Rhode Island
RIDTPPA Compliance Checklist for Rhode Island
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 7 primary sources cited on this page. How we verify our legal content

Complying with the Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA), R.I. Gen. Laws ch. 6-48.1, comes down to a short list of concrete steps: confirm you are covered under the section 6-48.1-4 thresholds, publish the website third-party disclosure required by section 6-48.1-3, build a privacy notice and a rights-request workflow, get opt-in consent before processing sensitive data, and put processor contracts in place. The law took effect January 1, 2026, so these obligations are live as of 2026.
The signature compliance item is the section 6-48.1-3 transparency duty: a commercial website or internet service provider that collects, stores, and sells personal data must list the categories of data it collects and identify all third parties to whom it has sold or may sell that data. Enforcement is handled solely by the Rhode Island Attorney General under section 6-48.1-8, violations are treated as deceptive trade practices, and there is no statutory right to cure, so building compliance before a complaint arrives matters.
Jurisdiction scope: This covers Rhode Island's Data Transparency and Privacy Protection Act (R.I. Gen. Laws ch. 6-48.1). It is general legal information, not legal advice.
Step 1: Confirm whether you are covered
Start with the applicability test in section 6-48.1-4. The law's threshold-based obligations in sections 6-48.1-4 through 6-48.1-7 apply only to a for-profit entity that conducts business in Rhode Island, or that produces products or services targeted to Rhode Island residents, and that during the preceding calendar year controlled or processed the personal data of either of two groups.
The first trigger is 35,000 or more customers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction. The second trigger is 10,000 or more customers combined with deriving more than 20 percent of gross revenue from the sale of personal data.
Read the measuring period carefully. Because the statute looks to the preceding calendar year, a business that crosses a threshold for the first time during the current year is not covered by these sections until the following year. Track your numbers year over year so you know when coverage begins.
Two things to map carefully. First, the statute uses "customer," defined in section 6-48.1-2 as an individual residing in Rhode Island acting in an individual or household context, so business-context and employment-context data generally does not count toward the thresholds. Second, several categories of entities and data sit outside the law under the exemptions in section 6-48.1-3, including government bodies, nonprofit organizations, institutions of higher education, national securities associations, certain Gramm-Leach-Bliley financial institutions, HIPAA-covered health entities, and Fair Credit Reporting Act data. Map both your entity status and your data sets against those exemptions before concluding you are covered.
Step 2: Build the website third-party disclosure (the signature step)
If you are a commercial website or internet service provider that collects, stores, and sells personal data, the most distinctive Rhode Island requirement applies to you. Section 6-48.1-3 requires you to designate a controller, and it requires that disclosure to do three specific things. This is the item most likely to be missed by businesses that have copied a generic privacy policy from another state.
First, identify all of the categories of personal data the controller collects through the website or online service. Second, identify all third parties to whom the controller has sold or may sell customers' personally identifiable information. Third, identify an active electronic mail address or other online mechanism that a customer can use to contact the controller about its data practices.
The second element is the one to handle with care. Most state privacy laws ask for categories of third parties; Rhode Island's text says "identify all third parties" to whom you have sold or may sell data. Plan to maintain a current list of those third parties rather than a generic category statement. If you sell personal data or process it for targeted advertising, section 6-48.1-3 also requires you to clearly and conspicuously disclose that processing.

Step 3: Write a compliant privacy notice and rights workflow
Stand up a privacy notice and a request-handling process keyed to sections 6-48.1-5 and 6-48.1-6. Customers can confirm and access their data, correct inaccuracies, delete data, obtain a portable copy, and opt out of targeted advertising, sale, and certain profiling, so your intake form should let a customer select each of those rights.
The timing rules are concrete. Under section 6-48.1-6, you must respond to a request without undue delay and no later than 45 days after receipt, with one possible 45-day extension when reasonably necessary, communicated within the first 45 days. Information must be free of charge once per customer in any 12-month period. You may decline or charge for a request only if you can demonstrate it is manifestly unfounded, excessive, or repetitive.
Build an appeal channel too. If you refuse a request, section 6-48.1-6 requires you to establish an appeal process that is clearly and conspicuously available, and to inform the customer in writing within 60 days of any action taken or not taken, with a written explanation of the reasons. The statute then provides that if the appeal is denied, the customer may submit a complaint to the Attorney General. Rhode Island does not require you to furnish a complaint mechanism for that step, but pointing a denied customer to the Attorney General is sensible practice. Note that you are not required to authenticate an opt-out request, though you may still deny one you reasonably and documentedly believe is fraudulent, so keep the opt-out path low-friction.
Step 4: Get opt-in consent for sensitive data
Identify any sensitive data you process and gate it behind consent. Under section 6-48.1-4, you may not process a customer's sensitive data without the customer's consent, and you may not process the sensitive data of a known child except with consent and in accordance with the federal Children's Online Privacy Protection Act.
Sensitive data is defined broadly in section 6-48.1-2. It includes data revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis, sex life, sexual orientation, or citizenship or immigration status, plus genetic or biometric data used to identify a person, data collected from a known child, and precise geolocation data.
Make consent revocable. Section 6-48.1-4 requires you to provide a mechanism to grant and revoke consent and to honor a revocation within 15 days of receipt. Audit your data flows so you know where sensitive data enters your systems and confirm an opt-in gate exists at each entry point.
Step 5: Put processor contracts and assessments in place
If you use vendors that process personal data on your behalf, section 6-48.1-7 requires a written contract. The contract must set out instructions for processing data, the nature and purpose of processing, the type of data subject to processing, the duration of processing, and the rights and obligations of both parties.
The processor must also be bound to duties of confidentiality, to delete or return data at the end of the engagement, to make information available to demonstrate compliance, to flow down requirements to subcontractors, and to cooperate with assessments. Inventory your vendors and confirm each contract carries these terms before processing begins.
Section 6-48.1-7 also requires a data protection assessment for higher-risk processing. You must conduct and document an assessment for each processing activity that presents a heightened risk of harm, which the statute identifies as targeted advertising, the sale of personal data, profiling that carries certain risks, and the processing of sensitive data. Keep these assessments on file, because the Attorney General may request them in an investigation.

Step 6: Understand enforcement and penalties
Enforcement under the RIDTPPA is straightforward and entirely public. Section 6-48.1-8 gives the Rhode Island Attorney General sole enforcement authority, and it expressly states that nothing in the section authorizes a private right of action. A customer cannot sue a business directly; the enforcement route is a complaint to the Attorney General.
Violations are treated as deceptive trade practices in violation of R.I. Gen. Laws ch. 6-13.1, which is Rhode Island's Deceptive Trade Practices Act and supplies the Attorney General's enforcement toolkit. Section 6-48.1-8 also sets a specific penalty for one kind of violation: a person who intentionally discloses personal data in violation of the chapter, or to a shell company formed to circumvent it, faces a civil penalty of not less than $100 and not more than $500 for each such disclosure.
Two compliance realities follow. First, the per-disclosure structure means penalties can scale quickly when many records are involved. Second, unlike several other state privacy laws, the RIDTPPA does not provide a statutory right to cure, so a covered business should not count on a grace period to fix a problem after the Attorney General identifies it. Building the controls above before launch, rather than after a complaint, is the safer posture.
RIDTPPA compliance at a glance
| Obligation | Statute | Key requirement |
|---|---|---|
| Coverage check | 6-48.1-4 | Preceding calendar year: 35,000 customers, or 10,000 plus 20% revenue from data sales |
| Website disclosure | 6-48.1-3 | List data categories and identify all third-party recipients |
| Privacy notice and rights | 6-48.1-5, 6-48.1-6 | 45-day response, 12-month free, 60-day appeal |
| Sensitive data | 6-48.1-4 | Opt-in consent; honor revocation within 15 days |
| Processor contracts | 6-48.1-7 | Written terms and data protection assessments |
| Enforcement | 6-48.1-8 | AG only; $100 to $500 per intentional disclosure; no cure |
Related guides
- Rhode Island data privacy laws parent hub
- What is the RIDTPPA?
- RIDTPPA consumer rights
- State data privacy law comparison
- What is the CCPA?
More Rhode Island Laws
Frequently Asked Questions
Who has to comply with the RIDTPPA?
Under R.I. Gen. Laws 6-48.1-4, the RIDTPPA applies to a for-profit business that conducts business in Rhode Island or targets Rhode Island residents and that, during the preceding calendar year, controlled or processed the personal data of 35,000 or more customers, or of 10,000 or more customers while deriving more than 20 percent of gross revenue from the sale of personal data. The 35,000 threshold excludes data processed solely to complete a payment transaction. Because coverage looks back to the prior year, crossing a threshold for the first time this year brings you in next year.
What is the RIDTPPA website disclosure requirement?
Section 6-48.1-3 requires a commercial website or internet service provider that collects, stores, and sells personal data to designate a controller and to identify all categories of personal data it collects, identify all third parties to whom it has sold or may sell customers' personally identifiable information, and provide an active electronic mail address or other online mechanism for contacting the controller. The duty to name third parties rather than just describe categories is the law's signature compliance step.
What are the RIDTPPA penalties?
Under section 6-48.1-8, violations are deceptive trade practices under R.I. Gen. Laws ch. 6-13.1. A person who intentionally discloses personal data in violation of the chapter, or to a shell company formed to circumvent it, faces a civil penalty of not less than $100 and not more than $500 for each such disclosure. The Attorney General enforces, and penalties can scale with the number of records involved.
Does the RIDTPPA have a right to cure?
No. As of 2026, the RIDTPPA does not provide a statutory right to cure. Section 6-48.1-8 gives the Attorney General sole enforcement authority without a guaranteed grace period, so a covered business should build compliance before a complaint arises rather than relying on time to fix violations afterward.
How quickly must a business answer a RIDTPPA request?
Under section 6-48.1-6, a controller must respond without undue delay and no later than 45 days after receiving a request, with one possible 45-day extension when reasonably necessary. Information must be provided free of charge once per customer in any 12-month period, and appeals must be answered in writing within 60 days.
Does the RIDTPPA require recognizing a universal opt-out signal?
No. The RIDTPPA does not require controllers to honor a universal opt-out preference signal such as the Global Privacy Control. Section 6-48.1-6 allows authorized agents to submit opt-out requests, but there is no statutory mandate to recognize a browser-level signal, which is one reason the law is considered lighter-touch than the Colorado or Connecticut models.
When does sensitive data require opt-in consent in Rhode Island?
Always, when the data falls within the definition. Section 6-48.1-4 prohibits processing a customer's sensitive data without consent. Section 6-48.1-2 defines sensitive data to include health, racial or ethnic origin, religious beliefs, sex life, sexual orientation, immigration status, genetic or biometric identifiers, a known child's data, and precise geolocation. Consent must be revocable, with revocation honored within 15 days.
Do I need processor contracts under the RIDTPPA?
Yes. Section 6-48.1-7 requires a written contract with any processor that handles personal data on your behalf. The contract must address processing instructions, the nature and purpose of processing, the data type, the duration, confidentiality, subcontractor flow-down, and cooperation with assessments. You must also document a data protection assessment for higher-risk processing such as targeted advertising, data sales, certain profiling, and sensitive data.
Updates
Corrected the RIDTPPA coverage test to the statute's preceding-calendar-year measuring period, replaced 'internet service application' with the statutory term 'internet service provider' in the section 6-48.1-3 disclosure duty, and corrected the appeal section: Rhode Island requires a written 60-day appeal response but does not require controllers to provide an Attorney General complaint channel.
Clarified that RIDTPPA's core obligations apply only to for-profit entities and added the nonprofit, higher-education, and securities-association exemptions; corrected the website-disclosure trigger to require collecting, storing, and selling data rather than merely collecting it; and clarified that authenticating an opt-out request is optional for a business, not prohibited.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Rhode Island General Laws, Title 6: Commercial Law
§ 6-48.1-4Processing of information. [Effective January 1, 2026.]In forcecited in 5 of our articles
(a) This section shall apply to for-profit entities that conduct business in the state or for-profit entities that produce products or services that are targeted to residents of the state and that during the preceding calendar year did any of the following: (1) Controlled or processed the personal data of not less than thirty-five thousand (35,000) customers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction. (2) Controlled or processed the personal data of not less than ten thousand (10,000) customers and derived more than twenty percent (20%) of their gross revenue from the sale of personal data. (b) The controller shall establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data. (c) The controller shall not process sensitive data concerning a customer without obtaining customer consent and shall not process sensitive data of a known child unless consent is obtained and the information is processed in accordance with COPPA.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at webserver.rilegislature.gov
Also relied on in: Rhode Island Data Privacy Laws: RIDTPPA Consumer Rights Guide (2026), Rhode Island Biometric Privacy Laws: Collection, Consent & Penalties (2026), What Is the RIDTPPA? Rhode Island Data Privacy Act
§ 6-48.1-3Information sharing practices. [Effective January 1, 2026.]In forcecited in 5 of our articles
(a) Any commercial website or internet service provider conducting business in Rhode Island or with customers in Rhode Island or otherwise subject to Rhode Island jurisdiction, shall designate a controller. If a commercial website or internet service provider collects, stores, and sells customers’ personally identifiable information, then the controller shall, in its customer agreement or incorporated addendum, or in another conspicuous location on its website or online service platform where similar notices are customarily posted: (1) Identify all categories of personal data that the controller collects through the website or online service about customers; (2) Identify all third parties to whom the controller has sold or may sell customers’ personally identifiable information; and (3) Identify an active electronic mail address or other online mechanism that the customer may use to contact the controller. (b) If a controller sells personal data to third parties or processes personal data for targeted advertising, the controller shall clearly and conspicuously disclose such processing.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at webserver.rilegislature.gov
Also relied on in: RIDTPPA Consumer Rights in Rhode Island Explained
§ 6-48.1-5Customer rights. [Effective January 1, 2026.]In forcecited in 7 of our articles
(a) This section shall apply to for-profit entities that conduct business in the state or for-profit entities that produce products or services that are targeted to residents of the state and that during the preceding calendar year did any of the following: (1) Controlled or processed the personal data of not less than thirty-five thousand (35,000) customers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction. (2) Controlled or processed the personal data of not less than ten thousand (10,000) customers and derived more than twenty percent (20%) of their gross revenue from the sale of personal data. (b) No controller shall discriminate against a customer for exercising their customer rights. (c) No controller shall deny goods or services, charge different prices or rates for goods or services, or provide a different level of quality of goods or services to the customer if the customer opts out to use of their data. However, if a customer opts out of data collection, the covered entity is not required to provide a service that requires this data collection.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at webserver.rilegislature.gov
Also relied on in: How to Request Your Personal Data: US Privacy Rights by State
§ 6-48.1-6Exercising customer rights. [Effective January 1, 2026.]In forcecited in 6 of our articles
(a) This section shall apply to for-profit entities that conduct business in the state or for-profit entities that produce products or services that are targeted to residents of the state and that during the preceding calendar year did any of the following: (1) Controlled or processed the personal data of not less than thirty-five thousand (35,000) customers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction. (2) Controlled or processed the personal data of not less than ten thousand (10,000) customers and derived more than twenty percent (20%) of their gross revenue from the sale of personal data. (b) A controller shall comply with a request by a customer to exercise the customer rights authorized as follows: (1) A controller shall respond to the customer without undue delay, but not later than forty-five (45) days after receipt of the request.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at webserver.rilegislature.gov
§ 6-48.1-7Controller and processor responsibilities. [Effective January 1, 2026.]In forcecited in 3 of our articles
(a) This section shall apply to for-profit entities that conduct business in the state or for-profit entities that produce products or services that are targeted to residents of the state and that during the preceding calendar year did any of the following: (1) Controlled or processed the personal data of not less than thirty-five thousand (35,000) customers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction. (2) Controlled or processed the personal data of not less than ten thousand (10,000) customers and derived more than twenty percent (20%) of their gross revenue from the sale of personal data. (b) A processor shall adhere to the instructions of a controller and shall assist the controller in meeting the controller’s obligations of this chapter. (c) A contract between a controller and a processor shall govern the processor’s data processing procedures with respect to processing performed on behalf of the controller.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at webserver.rilegislature.gov
§ 6-48.1-8Violations. [Effective January 1, 2026.]In forcecited in 5 of our articles
(a) A violation of this chapter constitutes a violation of the general regulatory provisions of commercial law in this title and shall constitute a deceptive trade practice in violation of chapter 13.1 of this title; provided, further, that in the event that any individual or entity intentionally discloses personal data: (1) To a shell company or any entity that has been formed or established solely, or in part, for the purposes of circumventing the intent of this chapter; or (2) In violation of any provision of this chapter, that individual or entity shall pay a fine of not less than one hundred dollars ($100) and no more than five hundred dollars ($500) for each such disclosure. (b) The attorney general shall have sole enforcement authority of the provisions of this chapter and may enforce a violation of this chapter pursuant to: (1) The provisions of this section; or (2) General regulatory provisions of commercial law in this title, or both. (c) Nothing in this section shall be construed to authorize any private right of action to enforce any provision of this chapter, any regulation hereunder, or any other provisions of law.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at webserver.rilegislature.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- R.I. Gen. Laws 6-48.1-3: Information sharing practices(webserver.rilegislature.gov).gov
- R.I. Gen. Laws 6-48.1-4: Processing of information(webserver.rilegislature.gov).gov
- R.I. Gen. Laws 6-48.1-5: Customer rights(webserver.rilegislature.gov).gov
- R.I. Gen. Laws 6-48.1-6: Exercising customer rights(webserver.rilegislature.gov).gov
- R.I. Gen. Laws 6-48.1-7: Controller and processor responsibilities(webserver.rilegislature.gov).gov
- R.I. Gen. Laws 6-48.1-8: Violations(webserver.rilegislature.gov).gov
- Rhode Island Office of the Attorney General(riag.ri.gov).gov