Tennessee Privacy Law
Tennessee Information Protection Act
Overview
The Tennessee Information Protection Act (TIPA), codified at Tenn. Code Ann. §§ 47-18-3201 through 47-18-3213 (Part 32 of the Tennessee Consumer Protection Act of 1977), was signed into law by Governor Bill Lee on May 11, 2023 as HB 1181 / SB 73, and took effect on July 1, 2025. Tennessee is the only U.S. state to pair a comprehensive privacy law with an explicit NIST Privacy Framework v1.0 affirmative defense, a feature championed by sponsor Rep. Johnny Garrett to incentivize risk-based privacy engineering over check-the-box compliance. As of April 2026, the TIPA is in the tenth month of its enforcement window, and Attorney General Jonathan Skrmetti — who has pursued a high-profile consumer-protection agenda including the 2024 multistate challenge to TikTok over minors' data and the January 2025 AG letter on generative-AI chatbot risks — has signaled that first-year enforcement will focus on documented privacy programs, sensitive-data consent flows, and opt-out mechanics rather than technical infractions.
The TIPA grants Tennessee residents (defined to exclude individuals acting in a commercial or employment context) a full suite of comprehensive-privacy-law rights: access, correction, deletion, portability, and opt-out of (a) sales of personal information, (b) targeted advertising, and (c) profiling in furtherance of decisions that produce legal or similarly significant effects. Controllers must respond within 45 days (with one 45-day extension available when reasonably necessary) and must offer a written appeal process under § 47-18-3205(c)(3) if a request is denied — with an AG complaint-submission link required in the appeals denial. Sensitive data processing requires opt-in consent (or for minors under 13, COPPA-verifiable parental consent). Controllers must conduct documented data protection assessments under § 47-18-3207 for five categories of higher-risk processing (targeted advertising, sale, profiling with significant effect, sensitive data, and any activity presenting a heightened risk of harm).
The TIPA's applicability test uses AND logic — a rare feature shared only with Utah among comprehensive state privacy laws — and applies to controllers and processors that (1) conduct business in Tennessee or produce products or services targeted to Tennessee residents, AND (2) exceed $25 million in annual revenue, AND (3) either (a) control or process personal data of 175,000 or more Tennessee consumers during a calendar year or (b) derive more than 50% of gross revenue from the sale of personal data AND control or process personal data of 25,000 or more consumers. This triple-threshold structure is the narrowest applicability test among all 21 state comprehensive privacy laws and exempts most small and mid-market businesses. Entity-level exemptions apply to HIPAA-covered entities and business associates, GLBA-regulated financial institutions, nonprofit organizations, institutions of higher education, insurers, and state agencies.
Enforcement is vested exclusively in the Tennessee AG (no private right of action) and proceeds through the Tennessee Consumer Protection Act enforcement framework (Tenn. Code Ann. § 47-18-101 et seq.), which allows the AG to seek injunctive relief, restitution, civil penalties, and attorney's fees. The TIPA provides a mandatory 60-day cure period before the AG may bring an enforcement action — one of the longer cure windows remaining in effect, as Connecticut (Dec 2024), Colorado (Jan 2025), Montana (Oct 2025), Rhode Island (Jan 2026), and New Jersey (by July 2026) have all sunset their cure periods. Civil penalties are capped at $7,500 per violation, with willful violations subject to treble damages under § 47-18-3209(c) — making Tennessee's effective maximum penalty $22,500 per willful violation, second only to Indiana's $7,500 plus TCPA enhancements. The NIST Privacy Framework affirmative defense under § 47-18-3213 remains the TIPA's signature differentiator: controllers and processors that create, maintain, and comply with a written privacy program that reasonably conforms to the NIST Privacy Framework (or a successor framework designated by the AG) can assert the framework adherence as an affirmative defense to a TIPA cause of action.
Applicability Thresholds
Conditions are joined by AND — ALL conditions must be met.
Consumer Rights
Key Changes in 2025-2026
- Law active since July 1, 2025 — now in the tenth month of enforcement with 60-day cure period still intact through at least 2026
- NIST Privacy Framework v1.0 affirmative defense under § 47-18-3213 remains the only such provision among 21 state comprehensive privacy laws — NIST released Privacy Framework v1.1 in April 2024, and the TIPA language ("reasonably conforms") allows controllers to update to v1.1 without legislative action
- AG Skrmetti's Consumer Protection Division publicly prioritizes: (1) minors' data, (2) AI chatbot and generative-AI deceptive design, (3) documented sensitive-data consent flows, and (4) opt-out link clarity
- Eight sensitive data categories under § 47-18-3202(24) now explicit — adding precise geolocation (1,750-foot radius) and known-child-under-13 data to the prior six categories (the 2023 enacted version's list as interpreted under § 47-18-3202(15) "precise geolocation data")
- AND-logic applicability test ($25M revenue + consumer count) is the narrowest among all 21 state comprehensive privacy laws — Utah UCPA uses the same AND structure; Virginia, Colorado, Connecticut, and the 17 other states use OR logic
- Treble damages under § 47-18-3209(c) for willful violations — effective maximum penalty rises to $22,500 per willful violation, making TIPA's per-violation exposure the highest among cure-period states when willfulness is proven
- Data protection assessments under § 47-18-3207 required for five categories of higher-risk processing: targeted advertising, sale, profiling with significant effect, sensitive data processing, and any activity presenting heightened risk — the TIPA's DPA requirements are narrower than Colorado's but broader than Utah's (which has no DPA requirement)
- No GPC mandate — aligns Tennessee with VA, IN, IA, KY, UT, RI; contrasts with the 12 GPC-mandating states. Multistate controllers typically still implement GPC recognition uniformly for operational simplicity
- 60-day cure period remains in effect, putting Tennessee in the minority as of 2026 — California, Connecticut (Dec 2024), Colorado (Jan 2025), Montana (Oct 2025), Rhode Island (Jan 2026), and New Jersey (by July 2026) have all sunset cure periods; Tennessee's cure window remains statutorily permanent
- COPPA Rule amendments became effective June 23, 2025, and the main compliance date passed April 22, 2026 — controllers relying on COPPA parental consent should audit against the expanded "personal information" definition (biometric identifiers, government IDs) in 16 C.F.R. § 312.2
Enforcement Details
Sensitive Data Categories
Consent model: opt-in
Universal Opt-Out / GPC Requirements
The TIPA does not require businesses to recognize universal opt-out mechanisms such as Global Privacy Control (GPC) — Tennessee joins Virginia, Indiana, Iowa, Kentucky, Utah, and Rhode Island as the seven comprehensive-privacy-law states that do not mandate GPC. Controllers must instead offer a clear and conspicuous opt-out link ("Your Privacy Choices" or equivalent) and at least one additional opt-out method (email, toll-free number, or web form). This contrasts with the twelve GPC-mandating states (California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas). Multistate controllers should still plan to implement GPC recognition for Tennessee traffic because the cost of dual-logic processing (honor-GPC for twelve states, ignore-GPC for seven) typically exceeds the cost of uniform GPC honor.
Minor / Child Protections
The TIPA requires COPPA-verifiable parental consent for processing personal data of known children under 13, aligning the state baseline with federal COPPA (16 C.F.R. Part 312) and the amended COPPA Rule, effective June 23, 2025 with a main compliance date of April 22, 2026. For teens aged 13-17, the TIPA prohibits processing personal data for targeted advertising or sale without affirmative opt-in consent. AG Skrmetti has publicly prioritized minors' online safety — Tennessee joined the 14-state amicus coalition in NetChoice v. Bonta (supporting California's AADC defense) and the multistate TikTok deceptive-design investigation. Controllers processing minors' data should document age verification logic and maintain a parental consent audit trail. TIPA minors' protections layer with the Tennessee Protecting Children from Social Media Act (Public Chapter 810, effective Jan 1, 2025 but preliminarily enjoined in NetChoice v. Skrmetti, M.D. Tenn.).
Compliance Checklist
- 1Applicability — confirm ALL three AND-logic thresholds: (1) business activity directed to Tennessee consumers, (2) $25M+ annual revenue, AND (3) either 175,000+ TN consumers in a calendar year OR (25,000+ consumers with 50%+ revenue from data sale). Document the threshold calculation. Confirm no entity-level exemption applies (HIPAA covered entity, GLBA financial institution, nonprofit, higher ed, insurer, state agency)
- 2Consider the NIST Privacy Framework affirmative defense — § 47-18-3213 provides an affirmative defense to any TIPA cause of action if the controller maintains a written privacy program that reasonably conforms to the NIST Privacy Framework (now v1.1, April 2024). Document NIST Core Categories: IDENTIFY-P, GOVERN-P, CONTROL-P, COMMUNICATE-P, PROTECT-P. Retain written program, policies, data maps, and governance artifacts. This is a documentary-compliance opportunity not available in any other state
- 3Privacy notice — update under § 47-18-3206 to include: (a) categories of personal data processed, (b) purposes of processing, (c) categories of personal data shared with third parties and categories of third parties, (d) consumer rights description, (e) how to exercise each right and appeal a denial, (f) how to opt out of sale, targeted ads, and profiling. Include the AG complaint-filing link for appeals denials
- 4Consumer rights request processing — establish verified-request intake, 45-day response timeline, one 45-day extension clause, and a written appeals process under § 47-18-3205(c)(3). Respond to free-of-charge first request within any 12-month period; subsequent requests may be charged a reasonable fee or declined as unfounded/excessive
- 5Sensitive data opt-in consent — implement opt-in consent flows for all 8 sensitive data categories. Ensure consent is freely given, specific, informed, and unambiguous (TIPA adopts this GDPR-style consent definition at § 47-18-3202(5)). Maintain consent records with timestamp, scope, and withdrawal method
- 6Children's data — implement COPPA-verifiable parental consent for under-13 processing. For teens 13-17, require opt-in consent for targeted advertising or sale. Audit age-gating logic and document the assumption basis (account registration date-of-birth, parental verification method)
- 7Opt-out mechanisms — implement a clear and conspicuous "Your Privacy Choices" link in the site footer and at least one additional opt-out method (email, web form, or toll-free number). While Tennessee does not mandate GPC, operationally recommend GPC honor for uniform multistate processing
- 8Data protection assessments — conduct and document DPAs under § 47-18-3207 for: (1) targeted advertising, (2) sale of personal data, (3) profiling with legal or similarly significant effect, (4) sensitive data processing, and (5) heightened risk of harm. DPAs must weigh benefits to controller, consumer, and public against risks. AG may request DPAs during investigation; document confidentiality protections
- 9Processor contracts — update under § 47-18-3208 to include: purpose and nature of processing, type of data, duration, obligations, processor confidentiality duties, data deletion/return at contract end, audit rights, and subprocessor cascade. Review all vendor agreements predating TIPA effective date (July 1, 2025) for compliance
- 10AG inquiry response playbook — prepare for § 47-18-3209 enforcement. Document: receipt of AG notice of alleged violation, internal forensic review, remediation within 60-day cure window, written notice of cure to AG, and documentation retention. Train legal and privacy-operations teams on the cure timeline
- 11Multistate mapping — if operating in multiple states, map TIPA obligations against UT (AND-logic peer), VA/IN (OR-logic but similar rights), CO (strictest enforcement), and CA (most comprehensive). Create a control matrix identifying TIPA-unique requirements (NIST affirmative defense, AND threshold) and shared obligations (sensitive data consent, DPA, rights response)
- 12Monitor 2026 amendments — Tennessee General Assembly adjourns sine die late April/early May 2026. Track HB/SB bills referencing Tenn. Code Ann. § 47-18-32 (Part 32). AG Skrmetti's 2025 generative-AI chatbot letter and 2026 minors-data priorities may drive amendments to expand TIPA scope or add AI-specific provisions
Termly builds and maintains a Tennessee-ready privacy policy, a cookie consent banner, opt-in consent capture for sensitive data, and a workflow for the access, deletion and correction requests TIPA grants.
Tennessee Privacy Law FAQ
Official Resources
- TIPA Full Text — Tenn. Code Ann. §§ 47-18-3201 et seq. (Tennessee Code)
- HB 1181 / SB 73 Bill Text (2023 Session, Tennessee General Assembly)
- Tennessee Attorney General Consumer Protection Division
- File a Consumer Complaint (Tennessee AG)
- NIST Privacy Framework v1.1 (National Institute of Standards and Technology)
- FTC COPPA Rule Amendments — Federal Register (90 FR 16918)
- Tennessee Consumer Protection Act (§ 47-18-101 et seq.) — Enforcement Framework