EnglishEspañol
Tennessee flag

Tennessee

What Is the TIPA? Tennessee Information Protection Act

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 3 primary sources cited on this page. How we verify our legal content

What Is the TIPA? Tennessee Information Protection Act

Frequently Asked Questions

What is the TIPA?

The TIPA, or Tennessee Information Protection Act, is Tennessee's comprehensive consumer data privacy law codified at Tenn. Code Ann. 47-18-3201 to 47-18-3213. It was enacted as House Bill 1181 (Public Chapter 408), signed by Governor Bill Lee on May 24, 2023, and took effect July 1, 2025. It gives Tennessee residents rights over their personal information and requires covered businesses to be transparent about how they collect, use, and disclose it.

When did the TIPA take effect?

TIPA took effect July 1, 2025, more than two years after it was signed on May 24, 2023. The long runway gave covered businesses time to build privacy programs before their obligations began. As of 2026, the effective date has passed and every covered business is fully subject to the law.

Who has to comply with the TIPA?

Under 47-18-3202, TIPA applies only to a business that conducts business in Tennessee producing products or services that target Tennessee residents and that exceeds $25,000,000 in revenue AND either controls or processes the data of 175,000-plus consumers, or 25,000-plus consumers while deriving more than 50 percent of gross revenue from selling personal information. Tennessee joined the conducting-business and targeting elements rather than offering them as alternatives, and both the revenue gate and a data trigger must also be met, so the coverage bar is among the highest in the country.

What is the NIST Privacy Framework affirmative defense?

Section 47-18-3213 is titled Affirmative defense - Voluntary privacy program, and adopting such a program is optional rather than required. A controller or processor that creates, maintains, and complies with a written privacy policy has an affirmative defense to a TIPA claim if that policy reasonably conforms to the NIST Privacy Framework (A Tool for Improving Privacy through Enterprise Risk Management, Version 1.0) or to other documented policies, standards, and procedures designed to safeguard consumer privacy, and provides consumers the substantive rights TIPA requires. The program's scale turns on the size and sensitivity of the business. No other state privacy law offers this defense as of 2026.

Does the TIPA require consent for sensitive data?

Yes. Under 47-18-3204(a)(6), a controller may not process sensitive data without first obtaining the consumer's consent, an opt-in model. Sensitive data under 47-18-3201 includes data revealing racial or ethnic origin, religious beliefs, a health diagnosis, sexual orientation, or immigration status, plus genetic or biometric data used to identify a person, a known child's data, and precise geolocation.

What rights do Tennessee consumers have under the TIPA?

Under 47-18-3203, Tennessee consumers can confirm whether a controller is processing their data and access it, correct inaccuracies, delete their data, obtain a portable copy, and opt out of the sale of personal information, targeted advertising, and profiling in furtherance of decisions producing legal or similarly significant effects. Controllers must respond within 45 days and offer an appeal process.

How is the TIPA different from the CCPA?

TIPA's thresholds are conjunctive (a business must exceed $25M revenue AND meet a data trigger), while the CCPA's are disjunctive (any one trigger suffices), so TIPA covers far fewer businesses. TIPA offers a voluntary privacy program affirmative defense, available under the NIST Privacy Framework or a comparable documented standard, that California does not. TIPA requires opt-in consent for sensitive data, while California uses an opt-out right to limit. And TIPA has no private right of action, while California allows a limited one for certain breaches.

Who enforces the TIPA?

The Tennessee Attorney General and Reporter has exclusive enforcement authority under 47-18-3212. There is no private right of action. Before suing, the AG must give a 60-day written notice and cure opportunity, and that cure period is permanent with no sunset. Civil penalties run up to $7,500 per violation, and a court may award treble damages for willful or knowing violations.

Updates

Corrected our description of Tenn. Code Ann. 47-18-3213: the written privacy program is voluntary rather than required, it may follow the NIST Privacy Framework or other comparable documented standards, a non-existent commercial-purposes requirement has been removed, the scope clause of 47-18-3202 is now stated conjunctively as enacted, and the signing date has been corrected to May 24, 2023.

Corrected the TIPA statute citations throughout the page: the affirmative-defense provision and the written-privacy-program requirement are both in Tenn. Code Ann. 47-18-3213, not a nonexistent '47-18-3214'; the NIST revision-conformance window is two years, not one; the scale-and-scope factors are in subsection (b), not (c); and the private-right-of-action bar is in 47-18-3212(e), not (h). Also fixed two stale citation links (an as-introduced bill PDF and a session-unqualified bill page) to point to the enacted Public Chapter 408 text.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Tennessee Public Chapter 408 (2023): Tennessee Information Protection Act (Enacted Text)(publications.tnsosfiles.com)
  2. Tennessee General Assembly: HB 1181 Bill Page and Public Chapter 408(wapp.capitol.tn.gov).gov
  3. Tennessee Attorney General: Tips and Guidelines on the Tennessee Information Protection Act (Apr. 30, 2025)(tn.gov).gov
  4. NIST Privacy Framework: A Tool for Improving Privacy through Enterprise Risk Management, Version 1.0(nist.gov).gov
  5. Tenn. Code Ann. 47-18-3202: Scope and Applicability Thresholds(publications.tnsosfiles.com)
  6. Tenn. Code Ann. 47-18-3213: Written Privacy Program (NIST Privacy Framework)(publications.tnsosfiles.com)
  7. Tenn. Code Ann. 47-18-3213: Affirmative Defense (Voluntary Privacy Program)(publications.tnsosfiles.com)
  8. Tenn. Code Ann. 47-18-3212: Attorney General Enforcement, Cure Period, and Civil Penalties(publications.tnsosfiles.com)
Share: