EnglishEspañol
Rhode Island flag

Rhode Island

What Is the RIDTPPA? Rhode Island Data Privacy Act

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 9 primary sources cited on this page. How we verify our legal content

What Is the RIDTPPA? Rhode Island Data Privacy Act

Frequently Asked Questions

What is the RIDTPPA?

The RIDTPPA, or Rhode Island Data Transparency and Privacy Protection Act, is Rhode Island's comprehensive consumer data privacy law codified at R.I. Gen. Laws ch. 6-48.1. It was enacted in 2024 through bills H 7787 and S 2500, became law in June 2024, and takes effect January 1, 2026. It gives Rhode Island residents rights over their personal data and requires covered businesses to disclose how they collect, use, and share it.

When does the Rhode Island Data Transparency and Privacy Protection Act take effect?

The RIDTPPA takes effect on January 1, 2026, the effective date set by the 2024 enacting legislation for the entire chapter. The law was passed in June 2024, so covered businesses had roughly eighteen months to prepare. As of 2026, the law is operative and the Attorney General has enforcement authority.

Who has to comply with the RIDTPPA?

Under section 6-48.1-4, the RIDTPPA applies to a for-profit business that conducts business in Rhode Island or targets Rhode Island residents and that, during a calendar year, controls or processes the personal data of 35,000 or more customers, or of 10,000 or more customers while deriving more than 20 percent of gross revenue from the sale of personal data. The first threshold excludes data processed solely to complete a payment transaction. Nonprofits, higher-education institutions, government bodies, GLBA financial institutions, and HIPAA covered entities and business associates are exempt from the chapter under 6-48.1-3(d).

What is the RIDTPPA third-party disclosure requirement?

Section 6-48.1-3 requires a commercial website or internet service provider that collects, stores, and sells customers' personally identifiable information to disclose the categories of personal data it collects and to identify all third parties to whom the controller has sold or may sell that information, along with an active means of contact. The duty to name third parties, rather than just disclose categories of third parties, is the law's signature feature and the reason it is called a transparency act.

Does the RIDTPPA require a universal opt-out signal?

No. As of 2026, the RIDTPPA does not require controllers to recognize a universal opt-out preference signal such as the Global Privacy Control. Section 6-48.1-6 describes how customers exercise opt-out rights and allows authorized agents, but it contains no universal opt-out mechanism mandate. This is one reason the law is viewed as lighter-touch than the Colorado or Connecticut models.

What counts as sensitive data under the RIDTPPA?

Under section 6-48.1-2, sensitive data includes data revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis, sex life, sexual orientation, or citizenship or immigration status. It also includes genetic or biometric data used to identify a person, personal data collected from a known child, and precise geolocation data. Processing sensitive data requires opt-in consent under section 6-48.1-4.

How is the RIDTPPA different from the CCPA?

Key differences: Rhode Island's coverage threshold is 35,000 customers with no dollar floor, while California's CCPA uses a $25 million revenue trigger among its tests; Rhode Island requires opt-in consent for sensitive data while California uses an opt-out right to limit; Rhode Island does not require a universal opt-out signal while California does; Rhode Island uniquely requires controllers to identify all third parties to whom they sell or may sell data; and California has a limited private right of action for certain breaches while Rhode Island has none.

Who enforces the RIDTPPA?

The Rhode Island Attorney General has sole enforcement authority under section 6-48.1-8. A violation is a deceptive trade practice under R.I. Gen. Laws ch. 6-13.1, which authorizes the Attorney General to seek a civil penalty of up to $10,000 per violation under 6-13.1-8. Intentional disclosure of personal data in violation of the chapter carries an additional fine of not less than $100 and no more than $500 for each such disclosure under 6-48.1-8(a)(2). There is no private right of action and no statutory right to cure.

Updates

Corrected the attribution of the law’s January 1, 2026 effective date: it is set by the 2024 enacting acts for the whole chapter, not by section 6-48.1-4.

Corrected the RIDTPPA website-disclosure trigger to require collecting, storing, and selling personal data (not merely collecting it); added the for-profit-only scope and the nonprofit, higher-education, government, GLBA, and HIPAA exemptions to the applicability section; clarified that a violation is also a deceptive trade practice exposing violators to a civil penalty of up to $10,000, on top of the existing $100-$500 per-disclosure fine; and removed an unverifiable claim about how the law was enacted, keeping the confirmed June 2024 enactment date.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. R.I. Gen. Laws Chapter 6-48.1: Rhode Island Data Transparency and Privacy Protection Act (Section Index)(webserver.rilegislature.gov).gov
  2. R.I. Gen. Laws 6-48.1-1: Short title(webserver.rilegislature.gov).gov
  3. R.I. Gen. Laws 6-48.1-2: Definitions(webserver.rilegislature.gov).gov
  4. R.I. Gen. Laws 6-48.1-3: Information sharing practices(webserver.rilegislature.gov).gov
  5. R.I. Gen. Laws 6-48.1-4: Processing of information(webserver.rilegislature.gov).gov
  6. R.I. Gen. Laws 6-48.1-8: Violations(webserver.rilegislature.gov).gov
  7. Rhode Island Office of the Attorney General(riag.ri.gov).gov
  8. R.I. Gen. Laws 6-48.1-5: Customer rights(webserver.rilegislature.gov).gov
  9. R.I. Gen. Laws 6-48.1-6: Exercising customer rights(webserver.rilegislature.gov).gov
Share: