Rhode Island
What Is the RIDTPPA? Rhode Island Data Privacy Act
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 9 primary sources cited on this page. How we verify our legal content

The Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA), codified at R.I. Gen. Laws ch. 6-48.1, is Rhode Island's first comprehensive consumer data privacy law. It was enacted in 2024 through companion bills H 7787 and S 2500, became law in June 2024, and takes effect on January 1, 2026. The law gives Rhode Island residents rights to access, correct, delete, and port their personal data and to opt out of targeted advertising, data sales, and certain profiling.
As of 2026, the RIDTPPA is enforced exclusively by the Rhode Island Attorney General. A violation is a deceptive trade practice under R.I. Gen. Laws ch. 6-13.1, which exposes a violator to a civil penalty of up to $10,000 per violation under 6-13.1-8, in addition to the $100 to $500 fine that 6-48.1-8(a)(2) sets for each intentional disclosure made in violation of the chapter. There is no private right of action and no statutory right to cure, so a covered business does not get a guaranteed grace period to fix a violation before the Attorney General can act.
Jurisdiction scope: This covers Rhode Island's Data Transparency and Privacy Protection Act (R.I. Gen. Laws ch. 6-48.1). It is general legal information, not legal advice.
What the RIDTPPA is: statute, enactment, and effective date
The Rhode Island Data Transparency and Privacy Protection Act is Rhode Island's first omnibus consumer privacy statute. It is codified in the General Laws at chapter 6-48.1, and section 6-48.1-1 provides that the chapter "shall be known and may be cited as" the Rhode Island Data Transparency and Privacy Protection Act. The name itself signals the law's focus on transparency about data sharing.
The chapter was created during the 2024 legislative session through two companion bills, H 7787 in the House and S 2500 in the Senate. The legislation cleared the General Assembly in June 2024 and became law that month. The 2024 enacting acts, P.L. 2024, ch. 430 and P.L. 2024, ch. 453, set a single effective date of January 1, 2026 for the entire chapter, giving covered businesses roughly eighteen months to prepare before their obligations begin. No individual section fixes that date; it is carried as a bracketed annotation in the heading of every section in chapter 6-48.1.
As of 2026, that effective date has arrived and the law is operative. Rhode Island joins a large group of states with omnibus privacy statutes loosely modeled on the framework first adopted in Virginia and Connecticut. The RIDTPPA shares much of that structure, including controller and processor roles, a consumer rights catalog, and opt-in consent for sensitive data. For the full controller and processor obligations, see the Rhode Island data privacy laws parent page.
Why the RIDTPPA is viewed as a lighter-touch law
Privacy practitioners widely describe the RIDTPPA as one of the more lightly drafted state privacy laws, and that nuance is worth stating plainly. The statute borrows the familiar rights catalog and the opt-in sensitive-data rule, but it omits several guardrails that newer laws include and uses looser drafting in places.
Two omissions stand out. First, the RIDTPPA does not require controllers to honor a universal opt-out preference signal such as the Global Privacy Control, a mechanism that Colorado, Connecticut, and a growing number of states now mandate. Section 6-48.1-6 describes how customers exercise their rights and permits authorized agents, but it contains no universal opt-out signal obligation. Second, the law provides no statutory right to cure, yet it also does not include the detailed data-minimization and contracting scaffolding that some sister statutes spell out at length.
The result is a law that grants real consumer rights but is generally seen as less prescriptive than the Connecticut or Colorado models. Businesses that already comply with a stricter state law will usually clear the Rhode Island bar with little additional work. The one place where Rhode Island asks for something distinctive is its website third-party disclosure duty, discussed next.

The signature feature: website third-party disclosure
The RIDTPPA's most distinctive requirement lives in section 6-48.1-3, titled "Information sharing practices." It applies to a commercial website or internet service provider that operates in Rhode Island or serves Rhode Island customers and that collects, stores, and sells customers' personally identifiable information. Once that conjunctive trigger is met, the controller must, in its customer-facing disclosure, do three things.
It must identify all of the categories of personal data that the controller collects through the website or application. It must identify all third parties to whom the controller has sold or may sell customers' personally identifiable information. And it must provide an active means by which a customer can contact the controller about its data practices.
The second item is the quirk. Most state privacy laws ask only for the categories of third parties with whom a controller shares data. Rhode Island's text reaches further, requiring a controller to "identify all third parties" to whom it "has sold or may sell" personal data. Read literally, that is a broader naming duty than the category-level disclosures elsewhere, and it is the feature that gives the act its "transparency" name. Section 6-48.1-3 also requires a controller that sells personal data or processes it for targeted advertising to clearly and conspicuously disclose that processing.
Who the RIDTPPA covers: applicability thresholds
The applicability test sits in section 6-48.1-4. The law reaches a for-profit entity that conducts business in Rhode Island, or that produces products or services targeted to Rhode Island residents, and that during a calendar year controlled or processed the personal data of either of two groups.
The first trigger is 35,000 or more customers, "excluding personal data controlled or processed solely for the purpose of completing a payment transaction." The payment carve-out means a retailer does not count routine card transactions toward the threshold when the only data involved is what is needed to complete that single purchase.
The second trigger is 10,000 or more customers, but only when the business "derived more than twenty percent (20%) of their gross revenue from the sale of personal data." This lower headcount captures data-driven businesses whose revenue depends on selling personal information. The 20 percent figure is notable, because several other state laws set the comparable revenue test at 25 percent, so Rhode Island's data-sale trigger is slightly easier to meet.
A defined term matters here. The statute uses "customer" rather than "consumer," and section 6-48.1-2 defines a customer as an individual residing in Rhode Island acting in an individual or household context. Data about people acting in a commercial or employment context is generally outside that definition.
RIDTPPA's threshold-based obligations also reach only for-profit entities. Section 6-48.1-4(a) limits its threshold test to for-profit entities, so a nonprofit that otherwise meets the customer-count test is not covered by it. Section 6-48.1-3(d) separately excludes the entire chapter for state and local government bodies, nonprofit organizations, institutions of higher education, national securities associations registered under 15 U.S.C. 78o-3, GLBA-regulated financial institutions, and HIPAA covered entities and business associates. Sections 6-48.1-3(e) and 6-48.1-10 add further carve-outs, including research data, FCRA-regulated consumer reporting agency data, driver's license data under the Driver's Privacy Protection Act, FERPA-covered education records, certain employment-context data, Airline Deregulation Act data, and information held by tax-exempt organizations.

Sensitive data and the opt-in consent rule
Sensitive data sits at the center of the RIDTPPA because processing it requires opt-in consent. Under section 6-48.1-4, a controller "shall not process sensitive data concerning a customer without obtaining customer consent," and may not process the sensitive data of a known child except with consent and in accordance with the federal Children's Online Privacy Protection Act. Consent must be a clear affirmative act, not a pre-checked box or inferred from inaction.
The definition of sensitive data in section 6-48.1-2 is broad. It includes personal data revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis, sex life, sexual orientation, or citizenship or immigration status. It also includes genetic or biometric data processed to uniquely identify an individual, personal data collected from a known child, and precise geolocation data.
Because sensitive data triggers an opt-in gate, the breadth of the definition has operational weight. A business that processes health information, immigration status, biometric identifiers, or precise location must obtain affirmative consent before that processing begins. Section 6-48.1-4 also requires a controller to give customers a way to grant and revoke consent, and to honor a revocation within 15 days of receipt.
RIDTPPA vs. CCPA: the key differences
Rhode Island's RIDTPPA and California's CCPA are often compared by companies that operate nationally. The state data privacy law comparison page covers the broader multistate picture, but several differences between the RIDTPPA and California's CCPA stand out.
| Feature | Rhode Island RIDTPPA | California CCPA/CPRA |
|---|---|---|
| Coverage threshold | 35,000 customers, or 10,000 plus 20% of revenue from data sales; no dollar floor | $25M revenue, 100,000 consumers, or 50% revenue from data sales |
| Third-party disclosure | Must identify all third parties sold or may sell to (6-48.1-3) | Categories of third parties disclosed |
| Sensitive data | Opt-in consent required (6-48.1-4) | Right to limit use; opt-out model |
| Universal opt-out signal | Not required | Required (GPC recognized) |
| Private right of action | None (6-48.1-8) | Limited, for certain data breaches |
The most consequential difference is the coverage net. Rhode Island's 35,000-customer threshold and the absence of a dollar-revenue floor pull in companies that California's $25 million revenue trigger would leave out, even though California's law is often described as the strictest in the country on other dimensions.
The two laws also differ on the universal opt-out signal and on sensitive data. California requires recognition of opt-out preference signals such as the Global Privacy Control and uses a "right to limit" the use of sensitive personal information. Rhode Island does not mandate a universal opt-out signal and instead requires opt-in consent before sensitive data may be processed. Where Rhode Island goes further than California is its named third-party disclosure duty under 6-48.1-3.
Related guides
- Rhode Island data privacy laws parent hub
- RIDTPPA consumer rights
- RIDTPPA compliance checklist
- State data privacy law comparison
- What is the CCPA?
More Rhode Island Laws
Frequently Asked Questions
What is the RIDTPPA?
The RIDTPPA, or Rhode Island Data Transparency and Privacy Protection Act, is Rhode Island's comprehensive consumer data privacy law codified at R.I. Gen. Laws ch. 6-48.1. It was enacted in 2024 through bills H 7787 and S 2500, became law in June 2024, and takes effect January 1, 2026. It gives Rhode Island residents rights over their personal data and requires covered businesses to disclose how they collect, use, and share it.
When does the Rhode Island Data Transparency and Privacy Protection Act take effect?
The RIDTPPA takes effect on January 1, 2026, the effective date set by the 2024 enacting legislation for the entire chapter. The law was passed in June 2024, so covered businesses had roughly eighteen months to prepare. As of 2026, the law is operative and the Attorney General has enforcement authority.
Who has to comply with the RIDTPPA?
Under section 6-48.1-4, the RIDTPPA applies to a for-profit business that conducts business in Rhode Island or targets Rhode Island residents and that, during a calendar year, controls or processes the personal data of 35,000 or more customers, or of 10,000 or more customers while deriving more than 20 percent of gross revenue from the sale of personal data. The first threshold excludes data processed solely to complete a payment transaction. Nonprofits, higher-education institutions, government bodies, GLBA financial institutions, and HIPAA covered entities and business associates are exempt from the chapter under 6-48.1-3(d).
What is the RIDTPPA third-party disclosure requirement?
Section 6-48.1-3 requires a commercial website or internet service provider that collects, stores, and sells customers' personally identifiable information to disclose the categories of personal data it collects and to identify all third parties to whom the controller has sold or may sell that information, along with an active means of contact. The duty to name third parties, rather than just disclose categories of third parties, is the law's signature feature and the reason it is called a transparency act.
Does the RIDTPPA require a universal opt-out signal?
No. As of 2026, the RIDTPPA does not require controllers to recognize a universal opt-out preference signal such as the Global Privacy Control. Section 6-48.1-6 describes how customers exercise opt-out rights and allows authorized agents, but it contains no universal opt-out mechanism mandate. This is one reason the law is viewed as lighter-touch than the Colorado or Connecticut models.
What counts as sensitive data under the RIDTPPA?
Under section 6-48.1-2, sensitive data includes data revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis, sex life, sexual orientation, or citizenship or immigration status. It also includes genetic or biometric data used to identify a person, personal data collected from a known child, and precise geolocation data. Processing sensitive data requires opt-in consent under section 6-48.1-4.
How is the RIDTPPA different from the CCPA?
Key differences: Rhode Island's coverage threshold is 35,000 customers with no dollar floor, while California's CCPA uses a $25 million revenue trigger among its tests; Rhode Island requires opt-in consent for sensitive data while California uses an opt-out right to limit; Rhode Island does not require a universal opt-out signal while California does; Rhode Island uniquely requires controllers to identify all third parties to whom they sell or may sell data; and California has a limited private right of action for certain breaches while Rhode Island has none.
Who enforces the RIDTPPA?
The Rhode Island Attorney General has sole enforcement authority under section 6-48.1-8. A violation is a deceptive trade practice under R.I. Gen. Laws ch. 6-13.1, which authorizes the Attorney General to seek a civil penalty of up to $10,000 per violation under 6-13.1-8. Intentional disclosure of personal data in violation of the chapter carries an additional fine of not less than $100 and no more than $500 for each such disclosure under 6-48.1-8(a)(2). There is no private right of action and no statutory right to cure.
Updates
Corrected the attribution of the law’s January 1, 2026 effective date: it is set by the 2024 enacting acts for the whole chapter, not by section 6-48.1-4.
Corrected the RIDTPPA website-disclosure trigger to require collecting, storing, and selling personal data (not merely collecting it); added the for-profit-only scope and the nonprofit, higher-education, government, GLBA, and HIPAA exemptions to the applicability section; clarified that a violation is also a deceptive trade practice exposing violators to a civil penalty of up to $10,000, on top of the existing $100-$500 per-disclosure fine; and removed an unverifiable claim about how the law was enacted, keeping the confirmed June 2024 enactment date.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Rhode Island General Laws, Title 6: Commercial Law
§ 6-48.1-3Information sharing practices. [Effective January 1, 2026.]In forcecited in 5 of our articles
(a) Any commercial website or internet service provider conducting business in Rhode Island or with customers in Rhode Island or otherwise subject to Rhode Island jurisdiction, shall designate a controller. If a commercial website or internet service provider collects, stores, and sells customers’ personally identifiable information, then the controller shall, in its customer agreement or incorporated addendum, or in another conspicuous location on its website or online service platform where similar notices are customarily posted: (1) Identify all categories of personal data that the controller collects through the website or online service about customers; (2) Identify all third parties to whom the controller has sold or may sell customers’ personally identifiable information; and (3) Identify an active electronic mail address or other online mechanism that the customer may use to contact the controller. (b) If a controller sells personal data to third parties or processes personal data for targeted advertising, the controller shall clearly and conspicuously disclose such processing.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at webserver.rilegislature.gov
Also relied on in: Rhode Island Data Privacy Laws: RIDTPPA Consumer Rights Guide (2026), RIDTPPA Compliance Checklist for Rhode Island, RIDTPPA Consumer Rights in Rhode Island Explained
§ 6-48.1-1Short title. [Effective January 1, 2026.]In forcecited in 3 of our articles
This chapter shall be known and may be cited as the “Rhode Island Data Transparency and Privacy Protection Act”.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at webserver.rilegislature.gov
Also relied on in: Rhode Island Ring Doorbell Laws: What You Need to Know in 2026
§ 6-48.1-2Definitions. [Effective January 1, 2026.]In forcecited in 5 of our articles
As used in this chapter: (1) “Affiliate” means any entity that shares common branding with another legal entity directly or indirectly, controls, is controlled by, or is under common control with another legal entity. For this purpose, “control” or “controlled” means ownership of, or the power to vote, more than fifty percent (50%) of the outstanding shares of any class of voting security of a company; control in any manner over the election of a majority of the directors or of individuals exercising similar functions; or the power to exercise controlling influence over the management of a company. (2) “Authenticate” means to use reasonable means to determine that a request to exercise any of the rights afforded under this chapter is being made by, or on behalf of, the customer who is entitled to exercise such customer rights with respect to the personal data at issue. (3) “Biometric data” means data generated by automatic measurements of an individual’s biological characteristics, such as a fingerprint, a voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that are used to identify a specific individual.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at webserver.rilegislature.gov
Also relied on in: Rhode Island Biometric Privacy Laws: Collection, Consent & Penalties (2026), Rhode Island Employee Monitoring Laws: Workplace Surveillance and Social Media (2026)
§ 6-48.1-4Processing of information. [Effective January 1, 2026.]In forcecited in 5 of our articles
(a) This section shall apply to for-profit entities that conduct business in the state or for-profit entities that produce products or services that are targeted to residents of the state and that during the preceding calendar year did any of the following: (1) Controlled or processed the personal data of not less than thirty-five thousand (35,000) customers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction. (2) Controlled or processed the personal data of not less than ten thousand (10,000) customers and derived more than twenty percent (20%) of their gross revenue from the sale of personal data. (b) The controller shall establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data. (c) The controller shall not process sensitive data concerning a customer without obtaining customer consent and shall not process sensitive data of a known child unless consent is obtained and the information is processed in accordance with COPPA.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at webserver.rilegislature.gov
§ 6-48.1-5Customer rights. [Effective January 1, 2026.]In forcecited in 7 of our articles
(a) This section shall apply to for-profit entities that conduct business in the state or for-profit entities that produce products or services that are targeted to residents of the state and that during the preceding calendar year did any of the following: (1) Controlled or processed the personal data of not less than thirty-five thousand (35,000) customers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction. (2) Controlled or processed the personal data of not less than ten thousand (10,000) customers and derived more than twenty percent (20%) of their gross revenue from the sale of personal data. (b) No controller shall discriminate against a customer for exercising their customer rights. (c) No controller shall deny goods or services, charge different prices or rates for goods or services, or provide a different level of quality of goods or services to the customer if the customer opts out to use of their data. However, if a customer opts out of data collection, the covered entity is not required to provide a service that requires this data collection.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at webserver.rilegislature.gov
Also relied on in: How to Request Your Personal Data: US Privacy Rights by State
§ 6-48.1-6Exercising customer rights. [Effective January 1, 2026.]In forcecited in 6 of our articles
(a) This section shall apply to for-profit entities that conduct business in the state or for-profit entities that produce products or services that are targeted to residents of the state and that during the preceding calendar year did any of the following: (1) Controlled or processed the personal data of not less than thirty-five thousand (35,000) customers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction. (2) Controlled or processed the personal data of not less than ten thousand (10,000) customers and derived more than twenty percent (20%) of their gross revenue from the sale of personal data. (b) A controller shall comply with a request by a customer to exercise the customer rights authorized as follows: (1) A controller shall respond to the customer without undue delay, but not later than forty-five (45) days after receipt of the request.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at webserver.rilegislature.gov
§ 6-48.1-8Violations. [Effective January 1, 2026.]In forcecited in 5 of our articles
(a) A violation of this chapter constitutes a violation of the general regulatory provisions of commercial law in this title and shall constitute a deceptive trade practice in violation of chapter 13.1 of this title; provided, further, that in the event that any individual or entity intentionally discloses personal data: (1) To a shell company or any entity that has been formed or established solely, or in part, for the purposes of circumventing the intent of this chapter; or (2) In violation of any provision of this chapter, that individual or entity shall pay a fine of not less than one hundred dollars ($100) and no more than five hundred dollars ($500) for each such disclosure. (b) The attorney general shall have sole enforcement authority of the provisions of this chapter and may enforce a violation of this chapter pursuant to: (1) The provisions of this section; or (2) General regulatory provisions of commercial law in this title, or both. (c) Nothing in this section shall be construed to authorize any private right of action to enforce any provision of this chapter, any regulation hereunder, or any other provisions of law.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at webserver.rilegislature.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- R.I. Gen. Laws Chapter 6-48.1: Rhode Island Data Transparency and Privacy Protection Act (Section Index)(webserver.rilegislature.gov).gov
- R.I. Gen. Laws 6-48.1-1: Short title(webserver.rilegislature.gov).gov
- R.I. Gen. Laws 6-48.1-2: Definitions(webserver.rilegislature.gov).gov
- R.I. Gen. Laws 6-48.1-3: Information sharing practices(webserver.rilegislature.gov).gov
- R.I. Gen. Laws 6-48.1-4: Processing of information(webserver.rilegislature.gov).gov
- R.I. Gen. Laws 6-48.1-8: Violations(webserver.rilegislature.gov).gov
- Rhode Island Office of the Attorney General(riag.ri.gov).gov
- R.I. Gen. Laws 6-48.1-5: Customer rights(webserver.rilegislature.gov).gov
- R.I. Gen. Laws 6-48.1-6: Exercising customer rights(webserver.rilegislature.gov).gov