Data Protection Impact Assessment (DPIA) (AL) - Alabama
DATA PROTECTION IMPACT ASSESSMENT (DPIA)
(State overlay: AL)
1. Project Overview
- Project name/ID: [name]; owner: [business owner]; sponsor: [executive].
- Purpose and objectives: [describe].
- Timeline and launch date: [dates].
2. Scope of Processing
- Data subjects: [customers/employees/vendors/end users].
- Personal data categories: [contact, IDs, financial, location, biometric, health, minors].
- Alabama sensitive personally identifying information: [map the data to Ala. Code § 8-38-2(6), including applicable government identifiers, financial-account credentials, medical or health-insurance information, and online-account credentials].
- Genetic data and biological samples: [determine whether the organization is a genetic testing company covered by Alabama Act 2024-384].
- Other legal or contractual consent requirements: [insert after counsel review].
- Volume and retention: [records/year], [retention schedule and deletion triggers].
- Processing activities: [collection, storage, analysis, sharing/sale/sharing status].
3. Legal Basis, Notices, and Rights
- Purpose of this worksheet: This is an internal risk-assessment tool. Do not state that Alabama law requires a DPIA for every organization or that Chapter 38 is the only potentially applicable privacy law.
- Chapter 38 scope: A covered entity is an entity that acquires or uses sensitive personally identifying information; a third-party agent is a contracted service provider that maintains, stores, processes, or otherwise may access that information for the covered entity. Ala. Code § 8-38-2.
- Security assessment: Covered entities and third-party agents must implement and maintain reasonable security measures. The assessment under § 8-38-3 considers the program as a whole, emphasizes multiple or systemic failures, and accounts for entity size, data volume and use, resources, risk identification, safeguards, service-provider contracts, change management, and management reporting.
- Genetic-testing-company screen: Alabama Act 2024-384 requires covered genetic testing companies to provide specified privacy notices, obtain purpose-specific express or informed consent, provide access/account-deletion/sample-and-data-destruction/consent-revocation processes, and bind contractors to use and confidentiality limits. Record whether the act applies and each requirement's implementation status.
- Other overlays: [Identify every other applicable federal, state, sectoral, contractual, and foreign requirement with counsel.]
4. Data Flow and Transfers
- Source systems: [list]; storage/hosting locations: [cloud region/data centers].
- Cross-border transfers: [locations]; reviewed transfer mechanism: [insert if applicable].
- Recipients/vendors: [processors/subprocessors/controllers]; due diligence status and DPAs in place.
- Access controls: RBAC groups, least privilege, joiner/mover/leaver process.
5. Security and Controls
- Technical controls: encryption in transit/at rest [specify], key management, network segmentation, endpoint protections, logging/monitoring, DLP, backups, vulnerability management.
- Organizational controls: policies, training cadence, vendor due diligence, incident response playbook, change management.
- Authentication/authorization: [MFA/SAML/SSO]; session timeouts; privileged access reviews cadence.
6. Risks and Impact Assessment
- Risks/threats: [unauthorized access, data minimization failure, purpose creep, profiling risk, transfer risk, children/minors risk].
- Likelihood: [low/medium/high]; Impact: [low/medium/high]; Risk rating matrix: [insert].
- State-specific employment, insurance, health, education, genetic-data, biometric, and anti-discrimination considerations: [identify applicable rules after counsel review].
7. Mitigations and Residual Risk
- Planned mitigations: [controls, timelines, owners].
- Testing/validation: [pen test, DPIA/ROPA updates, privacy-by-design checklist].
- Residual risk after mitigations: [rating]; decision: [accept/mitigate further/block].
8. Incident Response and Breach Notification
- Investigation: If a breach has or may have occurred, conduct the prompt, good-faith investigation required by Ala. Code § 8-38-4, including scope, affected information and individuals, unauthorized acquisition, likelihood of substantial harm, and restoration measures.
- Individual notice trigger and timing: When § 8-38-5's unauthorized-acquisition and substantial-harm test is met, notify each affected individual as expeditiously as possible and without unreasonable delay, no later than 45 days after receiving a third-party agent's breach notice or determining that the breach occurred and is reasonably likely to cause substantial harm.
- Law-enforcement delay: Delay individual notice only upon the written request described in § 8-38-5(c), for the period stated or extended by the requesting agency.
- Third-party agents: Notify the covered entity as expeditiously as possible and without unreasonable delay, no later than 10 days after determining a breach occurred or having reason to believe it occurred. Ala. Code § 8-38-8.
- Attorney General: If the number of individuals required to receive notice exceeds 1,000, provide the Attorney General the written notice and contents required by § 8-38-6 on that section's timing.
- Consumer reporting agencies: If circumstances require notice to more than 1,000 individuals at a single time, notify all nationwide consumer reporting agencies without unreasonable delay of the timing, distribution, and content of the notices. Ala. Code § 8-38-7.
- No-notice determination: If the covered entity determines that individual notice is not required, document that determination in writing and retain the related records for at least five years. Ala. Code § 8-38-5(f).
- Enforcement: Section 8-38-9 makes notification violations an unlawful trade practice and gives the Attorney General exclusive authority to seek the chapter's civil penalties. The chapter does not create a private cause of action under Ala. Code § 8-19-10, but it expressly preserves rights available at common law, by statute, or otherwise.
- Disposal and exemptions: Apply § 8-38-10's disposal rule and document whether the conditional federal or state alternate-compliance exemptions in §§ 8-38-11 and 8-38-12 apply.
- Multi-jurisdiction response: [Map every other applicable notification, regulator, contractual, and sector-specific requirement.]
9. State Overlay Checklist (AL)
- ☐ Chapter 38 covered-entity and third-party-agent roles mapped.
- ☐ Sensitive personally identifying information mapped to Ala. Code § 8-38-2(6).
- ☐ Section 8-38-3 security-program factors assessed and remediation owners assigned.
- ☐ Genetic testing company applicability under Alabama Act 2024-384 decided and documented.
- ☐ Breach investigation, substantial-harm decision, and restoration steps documented.
- ☐ Individual, Attorney General, consumer-reporting-agency, and third-party-agent thresholds and clocks separately calendared.
- ☐ Any no-notice determination retained for at least five years.
- ☐ Disposal duties and federal/state alternate-compliance exemptions reviewed.
- ☐ Other applicable legal and contractual overlays identified by counsel.
10. Approvals and Accountability
- Privacy lead/DPO review: [name/date].
- Security review: [name/date].
- Legal review (state law overlay): [name/date].
- Business owner certification: [name/date].
- Executive approver: [name/title/date].
11. Attachments
- Data flow diagrams/architecture.
- Records of processing activities entry.
- Vendor list and applicable data-protection agreements.
- Legitimate interests assessment or risk assessment (if applicable).
- Testing summaries and pen test reports (if applicable).
- State-specific notices/links and breach templates.
Sources and References
- Alabama Legislature — Ala. Code § 8-38-2
- Alabama Legislature — Ala. Code § 8-38-3
- Alabama Legislature — Ala. Code § 8-38-4
- Alabama Legislature — Ala. Code § 8-38-5
- Alabama Legislature — Ala. Code § 8-38-6
- Alabama Legislature — Ala. Code § 8-38-7
- Alabama Legislature — Ala. Code § 8-38-8
- Alabama Legislature — Ala. Code § 8-38-9
- Alabama Legislature — Ala. Code § 8-38-10
- Alabama Legislature — Ala. Code § 8-38-11
- Alabama Legislature — Ala. Code § 8-38-12
- Alabama Secretary of State — Act 2024-384 record
- Alabama Secretary of State — Act 2024-384 enrolled text
About this template
- Last updated
- August 15, 2026
- Citations checked
- August 15, 2026
- Jurisdiction
- Alabama
- Category
- Compliance & Regulatory
Legal authority
- Ala. Code §§ 8-38-2 through 8-38-12 (Alabama Data Breach Notification Act of 2018)
- Alabama Act 2024-384 (Alabama Genetic Data Privacy Act, effective October 1, 2024)
Compliance documents are what regulated businesses use to prove they follow the rules that apply to their industry, whether that is privacy, anti-money-laundering, consumer protection, or sector-specific requirements. Regulators look for consistent policies, up-to-date records, and clear evidence of employee training. The cost of getting compliance paperwork right is almost always smaller than the cost of an enforcement action, fine, or public disclosure.
Not legal advice
This template is provided for informational purposes. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.
Checked against the law it cites
A reviewer verified this template's legal citations against the official source on August 15, 2026.
Draft your Data Protection Impact Assessment (DPIA) (AL) in the editor
Answer a few questions, let the AI editor draft each section from your answers, review it, and download Word and PDF. $99 one time, or $249 per month for every document and every Ezel app.