EnglishEspañol
Rhode Island flag

Rhode Island

RIDTPPA Compliance Checklist for Rhode Island

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 7 primary sources cited on this page. How we verify our legal content

RIDTPPA Compliance Checklist for Rhode Island

Frequently Asked Questions

Who has to comply with the RIDTPPA?

Under R.I. Gen. Laws 6-48.1-4, the RIDTPPA applies to a for-profit business that conducts business in Rhode Island or targets Rhode Island residents and that, during the preceding calendar year, controlled or processed the personal data of 35,000 or more customers, or of 10,000 or more customers while deriving more than 20 percent of gross revenue from the sale of personal data. The 35,000 threshold excludes data processed solely to complete a payment transaction. Because coverage looks back to the prior year, crossing a threshold for the first time this year brings you in next year.

What is the RIDTPPA website disclosure requirement?

Section 6-48.1-3 requires a commercial website or internet service provider that collects, stores, and sells personal data to designate a controller and to identify all categories of personal data it collects, identify all third parties to whom it has sold or may sell customers' personally identifiable information, and provide an active electronic mail address or other online mechanism for contacting the controller. The duty to name third parties rather than just describe categories is the law's signature compliance step.

What are the RIDTPPA penalties?

Under section 6-48.1-8, violations are deceptive trade practices under R.I. Gen. Laws ch. 6-13.1. A person who intentionally discloses personal data in violation of the chapter, or to a shell company formed to circumvent it, faces a civil penalty of not less than $100 and not more than $500 for each such disclosure. The Attorney General enforces, and penalties can scale with the number of records involved.

Does the RIDTPPA have a right to cure?

No. As of 2026, the RIDTPPA does not provide a statutory right to cure. Section 6-48.1-8 gives the Attorney General sole enforcement authority without a guaranteed grace period, so a covered business should build compliance before a complaint arises rather than relying on time to fix violations afterward.

How quickly must a business answer a RIDTPPA request?

Under section 6-48.1-6, a controller must respond without undue delay and no later than 45 days after receiving a request, with one possible 45-day extension when reasonably necessary. Information must be provided free of charge once per customer in any 12-month period, and appeals must be answered in writing within 60 days.

Does the RIDTPPA require recognizing a universal opt-out signal?

No. The RIDTPPA does not require controllers to honor a universal opt-out preference signal such as the Global Privacy Control. Section 6-48.1-6 allows authorized agents to submit opt-out requests, but there is no statutory mandate to recognize a browser-level signal, which is one reason the law is considered lighter-touch than the Colorado or Connecticut models.

When does sensitive data require opt-in consent in Rhode Island?

Always, when the data falls within the definition. Section 6-48.1-4 prohibits processing a customer's sensitive data without consent. Section 6-48.1-2 defines sensitive data to include health, racial or ethnic origin, religious beliefs, sex life, sexual orientation, immigration status, genetic or biometric identifiers, a known child's data, and precise geolocation. Consent must be revocable, with revocation honored within 15 days.

Do I need processor contracts under the RIDTPPA?

Yes. Section 6-48.1-7 requires a written contract with any processor that handles personal data on your behalf. The contract must address processing instructions, the nature and purpose of processing, the data type, the duration, confidentiality, subcontractor flow-down, and cooperation with assessments. You must also document a data protection assessment for higher-risk processing such as targeted advertising, data sales, certain profiling, and sensitive data.

Updates

Corrected the RIDTPPA coverage test to the statute's preceding-calendar-year measuring period, replaced 'internet service application' with the statutory term 'internet service provider' in the section 6-48.1-3 disclosure duty, and corrected the appeal section: Rhode Island requires a written 60-day appeal response but does not require controllers to provide an Attorney General complaint channel.

Clarified that RIDTPPA's core obligations apply only to for-profit entities and added the nonprofit, higher-education, and securities-association exemptions; corrected the website-disclosure trigger to require collecting, storing, and selling data rather than merely collecting it; and clarified that authenticating an opt-out request is optional for a business, not prohibited.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. R.I. Gen. Laws 6-48.1-3: Information sharing practices(webserver.rilegislature.gov).gov
  2. R.I. Gen. Laws 6-48.1-4: Processing of information(webserver.rilegislature.gov).gov
  3. R.I. Gen. Laws 6-48.1-5: Customer rights(webserver.rilegislature.gov).gov
  4. R.I. Gen. Laws 6-48.1-6: Exercising customer rights(webserver.rilegislature.gov).gov
  5. R.I. Gen. Laws 6-48.1-7: Controller and processor responsibilities(webserver.rilegislature.gov).gov
  6. R.I. Gen. Laws 6-48.1-8: Violations(webserver.rilegislature.gov).gov
  7. Rhode Island Office of the Attorney General(riag.ri.gov).gov
Share: