Rhode Island Privacy Law
Rhode Island Data Transparency and Privacy Protection Act
Overview
The Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) was signed into law by Governor Dan McKee on June 29, 2024 (H 7787A), codified at R.I. Gen. Laws §§ 6-48.1-1 through 6-48.1-14, and became effective on January 1, 2026. Rhode Island adopted relatively low applicability thresholds compared to most state privacy laws — 35,000 consumers or 10,000 consumers with 20%+ data sale revenue — making the law applicable to a broader range of businesses than typical state privacy laws requiring 100,000+ consumers. The RIDTPPA is enforced exclusively by the Rhode Island Attorney General through the Consumer Protection Unit, currently under Attorney General Peter Neronha. AG Neronha, who has been active on privacy and data security issues including leading multistate coalitions challenging federal data demands on educational institutions, has enforcement authority to treat RIDTPPA violations as deceptive trade practices under the Rhode Island Deceptive Trade Practices Act (R.I. Gen. Laws § 6-13.1-1 et seq.), carrying civil penalties of up to $10,000 per violation plus $100 to $500 per intentional disclosure of personal data — a unique dual-penalty structure among state privacy laws.
The RIDTPPA provides Rhode Island consumers with comprehensive privacy rights, including the right to access, correct, delete, and port personal data, as well as opt-out rights for data sales, targeted advertising, and profiling with significant legal or similarly significant effects. The law includes a mandatory appeals process for denied consumer requests — controllers must respond within 60 days and inform consumers of their right to file a complaint with the Attorney General. Rhode Island defines eight categories of sensitive data requiring opt-in consent, including precise geolocation data (within a radius of 1,750 feet or 533.4 meters) and personal data of known children under 13. The sensitive data definition also covers racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, and genetic or biometric data processed for identification purposes (excluding digital photographs or audio/video recordings from biometric data). Controllers must obtain freely given, specific, informed, and unambiguous opt-in consent before processing any sensitive data category.
The RIDTPPA is notable among state privacy laws for having no cure period — the Attorney General can pursue enforcement immediately upon discovering violations without giving businesses time to correct them. Rhode Island joins only a handful of states (including California and, since January 2025, Connecticut and Colorado) that enforce comprehensive privacy laws without any cure window, making proactive compliance essential. The law applies to for-profit entities conducting business in Rhode Island or targeting Rhode Island consumers that control or process personal data of 35,000 or more consumers (excluding data processed solely to complete payment transactions), or control or process personal data of 10,000 or more consumers while deriving more than 20% of gross revenue from the sale of personal data. Entity-level exemptions cover HIPAA-covered entities, GLBA-covered financial institutions, nonprofit organizations, government entities, and higher education institutions. Data-level exemptions apply to HIPAA-regulated health data, GLBA-regulated financial data, data subject to FERPA, and data processed in employment, job applicant, and B2B contexts. The RIDTPPA does not require recognition of universal opt-out mechanisms such as Global Privacy Control (GPC), aligning with Virginia, Indiana, Iowa, Kentucky, and Utah rather than the growing bloc of 12 states that mandate GPC recognition.
Applicability Thresholds
Conditions are joined by OR — meeting ANY one triggers applicability.
Consumer Rights
Key Changes in 2025-2026
- Law became effective January 1, 2026 — businesses must be in full compliance from day one with no grace period
- No cure period — Rhode Island is one of the few states where the AG can enforce immediately without offering businesses time to fix violations, joining California, Connecticut (since Dec 2024), and Colorado (since Jan 2025)
- Lower thresholds than most states — 35,000 consumers or 10,000 consumers with 20%+ data sale revenue, compared to 100,000 in most VCDPA-model states
- Violations enforced as deceptive trade practices under R.I. Deceptive Trade Practices Act (§ 6-13.1-1) — $10,000 per violation plus $100-$500 per intentional disclosure (unique dual-penalty structure)
- Eight sensitive data categories require opt-in consent — including precise geolocation data (1,750-foot radius) and personal data of known children under 13
- AG Neronha active on privacy enforcement — joined multistate coalitions on data privacy issues and led challenge to federal educational data demands
- AG leadership transition upcoming — Neronha is term-limited; four Democratic candidates running to succeed him in 2026 election. New AG may set different enforcement priorities
- COPPA Rule amendments became effective June 23, 2025, with the main compliance date passing April 22, 2026 — RIDTPPA children's data provisions interact with the amended federal requirements for expanded personal information definition
- No GPC mandate — Rhode Island does not require universal opt-out signals, unlike the 12 states that mandate GPC recognition. Businesses only need traditional opt-out mechanisms
- Entity-level exemptions for HIPAA, GLBA, nonprofits, government, and higher education — but data processed outside exempted activities is still subject to the RIDTPPA
Enforcement Details
Sensitive Data Categories
Consent model: opt-in
Universal Opt-Out / GPC Requirements
The RIDTPPA does not mandate universal opt-out signal recognition such as Global Privacy Control (GPC). Rhode Island aligns with Virginia, Indiana, Iowa, Kentucky, and Utah in not requiring GPC. States that do mandate GPC recognition include California, Colorado, Connecticut, Texas, Montana, Oregon, Delaware, New Hampshire, New Jersey, Maryland, Minnesota, and Nebraska. Businesses may voluntarily support GPC as a best practice for consumer privacy.
Minor / Child Protections
The RIDTPPA requires opt-in consent before processing personal data of known children under 13, classified as sensitive data under R.I. Gen. Laws § 6-48.1-2. Controllers must obtain verifiable parental consent before collecting, processing, or selling a child's personal data. Enhanced protections apply for teens (13-17), requiring opt-in consent before processing data for targeted advertising or data sales. The RIDTPPA aligns with COPPA federal requirements for children under 13 but extends state-level protections for teens. The no-cure-period enforcement posture means the AG can pursue penalties immediately for any violation involving children's data without first offering remediation time.
Compliance Checklist
- 1Assess applicability — note the significantly lower thresholds: 35,000 consumers (excluding payment-only data) OR 10,000 consumers with 20%+ data sale revenue. Also verify entity-level exemptions: HIPAA-covered entities, GLBA financial institutions, nonprofits, government, higher education. Note exemptions apply at entity level; data processed outside exempted activities remains covered
- 2Update privacy notices with all RIDTPPA-required disclosures: categories of personal data processed, purposes of processing, categories of third parties receiving data, consumer rights and exercise methods, data sale and targeted advertising disclosures, and controller contact information
- 3Implement consumer rights request mechanisms with 45-day response period (extendable by 45 additional days with notice and justification). Include identity verification procedures proportionate to the sensitivity of the data and risk of unauthorized access
- 4Obtain opt-in consent for all eight sensitive data categories: racial/ethnic origin, religious beliefs, health diagnosis, sexual orientation, citizenship/immigration status, genetic/biometric data (processed for identification, excluding photos/audio/video), precise geolocation (within 1,750-foot radius), and known children's data (under 13). Consent must be freely given, specific, informed, and unambiguous
- 5Implement children's data protections — obtain verifiable parental consent before processing data of known children under 13. For teens (13-17), obtain opt-in consent before targeted advertising or data sales. Align with the COPPA Rule amendments effective June 23, 2025 and fully applicable after the April 22, 2026 main compliance date
- 6Implement opt-out mechanisms for data sales, targeted advertising, and profiling with significant legal or similarly significant effects. No GPC mandate — traditional opt-out links and methods are sufficient, but must be clear, conspicuous, and functional
- 7Establish a documented appeals process for denied consumer requests — respond within 60 days and inform consumers of their right to file complaints with the Rhode Island Attorney General's Consumer Protection Unit
- 8Execute processor agreements (Data Processing Agreements) with all service providers processing personal data. Include RIDTPPA-mandated provisions: processing instructions, confidentiality obligations, data security requirements, sub-processor controls, deletion/return obligations, and cooperation with consumer rights requests
- 9Conduct data protection assessments for processing activities presenting heightened risk to consumers: targeted advertising, data sales, profiling, processing sensitive data, and any processing creating foreseeable risk of substantial injury. Document assessments and retain records
- 10Implement data minimization practices — collect only personal data that is adequate, relevant, and reasonably necessary for the disclosed purposes. Establish data retention schedules and purge data no longer needed
- 11Prepare for AG enforcement inquiries — there is no cure period, so have a documented compliance program ready. Maintain records of consent, consumer requests, data protection assessments, and processor agreements. The AG can investigate and pursue penalties immediately upon discovery of violations
- 12Map multistate compliance obligations — compare RIDTPPA requirements against Delaware (similar low thresholds, GPC required), New Hampshire (GPC required since January 1, 2025; cure period expired), and Maryland (data minimization, GPC required). Identify gaps where RI-specific obligations differ from sister states
Termly builds and maintains a Rhode Island-ready privacy policy, a cookie consent banner, opt-in consent capture for sensitive data, and a workflow for the access, deletion and correction requests RIDTPPA grants.
Rhode Island Privacy Law FAQ
Official Resources
- RIDTPPA Full Text — R.I. Gen. Laws §§ 6-48.1 (Rhode Island Legislature)
- H 7787A Bill Text (2024 Session)
- Rhode Island Attorney General — Consumer Protection
- File a Consumer Complaint (Rhode Island AG)
- Rhode Island Deceptive Trade Practices Act (§ 6-13.1)
- FTC COPPA Rule Amendments — Federal Register (90 FR 16918)
- IAPP — Rhode Island Enacts Comprehensive Privacy Law