Rhode Island Identity Theft Protection Act of 2015 (information security and breach notification)
RI ITPA
Breach notification · Data security · Government records
Rhode Island's main data security and breach notification statute. It requires businesses and government agencies holding Rhode Island residents' personal information to keep a risk-based information security program, limit retention, destroy data securely and bind vendors by contract to reasonable security. When a breach poses a significant risk of identity theft, affected residents must be notified within 45 days (30 days for agencies), with notice to the Attorney General and credit bureaus if more than 500 residents are affected.
- Where
- Rhode Island
- Citation
- R.I. Gen. Laws §§ 11-49.3-1 to 11-49.3-7
- Status
- In force
- Last amended
- 2023-06-27
- Enforced by
- Rhode Island Attorney General
- People can sue
- No
- Penalties
- Civil penalties of up to $100 per record for each reckless violation and up to $200 per record for each knowing and willful violation, recoverable by the Attorney General (§ 11-49.3-5). The chapter creates no private cause of action.
- Applies to
- Any person (individual or commercial entity) that stores, collects, processes, maintains, acquires, uses, owns or licenses personal information about a Rhode Island resident
- State agencies and municipal agencies (with shorter notice deadlines and mandatory remediation services)
- Deemed compliance for entities following their own breach procedures that meet the statutory timing, entities following their primary or functional federal regulator's rules, financial institutions found compliant with the federal interagency response-program guidance, and HIPAA-covered health care entities
Practices it requires
- Do not retain personal information longer than reasonably required for the requested services, the collection purpose, a written retention policy or legal requirements, and destroy it securely in any medium (for example shredding, pulverizing, incinerating or erasing).R.I. Gen. Laws § 11-49.3-2(a)
Security duties
- Require by written contract that nonaffiliated third parties receiving Rhode Island residents' personal information maintain reasonable security procedures (for contracts entered into after the 2015 act took effect).R.I. Gen. Laws § 11-49.3-2(b)
- Implement and maintain a risk-based information security program with reasonable procedures appropriate to the organization's size, the nature of the information and the purpose of collection.R.I. Gen. Laws § 11-49.3-2(a)
Breach duties
- If more than 500 Rhode Island residents are to be notified, also notify the Attorney General and the major credit reporting agencies of the timing, content, distribution and approximate number of notices, without delaying notice to residents.R.I. Gen. Laws § 11-49.3-4(a)(2) · Only if: More than 500 Rhode Island residents affected
- State and municipal agencies must offer remediation services of at least five years for adults, and for minors until age 18 plus at least two more years, and must notify the collective bargaining agent when unionized employees are affected.R.I. Gen. Laws § 11-49.3-4(a)(2)(i), (e) · Only if: State and municipal agencies only
- Individual notices must describe, to the extent known, the incident and number affected, the data types, breach and discovery dates, remediation services with contacts for credit bureaus, remediation providers and the Attorney General, and how to obtain a police report and a security freeze.R.I. Gen. Laws § 11-49.3-4(d)
- Notify affected Rhode Island residents of any disclosure or breach of personal information that poses a significant risk of identity theft in the most expedient time possible and no later than 45 calendar days after confirming the breach (30 days for state and municipal agencies), subject to law-enforcement delay.R.I. Gen. Laws § 11-49.3-4(a)-(b)
Other duties
- State and municipal agencies must report any detected cybersecurity incident to the Rhode Island State Police within 24 hours.R.I. Gen. Laws § 11-49.3-7 · Only if: State and municipal agencies only · From 2023-06-27
Sources
- Official text
- R.I. Gen. Laws ch. 11-49.3 (Rhode Island General Assembly)
- R.I. Gen. Laws § 11-49.3-4, Notification of breach
- R.I. Gen. Laws § 11-49.3-3, Definitions (personal information incl. medical, health insurance and email-credential elements)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: Original effective date of P.L. 2015, chs. 138 and 148 (commonly reported as July 2, 2016) was not confirmed on an official page, so effective_date is null. | Attorney General breach-reporting form or portal was not fetched.
Research reference, not legal advice.