1
Assess applicability — note the significantly lower thresholds: 35,000 consumers (excluding payment-only data) OR 10,000 consumers with 20%+ data sale revenue. Also verify entity-level exemptions: HIPAA-covered entities, GLBA financial institutions, nonprofits, government, higher education. Note exemptions apply at entity level; data processed outside exempted activities remains covered
2
Update privacy notices with all RIDTPPA-required disclosures: categories of personal data processed, purposes of processing, categories of third parties receiving data, consumer rights and exercise methods, data sale and targeted advertising disclosures, and controller contact information
3
Implement consumer rights request mechanisms with 45-day response period (extendable by 45 additional days with notice and justification). Include identity verification procedures proportionate to the sensitivity of the data and risk of unauthorized access
4
Obtain opt-in consent for all eight sensitive data categories: racial/ethnic origin, religious beliefs, health diagnosis, sexual orientation, citizenship/immigration status, genetic/biometric data (processed for identification, excluding photos/audio/video), precise geolocation (within 1,750-foot radius), and known children's data (under 13). Consent must be freely given, specific, informed, and unambiguous
5
Implement children's data protections — obtain verifiable parental consent before processing data of known children under 13. For teens (13-17), obtain opt-in consent before targeted advertising or data sales. Align with the COPPA Rule amendments effective June 23, 2025 and fully applicable after the April 22, 2026 main compliance date
6
Implement opt-out mechanisms for data sales, targeted advertising, and profiling with significant legal or similarly significant effects. No GPC mandate — traditional opt-out links and methods are sufficient, but must be clear, conspicuous, and functional
7
Establish a documented appeals process for denied consumer requests — respond within 60 days and inform consumers of their right to file complaints with the Rhode Island Attorney General's Consumer Protection Unit
8
Execute processor agreements (Data Processing Agreements) with all service providers processing personal data. Include RIDTPPA-mandated provisions: processing instructions, confidentiality obligations, data security requirements, sub-processor controls, deletion/return obligations, and cooperation with consumer rights requests
9
Conduct data protection assessments for processing activities presenting heightened risk to consumers: targeted advertising, data sales, profiling, processing sensitive data, and any processing creating foreseeable risk of substantial injury. Document assessments and retain records
10
Implement data minimization practices — collect only personal data that is adequate, relevant, and reasonably necessary for the disclosed purposes. Establish data retention schedules and purge data no longer needed
11
Prepare for AG enforcement inquiries — there is no cure period, so have a documented compliance program ready. Maintain records of consent, consumer requests, data protection assessments, and processor agreements. The AG can investigate and pursue penalties immediately upon discovery of violations
12
Map multistate compliance obligations — compare RIDTPPA requirements against Delaware (similar low thresholds, GPC required), New Hampshire (GPC required since January 1, 2025; cure period expired), and Maryland (data minimization, GPC required). Identify gaps where RI-specific obligations differ from sister states