Privacy Law Library

Electronic Mail Fraud Regulatory Act (anti-phishing)

RI Anti-Phishing Act

Other · Financial · Biometric

Rhode Island's anti-phishing law. It prohibits using websites, emails or other internet means to trick people into giving personal identifying information, such as SSNs, account numbers, passwords or biometric data, by pretending to be a business or person without authorization.

Where
Rhode Island
Citation
R.I. Gen. Laws §§ 6-49-1 to 6-49-6
Status
In force
Enforced by
Courts via consumer, ISP, website-owner and trademark-owner actions
People can sue
Yes
Penalties
Consumers may recover the greater of actual damages or up to per violation; ISPs, web page owners and trademark owners may obtain injunctions and the greater of actual damages or ,000 per violation. Damages may be tripled for a pattern and practice, with fees and costs to the prevailing party (§ 6-49-5).
Applies to
  • Any person who uses a web page, email or other internet means to induce others to provide personally identifying information
  • Persons who conspire in such schemes

Practices it requires

  • Do not solicit or induce anyone to provide personally identifying information by web page, email or other internet means while impersonating a business or individual without authorization.R.I. Gen. Laws § 6-49-4

Other duties

  • Personally identifying information covered includes SSNs, driver's license, bank, card and PIN numbers, electronic signatures, unique biometric data, account passwords and other data usable to access financial accounts.R.I. Gen. Laws § 6-49-3(12)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Effective date of P.L. 2006, ch. 628 not confirmed.

Research reference, not legal advice.