EnglishEspañol
Tennessee flag

Tennessee

TIPA Compliance Checklist: Tennessee Privacy Law

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 3 primary sources cited on this page. How we verify our legal content

TIPA Compliance Checklist: Tennessee Privacy Law

Frequently Asked Questions

How do I know if my business has to comply with the TIPA?

Under 47-18-3202, TIPA applies only if your business conducts business in Tennessee producing products or services that target Tennessee residents and exceeds $25,000,000 in revenue AND either processes the data of 175,000-plus consumers, or 25,000-plus consumers with more than 50 percent of gross revenue from selling personal information. That scope clause is conjunctive, so operating in the state and targeting its residents are both required, and on top of that both the revenue gate and a data trigger must be met. Check the 47-18-3210 exemptions too, which exclude GLBA financial institutions, HIPAA entities, nonprofits, and higher-education institutions.

What is the NIST Privacy Framework affirmative defense and how do I get it?

Under 47-18-3213(a), a controller or processor that creates, maintains, and complies with a written privacy policy reasonably conforming to the NIST Privacy Framework (Version 1.0), or to other documented policies, standards, and procedures designed to safeguard consumer privacy, has an affirmative defense to a TIPA claim. NIST is the framework the statute names, but it is not the only route. To earn the defense, document the program, provide consumers their TIPA rights, and update it within two years of a revision to the NIST or comparable framework. Under 47-18-3213(c), APEC Cross Border Privacy Rules and Privacy Recognition for Processors certifications may be considered as well. No other state privacy law offers this defense.

Does a small business have to build the same NIST program as a large one?

No. Under 47-18-3213(b), the appropriate scale and scope of the program depends on the size and complexity of the business, the nature and scope of its activities, the sensitivity of the data it processes, the cost and availability of tools, and compliance with comparable laws. A smaller covered business is not held to the same program as a large data broker. Document how your program maps to those five factors.

What has to be in a TIPA privacy notice?

Under 47-18-3204(c), the notice must state the categories of personal information processed, the purpose for processing, how consumers exercise and appeal their rights, the categories of personal information sold to third parties if any, the categories of third parties sold to if any, and the right to opt out of sale plus the ability to request deletion or correction. If you sell data or run targeted advertising, 47-18-3204(d) requires a clear and conspicuous disclosure and opt-out method.

Do I need consent to process sensitive data under the TIPA?

Yes. Under 47-18-3204(a)(6), you may not process sensitive data without first obtaining the consumer's consent, an opt-in rule. Build a consent mechanism that captures a clear affirmative, freely given, specific, informed, and unambiguous agreement. Sensitive data under 47-18-3201 includes race or ethnicity, religion, health diagnosis, sexual orientation, immigration status, genetic or biometric identifiers, a known child's data, and precise geolocation.

When do I have to conduct a data protection assessment?

Under 47-18-3206(a), you must conduct and document a data protection assessment for targeted advertising, the sale of personal information, profiling that poses a foreseeable risk of harm, the processing of sensitive data, and any processing that presents a heightened risk of harm. The assessment weighs the benefits of the processing against the risks to consumers. The Attorney General can request these during an investigation, and they stay confidential and privileged.

What is the TIPA cure period and does it expire?

Under 47-18-3212(b), the Attorney General must give 60 days' written notice before suing, and if the business cures the violation and certifies in writing that it will not recur, the AG may not bring an action. This 60-day cure period is permanent, with no sunset date, which differs from states whose cure windows expire. There is no private right of action under 47-18-3212(e).

What are the penalties for violating the TIPA?

Under 47-18-3212(d)(1), a court may impose a civil penalty of up to $7,500 per violation. Under 47-18-3212(d)(2), a court may award treble damages for willful or knowing violations. The Attorney General may also recover attorney fees and investigative costs. A conforming written privacy policy under 47-18-3213 supplies an affirmative defense.

Updates

Corrected the TIPA applicability test to the conjunctive wording of Tenn. Code Ann. 47-18-3202 and clarified that the 47-18-3213 affirmative defense can rest on other documented privacy policies, standards, and procedures, not only the NIST Privacy Framework.

Corrected the TIPA affirmative-defense citations: the earlier version pointed to a nonexistent code section (47-18-3214) and misstated the NIST-revision update window as one year, the five-factor scale test's subsection letter, the request-channel requirement, and the civil-penalty multiplier; all now match the enacted Public Chapter 408 text.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Tennessee Public Chapter 408 (2023): Tennessee Information Protection Act (Enacted Text)(publications.tnsosfiles.com)
  2. Tennessee General Assembly: HB 1181 Bill Page and Public Chapter 408(wapp.capitol.tn.gov).gov
  3. Tennessee Attorney General: Tips and Guidelines on the Tennessee Information Protection Act (Apr. 30, 2025)(tn.gov).gov
  4. NIST Privacy Framework: A Tool for Improving Privacy through Enterprise Risk Management, Version 1.0(nist.gov).gov
  5. Tenn. Code Ann. 47-18-3213: Written Privacy Program (NIST Privacy Framework)(publications.tnsosfiles.com)
  6. Tenn. Code Ann. 47-18-3213: Affirmative Defense (Voluntary Privacy Program)(publications.tnsosfiles.com)
  7. Tenn. Code Ann. 47-18-3206: Data Protection Assessments(publications.tnsosfiles.com)
  8. Tenn. Code Ann. 47-18-3205: Controller and Processor Contract Requirements(publications.tnsosfiles.com)
  9. Tenn. Code Ann. 47-18-3212: Enforcement, 60-Day Cure, Civil Penalty, and Treble Damages(publications.tnsosfiles.com)
Share: