Rhode Island
Rhode Island Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 5 primary sources cited on this page. How we verify our legal content

Under the Rhode Island Identity Theft Protection Act, R.I. Gen. Laws 11-49.3, private businesses must notify affected residents within 45 days of confirming a data breach. When more than 500 Rhode Island residents are affected, businesses must also notify the Attorney General and major credit reporting agencies.
If your business handles personal information belonging to Rhode Island residents, a data breach triggers specific legal obligations under the state's Identity Theft Protection Act of 2015. Codified at R.I. Gen. Laws 11-49.3, the law sets out who must notify, what information triggers notification, the timeline for action, and the penalties for noncompliance.
Rhode Island replaced its original breach notification statute (Chapter 11-49.2) with this more comprehensive framework, which took effect on July 2, 2016. The law applies to any entity that stores, owns, collects, processes, maintains, acquires, uses, or licenses computerized data containing the personal information of Rhode Island residents, regardless of where the entity is located.
This guide covers the full scope of Rhode Island's breach notification requirements, including how they connect to the broader Rhode Island data privacy laws framework.

Who Must Comply With Rhode Island's Breach Notification Law
Rhode Island's law applies broadly. Under Section 11-49.3-4, any municipal agency, state agency, or person that stores, owns, collects, processes, maintains, acquires, uses, or licenses data that includes personal information must comply.
The term "person" covers individuals, corporations, businesses, partnerships, associations, and any other legal entity. Businesses based outside Rhode Island are subject to the law if they hold data belonging to Rhode Island residents.
Third-Party Data Holders
Rhode Island's notification duty is not limited to the entity that originally collected the data. Under Section 11-49.3-4, the duty to notify falls directly on any municipal agency, state agency, or person who stores, owns, collects, processes, maintains, acquires, uses, or licenses data containing personal information. That broad definition means a third-party processor or vendor holding data on another company's behalf can independently owe its own notification obligations under the statute, not just the company whose customers are affected.
Entities With Their Own Security Procedures
Under Section 11-49.3-6, a municipal agency, state agency, or person is deemed in compliance with the notification requirements of Section 11-49.3-4 if it maintains its own security breach procedures as part of an information security policy for the treatment of personal information, otherwise complies with the timing requirements of Section 11-49.3-4, and notifies subject persons in accordance with its own notification policies. The statute does not impose a test comparing an internal policy against the state requirements.
This route reaches only the Section 11-49.3-4 notice duty. It does not displace the separate risk-based information security program, retention limit, and secure destruction obligations in Section 11-49.3-2, discussed below.
Two federal pathways go further and are written as compliance with the whole chapter. Under Section 11-49.3-6(b), a financial institution, trust company, credit union, or affiliate that is subject to, examined for, and found in compliance with the Federal Interagency Guidelines on Response Programs for Unauthorized Access to Customer Information and Customer Notice is deemed in compliance with the chapter. Under Section 11-49.3-6(c), the same is true for a healthcare provider, healthcare service plan, health insurer, or covered entity governed by the HIPAA privacy and security rules at 45 C.F.R. Parts 160 and 164. Separately, Section 11-49.3-6(a)(2) covers a person who maintains breach procedures set by its primary or functional regulator as defined in 15 U.S.C. 6809(2) and notifies under those rules.
What Triggers Notification
Notification is required when there is unauthorized access to or acquisition of unencrypted computerized data that compromises the security, confidentiality, or integrity of personal information, and the breach poses a significant risk of identity theft to a Rhode Island resident.
This "risk of identity theft" standard means not every technical unauthorized access automatically triggers notification. The entity must assess whether the nature of the compromised information creates a meaningful risk.
Good Faith Exception
A good faith acquisition of personal information by an employee or agent of the entity does not constitute a breach, provided the data is not used or disclosed in an unauthorized manner.
Personal Information That Triggers the Law
Under Section 11-49.3-3, personal information means an individual's first name or first initial and last name combined with any one or more of the following data elements, when the name and the data elements are not encrypted or are in hard copy, paper format:
- Social Security number
- Driver's license number, Rhode Island identification card number, or tribal identification number
- Account number, credit or debit card number, in combination with any required security code, access code, password, or PIN that would permit access to the account
- Medical information (any information regarding an individual's medical history, mental or physical condition, or medical treatment or diagnosis by a healthcare professional)
- Health insurance information (health insurance policy number, subscriber identification number, or any unique identifier used by a health insurer)
- Email address with any required security code, access code, or password that would permit access to a personal, medical, insurance, or financial account
The "hard copy, paper format" language matters. The breach trigger in Section 11-49.3-3(a)(1) reaches only unencrypted computerized data, so a paper-only incident does not by itself start the notification clock. The same definition, however, drives the Section 11-49.3-2 security, retention, and secure destruction duties, which apply to personal information regardless of the medium it is stored in.
Rhode Island's inclusion of medical information, health insurance data, and email credentials makes its definition broader than many states. Personal information does not include publicly available information lawfully obtained from federal, state, or local government records.

The 128-Bit Encryption Safe Harbor
Rhode Island is one of few states that specifies a minimum encryption standard in its breach notification law. Under Section 11-49.3-3, "encrypted" means the transformation of data through the use of a 128-bit or higher algorithmic process into a form in which there is a low probability of assigning meaning without use of a confidential process or key.
If personal information was encrypted to this standard at the time of the breach, and the encryption key was not also acquired during the incident, notification is not required.
However, data is not considered encrypted if it was acquired in combination with any key, security code, or password that would permit access. A breach that compromises both the encrypted data and the decryption key triggers full notification obligations.
Practical Implications
This 128-bit threshold means AES-128, AES-256, and similar modern algorithms all qualify. Weaker or proprietary encryption methods that do not meet the 128-bit standard would not provide safe harbor protection.
Notification Timeline: 45 Days and 30 Days
Rhode Island imposes two different deadlines depending on the type of entity involved.
Private Entities: 45 Calendar Days
For persons (businesses, corporations, and other non-governmental entities), notification must be provided no later than 45 calendar days after confirmation of the breach and the ability to ascertain the information required to fulfill the notice requirements.
Government Agencies: 30 Calendar Days
State and municipal agencies face a shorter deadline of 30 calendar days after the same confirmation and ascertainment threshold. Separately, under Section 11-49.3-7, any municipal or state agency that detects a cybersecurity incident must notify the Rhode Island State Police within 24 hours of detection, a faster and distinct obligation from the 30-day breach notice.
When the Clock Starts
The deadline runs from the date the entity both confirms a breach occurred and can ascertain the details needed for the notification (who was affected, what data was involved). The entity may take reasonable time to investigate, but must not use investigation as a pretext for delay.
Law enforcement may request a delay if notification would impede a criminal investigation. Once law enforcement determines that notification will no longer compromise the investigation, the countdown resumes.
Who Must Be Notified
Affected Individuals
Every Rhode Island resident whose personal information was or is reasonably believed to have been acquired by an unauthorized person or entity must receive individual notification.
Attorney General and Credit Reporting Agencies (More Than 500 Threshold)
Under Section 11-49.3-4, when more than 500 Rhode Island residents must be notified, the entity must also notify the Rhode Island Attorney General and the major consumer credit reporting agencies (Equifax, Experian, and TransUnion). The notice must include the timing, content, and distribution of the consumer notices and the approximate number of affected individuals.
Methods of Notification
Rhode Island permits several notification methods:
- Written notice sent to the individual's last known mailing address
- Electronic notice, if consistent with the federal E-SIGN Act (15 U.S.C. 7001 et seq.)
- Substitute notice, if the entity demonstrates that the cost of individual notice exceeds $25,000, the affected population exceeds 50,000 residents, or the entity does not have sufficient contact information. Substitute notice requires all three of: email notice to available addresses, conspicuous posting on the entity's website, and notification to statewide media.
Required Content of the Notification
Rhode Island is unusually specific about what the notification must contain. The notice must include:
- A general description of the incident, including how the breach occurred and the number of affected individuals
- The type of personal information subject to the breach
- The date of the breach, estimated date, or date range
- The date the breach was discovered
- A description of any remediation services offered, including toll-free numbers and websites to contact credit reporting agencies, remediation service providers, and the Attorney General
- A description of the consumer's ability to file a police report
- How to request a security freeze
- Information that fees may be required to be paid to consumer reporting agencies for security freezes

Penalties for Noncompliance
Under Section 11-49.3-5, Rhode Island imposes per-record civil penalties:
- Reckless violations: Up to $100 per record
- Knowing and willful violations: Up to $200 per record
There is no statutory aggregate cap on these penalties. For a breach affecting thousands of records, exposure can grow rapidly.
Enforcement Authority
Only the Rhode Island Attorney General can enforce this statute. When the AG has reason to believe a violation has occurred and that proceedings would be in the public interest, the AG may bring an action in the name of the state.
No Private Right of Action
Rhode Island's breach notification law does not create a private right of action. Individuals cannot sue under this statute for failure to notify. However, affected individuals may pursue claims under other legal theories, such as negligence or the state's Deceptive Trade Practices Act, depending on the circumstances.
Information Security Program Requirement
Rhode Island goes beyond notification alone. Under Section 11-49.3-2, any municipal or state agency, or person, that stores, collects, processes, maintains, acquires, or uses personal information must implement and maintain a risk-based information security program with reasonable security procedures and practices appropriate to the size of the entity, the nature of the data stored, and the purpose for collecting the information.
This requirement applies independently of whether a breach occurs. It means Rhode Island can hold entities accountable not only for failing to notify after a breach, but also for failing to maintain adequate security to prevent breaches in the first place.
This article provides general legal information about Rhode Island data privacy laws and breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in Rhode Island for guidance specific to your situation.
More Rhode Island Laws
Frequently Asked Questions
How quickly must a business notify Rhode Island residents after a data breach?
Private entities (businesses, corporations, and other non-governmental organizations) must notify affected Rhode Island residents within 45 calendar days after confirming the breach and ascertaining the required notification details. State and municipal agencies face a shorter 30-day deadline.
What encryption standard qualifies for Rhode Island's safe harbor?
Rhode Island requires 128-bit or higher algorithmic encryption to qualify for the safe harbor. If personal information was encrypted to this standard and the encryption key was not compromised during the breach, notification is not required. Common algorithms like AES-128 and AES-256 meet this threshold.
Does Rhode Island require Attorney General notification for all data breaches?
No. The Attorney General and major credit reporting agencies must be notified only when more than 500 Rhode Island residents are affected. Breaches affecting 500 or fewer residents require individual notification to affected consumers but not to the AG.
Can individuals sue a company for failing to send breach notification in Rhode Island?
No. Rhode Island's Identity Theft Protection Act does not create a private right of action. Only the Attorney General can enforce the statute. However, individuals may pursue claims under other legal theories such as negligence or the state's deceptive trade practices laws.
Does Rhode Island's breach notification law cover medical and health insurance information?
Yes. Rhode Island's definition of personal information includes medical information (medical history, mental or physical conditions, treatment, or diagnosis) and health insurance information (policy numbers, subscriber IDs, or any unique health insurer identifier). This makes Rhode Island's definition broader than many states that only cover financial data.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the description of Rhode Island Section 11-49.3-6: an entity following its own breach procedures is deemed compliant only with the Section 11-49.3-4 notification requirements under three specific statutory conditions, not with the whole chapter, and the personal information definition now includes the statute’s "or are in hard copy, paper format" qualifier.
Corrected the Attorney General and credit-bureau notification threshold from '500 or more' to the statute's actual 'more than 500' Rhode Island residents (fixed in five spots), replaced an inaccurate third-party notice-chain description with the law's actual direct-duty rule, restored two missing items in the required notice-content list (date the breach was discovered, and remediation service providers as a contact category), fixed a mislinked statute citation, and added a note on the state's separate 24-hour cybersecurity-incident reporting duty for government agencies.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Rhode Island General Laws, Title 11: Criminal Offenses, Chapter 11-49.3: Identity Theft Protection Act of 2015
§ 11-49.3-4Notification of breachIn forcecited in 3 of our articles
(a)(1) Any municipal agency, state agency, or person who or that stores, owns, collects, processes, maintains, acquires, uses, or licenses data that includes personal information shall provide notification as set forth in this section of any disclosure of personal information, or any breach of the security of the system, that poses a significant risk of identity theft to any resident of Rhode Island whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person or entity. (2) The notification shall be made in the most expedient time possible, subject to the following: (i) For state and municipal agencies, no later than thirty (30) calendar days after confirmation of the breach and the ability to ascertain the information required to fulfill the notice requirements contained in subsection (d), and shall be consistent with the legitimate needs of law enforcement as provided in subsection (b).
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at webserver.rilegislature.gov
Also relied on in: Rhode Island Data Privacy Laws: RIDTPPA Consumer Rights Guide (2026), Rhode Island Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 11-49.3-3DefinitionsIn force
(a) The following definitions apply to this chapter: (1) “Breach of the security of the system” means unauthorized access or acquisition of unencrypted, computerized data information that compromises the security, confidentiality, or integrity of personal information maintained by the municipal agency, state agency, or person. Good-faith acquisition of personal information by an employee or agent of the agency for the purposes of the agency is not a breach of the security of the system; provided, that the personal information is not used or subject to further unauthorized disclosure. (2) “Classified data” means any data that is not public (private, sensitive, confidential). Classified data requires additional security controls, such as access restrictions and encryption. Classified data includes personally identifiable information (PII), personally identifiable health information (PHI), or federal tax information (FTI). (3) “Cybersecurity incident” means unauthorized access that could jeopardize the confidentiality, integrity, or availability of critical information systems and critical infrastructure systems (i.e., first responder networks, water, energy).
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at webserver.rilegislature.gov
§ 11-49.3-5Penalties for violationIn forcecited in 2 of our articles
(a) Each reckless violation of this chapter is a civil violation for which a penalty of not more than one hundred dollars ($100) per record may be adjudged against a defendant. (b) Each knowing and willful violation of this chapter is a civil violation for which a penalty of not more than two hundred dollars ($200) per record may be adjudged against a defendant. (c) Whenever the attorney general has reason to believe that a violation of this chapter has occurred and that proceedings would be in the public interest, the attorney general may bring an action in the name of the state against the business or person in violation.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at webserver.rilegislature.gov
United States Code Title 15
§ 7001General rule of validityIn forcecited in 18 of our articles
Notwithstanding any statute, regulation, or other rule of law (other than this subchapter and subchapter II), with respect to any transaction in or affecting interstate or foreign commerce— a signature, contract, or other record relating to such transaction may not be denied legal effect, validity, or enforceability solely because it is in electronic form; and a contract relating to such transaction may not be denied legal effect, validity, or enforceability solely because an electronic signature or electronic record was used in its formation. This subchapter does not— limit, alter, or otherwise affect any requirement imposed by a statute, regulation, or rule of law relating to the rights and obligations of persons under such statute, regulation, or rule of law other than a requirement that contracts or other records be written, signed, or in nonelectronic form; or require any person to agree to use or accept electronic records or electronic signatures, other than a governmental agency with respect to a record other than a contract to which it is a party.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 132 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Metropolitan Regional Information Systems v. American Home Realty Network (2012) applied 15 U.S.C. 7001(a) to hold an electronic assignment process satisfied the signed writing requirement of Copyright Act 204(a). Blatt v. Capital One Auto Finance (2017) held 7001(c) disclosures were not required where the record was delivered on paper.
Opinions citing this section in our collection:
- Metropolitan Regional Information Systems, Inc. v. American Home Realty Network, Inc. (District Court, D. Maryland 2012, 904 F. Supp. 2d 530)✓Subscribers assigned photo copyrights to a real estate database by uploading images under online terms of use; the court relied on E-SIGN, 15 U.S.C. section 7001, to hold those electronic assignments met the Copyright Act signed-writing rule, and denied reconsideration.
- Cutrone v. Mortgage Electronic Registration Systems, Inc. (District Court, E.D. New York 2013, 981 F. Supp. 2d 144)✓Homeowners sued MERS in state court over a second mortgage recording tax on an E-Sign mortgage; MERS removed under 15 U.S.C. section 7001, but the court held that statute gives no private right of action and at most a federal defense, which cannot support removal, and remanded.
- Blatt v. Capital One Auto Finance, Inc. (District Court, M.D. Tennessee 2017, 237 F. Supp. 3d 688)“…legal effect ..solely because it is in electronic form[.]” 15 U.S.C. § 7001 (a)(1).. Furthermore, it mandates that…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Mississippi Data Breach Notification Laws: Reporting Rules & Timelines (2026), Mississippi Data Privacy Laws: Breach Notification & Consumer Rights (2026), Montana Data Privacy Laws: MCDPA Consumer Rights Guide (2026)
Explore the law
This article also draws on these acts and chapters (opening at their first section): Rhode Island General Laws, Title 11: Criminal Offenses, Chapter 11-49.3: Identity Theft Protection Act of 2015 § 11-49.3-1 (Short title)
Related law for further reading — not part of this article’s citations.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- R.I. Gen. Laws Chapter 11-49.3 - Identity Theft Protection Act of 2015(webserver.rilegislature.gov).gov
- Section 11-49.3-3 - Definitions(webserver.rilegislature.gov).gov
- Section 11-49.3-4 - Notification of Breach(webserver.rilegislature.gov).gov
- Section 11-49.3-5 - Penalties for Violation(webserver.rilegislature.gov).gov
- Rhode Island AG - Data Breach Notifications(riag.ri.gov).gov
- R.I. Gen. Laws Section 11-49.3-6 - Agencies or Persons With Security Breach Procedures(webserver.rilegislature.gov)
- R.I. Gen. Laws Section 11-49.3-2 - Risk-Based Information Security Program(webserver.rilegislature.gov)