EnglishEspañol
Rhode Island flag

Rhode Island

Rhode Island Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 5 primary sources cited on this page. How we verify our legal content

Rhode Island Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must a business notify Rhode Island residents after a data breach?

Private entities (businesses, corporations, and other non-governmental organizations) must notify affected Rhode Island residents within 45 calendar days after confirming the breach and ascertaining the required notification details. State and municipal agencies face a shorter 30-day deadline.

What encryption standard qualifies for Rhode Island's safe harbor?

Rhode Island requires 128-bit or higher algorithmic encryption to qualify for the safe harbor. If personal information was encrypted to this standard and the encryption key was not compromised during the breach, notification is not required. Common algorithms like AES-128 and AES-256 meet this threshold.

Does Rhode Island require Attorney General notification for all data breaches?

No. The Attorney General and major credit reporting agencies must be notified only when more than 500 Rhode Island residents are affected. Breaches affecting 500 or fewer residents require individual notification to affected consumers but not to the AG.

Can individuals sue a company for failing to send breach notification in Rhode Island?

No. Rhode Island's Identity Theft Protection Act does not create a private right of action. Only the Attorney General can enforce the statute. However, individuals may pursue claims under other legal theories such as negligence or the state's deceptive trade practices laws.

Does Rhode Island's breach notification law cover medical and health insurance information?

Yes. Rhode Island's definition of personal information includes medical information (medical history, mental or physical conditions, treatment, or diagnosis) and health insurance information (policy numbers, subscriber IDs, or any unique health insurer identifier). This makes Rhode Island's definition broader than many states that only cover financial data.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the description of Rhode Island Section 11-49.3-6: an entity following its own breach procedures is deemed compliant only with the Section 11-49.3-4 notification requirements under three specific statutory conditions, not with the whole chapter, and the personal information definition now includes the statute’s "or are in hard copy, paper format" qualifier.

Corrected the Attorney General and credit-bureau notification threshold from '500 or more' to the statute's actual 'more than 500' Rhode Island residents (fixed in five spots), replaced an inaccurate third-party notice-chain description with the law's actual direct-duty rule, restored two missing items in the required notice-content list (date the breach was discovered, and remediation service providers as a contact category), fixed a mislinked statute citation, and added a note on the state's separate 24-hour cybersecurity-incident reporting duty for government agencies.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. R.I. Gen. Laws Chapter 11-49.3 - Identity Theft Protection Act of 2015(webserver.rilegislature.gov).gov
  2. Section 11-49.3-3 - Definitions(webserver.rilegislature.gov).gov
  3. Section 11-49.3-4 - Notification of Breach(webserver.rilegislature.gov).gov
  4. Section 11-49.3-5 - Penalties for Violation(webserver.rilegislature.gov).gov
  5. Rhode Island AG - Data Breach Notifications(riag.ri.gov).gov
  6. R.I. Gen. Laws Section 11-49.3-6 - Agencies or Persons With Security Breach Procedures(webserver.rilegislature.gov)
  7. R.I. Gen. Laws Section 11-49.3-2 - Risk-Based Information Security Program(webserver.rilegislature.gov)
Share: