Many business owners who hear about Florida’s Digital Bill of Rights (FDBR) assume one thing and move on. They assume it applies only to large companies and not to them, which is a correct assumption for much of what the law requires. But there are many conditions that have nothing to do with large companies as a whole, and those tend to surprise earlier or smaller companies.
The FDBR is the largest out of the three parts of Florida Senate Bill 262. The other two parts consist of restricting government employees and agencies from encouraging social media platforms to remove content or accounts, and protections for children on online platforms. The FDBR is a general consumer data privacy law with data protections that began on July 1st, 2024. This law excludes some industries, such as health care companies covered by HIPPA, financial companies, nonprofits, and colleges.
Within the FDBR, companies are split into “controllers” and “processors.” The controllers decide how personal data is used, and processors handle data on the controller’s behalf. Controllers have to let data subjects see, correct, delete, or download their own data and opt out of activities such as targeted ads. Processors have to follow the controller's instructions and sign a data-handling contract. Regardless of the data controller's size, Florida residents are provided protection of three distinct categories of information: sensitive data, children's privacy, and ownership structure.
Sensitive Data
When it comes to selling sensitive data, any data controller must receive a person’s clear “yes” before the sale. This includes race or ethnicity, health conditions, immigration status, religion, sexual orientation, genetic or biometric data, location, and anything collected from a child. This is important because selling data doesn’t take place only when a cash transaction is involved. FDBR covers essentially any exchange of personal data for money. This can include data sharing arrangements that startups will take part in without considering them to be a sale. Startups don’t need to be large to have to participate in the consent requirement.
Children’s Privacy
If a game, platform, or app is geared toward children, FDBR imparts mandatory rules, regardless of how big or small the company behind it is. These rules limit how much a platform can profile a child user, control when and how it can collect location data, ban manipulative design patterns aimed at getting kids to hand over more information than they should, and cap how long data collected to estimate a user's age may be kept. This can impact companies that don’t view themselves as “kids companies” but have a large number of users under 18. This includes apps that have a younger audience, even if that wasn’t their original intention of the platform.
Ownership Information
The FDBR says a company counts as a "controller" if it's controlled by, or controls, another company that already meets the controller definition on its own. This rule is in place to stop large companies from routing sensitive data through smaller groups to avoid the law, but it also means the trigger isn’t about a company’s size at all. If a large platform invests in a startup, buys a stake in it, or spins it out as a subsidiary, that startup can unknowingly inherit controller status, even if there are only a few employees and little revenue. Founders often miss this because it comes up during fundraising or acquisition talks, when the focus is on deal terms, not on whether a new investor already counts as a controller under Florida law.
Conclusion
Rather than questioning if they’re big enough for the Florida Digital Bill of Rights to apply, founders and business owners should consider a few simple things. Do they sell or share any sensitive data, even through a vendor or ad partner? Are their products mostly used by children? And are they owned by, or do they own, a larger company that might already count as a controller? If the answer to any of these is yes, the Florida Digital Bill of Rights already applies, regardless of revenue.