Rhode Island Data Transparency and Privacy Protection Act
RIDTPPA
Comprehensive privacy · Children · Health · Genetic · Biometric · Location
Rhode Island's comprehensive consumer privacy law, effective January 1, 2026. It requires commercial websites and internet service providers that sell customers' personal information to disclose what they collect and to whom they sell it, and gives residents of larger covered businesses rights to access, correct, delete and port their data and to opt out of targeted advertising, sales and significant automated profiling. Covered controllers need opt-in consent for sensitive data (including health, biometric, genetic, precise geolocation and known-child data) and must run data protection assessments for high-risk processing.
- Where
- Rhode Island
- Citation
- R.I. Gen. Laws §§ 6-48.1-1 to 6-48.1-10
- Status
- In force
- In force since
- 2026-01-01
- Enforced by
- Rhode Island Attorney General (sole enforcement authority)
- People can sue
- No
- Penalties
- A violation is a deceptive trade practice under R.I. Gen. Laws ch. 6-13.1, so the Attorney General may seek civil penalties of up to $10,000 per violation (§ 6-13.1-8) and injunctive relief. Intentional disclosure of personal data to a shell company formed to evade the chapter, or otherwise in violation of it, carries an added fine of $100 to $500 per disclosure. There is no cure period in the text and no private right of action (§ 6-48.1-8(c)).
- Applies to
- Notice duty (§ 6-48.1-3): any commercial website or internet service provider doing business in Rhode Island or with Rhode Island customers that collects, stores and sells customers' personally identifiable information, with no size threshold
- Rights, consent, security and assessment duties (§§ 6-48.1-4 to -7): for-profit entities doing business in Rhode Island or targeting its residents that in the preceding calendar year controlled or processed personal data of at least 35,000 customers (excluding data processed solely to complete a payment transaction), or of at least 10,000 customers while deriving more than 20% of gross revenue from selling personal data
- Processors acting on behalf of controllers
- Excludes state and local government bodies, nonprofits, institutions of higher education, registered national securities associations, GLBA financial institutions and their affiliates, GLBA data, HIPAA covered entities and business associates, and listed data types (PHI, FCRA, DPPA, FERPA, Farm Credit Act, employment-context data)
What a privacy notice must say
- Commercial websites and ISPs that collect, store and sell customers' personally identifiable information must designate a controller and, in the customer agreement or a conspicuous website location, list the categories of personal data collected, all third parties to whom data has been or may be sold, and an active email address or online contact mechanism.R.I. Gen. Laws § 6-48.1-3(a) · Only if: Applies without the 35,000/10,000-customer thresholds
- A controller that sells personal data or processes it for targeted advertising must clearly and conspicuously disclose that processing.R.I. Gen. Laws § 6-48.1-3(b)
Rights it gives people
- Customers may designate an authorized agent to submit opt-out requests; controllers need not authenticate opt-out requests but may deny those they document as fraudulent, with notice to the requester.R.I. Gen. Laws § 6-48.1-6(b)(4), (7)
- Customers may confirm processing and access their data, correct inaccuracies, delete data, obtain a portable copy, and opt out of targeted advertising, sale of personal data, and profiling in furtherance of solely automated decisions with legal or similarly significant effects.R.I. Gen. Laws § 6-48.1-5(e)
Practices it requires
- Respond to rights requests within 45 days (extendable once by 45 days with notice), free of charge once per 12 months, and provide a conspicuous appeal process answered in writing within 60 days, telling the customer they may complain to the Attorney General if the appeal is denied.R.I. Gen. Laws § 6-48.1-6(b)(1)-(3), (6)
- Processing must be reasonably necessary and proportionate to the disclosed purposes and limited to what is adequate, relevant and necessary.R.I. Gen. Laws § 6-48.1-7(s)
- Do not process sensitive data without the customer's consent; sensitive data of a known child may be processed only with consent and in accordance with COPPA. Provide a way to revoke consent and stop processing within 15 days of revocation.R.I. Gen. Laws § 6-48.1-4(c), (e)
- Do not discriminate against customers for exercising rights, or deny goods, charge different prices or reduce quality because a customer opts out, except for bona fide voluntary loyalty, rewards, premium or discount programs.R.I. Gen. Laws § 6-48.1-5(b)-(d)
- Conduct and document a data protection assessment for processing that presents a heightened risk of harm, including targeted advertising, sale of personal data, risky profiling and processing sensitive data; the Attorney General may require its disclosure, and it stays confidential.R.I. Gen. Laws § 6-48.1-7(e)-(f), (i) · From 2026-01-01
- Controllers holding de-identified data must take reasonable measures against re-identification, publicly commit not to re-identify it, and contractually bind recipients to the chapter.R.I. Gen. Laws § 6-48.1-7(j)
Security duties
- Covered controllers must establish, implement and maintain reasonable administrative, technical and physical data security practices protecting the confidentiality, integrity and accessibility of personal data.R.I. Gen. Laws § 6-48.1-4(b)
Other duties
- Controller-processor contracts must set processing instructions, duration and data types, and require processor confidentiality, deletion or return of data at the end of services, compliance information on request, subcontractor flow-down after an opportunity to object, and cooperation with assessments.R.I. Gen. Laws § 6-48.1-7(b)-(c)
Sources
- Official text
- R.I. Gen. Laws ch. 6-48.1, index and §§ 6-48.1-1 to -10 (Rhode Island General Assembly)
- R.I. Gen. Laws § 6-48.1-8, Violations
- R.I. Gen. Laws § 6-13.1-8, Civil penalties (deceptive trade practices)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: The chapter text lacks a stand-alone privacy-notice content section like other state laws; § 6-48.1-5(f) refers to a 'privacy notice' but its required contents come only from § 6-48.1-3. Maintainers should not infer additional notice contents. | No Attorney General regulations or enforcement actions under ch. 6-48.1 were located as of 2026-09-25. | Enacted by P.L. 2024, ch. 430 and ch. 453 (2024-H 7787 Sub A / 2024-S 2500 Sub A), which became law without the Governor's signature per legislature press materials; the enrollment history was not fetched separately.
Research reference, not legal advice.