EnglishEspañol
Rhode Island flag

Rhode Island

Rhode Island Data Privacy Laws: RIDTPPA Consumer Rights Guide (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 18 primary sources cited on this page. How we verify our legal content

Rhode Island Data Privacy Laws: RIDTPPA Consumer Rights Guide (2026)

Frequently Asked Questions

When did the Rhode Island Data Transparency and Privacy Protection Act take effect?

The RIDTPPA took effect on January 1, 2026. Governor Daniel McKee transmitted the law without signature on June 25, 2024, after the General Assembly passed it through companion bills H7787 and S2500. It is codified as R.I. Gen. Laws Chapter 6-48.1.

Does Rhode Island give businesses a chance to fix data privacy violations before imposing penalties?

No. Rhode Island is one of the few states that provides no cure period. The Attorney General can pursue enforcement action immediately upon determining a violation has occurred. Most other states provide 30 to 60 days for businesses to remedy violations before penalties apply. Indiana and Kentucky, which share the January 1, 2026 effective date, both allow 30-day cure periods; Rhode Island's law contains no such provision.

Can I sue a company directly for violating my data privacy rights in Rhode Island?

No. The RIDTPPA does not include a private right of action. Only the Rhode Island Attorney General can enforce the law. If you believe a company has violated your data privacy rights, you can file a complaint with the Rhode Island Attorney General's office at riag.ri.gov.

What makes Rhode Island's data privacy law different from other states?

The RIDTPPA stands out in several ways: it has no cure period, requires businesses to disclose potential future data recipients (not just current ones), sets lower applicability thresholds at 35,000 consumers, and classifies violations as deceptive trade practices carrying up to $10,000 per violation. The law also applies its privacy notice requirements broadly to any commercial website selling personal data in Rhode Island, regardless of the standard processing thresholds.

How quickly must a business notify me of a data breach in Rhode Island?

Private businesses must notify affected Rhode Island residents within 45 calendar days of confirming a breach. State and municipal agencies have a shorter deadline of 30 calendar days. If a breach affects more than 500 residents, the entity must also notify the Rhode Island Attorney General and major credit reporting agencies. Notifications must include details about the breach, the types of information affected, and instructions for obtaining identity protection services.

How does Rhode Island's privacy law compare to Indiana's and Kentucky's?

All three laws took effect January 1, 2026. Indiana and Kentucky are modeled on Virginia's law with 100,000-consumer thresholds and 30-day cure periods; penalties cap at $7,500 per violation. Rhode Island has a lower 35,000-consumer threshold, no cure period, a higher $10,000 maximum penalty, and a unique requirement to disclose potential future data recipients. Rhode Island is the stricter law by every enforcement metric.

Is there a federal deepfake law that applies in Rhode Island?

Yes. The TAKE IT DOWN Act (Pub. L. 119-12), signed May 19, 2025, criminalizes publishing nonconsensual intimate imagery, including AI-generated deepfakes. Starting May 19, 2026, covered platforms must remove flagged content within 48 hours of a valid request. The FTC enforces the platform obligations and can impose civil penalties of $53,088 per violation. Rhode Island also enacted its own complementary deepfake law on July 2, 2025.

Does Rhode Island have its own deepfake law?

Yes. Rhode Island enacted H5046/S0136, signed into law on July 2, 2025, which criminalizes distributing synthetic intimate imagery of a real person without their consent. First offenses are misdemeanors (up to 1 year in prison and a $1,000 fine); subsequent offenses are felonies (up to 3 years and a $3,000 fine). Threatening to disclose such an image in order to obtain a benefit is a separate felony under R.I. Gen. Laws 11-64-3(e), carrying up to 5 years and a $5,000 fine. This state law applies independently of the federal TAKE IT DOWN Act.

Updates

Corrected the penalty for a second or subsequent Rhode Island deepfake/NCII dissemination offense to up to 3 years in prison and a $3,000 fine under R.I. Gen. Laws 11-64-3(d), and clarified that the 5-year, $5,000 felony applies to threatening to disclose such an image for gain under 11-64-3(e).

Corrected the statutory citation for the RIDTPPA's exemption lists to R.I. Gen. Laws Section 6-48.1-3(d)-(e).

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

May 2026 refresh: corrected enactment history (McKee transmitted without signature; Rhode Island is the twentieth, not nineteenth, state to enact comprehensive data privacy legislation); added Rhode Island deepfake/NCII law (H5046/S0136, signed July 2, 2025); added TAKE IT DOWN Act federal overlay with FTC enforcement effective May 19, 2026; added January 2026 enforcement status section; added Indiana/Kentucky comparison table; expanded FAQ from 5 to 8 questions; updated SourcesList to correct component prop and add FTC sources.

Reviewed and approved by an editor

Sources and References

  1. Rhode Island Data Transparency and Privacy Protection Act - R.I. Gen. Laws Chapter 6-48.1 (Full Text)(webserver.rilegislature.gov).gov
  2. RIDTPPA Definitions - R.I. Gen. Laws Section 6-48.1-2(webserver.rilegislature.gov).gov
  3. RIDTPPA Information Sharing Practices - R.I. Gen. Laws Section 6-48.1-3(webserver.rilegislature.gov).gov
  4. RIDTPPA Processing of Information - R.I. Gen. Laws Section 6-48.1-4(webserver.rilegislature.gov).gov
  5. RIDTPPA Customer Rights - R.I. Gen. Laws Section 6-48.1-5(webserver.rilegislature.gov).gov
  6. RIDTPPA Exercising Customer Rights - R.I. Gen. Laws Section 6-48.1-6(webserver.rilegislature.gov).gov
  7. RIDTPPA Controller and Processor Responsibilities - R.I. Gen. Laws Section 6-48.1-7(webserver.rilegislature.gov).gov
  8. RIDTPPA Violations - R.I. Gen. Laws Section 6-48.1-8(webserver.rilegislature.gov).gov
  9. RIDTPPA Information Sharing Practices (incl. exemptions) - R.I. Gen. Laws Section 6-48.1-3(webserver.rilegislature.gov).gov
  10. House Bill H7787 Substitute A as Amended (Enacted Text)(webserver.rilegislature.gov).gov
  11. Senate Bill S2500 Substitute A as Amended (Enacted Text)(webserver.rilegislature.gov).gov
  12. Rhode Island Identity Theft Protection Act of 2015 - R.I. Gen. Laws Chapter 11-49.3(webserver.rilegislature.gov).gov
  13. Breach Notification Requirements - R.I. Gen. Laws Section 11-49.3-4(webserver.rilegislature.gov).gov
  14. Breach Notification Penalties - R.I. Gen. Laws Section 11-49.3-5(webserver.rilegislature.gov).gov
  15. Rhode Island Attorney General - Data Breach Notifications(riag.ri.gov).gov
  16. Rhode Island Legislature Press Release - Data Transparency and Privacy Protection Act(rilegislature.gov).gov
  17. FTC Begins Enforcing the TAKE IT DOWN Act (May 2026)(ftc.gov).gov
  18. Complying With the Take It Down Act - FTC Business Guidance(ftc.gov).gov
  19. New State Privacy Laws Effective January 1, 2026: Indiana, Kentucky, and Rhode Island - Koley Jessen(koleyjessen.com)
  20. Unauthorized Dissemination of Sexually Explicit Images - R.I. Gen. Laws Section 11-64-3(webserver.rilegislature.gov)
Share: