Home
Florida FDBR: Cookies Policy

Florida FDBR: Cookies Policy

5 months ago
João Bruno Soares
8 minutes

Every tracker you install on your site starts collecting data before the user makes any conscious decision about what they accept or reject.

This page covers one piece of the picture. For the full scope of the FDBR — who must comply, the thresholds, the consumer rights and the penalties — start with our complete guide to the FDBR and cookies.

An advertising pixel registers the visit. An analytics cookie begins measuring behavior. A support chat already knows the visitor's origin before the first message.

The Florida Digital Bill of Rights (FDBR, §§ 501.701 to 501.721), in effect since July 1, 2024, has specific requirements for how these trackers operate and what must be documented about them.

This article focuses exclusively on what the FDBR requires from a Cookies Policy: what the document must contain, how tracker consent must work, and what the law's specific rights imply for your cookie strategy.

Cookies Policy vs. cookie banner: the necessary distinction

The cookie banner is the visual consent element. It is what the visitor sees when they first access the site. It must be clear, offer real options, block non-essential trackers before they fire, and not use dark patterns.

The Cookies Policy is the detailed document. It is where the user finds complete information about every technology operating on the site: what it collects, what it is for, who receives the data, and how long it is stored.

Both need to exist. Both need to be aligned. And the Cookies Policy must be accessible through a clear link within the consent notice itself.

What the FDBR specifically requires for cookies

Specific purpose for each category

§ 501.71(2)(a) prohibits processing for purposes incompatible with those disclosed. And § 501.711(1)(b) requires the purpose of processing to be included in the privacy notice.

For cookies, each category needs a specific purpose description, not a generic one.

What does not work: "cookies to improve your experience." That is not a purpose. It is a vague description that provides no compliance and no protection.

What works:

"Analytics cookies: collect browsing behavior data including pages visited, session duration, and traffic source. Used to identify opportunities to improve site content and prioritize usability corrections."

"Advertising cookies: collect behavioral data across affiliated and non-affiliated websites over time to build interest profiles and display personalized ads. Include pixels from platforms such as Meta Ads, Google Ads, and programmatic DSPs."

The categories of cookies present on the site

The Policy must list the categories of trackers operating on the site with a description of what each one does. The main categories:

Necessary cookies: essential for basic functionality. Authentication, session security. These do not require consent but must be documented.

Analytics cookies: measure browsing behavior. These generally require consent because they collect data that may identify users through cross-referencing.

Advertising cookies: feed ad pixels, build behavioral profiles, enable retargeting. These require explicit consent and the specific disclosure mandated by the FDBR.

Functional cookies: remember user preferences. May or may not require consent depending on the nature of the data.

Third-party cookies: fired by external services integrated into the site. Correct tag categorization is what makes it possible to document each one accurately.

Targeted advertising: the FDBR's broader definition

The FDBR defines targeted advertising (§ 501.702(33)) as ads based on consumer activity data over time across affiliated or non-affiliated websites and online applications.

This is an important point of difference. The VCDPA, for example, covers only non-affiliated websites. The FDBR includes affiliated ones, meaning that trackers operating within the ecosystem of companies in the same corporate group may constitute targeted advertising under the FDBR.

§ 501.711(4) requires clear and conspicuous disclosure of any data sale or targeted advertising processing, along with the opt-out mechanism. This must be in the Cookies Policy.

Sale of data: includes non-monetary consideration

§ 501.702(29) defines sale of personal data as sharing, disclosing, or transferring for monetary or other valuable consideration.

This is broader than the VCDPA, which mentions only monetary consideration. A company that exchanges user data with partners in return for services, technology, or other benefits may be conducting a "sale" under the FDBR. The Cookies Policy must assess whether site integrations fall under this definition.

Categories of data shared with third parties via cookies

§ 501.711(1)(d) and (e) require the privacy notice to disclose which categories of data are shared with third parties and which categories of third parties receive them.

For cookies, this means clearly declaring:

If a Meta Pixel transfers behavioral data to Meta, it must be documented.

If Google Analytics sends session data to Google, it must be stated.

If CRM tools receive browsing data from the site, they must be identified.

Every data flow leaving the controller's environment via cookies must be categorized.

Retention period: the 2-year limit

§ 501.719(3) requires adoption of a retention schedule that prohibits use or retention of personal data after the initial purpose is fulfilled, after the contract ends, or 2 years after the consumer's last interaction.

For cookies, the Policy must document:

How long each cookie category remains active on the user's device.

How long data collected via cookies is retained in the business's systems.

How and when data is deleted, respecting the 2-year limit.

The opt-out for sensitive data via cookies

The FDBR has a right that does not exist in other US state privacy laws: consumers may opt out of the collection of sensitive data (§ 501.705(2)(f)), including precise geolocation data.

If the site collects precise geolocation data (within 1,750 feet) via cookies or location scripts, this is sensitive data under the FDBR (§ 501.702(31)(d)). The consumer has the right to refuse this collection, and the opt-out mechanism must be accessible in the Cookies Policy.

The opt-out for voice and facial recognition

The FDBR's seventh right (§ 501.705(2)(g)) guarantees consumers the opt-out of data collection via voice or facial recognition features.

If the site uses any voice recognition technology (voice chat, audio commands) or facial recognition (identity verification, camera filters), the Cookies Policy must mention these technologies, explain their purpose, and describe how the consumer can exercise the opt-out.

What constitutes valid consent for cookies under the FDBR

§ 501.702(7) defines consent as a clear affirmative act signifying a consumer's freely given, specific, informed, and unambiguous agreement.

The correct standard: non-essential cookies off by default. The user chooses what to enable, not what to disable.

What is not valid consent:

Accepting general terms that contain cookie descriptions alongside other conditions.

Hovering over or closing a banner.

Any agreement obtained through dark patterns.

Dark patterns prohibited by the FDBR

Dark patterns are defined in § 501.702(11) as interfaces designed with the substantial effect of subverting or impairing user autonomy, decision-making, or choice, including any practice the FTC refers to as a dark pattern.

In the context of cookies, common patterns the FDBR invalidates:

An "accept all" button prominently displayed with the reject option hard to find.

Non-essential cookies enabled by default.

Confusing language in the choice options.

Cookie walls blocking content until all cookies are accepted.

Banners that reappear repeatedly until the user accepts.

Special protection for children's data via cookies

The FDBR defines "known child" as any individual under 18 years of age of whose age the controller has actual knowledge or willfully disregards (§ 501.702(17)).

This is a much higher threshold than other US laws. For known children:

Between 13 and 18: their affirmative authorization is required to process sensitive data (§ 501.71(2)(d)).

Under 13: COPPA applies.

If the site may have users under 18 whose age the controller knows, the Cookies Policy must describe how their data is treated differently, including the prohibition on using dark patterns to obtain data beyond what is necessary.

Penalties for violations involving known children are automatically tripled under the FDBR (§ 501.72(1)(a)).

Two or more opt-out channels: FDBR-exclusive requirement

§ 501.709 requires the controller to establish two or more methods for consumers to submit requests. This includes opt-out requests.

The Cookies Policy must describe at least two channels through which the consumer can exercise opt-outs for targeted advertising, data sale, sensitive data, and voice/facial recognition.

A consent management platform integrated into the site can be one of these channels. A DSAR form on the website can be another.

When to update the Cookies Policy

§ 501.711(1) requires updates at least annually. Beyond the mandatory annual review, situations requiring immediate update include:

Adding a new advertising pixel.

A new analytics, heatmap, or session recording tool.

A new chat, support, or engagement plugin.

A new CRM or email marketing platform integration.

Any new technology that collects voice, video, or location data.

New partners receiving behavioral data from users.

Continuous data mapping is what maintains synchronization between the tool inventory and the Cookies Policy.

Enforcement: high and triplicable penalties

Violations of cookie-related requirements under the FDBR are treated as unfair trade practices, with penalties up to US$ 50,000 per violation (§ 501.72).

Penalties are triplicable (reaching US$ 150,000 per violation) when:

The violation involves a known Florida child.

The business continues to sell or share data after the consumer opts out.

There is a failure to delete data after an authenticated request.

The 45-day cure period is discretionary and does not apply to violations involving children.

How AdOpt helps with the Cookies Policy under the FDBR

AdOpt's automatic scan identifies all technologies active on the site, feeding the list of categories that must appear in the Cookies Policy.

The cookie notice configured through AdOpt blocks non-essential trackers before acceptance, presents categories with clear descriptions, offers real choice options without dark patterns, and logs every interaction for audit purposes.

The system supports the configuration of FDBR-specific opt-outs, including sensitive data and voice/facial recognition.

Over 60,000 websites already run with AdOpt.

Privacy is not a banner. It is a position.

Want to build a Cookies Policy for your site that complies with the FDBR? Talk to our team.

Checklist: what your Cookies Policy needs for the FDBR

Visible link in the site footer and within the cookie banner itself.

Listing of cookie categories with a description of what each one does on the site.

Specific purpose for each category, without vague descriptions (§ 501.711(1)(b)).

Disclosure of targeted advertising, including affiliated sites (§ 501.702(33)), with an accessible opt-out (§ 501.711(4)).

Data sale declaration, including non-monetary consideration if applicable (§ 501.702(29)).

Notice of sensitive data sale when applicable (§ 501.711(2)).

Notice of biometric data sale when applicable (§ 501.711(3)).

Categories of data shared with third parties via cookies (§ 501.711(1)(d)).

Categories of third parties that receive data via cookies (§ 501.711(1)(e)).

Opt-out of sensitive data and geolocation clearly described (§ 501.705(2)(f)).

Opt-out of voice and facial recognition described (§ 501.705(2)(g)).

Retention period for each category, including the 2-year limit (§ 501.719(3)).

Non-essential cookies disabled by default, without dark patterns (§ 501.702(11)).

Special protection for known children under 18 years of age (§ 501.702(17)).

Two or more submission channels described for opt-out requests (§ 501.709).

Accessible language, without legal jargon.

No cookie walls.

Annual update of the document at minimum.

FAQ: FDBR and Cookies Policy

1. Does the FDBR require a separate document called a "Cookies Policy"?
Not by name. The disclosure requirements for trackers are distributed between the privacy notice (§ 501.711) and the controller's specific duties (§ 501.71). A dedicated Cookies Policy is the most organized way to meet all of these requirements in a user-accessible format.

2. Is the FDBR's definition of targeted advertising different from other laws?
Yes. The FDBR (§ 501.702(33)) includes ads based on activity data from affiliated or non-affiliated websites, while the VCDPA, for example, covers only non-affiliated websites. This broadens the scope of advertising practices requiring disclosure and opt-out. A retargeting campaign within the same corporate group's ecosystem may constitute targeted advertising under the FDBR.

3. What changes for cookies when the user is a known child under 18?
For known children between 13 and 18, their affirmative authorization is required to process sensitive data (§ 501.71(2)(d)). For children under 13, COPPA applies. A controller that willfully disregards a user's age is treated as having actual knowledge of it (§ 501.702(17)). Penalties for violations involving known children are automatically tripled.

4. Does the FDBR require an opt-out for geolocation via cookies?
Yes. Precise geolocation data is sensitive data under the FDBR (§ 501.702(31)(d)). The consumer has the right to opt out of the collection of sensitive data (§ 501.705(2)(f)). If the site uses location scripts that identify the user within a radius of 1,750 feet, the opt-out for this tracking must be available and described in the Cookies Policy.

5. What are the specific penalties related to cookies under the FDBR?
All violations can result in up to US$ 50,000 per violation (§ 501.72(1)). Penalties are triplicable for violations involving known children, continuation of sharing or selling data after consumer opt-out, and failure to delete data after an authenticated request. A cookie that continues tracking after opt-out can result in a tripled penalty for each affected consumer.

Ready to build a Cookies Policy for your site that complies with the FDBR? Talk to our team.

Tags

Latest updates
CMP
Cookies
FDBR
Cookie Banner

Related posts

5 Common Cookie Consent Mistakes Hurting Your Compliance

Discover the 5 common **cookie consent mistakes** that risk your **compliance** and learn how to avoid heavy **fines**. Simplify your **data privacy** strategy using a reliable **[Cookie notice/banner](https://goadopt.io/en/blog/why-the-cookie-banner/)**.

AdOpt post

Connecticut CTDPA: Cookies Policy

What the Connecticut CTDPA requires from your Cookies Policy: opt-out link, opt-out preference signal from January 2025, 15-day consent revocation, teen protections, and targeted advertising definition.

AdOpt post

7 Steps to GDPR-Compliant Cookie Banners in 2025

Learn the essential steps for creating GDPR-compliant cookie banners in 2025, ensuring user consent and privacy protection.

AdOpt post

5 Signs Your Website Needs an Cookie Consent Strategy

How does your website handle LGPD? What strategies does it use to comply with the General Data Protection Law? Have you thought about using a cookie notice but don't know if your site has cookies or if it's enough? If you can't answer these questions, be cautious! Your page may be exposed to fines and other sanctions.

AdOpt post

How long can we ignore LGPD?

LGPD is in effect. Despite that, there are still many companies ignoring it, but is that possible? How long can we ignore LGPD?

AdOpt post

California CCPA: DSAR Privacy Portal

How to handle DSARs under the California CCPA/CPRA: 7 consumer rights, 45-day deadline, toll-free number required, 12-month lookback, private right of action for breaches, and CPPA enforcement.

AdOpt post

LGPD: An Opportunity for Digital Marketing Agencies!

Have you ever thought that your marketing agency could find a great business opportunity in LGPD? Well, unlike what many think, it brings changes that can accelerate the demand for the services of these companies.

AdOpt post

Why Give Consent on Every Website I Visit?

Have you ever noticed that every time you sign up for a service to access information or register on a website for purchases, you need to give consent? If you're wondering why you have to give consent on every website you visit, you'll find the answer here.

AdOpt post

New Hampshire NHDPA: Privacy Policy

Learn what your Privacy Policy must contain under the NHDPA. We break down the 8 mandatory elements and how to comply with New Hampshire's data privacy law.

AdOpt post

The Impact of Cookie Banners on Your E-commerce - LGPD

Having a cookie banner on your brand's website has become indispensable for many. However, for e-commerce websites, it has practically become an obligation to have one. This is because this type of website has a technological composition in which cookies are a structural part. Login flow, items in the shopping cart, recommendation showcases, remarketing... Most of them rely on cookies.

AdOpt post

California CPRA and Cookies: All you need to know

California CPRA explained: CCPA vs CPRA timeline and key differences, sensitive personal information, sharing of data, CPPA enforcement, GPC requirement, and tripled penalties for minors.

AdOpt post

MTCDPA Montana and Cookies: All you need to know

Find out if the MTCDPA applies to your site, key compliance deadlines, and new rules for cookies and consent in Montana

AdOpt post

IOWA ICDPA: DSAR and Privacy Portal

Iowa ICDPA DSAR guide: 90-day response deadline, 45-day extension, 60-day appeal process, limited deletion scope, opt-out from data sales, targeted advertising disclosure requirement, and 90-day cure period.

AdOpt post

Utah UCPA: DSAR and Privacy Portal

Utah UCPA DSAR guide: four consumer rights, limited deletion scope, no right to correct, no formal appeal process, no opt-out of profiling, 45-day deadline, and the guaranteed 30-day cure period.

AdOpt post

Montana MTCDPA: Privacy Policy

Learn what your MTCDPA Privacy Policy must include after Montana's SB 297 amendments from the conspicuous "privacy" hyperlink and last-updated date requirements to sale disclosures, minor protections, and how to keep your notice operationally aligned with your stack.

AdOpt post

How does a cookie banner operate?

Here is a step-by-step explanation of how consent registration works in AdOpt.

AdOpt post

New Hampshire NHDPA: DSAR Privacy Portal

What is a DSAR under NHDPA? Complete guide to consumer rights, response deadlines, and building a compliant Privacy Portal for your site.

AdOpt post

Tenesse TIPA: Cookies Policy

Learn how to build a defensible TIPA Cookies Policy for Tennessee compliance covering consent architecture, opt-out requirements, the NIST affirmative defense, and how your cookie banner, privacy notice, and vendor management must work together under the Tennessee Information Protection Act.

AdOpt post

Connecticut CTDPA and Cookies: All You Need to Know

The Connecticut Data Privacy Act (CTDPA) is a state regulation designed to protect the privacy of Connecticut residents. It also regards cookies, so in this article we will help you understand all about this new privacy regulation.

AdOpt post

Florida FDBR and Cookies: All You Need to Know

Everything you need to know about the Florida Digital Bill of Rights (FDBR): who must comply, the $1 billion threshold, 7 consumer rights, FIPA vs FDBR explained, penalties, and cookies.

AdOpt post

Colorado CPA: Cookies Policy

What the Colorado CPA requires from your Cookies Policy: mandatory Universal Opt-Out Mechanism from July 2024, targeted advertising definition, dark pattern rules, and the 24-month consent refresh.

AdOpt post

Oregon OCPA and Cookies: All You Need to Know

Everything about the Oregon OCPA: who must comply, the payment transaction exclusion, 25% revenue threshold, derived data in scope, GPC requirement from January 2026, and elimination of the cure period.

AdOpt post

LGPD and Cookies all do you need to know?

In this article, you will have a great introduction to the topic, as well as various other variations that revolve around the subject: Cookies and LGPD.

AdOpt post

California CPRA: Privacy Policy

What the California CPRA requires from your Privacy Policy: SPI category, two mandatory links, data retention periods, sharing disclosure, right to correct, GPC, and minor protections.

AdOpt post

Google Consent Mode: Beginner to Advanced Guide.

Google Consent Mode (GCM) is nothing more than a way for you to integrate the consent you collect from your visitors into Google technologies. In this way, upon receiving this consent information, collection can only occur with authorization, thus complying with the legislation and having direct evidence of compliance as defense for both you and Google.

AdOpt post

Colorado CPA and Cookies: All You Need to Know

The Colorado Consumer Privacy Act went into effect July 1, 2023 (CPA). CPA is a vital piece of legislation designed to protect the privacy of residents in Colorado. Understanding its requirements is essential for any business operating in the state. This act is all about giving control back to the consumers regarding their personal data. But what does this mean for you and your business, especially when it comes to managing cookies on your website?

AdOpt post

Florida FDBR: Privacy Policy

What the Florida FDBR requires from your Privacy Policy: annual updates, 6 mandatory content categories, specific notices for sensitive and biometric data sales, and the 7 consumer rights.

AdOpt post

California CCPA: Privacy Policy

What the California CCPA/CPRA requires from your Privacy Policy: 12-month lookback, annual updates, Do Not Sell link, sensitive PI disclosures, toll-free number, and the 7 consumer rights.

AdOpt post

Connecticut CTDPA: Privacy Policy

What the Connecticut CTDPA requires from your Privacy Policy: active email contact, opt-out link, 15-day consent revocation, opt-out preference signal from January 2025, and teen protections.

AdOpt post

Colorado CPA: Privacy Policy

What the Colorado CPA requires from your Privacy Policy: 5 mandatory elements, purpose specification duty, secondary use prohibition, 24-month consent refresh, and Universal Opt-Out Mechanism disclosure.

AdOpt post

Utah UCPA and Cookies: All you need to know

Utah UCPA explained: the most business-friendly US state privacy law, dual threshold requirement, opt-out for sensitive data, no right to correct, guaranteed 30-day cure period, and key differences from other state laws.

AdOpt post

Oregon OCPA: Cookies Policy

What the Oregon OCPA requires from your Cookies Policy: opt-out link, GPC from January 2026, opt-out without authentication, derived data in scope, teen protections, and the elimination of the cure period.

AdOpt post

California CPRA: DSAR and Privacy Portal

California CPRA DSAR guide: new rights to correct and limit SPI, opt-out without multiple steps, GPC as valid opt-out, 12-month minor rule, private right of action, and CPPA enforcement.

AdOpt post

Texas TDPSA and Cookies: All You Need to Know

Your website have users accessing from Texas? So be ready… the Texas Data Privacy and Security Act is here to shake things up. Don't worry; we've got your back. This guide will walk you through everything you need to know to ensure your website complies with the new regulations.

AdOpt post

Virginia VCDPA: DSAR Privacy Portal

How to handle DSARs under the Virginia VCDPA: consumer rights, 45-day response deadlines, the appeal process, free requests twice per year, and how to build a compliant Privacy Portal.

AdOpt post

GDPR Legal Basis: An Introduction

In this article, we'll explore the GDPR foundations and provide practical insights from the basics to more advanced concepts of its legal basis.

AdOpt post

Florida FDBR: DSAR Privacy Portal

How to handle DSARs under the Florida FDBR: 7 consumer rights, two required submission channels, 45-day deadline with only 15-day extension, tripled penalties for children, and compliance guide.

AdOpt post

IOWA ICDPA: Cookies Policy

What the Iowa ICDPA requires from your Cookies Policy: opt-out for data sales and targeted advertising, opt-out model for sensitive data, no GPC requirement, no specific link text required, and the 90-day cure period.

AdOpt post

Best practices in tag categorization

It's time to talk about one of the most impactful tasks, both for the company and for the visitors of your websites: tag categorization. But why is it so impactful? What is the relevance of this configuration and how can it affect us? It is precisely because of these common questions we receive from our clients that we have written this article on best practices in tag categorization.

AdOpt post

Montana MTCDPA: DSAR Policy

Rights, Policy and how to understand about the DSAR Montana MTCDPA

AdOpt post

What is the difference between cookies, local storage, and session storage?

Despite cookies being more well-known, what is the main difference between cookies and session storage and local storage? Why choose one over the other? This article will help you with these doubts!

AdOpt post

California CPRA: Cookies Policy

What the California CPRA requires from your Cookies Policy: the sharing concept, GPC as valid opt-out, Do Not Sell or Share link, SPI geolocation, minor protections, and retention periods.

AdOpt post

How to choose a Cookie Banner for your website

What are the criteria for this choice, and what are the strengths and weaknesses of each option? Well, we're here to help you because this decision needs to be well thought out!

AdOpt post

New Hampshire NHDPA: Cookies Policy

Cookies Policy under NHDPA explained. Discover what's mandatory, dark patterns to avoid, and how to implement legal cookie consent.

AdOpt post

Virginia VCDPA and Cookies: All you need to know

Everything you need to know about the Virginia Consumer Data Protection Act (VCDPA): who must comply, consumer rights, cookie requirements, penalties, and how to get your site in compliance.

AdOpt logoAdOpt logo

Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819

15 Rue du Général Campredon, 34000 Montpellier, France

207 Rue de Bercy, 75012 Paris, France

EIN: 86-3965064

Phone: +1 (407) 768-3792

AdOpt

Resources

Product

Certifications

Google CMP PartnerIAB Europe TCF Registered Vendor

© GO ADOPT, LLC since 2020 - Made by people who love🍪