Rhode Island
RIDTPPA Consumer Rights in Rhode Island Explained
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 7 primary sources cited on this page. How we verify our legal content

The Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA), R.I. Gen. Laws ch. 6-48.1, gives Rhode Island residents five core data rights as of its January 1, 2026 effective date: the right to confirm and access their personal data, correct inaccuracies, delete data, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and certain profiling. These rights live in section 6-48.1-5, and the process for exercising them is in section 6-48.1-6.
A controller must respond to a rights request within 45 days, with one possible 45-day extension, and must provide the information free of charge once per 12-month period. If a controller refuses a request, the customer can appeal, and the controller has 60 days to respond to that appeal. Enforcement is handled solely by the Rhode Island Attorney General; there is no private right of action under section 6-48.1-8.
Jurisdiction scope: This covers Rhode Island's Data Transparency and Privacy Protection Act (R.I. Gen. Laws ch. 6-48.1). It is general legal information, not legal advice.
The five core consumer rights under the RIDTPPA
Section 6-48.1-5 sets out the rights that Rhode Island customers can exercise against a covered controller. The statute uses the term "customer," defined in section 6-48.1-2 as an individual residing in Rhode Island acting in an individual or household context. Data about people acting in a commercial or employment context is generally outside that definition.
Coverage is narrower than the rights themselves suggest, and it is the first thing to check. Sections 6-48.1-4(a), 6-48.1-5(a) and 6-48.1-6(a) each apply only to for-profit entities that conduct business in Rhode Island, or that produce products or services targeted to Rhode Island residents, and that during the preceding calendar year did one of two things: controlled or processed the personal data of at least 35,000 customers, excluding personal data controlled or processed solely to complete a payment transaction; or controlled or processed the personal data of at least 10,000 customers while deriving more than 20 percent of gross revenue from the sale of personal data.
A business below both thresholds is not subject to the access, correction, deletion, portability, opt-out, or sensitive-data consent requirements described below, so a request to that business carries no statutory response duty. Many businesses a Rhode Island resident deals with day to day, and every nonprofit, fall outside those sections. The transparency duty in section 6-48.1-3, covered further down this page, is the exception: it carries no customer-count threshold.
The first right is confirmation and access. A customer may confirm whether a controller is processing the customer's personal data and access that data. This is the entry point for the other rights, because it lets a person see what a business holds before deciding what to do about it.
The second and third rights are correction and deletion. A customer may correct inaccuracies in the customer's personal data, taking into account the nature of the data and the purposes of processing, and may delete personal data "provided by, or obtained about," the customer. The deletion right reaches both data a customer supplied directly and data the controller gathered from other sources.
The fourth right is data portability. A customer may obtain a copy of personal data the controller processes in a portable and, to the extent technically feasible, readily usable format that allows the customer to transmit the data to another controller without undue delay, where the processing is carried out by automated means.
The opt-out rights: advertising, sale, and profiling
The fifth right under section 6-48.1-5 is the opt-out, and it has three parts. A customer may opt out of the processing of personal data for purposes of targeted advertising. A customer may opt out of the sale of personal data. And a customer may opt out of profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the customer.
The definition of "sale" matters for the second opt-out. Under section 6-48.1-2, a sale is the exchange of personal data for monetary or other valuable consideration by the controller to a third party. The "other valuable consideration" language means a sale is not limited to cash transactions, though the statute lists exclusions for transfers to processors, affiliates, and certain transactions.
Profiling that triggers the third opt-out is narrow. It applies to solely automated decisions that produce legal or similarly significant effects, the kind of automated decision-making that determines access to things like credit, housing, employment, insurance, or essential services. Routine personalization that does not produce a legally significant effect falls outside this opt-out.
Rhode Island differs from several newer state laws in one respect: it does not require controllers to honor a universal opt-out preference signal. Section 6-48.1-5(f) allows a customer to use an authorized agent to exercise the opt-out rights on the customer's behalf, but the statute does not mandate recognition of a browser-level signal such as the Global Privacy Control. Customers exercise opt-outs through whatever mechanism the controller provides.

How to exercise your rights: the request process
Section 6-48.1-6 governs how a controller must handle and respond to a request. The submission channel itself comes from section 6-48.1-5(f): a customer exercises these rights by secure and reliable means established by the controller and described to the customer in the controller's privacy notice.
A controller must respond to a request without undue delay, but not later than 45 days after receipt. The controller may extend the response period by 45 additional days when reasonably necessary, taking into account the complexity and number of requests, and must tell the customer about any extension within the initial 45-day window along with the reason for the delay.
Information provided in response to a request must be free of charge once per customer during any 12-month period. If requests from a customer are manifestly unfounded, excessive, or repetitive, the controller may either charge a reasonable fee to cover administrative costs or decline to act, but the controller bears the burden of demonstrating that the request meets that standard.
Authentication is built into the process. Under section 6-48.1-6(b)(4), if a controller is unable to authenticate a request, it is not required to comply, but it must notify the customer that it cannot authenticate the request until the customer supplies the additional information reasonably necessary to authenticate the customer and the request. One exception is important: a controller is not required to authenticate an opt-out request, which keeps the opt-out low-friction, though it may deny an opt-out request it has a reasonable and documented belief is fraudulent, with notice of that belief to the person who submitted it.
The appeal right
If a controller declines to act on a request, the customer is not without recourse. Section 6-48.1-6 requires a controller to establish a process for a customer to appeal the controller's refusal to take action within a reasonable period after the customer receives the decision. The appeal process must be clearly and conspicuously available.
Not later than 60 days after receipt of an appeal, the controller must inform the customer in writing of any action taken or not taken in response, along with a written explanation of the reasons supporting the decision. If the appeal is denied, the customer may submit a complaint to the Rhode Island Attorney General.
This appeal-to-regulator pathway is how individual complaints reach the enforcer. Because there is no private right of action under section 6-48.1-8, the Attorney General complaint channel is the practical route for a customer who believes a controller mishandled a request.

The transparency disclosures consumers can rely on
Beyond the request rights, Rhode Island customers benefit from the RIDTPPA's distinctive transparency duty in section 6-48.1-3. Any commercial website or internet service provider conducting business in Rhode Island, or with customers in Rhode Island, or otherwise subject to Rhode Island jurisdiction, and that collects, stores, and sells customers' personally identifiable information, must publish three things customers can read before deciding whether to exercise their rights. Unlike the rights sections, this duty is not limited to businesses above a customer-count threshold.
The controller must identify all of the categories of personal data it collects through the site or service. The controller must identify all third parties to whom it has sold or may sell customers' personally identifiable information. And the controller must provide an active means for a customer to contact it about its data practices.
The second disclosure is unusual. Most state privacy laws ask only for the categories of third parties a controller shares data with. Rhode Island's text requires the controller to "identify all third parties" to whom it has sold or may sell data, a more granular disclosure that gives customers a clearer picture of where their information may go. A controller that sells personal data or processes it for targeted advertising must also clearly and conspicuously disclose that processing under section 6-48.1-3.
Sensitive data and consent rights
Customers also have consent-based protection for sensitive data. Under section 6-48.1-4, a controller may not process a customer's sensitive data without obtaining the customer's consent, and may not process the sensitive data of a known child except with consent and in accordance with the federal Children's Online Privacy Protection Act. Like the rights sections, section 6-48.1-4 reaches only for-profit entities that clear the 35,000-customer or 10,000-customer-plus-20-percent-revenue threshold.
Sensitive data is defined broadly in section 6-48.1-2. It includes data revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis, sex life, sexual orientation, or citizenship or immigration status, as well as genetic or biometric data used to identify a person, data collected from a known child, and precise geolocation data.
Consent must be revocable. Section 6-48.1-4 requires a controller to provide customers with a mechanism to grant and revoke consent, and the controller must stop processing as soon as is practicable and no later than 15 days after receiving a revocation. That makes the sensitive-data consent right a continuing one rather than a one-time choice.
Related guides
- Rhode Island data privacy laws parent hub
- What is the RIDTPPA?
- RIDTPPA compliance checklist
- State data privacy law comparison
- What is the CCPA?
More Rhode Island Laws
Frequently Asked Questions
What rights do I have under the RIDTPPA?
Under R.I. Gen. Laws 6-48.1-5, Rhode Island customers can confirm and access their personal data, correct inaccuracies, delete data provided by or obtained about them, obtain a portable copy of their data, and opt out of targeted advertising, the sale of personal data, and profiling in furtherance of solely automated decisions that produce legal or similarly significant effects. These rights took effect January 1, 2026.
Do these rights apply to every business I deal with?
No. Sections 6-48.1-4(a), 6-48.1-5(a) and 6-48.1-6(a) apply only to for-profit entities that do business in Rhode Island or target products or services to Rhode Island residents and that, during the preceding calendar year, either controlled or processed the personal data of at least 35,000 customers, excluding data handled solely to complete a payment transaction, or controlled or processed the personal data of at least 10,000 customers while deriving more than 20 percent of gross revenue from selling personal data. A business below both thresholds has no duty to answer an access, deletion, or opt-out request. The separate transparency duty in section 6-48.1-3 has no such threshold.
How long does a company have to respond to my RIDTPPA request?
Under section 6-48.1-6, a controller must respond without undue delay and no later than 45 days after receiving the request. It may extend that period once by 45 additional days when reasonably necessary, and must notify you of the extension and the reason within the first 45 days.
Is there a fee to exercise my Rhode Island data privacy rights?
No, not in most cases. Section 6-48.1-6 requires a controller to provide the requested information free of charge once per customer during any 12-month period. A controller may charge a reasonable fee or decline only if it can show the request is manifestly unfounded, excessive, or repetitive.
Can I appeal if a company refuses my RIDTPPA request?
Yes. Section 6-48.1-6 requires controllers to establish an appeal process that is clearly and conspicuously available. The controller must respond to your appeal in writing within 60 days, explaining its decision. If the appeal is denied, you may submit a complaint to the Rhode Island Attorney General. The statute does not require the controller to build a complaint mechanism for you.
Can I opt out of having my data sold under the RIDTPPA?
Yes. Section 6-48.1-5 gives you the right to opt out of the sale of your personal data, along with the right to opt out of targeted advertising and certain automated profiling. Under section 6-48.1-2, a sale is the exchange of personal data for monetary or other valuable consideration, so it is not limited to cash transactions.
Does Rhode Island recognize a universal opt-out signal like Global Privacy Control?
No. As of 2026, the RIDTPPA does not require controllers to honor a universal opt-out preference signal. Section 6-48.1-5(f) allows you to use an authorized agent to exercise an opt-out on your behalf, but you must use the opt-out mechanism the controller provides rather than relying on a browser-level signal.
What must a website tell me about who it shares my data with?
Under section 6-48.1-3, a commercial website or internet service provider conducting business in Rhode Island, or with customers in Rhode Island, or otherwise subject to Rhode Island jurisdiction, that collects, stores, and sells your personally identifiable information must identify all categories of personal data it collects and identify all third parties to whom it has sold or may sell your personally identifiable information, plus give you an active way to contact the controller. This third-party naming duty is more specific than most other state privacy laws.
What can I do if a company ignores my RIDTPPA rights?
The RIDTPPA has no private right of action under section 6-48.1-8, so you cannot sue the company directly. Instead, after exhausting the controller's appeal process, you can submit a complaint to the Rhode Island Attorney General, who has sole authority to enforce the law and treat violations as deceptive trade practices.
Updates
Added the RIDTPPA business-size thresholds that determine which companies must honor these rights, corrected the authentication and appeal standards to the statute’s actual wording, fixed the section citation for how requests are submitted, and corrected the description of who the section 6-48.1-3 transparency duty covers.
Corrected the trigger for RIDTPPA's website transparency disclosure (it applies only to sites that collect, store, and sell personal data, not any site that merely collects it), removed two requirements not found in the statute (a 'normal interaction' authentication standard and a controller-provided online AG-complaint mechanism), and fixed a misquoted portability standard (the statute says 'without undue delay,' not 'without hindrance').
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Removed an invented 'at least as easy as it was given' consent-revocation requirement not present in R.I. Gen. Laws 6-48.1-4(e), which requires only a revocation mechanism and a 15-day compliance window.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Rhode Island General Laws, Title 6: Commercial Law
§ 6-48.1-5Customer rights. [Effective January 1, 2026.]In forcecited in 7 of our articles
(a) This section shall apply to for-profit entities that conduct business in the state or for-profit entities that produce products or services that are targeted to residents of the state and that during the preceding calendar year did any of the following: (1) Controlled or processed the personal data of not less than thirty-five thousand (35,000) customers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction. (2) Controlled or processed the personal data of not less than ten thousand (10,000) customers and derived more than twenty percent (20%) of their gross revenue from the sale of personal data. (b) No controller shall discriminate against a customer for exercising their customer rights. (c) No controller shall deny goods or services, charge different prices or rates for goods or services, or provide a different level of quality of goods or services to the customer if the customer opts out to use of their data. However, if a customer opts out of data collection, the covered entity is not required to provide a service that requires this data collection.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at webserver.rilegislature.gov
Also relied on in: Rhode Island Data Privacy Laws: RIDTPPA Consumer Rights Guide (2026), Rhode Island Biometric Privacy Laws: Collection, Consent & Penalties (2026), RIDTPPA Compliance Checklist for Rhode Island
§ 6-48.1-6Exercising customer rights. [Effective January 1, 2026.]In forcecited in 6 of our articles
(a) This section shall apply to for-profit entities that conduct business in the state or for-profit entities that produce products or services that are targeted to residents of the state and that during the preceding calendar year did any of the following: (1) Controlled or processed the personal data of not less than thirty-five thousand (35,000) customers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction. (2) Controlled or processed the personal data of not less than ten thousand (10,000) customers and derived more than twenty percent (20%) of their gross revenue from the sale of personal data. (b) A controller shall comply with a request by a customer to exercise the customer rights authorized as follows: (1) A controller shall respond to the customer without undue delay, but not later than forty-five (45) days after receipt of the request.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at webserver.rilegislature.gov
Also relied on in: How to Request Your Personal Data: US Privacy Rights by State, What Is the RIDTPPA? Rhode Island Data Privacy Act
§ 6-48.1-2Definitions. [Effective January 1, 2026.]In forcecited in 5 of our articles
As used in this chapter: (1) “Affiliate” means any entity that shares common branding with another legal entity directly or indirectly, controls, is controlled by, or is under common control with another legal entity. For this purpose, “control” or “controlled” means ownership of, or the power to vote, more than fifty percent (50%) of the outstanding shares of any class of voting security of a company; control in any manner over the election of a majority of the directors or of individuals exercising similar functions; or the power to exercise controlling influence over the management of a company. (2) “Authenticate” means to use reasonable means to determine that a request to exercise any of the rights afforded under this chapter is being made by, or on behalf of, the customer who is entitled to exercise such customer rights with respect to the personal data at issue. (3) “Biometric data” means data generated by automatic measurements of an individual’s biological characteristics, such as a fingerprint, a voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that are used to identify a specific individual.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at webserver.rilegislature.gov
Also relied on in: Rhode Island Employee Monitoring Laws: Workplace Surveillance and Social Media (2026)
§ 6-48.1-3Information sharing practices. [Effective January 1, 2026.]In forcecited in 5 of our articles
(a) Any commercial website or internet service provider conducting business in Rhode Island or with customers in Rhode Island or otherwise subject to Rhode Island jurisdiction, shall designate a controller. If a commercial website or internet service provider collects, stores, and sells customers’ personally identifiable information, then the controller shall, in its customer agreement or incorporated addendum, or in another conspicuous location on its website or online service platform where similar notices are customarily posted: (1) Identify all categories of personal data that the controller collects through the website or online service about customers; (2) Identify all third parties to whom the controller has sold or may sell customers’ personally identifiable information; and (3) Identify an active electronic mail address or other online mechanism that the customer may use to contact the controller. (b) If a controller sells personal data to third parties or processes personal data for targeted advertising, the controller shall clearly and conspicuously disclose such processing.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at webserver.rilegislature.gov
§ 6-48.1-4Processing of information. [Effective January 1, 2026.]In forcecited in 5 of our articles
(a) This section shall apply to for-profit entities that conduct business in the state or for-profit entities that produce products or services that are targeted to residents of the state and that during the preceding calendar year did any of the following: (1) Controlled or processed the personal data of not less than thirty-five thousand (35,000) customers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction. (2) Controlled or processed the personal data of not less than ten thousand (10,000) customers and derived more than twenty percent (20%) of their gross revenue from the sale of personal data. (b) The controller shall establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data. (c) The controller shall not process sensitive data concerning a customer without obtaining customer consent and shall not process sensitive data of a known child unless consent is obtained and the information is processed in accordance with COPPA.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at webserver.rilegislature.gov
§ 6-48.1-8Violations. [Effective January 1, 2026.]In forcecited in 5 of our articles
(a) A violation of this chapter constitutes a violation of the general regulatory provisions of commercial law in this title and shall constitute a deceptive trade practice in violation of chapter 13.1 of this title; provided, further, that in the event that any individual or entity intentionally discloses personal data: (1) To a shell company or any entity that has been formed or established solely, or in part, for the purposes of circumventing the intent of this chapter; or (2) In violation of any provision of this chapter, that individual or entity shall pay a fine of not less than one hundred dollars ($100) and no more than five hundred dollars ($500) for each such disclosure. (b) The attorney general shall have sole enforcement authority of the provisions of this chapter and may enforce a violation of this chapter pursuant to: (1) The provisions of this section; or (2) General regulatory provisions of commercial law in this title, or both. (c) Nothing in this section shall be construed to authorize any private right of action to enforce any provision of this chapter, any regulation hereunder, or any other provisions of law.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at webserver.rilegislature.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- R.I. Gen. Laws 6-48.1-5: Customer rights(webserver.rilegislature.gov).gov
- R.I. Gen. Laws 6-48.1-6: Exercising customer rights(webserver.rilegislature.gov).gov
- R.I. Gen. Laws 6-48.1-3: Information sharing practices(webserver.rilegislature.gov).gov
- R.I. Gen. Laws 6-48.1-4: Processing of information(webserver.rilegislature.gov).gov
- R.I. Gen. Laws 6-48.1-2: Definitions(webserver.rilegislature.gov).gov
- R.I. Gen. Laws 6-48.1-8: Violations(webserver.rilegislature.gov).gov
- Rhode Island Office of the Attorney General(riag.ri.gov).gov