Rhode Island
Rhode Island Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Rhode Island has no standalone biometric privacy statute. Instead, the Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA), R.I. Gen. Laws Chapter 6-48.1, classifies biometric data as sensitive data and requires opt-in consent before businesses process it for identification purposes.
Rhode Island does not have a standalone biometric privacy statute like Illinois's BIPA or Texas's CUBI. Instead, biometric data protections in the state come from the Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA), a comprehensive consumer privacy law that classifies biometric identifiers as sensitive data requiring affirmative consent before processing.
Governor Daniel McKee signed House Bill 7787 into law on June 29, 2024, making Rhode Island one of the first 20 states to enact a comprehensive consumer data privacy law. The RIDTPPA took effect on January 1, 2026.
For an overview of Rhode Island's broader privacy framework, see the parent guide to Rhode Island Data Privacy Laws.

How the RIDTPPA Defines Biometric Data
The RIDTPPA defines biometric data under R.I. Gen. Laws 6-48.1-2 as data generated by automatic measurements of an individual's biological characteristics that are used to identify a specific individual. The statute lists these examples:
- Fingerprints
- Voiceprints
- Eye retinas
- Irises
- Other unique biological patterns or characteristics
The law draws a clear boundary around what does not qualify. A physical or digital photograph, a video recording, or an audio recording is not biometric data unless that data is specifically processed to identify a particular individual.
This definition follows the approach used in Connecticut, Kentucky, and several other state comprehensive privacy laws. It is narrower than the definition found in Illinois's BIPA, which covers a broader set of biometric identifiers.
Sensitive Data Classification and Consent Requirements
Under the RIDTPPA, biometric data processed for the purpose of uniquely identifying an individual qualifies as "sensitive data." This is the highest protection category in the law.
Other categories of sensitive data under R.I. Gen. Laws 6-48.1-2 include:
- Data revealing racial or ethnic origin
- Religious beliefs
- Mental or physical health conditions or diagnoses
- Sexual orientation
- Sex life
- Citizenship or immigration status
- Genetic data processed for identification
- Precise geolocation data (within 1,750 feet)
- Personal data collected from a known child under 13
Consent requirement. Controllers must obtain a customer's opt-in consent before processing sensitive data, including biometric data. Under R.I. Gen. Laws 6-48.1-4, a business cannot collect your fingerprint, faceprint, or iris scan for identification purposes without first obtaining your affirmative agreement.
This consent must be a "clear, affirmative act" that is freely given, specific, informed, and unambiguous. A buried clause in a terms-of-service agreement does not qualify. The statute specifically prohibits the use of dark patterns to obtain consent.
Consent revocation. Customers have the right to revoke their consent at any time. Once a customer withdraws consent, the controller must stop processing the biometric data as soon as practicable and no later than 15 days after receiving the revocation request.
Who Must Comply With the RIDTPPA
The RIDTPPA applies to for-profit entities that conduct business in Rhode Island or produce products or services targeted to Rhode Island residents and meet one of these thresholds:
- Process personal data of 35,000 or more Rhode Island customers during a calendar year (excluding data processed solely for payment transactions), or
- Process personal data of 10,000 or more Rhode Island customers and derive over 20% of gross revenue from the sale of personal data
The 35,000-customer threshold places Rhode Island at the lower end compared to states like Virginia and Colorado, which set their thresholds at 100,000 consumers. This means the RIDTPPA captures a broader range of businesses operating in the state.
Key Exemptions
The RIDTPPA carves out several categories of entities and data types from coverage:
Entity exemptions:
- Nonprofit organizations
- Government agencies and political subdivisions
- HIPAA-covered entities and their business associates
- Financial institutions subject to the Gramm-Leach-Bliley Act (GLBA)
- Higher education institutions
Data exemptions:
- Healthcare information regulated under HIPAA
- Financial data governed by the GLBA
- Data covered by the Fair Credit Reporting Act (FCRA)
- Data under the Family Educational Rights and Privacy Act (FERPA)
- Data regulated under the Driver's Privacy Protection Act (DPPA)
- Employment-related data collected in a commercial or employment context
The employee data exemption is significant for biometric privacy. If your employer collects fingerprints for timekeeping or uses facial recognition for building access, the RIDTPPA does not regulate that activity.

Customer Rights Over Biometric Data
The RIDTPPA grants Rhode Island customers several rights regarding their personal data, including biometric data. Under R.I. Gen. Laws 6-48.1-5, you have the right to:
- Confirm and access whether a controller is processing your biometric data
- Correct inaccuracies in your personal data
- Delete your personal data, including biometric identifiers
- Obtain a portable copy of your data in a readily usable format
- Opt out of the processing of personal data for targeted advertising, sale of data, or profiling
Controllers must respond to these requests without unreasonable delay. The law also prohibits discrimination against customers who exercise their rights.
Data Protection Assessments for Biometric Processing
Controllers must conduct and document data protection assessments for processing activities that present a heightened risk of harm to customers. Under R.I. Gen. Laws 6-48.1-7, this includes:
- Processing sensitive data (which includes biometric data)
- Processing personal data for targeted advertising
- Selling personal data
- Certain types of profiling that create foreseeable risks of unfair treatment or substantial customer injury
The law does not provide detailed guidance on what factors a controller should consider during these assessments. Data protection assessments conducted under other applicable laws (such as the GDPR or other state privacy laws) satisfy the RIDTPPA requirement if they are reasonably similar in scope.
This obligation applies only to processing activities that begin on or after January 1, 2026. It is not retroactive.
Transparency and Disclosure Requirements
The RIDTPPA imposes specific transparency obligations on controllers. Under R.I. Gen. Laws 6-48.1-3, businesses must:
- Identify all categories of personal data collected, including biometric data
- Disclose all third parties that receive personal data
- Clearly and conspicuously disclose when personal data is sold or used for targeted advertising
- Provide contact mechanisms for customer inquiries
- Make this information available in their customer agreement or another conspicuous location on their website
One notable and atypical feature of the RIDTPPA is the requirement to identify third parties to whom personally identifiable information has been sold or may be sold. Most state privacy laws only require disclosure of categories of third parties, not specific entities.

Enforcement and Penalties
The Rhode Island Attorney General holds exclusive enforcement authority under R.I. Gen. Laws 6-48.1-8. Key enforcement details include:
- Deceptive trade practice. A RIDTPPA violation is treated as a deceptive trade practice under R.I. Gen. Laws Chapter 6-13.1
- $100 to $500 for each disclosure when an individual or entity intentionally discloses personal data in violation of the chapter
- No private right of action. Individual consumers cannot file lawsuits under the RIDTPPA
- No mandatory cure period. Unlike many other state privacy laws, the RIDTPPA does not give businesses an opportunity to fix violations before penalties apply
The absence of a cure period is a significant departure from the approach taken by states like Virginia and Indiana, which provide 30-day or 60-day windows for businesses to remedy violations. Rhode Island's approach gives the Attorney General more flexibility to pursue enforcement actions immediately.
To file a complaint about potential biometric data violations, contact the Rhode Island Attorney General's Office.
Breach Notification Requirements for Biometric Data
Separate from the RIDTPPA, Rhode Island's Identity Theft Protection Act (R.I. Gen. Laws 11-49.3) requires notification when a security breach compromises unencrypted personal information.
Notification timelines:
- Private entities: No later than 45 calendar days after confirmation of the breach
- State and municipal agencies: No later than 30 calendar days after confirmation of the breach
- Attorney General notification: Required when more than 500 Rhode Island residents are affected
- Law enforcement reporting: State and municipal agencies must report cybersecurity incidents to Rhode Island State Police within 24 hours
Encryption standard. The law defines encryption as the transformation of data through the use of a 128-bit or higher algorithmic process into a form with a low probability of assigning meaning without use of a confidential process or key. Data protected by 128-bit or higher encryption is not considered "unencrypted" and does not trigger notification obligations if the encryption key was not also compromised.
Required notification content:
- Description of the incident, including how the breach occurred and the number of affected individuals
- Type of information compromised
- Date of breach or estimated timeframe
- Date the breach was discovered
- Description of remediation services offered
- Contact information for credit agencies, the Attorney General, and relevant service providers
- Information about filing police reports and obtaining security freezes
Remediation services for government breaches. When a state or municipal agency is responsible for a breach, it must provide affected adults with a minimum of five years of credit monitoring and identity theft protection coverage. For minors, coverage must extend until age 18, plus a minimum of two additional years.
How Rhode Island Compares to Other States
Rhode Island's biometric data protections fall into the "comprehensive privacy law" category alongside states like Connecticut, Colorado, and Virginia. Here is how the RIDTPPA stacks up on key provisions:
| Feature | Rhode Island | Illinois (BIPA) | Texas (CUBI) |
|---|---|---|---|
| Law type | Comprehensive privacy | Standalone biometric | Standalone biometric |
| Consent required | Opt-in for sensitive data | Written informed consent | Informed consent |
| Private right of action | No | Yes | No |
| Cure period | None | N/A | 30 days |
| Penalties | $100-$500 per intentional disclosure | $1,000-$5,000/violation | Up to $25,000/violation |
| Enforcement | AG only | Private + AG | AG only |
| Employee data covered | No | Yes | Yes |
The most significant gap in Rhode Island's framework compared to states with standalone biometric laws is the exclusion of employee data. Illinois's BIPA and Texas's CUBI both cover biometric data collected in the workplace, while the RIDTPPA exempts employment-context data entirely.
Sources and References
This article references Rhode Island statutes and official state government publications. For the full text of the RIDTPPA, visit the Rhode Island General Assembly website. For the Identity Theft Protection Act, see R.I. Gen. Laws Chapter 11-49.3. For guidance on filing complaints, visit the Rhode Island Attorney General.
This article provides general legal information about Rhode Island biometric privacy laws. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official Rhode Island government sources.
More Rhode Island Laws
Frequently Asked Questions
Does Rhode Island have a standalone biometric privacy law?
No. Rhode Island does not have a dedicated biometric privacy statute. Instead, the Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA), effective January 1, 2026, classifies biometric data as sensitive data within its comprehensive consumer privacy framework. The RIDTPPA requires businesses to obtain opt-in consent before processing biometric data for identification purposes, but it does not include the detailed retention, destruction, and private right of action provisions found in Illinois BIPA.
Can I sue a company in Rhode Island for collecting my biometric data without consent?
Not under the RIDTPPA. The Rhode Island Attorney General has exclusive enforcement authority, and the law does not include a private right of action. If you believe a company collected your biometric data without consent, you can file a complaint with the Rhode Island Attorney General's Office at riag.ri.gov. The AG can investigate and pursue fines of $100 to $500 for each intentional unlawful disclosure of personal data.
Does the RIDTPPA protect my biometric data at work?
No. The RIDTPPA exempts data collected in an employment context. If your employer collects fingerprints for timekeeping, uses facial recognition for building access, or requires biometric scans, the RIDTPPA does not regulate that activity. Rhode Island does not have a separate law governing employer use of biometric data. The breach notification law (R.I. Gen. Laws 11-49.3) does apply if an employer experiences a data breach involving personal information.
What encryption standard does Rhode Island require for protecting biometric data?
Rhode Island's Identity Theft Protection Act (R.I. Gen. Laws 11-49.3) defines encryption as the transformation of data through a 128-bit or higher algorithmic process. If biometric data is encrypted to this standard and the encryption key is not compromised during a breach, notification obligations are not triggered. The RIDTPPA separately requires controllers to implement reasonable administrative, technical, and physical data security practices to protect all personal data, including biometric identifiers.
How quickly must a company notify me of a biometric data breach in Rhode Island?
Private entities must notify affected Rhode Island residents no later than 45 calendar days after confirming the breach. State and municipal agencies face a shorter deadline of 30 calendar days. If more than 500 residents are affected, the entity must also notify the Rhode Island Attorney General. State agencies must additionally report cybersecurity incidents to the Rhode Island State Police within 24 hours.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected an unverified '$10,000 per violation' RIDTPPA penalty figure to the $100-$500-per-disclosure fine actually set out in R.I. Gen. Laws 6-48.1-8(a)(2), matching two sibling RI pages describing the same enforcement scheme.
Corrected the Attorney General breach-notification threshold from '500 or more' to 'more than 500' Rhode Island residents, matching R.I. Gen. Laws 11-49.3-4's actual trigger.
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 7 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
Rhode Island General Laws, Title 11: Criminal Offenses, Chapter 11-49.3: Identity Theft Protection Act of 2015
§ 11-49.3-4Notification of breachIn forcecited in 3 of our articles
(a)(1) Any municipal agency, state agency, or person who or that stores, owns, collects, processes, maintains, acquires, uses, or licenses data that includes personal information shall provide notification as set forth in this section of any disclosure of personal information, or any breach of the security of the system, that poses a significant risk of identity theft to any resident of Rhode Island whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person or entity. (2) The notification shall be made in the most expedient time possible, subject to the following: (i) For state and municipal agencies, no later than thirty (30) calendar days after confirmation of the breach and the ability to ascertain the information required to fulfill the notice requirements contained in subsection (d), and shall be consistent with the legitimate needs of law enforcement as provided in subsection (b).
Official text (excerpt) · as of 2026-07-30 · Read the full section at webserver.rilegislature.gov
Also relied on in: Rhode Island Data Privacy Laws: RIDTPPA Consumer Rights Guide (2026), Rhode Island Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Rhode Island General Laws, Title 6: Commercial Law
§ 6-48.1-2Definitions. [Effective January 1, 2026.]In forcecited in 5 of our articles
As used in this chapter: (1) “Affiliate” means any entity that shares common branding with another legal entity directly or indirectly, controls, is controlled by, or is under common control with another legal entity. For this purpose, “control” or “controlled” means ownership of, or the power to vote, more than fifty percent (50%) of the outstanding shares of any class of voting security of a company; control in any manner over the election of a majority of the directors or of individuals exercising similar functions; or the power to exercise controlling influence over the management of a company. (2) “Authenticate” means to use reasonable means to determine that a request to exercise any of the rights afforded under this chapter is being made by, or on behalf of, the customer who is entitled to exercise such customer rights with respect to the personal data at issue. (3) “Biometric data” means data generated by automatic measurements of an individual’s biological characteristics, such as a fingerprint, a voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that are used to identify a specific individual.
Official text (excerpt) · as of 2026-07-30 · Read the full section at webserver.rilegislature.gov
Also relied on in: RIDTPPA Consumer Rights in Rhode Island Explained, What Is the RIDTPPA? Rhode Island Data Privacy Act, Rhode Island Employee Monitoring Laws: Workplace Surveillance and Social Media (2026)
§ 6-48.1-3Information sharing practices. [Effective January 1, 2026.]In forcecited in 5 of our articles
(a) Any commercial website or internet service provider conducting business in Rhode Island or with customers in Rhode Island or otherwise subject to Rhode Island jurisdiction, shall designate a controller. If a commercial website or internet service provider collects, stores, and sells customers’ personally identifiable information, then the controller shall, in its customer agreement or incorporated addendum, or in another conspicuous location on its website or online service platform where similar notices are customarily posted: (1) Identify all categories of personal data that the controller collects through the website or online service about customers; (2) Identify all third parties to whom the controller has sold or may sell customers’ personally identifiable information; and (3) Identify an active electronic mail address or other online mechanism that the customer may use to contact the controller. (b) If a controller sells personal data to third parties or processes personal data for targeted advertising, the controller shall clearly and conspicuously disclose such processing.
Official text (excerpt) · as of 2026-07-30 · Read the full section at webserver.rilegislature.gov
Also relied on in: RIDTPPA Compliance Checklist for Rhode Island
§ 6-48.1-4Processing of information. [Effective January 1, 2026.]In forcecited in 5 of our articles
(a) This section shall apply to for-profit entities that conduct business in the state or for-profit entities that produce products or services that are targeted to residents of the state and that during the preceding calendar year did any of the following: (1) Controlled or processed the personal data of not less than thirty-five thousand (35,000) customers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction. (2) Controlled or processed the personal data of not less than ten thousand (10,000) customers and derived more than twenty percent (20%) of their gross revenue from the sale of personal data. (b) The controller shall establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data. (c) The controller shall not process sensitive data concerning a customer without obtaining customer consent and shall not process sensitive data of a known child unless consent is obtained and the information is processed in accordance with COPPA.
Official text (excerpt) · as of 2026-07-30 · Read the full section at webserver.rilegislature.gov
§ 6-48.1-5Customer rights. [Effective January 1, 2026.]In forcecited in 4 of our articles
(a) This section shall apply to for-profit entities that conduct business in the state or for-profit entities that produce products or services that are targeted to residents of the state and that during the preceding calendar year did any of the following: (1) Controlled or processed the personal data of not less than thirty-five thousand (35,000) customers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction. (2) Controlled or processed the personal data of not less than ten thousand (10,000) customers and derived more than twenty percent (20%) of their gross revenue from the sale of personal data. (b) No controller shall discriminate against a customer for exercising their customer rights. (c) No controller shall deny goods or services, charge different prices or rates for goods or services, or provide a different level of quality of goods or services to the customer if the customer opts out to use of their data. However, if a customer opts out of data collection, the covered entity is not required to provide a service that requires this data collection.
Official text (excerpt) · as of 2026-07-30 · Read the full section at webserver.rilegislature.gov
§ 6-48.1-7Controller and processor responsibilities. [Effective January 1, 2026.]In forcecited in 3 of our articles
(a) This section shall apply to for-profit entities that conduct business in the state or for-profit entities that produce products or services that are targeted to residents of the state and that during the preceding calendar year did any of the following: (1) Controlled or processed the personal data of not less than thirty-five thousand (35,000) customers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction. (2) Controlled or processed the personal data of not less than ten thousand (10,000) customers and derived more than twenty percent (20%) of their gross revenue from the sale of personal data. (b) A processor shall adhere to the instructions of a controller and shall assist the controller in meeting the controller’s obligations of this chapter. (c) A contract between a controller and a processor shall govern the processor’s data processing procedures with respect to processing performed on behalf of the controller.
Official text (excerpt) · as of 2026-07-30 · Read the full section at webserver.rilegislature.gov
§ 6-48.1-8Violations. [Effective January 1, 2026.]In forcecited in 5 of our articles
(a) A violation of this chapter constitutes a violation of the general regulatory provisions of commercial law in this title and shall constitute a deceptive trade practice in violation of chapter 13.1 of this title; provided, further, that in the event that any individual or entity intentionally discloses personal data: (1) To a shell company or any entity that has been formed or established solely, or in part, for the purposes of circumventing the intent of this chapter; or (2) In violation of any provision of this chapter, that individual or entity shall pay a fine of not less than one hundred dollars ($100) and no more than five hundred dollars ($500) for each such disclosure. (b) The attorney general shall have sole enforcement authority of the provisions of this chapter and may enforce a violation of this chapter pursuant to: (1) The provisions of this section; or (2) General regulatory provisions of commercial law in this title, or both. (c) Nothing in this section shall be construed to authorize any private right of action to enforce any provision of this chapter, any regulation hereunder, or any other provisions of law.
Official text (excerpt) · as of 2026-07-30 · Read the full section at webserver.rilegislature.gov
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)(rilegislature.gov).gov
- R.I. Gen. Laws 6-48.1-2 - RIDTPPA Definitions(rilegislature.gov).gov
- R.I. Gen. Laws 6-48.1-4 - Processing of Information(rilegislature.gov).gov
- R.I. Gen. Laws 6-48.1-5 - Customer Rights(rilegislature.gov).gov
- R.I. Gen. Laws 6-48.1-7 - Controller and Processor Responsibilities(rilegislature.gov).gov
- R.I. Gen. Laws 6-48.1-8 - Violations(rilegislature.gov).gov
- R.I. Gen. Laws 6-48.1-3 - Information Sharing Practices(rilegislature.gov).gov
- R.I. Gen. Laws 11-49.3-4 - Breach Notification(rilegislature.gov).gov
- H.B. 7787 Substitute A as Amended (Enrolled Bill)(rilegislature.gov).gov
- Rhode Island Attorney General - Complaint Form(riag.ri.gov).gov