Florida Information Protection Act · Compliance readiness
If you hold a Florida resident's data, the Act gives you thirty days to notify after a breach. Most businesses learn about the clock once it is running.
The reasonable measures the Act requires, documented, and the thirty-day breach process ready before it is needed.
How we workSame six steps, every project
- 1Issue
- 2Input
- 3Plan
- 4Solution
- 5Execution
- 6Happy client
Step 3 of 6: Plan
See the six steps for thisIn force since 2014. If you keep personal information about Florida residents – customers, patients, or your own staff – it applies to you, wherever your business sits. It asks for reasonable measures to protect that information, and it puts a clock on you when the information leaks: thirty days.
What it actually asks for
Reasonable measures to protect and secure the personal information you hold in electronic form – a name together with a Social Security, driver’s license or passport number, a financial account number with its code, medical or health-insurance details, or an email address with its password. When that information is breached, notice to the people affected within thirty days, notice to the Florida Attorney General when five hundred or more Florida residents are involved, and proper disposal of records you no longer keep. A vendor holding your data has ten days to tell you about a breach on their side.
Two things soften it. Encrypted data that leaks without its key is not a breach the Act makes you announce. And if an investigation finds the leak is not likely to cause harm, you can skip the individual notices – provided the written determination is kept for five years and handed to the Attorney General within thirty days of being asked. Missing the clock costs $1,000 a day for the first thirty days and $50,000 for each thirty-day period after, up to $500,000 per breach.
What it does not give you is a checklist or a certificate, which is what makes it easy to ignore and awkward to be measured against after the fact. This is not legal advice; it is what the requirement looks like in practice.
What readiness looks like here
An inventory of what personal information you hold about Florida residents and where it lives. Encryption on every laptop and phone that leaves the building – the single cheapest item on the list, and the one the Act rewards outright. Access control and multi-factor authentication. A written breach procedure with the thirty-day clock and the who-notifies-whom decided in advance, and the vendor’s ten days written into the agreements. A disposal process. And the records kept, so that a decision not to notify can be defended five years later. If you also hold New Yorkers’ data, the SHIELD Act applies alongside; one program covers both.
What is included
- Data inventory: what you hold about Florida residents, and where
- Encryption on every device that leaves the building
- Access control and multi-factor authentication
- Breach procedure with the thirty-day clock, rehearsed
- Vendor agreements with the ten-day notice written in
- Disposal, and the records the Act lets you rely on
Why clients stay
- 2004
- In business since
- 950+
- People we support
- 60 days
- Money-back guarantee
“After meeting Mariusz and discussing what our needs were with the budget we were looking to work with, a network system was designed and installed. When needed the Interactive AV-IT team has gone above and beyond the call of duty to resolve any issues.”
Ready to talk?
Book a fifteen-minute call, or tell us what you are dealing with and we will tell you what we would check first. No obligation.
Why businesses choose us
- One team for IT and AV – the network, the security, the phones and the boardroom.
- 24/7/365 monitoring, with a helpdesk that knows your office.
- A 60-day money-back guarantee for new managed clients.
- Based in Hauppauge, on site across Long Island and New York City since 2004 – and now in Boca Raton, FL.