EnglishEspañol
Rhode Island flag

Rhode Island

Rhode Island Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 10 primary sources cited on this page. How we verify our legal content

Rhode Island Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Frequently Asked Questions

Does Rhode Island have a standalone biometric privacy law?

No. Rhode Island does not have a dedicated biometric privacy statute. Instead, the Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA), effective January 1, 2026, classifies biometric data as sensitive data within its comprehensive consumer privacy framework. The RIDTPPA requires businesses to obtain opt-in consent before processing biometric data for identification purposes, but it does not include the detailed retention, destruction, and private right of action provisions found in Illinois BIPA.

Can I sue a company in Rhode Island for collecting my biometric data without consent?

Not under the RIDTPPA. The Rhode Island Attorney General has exclusive enforcement authority, and the law does not include a private right of action. If you believe a company collected your biometric data without consent, you can file a complaint with the Rhode Island Attorney General's Office at [riag.ri.gov/forms/consumer-complaint](https://riag.ri.gov/forms/consumer-complaint). The AG can investigate and pursue fines of $100 to $500 for each intentional unlawful disclosure of personal data.

Does the RIDTPPA protect my biometric data at work?

No. The RIDTPPA does not regulate employment-context data because the law only protects customers, and its definition of customer excludes people acting in a commercial or employment context or as an employee, owner, director, officer, or contractor. If your employer collects fingerprints for timekeeping, uses facial recognition for building access, or requires biometric scans, the RIDTPPA does not regulate that activity. Rhode Island does not have a separate law governing employer use of biometric data. The breach notification law (R.I. Gen. Laws 11-49.3) can still apply if an employer has a data breach, but only for the categories of personal information that statute covers, such as a Social Security number, driver's license number, or financial account number, not biometric data by itself.

What encryption standard does Rhode Island require for protecting biometric data?

Rhode Island's Identity Theft Protection Act (R.I. Gen. Laws 11-49.3) defines encryption as the transformation of data through a 128-bit or higher algorithmic process, but that standard applies to the categories of personal information the statute actually covers, such as Social Security numbers, driver's license numbers, financial account or card numbers, medical or health insurance information, and email addresses with access codes. Biometric identifiers are not on that list, so encrypting biometric data has no effect on notification duties under this statute one way or the other. The RIDTPPA separately requires controllers to implement reasonable administrative, technical, and physical data security practices to protect all personal data, including biometric identifiers.

How quickly must a company notify me of a biometric data breach in Rhode Island?

Rhode Island's breach notification law does not treat biometric data alone as covered personal information, so a breach that exposes only biometric identifiers does not trigger this notification duty by itself. When a breach does involve personal information the statute covers, such as a Social Security number, driver's license number, or financial account number, private entities must notify affected Rhode Island residents no later than 45 calendar days after confirming the breach. State and municipal agencies face a shorter deadline of 30 calendar days. If more than 500 residents are affected, the entity must also notify the Rhode Island Attorney General. State agencies must additionally report cybersecurity incidents to the Rhode Island State Police within 24 hours.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Clarified that Rhode Island's $100 to $500 penalty applies only to intentional disclosures, and corrected the comparison between the RIDTPPA and Illinois BIPA biometric-data definitions.

Corrected this article to clarify that Rhode Island's breach notification law (R.I. Gen. Laws 11-49.3) does not cover biometric data alone, re-attributed the employee-data carve-out to the RIDTPPA's customer definition rather than its data-exemption list, fixed a dead Attorney General complaint-form link, and corrected the comparison table to show Texas CUBI has no cure period.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Corrected an unverified '$10,000 per violation' RIDTPPA penalty figure to the $100-$500-per-disclosure fine actually set out in R.I. Gen. Laws 6-48.1-8(a)(2), matching two sibling RI pages describing the same enforcement scheme.

Corrected the Attorney General breach-notification threshold from '500 or more' to 'more than 500' Rhode Island residents, matching R.I. Gen. Laws 11-49.3-4's actual trigger.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)(rilegislature.gov).gov
  2. R.I. Gen. Laws 6-48.1-2 - RIDTPPA Definitions(rilegislature.gov).gov
  3. R.I. Gen. Laws 6-48.1-4 - Processing of Information(rilegislature.gov).gov
  4. R.I. Gen. Laws 6-48.1-5 - Customer Rights(rilegislature.gov).gov
  5. R.I. Gen. Laws 6-48.1-7 - Controller and Processor Responsibilities(rilegislature.gov).gov
  6. R.I. Gen. Laws 6-48.1-8 - Violations(rilegislature.gov).gov
  7. R.I. Gen. Laws 6-48.1-3 - Information Sharing Practices(rilegislature.gov).gov
  8. R.I. Gen. Laws 11-49.3-4 - Breach Notification(rilegislature.gov).gov
  9. H.B. 7787 Substitute A as Amended (Enrolled Bill)(rilegislature.gov).gov
  10. Rhode Island Attorney General - Consumer Complaint Form(riag.ri.gov).gov
Share: