law.jpg)

## Breach Notification Guide in Alabama

Alabama S.B. 318 was put into law March 28, 2018 and became effective June 1 that year. Breach laws for Alabama apply to individuals or commercial entities pertaining to sensitive PI. A breach in Alabama is the unauthorized acquisition of such data electronically.

### Legal Requirements

When it comes to a business’s obligation to notify affected parties, should PI have been breached which can harm those affected, notice is required to each affected  
 party. Also, consumer reporting agencies should be notified if 1,000 or more entities are affected. This must be done as expediently as possible. Also, 1,000 or more affected parties require entities to notify the AG with matching expediency. If substantial harm is determined from a breach, the AG must be notified no later than 45 days. Thankfully, time to investigate is included in reporting windows.

PI, as defined by Alabama, refers to a person’s last name and first name, or the first initial of their first name, combined with other details like SSNs, driver’s license or other identification, financial information, medical history, health insurance, email addresses, or any password/PIN information. If that data is effectively encrypted, it’s not classified as a PI breach. Anything lawfully public in a federal, state, or local government sense, or info widely distributed by MSM outlets, isn’t included in this definition.

### Penalties

Alabama does not allow for telephone notification. Affected parties must be notified either by email or written notice. If the cost of notifying personnel exceeds the breached party’s resources (Alabama defines this as a cost in excess of $500k), more than 100,000 people have been affected, or there isn’t enough contact information available to reach affected parties, substitute notification options include posting conspicuously on affected parties’ websites over a thirty day period or providing breach notification to major media broadcasting agencies including urban or rural outlets where affected parties may live.

Exceptions include entities that are subject to other laws. When said entity maintains idiosyncratic requirements reflecting those laws, give proper notice considering those laws, and lets the AG know what happened ASAP should more than 1,000 individuals are affected, that entity is in compliance.

### Contact SCA for More Information about Breach Notification Law in Alabama

Security Compliance Associates has years of experience with breach notification law and [information security](https://scasecurity.com/compliance/industry/) in Alabama and throughout the United States. For more information about breach notification law in Alabama and any other part of the United States, download your [free SCA Breach Notification Guide](https://scasecurity.com/breach-notification-guide/) today. Contact SCA today at 727-571-1141 for more information and to schedule a free system analysis.

#### Subscribe

Email\*

Notification Frequency

[Data Breach](https://blog.scasecurity.com/tag/data-breach)

[September 26, 2024 6 Functions of the NIST Cybersecurity Framework](https://blog.scasecurity.com/nist-security-framework) [September 14, 2023 7 Lessons Learned from the Dish TV Ransomware Attack](https://blog.scasecurity.com/7-lessons-learned-from-the-dish-tv-ransomware-attack) [August 27, 2023 Cybersecurity Consulting: Five Considerations for AI and Privacy Issues](https://blog.scasecurity.com/cybersecurity-consulting-five-considerations-for-ai-and-privacy-issues)

### Comments

© 2026 - All rights reserved.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "SCA Editor",
    "url" : "https://blog.scasecurity.com/author/sca-editor"
  },
  "dateModified" : "2025-04-10T15:37:06.800Z",
  "datePublished" : "2019-10-18T04:00:00.000Z",
  "headline" : "Alabama Breach Notification Law - SCA Security",
  "image" : [ "https://blog.scasecurity.com/hubfs/Imported_Blog_Media/alabama-breach-notification-law.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.scasecurity.com/alabama-breach-notification-law",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.scasecurity.com/hubfs/sca-logo-r.png"
    },
    "name" : "Security Compliance Associates"
  }
}
```