Rhode Island — Comprehensive Law

Rhode Island Privacy Law

Rhode Island’s statute runs on two tracks that most comprehensive laws combine into one. Section 6-48.1-3 imposes a disclosure duty on any commercial website or internet service provider doing business in the state or with customers here, with no threshold at all: designate a controller, and if the business collects, stores and sells personally identifiable information, identify all the categories collected and all the third parties to whom it has sold or may sell them. Section 6-48.1-4 then adds the familiar controller obligations, but only to for-profit entities above 35,000 customers or 10,000 with a fifth of revenue from data sales. There is no right to cure. Enforcement runs through the Deceptive Trade Practices chapter, with a separate fine of $100 to $500 for each intentional disclosure — including any made to a shell company formed to circumvent the chapter.

The Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)

Enacted by P.L. 2024, ch. 430, § 2 and P.L. 2024, ch. 453, § 2, chapter 6-48.1 took effect January 1, 2026, and every section of it carries that effective-date notation. Its structure is unusual. Section 6-48.1-3(a) reaches any commercial website or internet service provider conducting business in Rhode Island, with customers in Rhode Island, or otherwise subject to Rhode Island jurisdiction, and requires each to designate a controller — a duty attached to no threshold. Where such a business collects, stores and sells customers’ personally identifiable information, the controller must, in the customer agreement or an incorporated addendum or another conspicuous location where similar notices are customarily posted, identify all categories of personal data it collects about customers through the site or service, identify all third parties to whom it has sold or may sell that information, and identify an active electronic mail address or other online mechanism the customer may use to contact it. Subsection (b) requires clear and conspicuous disclosure where the controller sells personal data to third parties or processes it for targeted advertising. Subsection (d) exempts state and local bodies, nonprofit organizations, institutions of higher education, registered national securities associations, financial institutions and Gramm-Leach-Bliley data, and HIPAA covered entities and business associates. Section 6-48.1-4(a) then applies the processing obligations, beginning with reasonable administrative, technical and physical data security practices, to for-profit entities meeting the thresholds. Section 6-48.1-9 makes any waiver of the chapter void and unenforceable.

Effective dateJanuary 1, 2026
CitationR.I. Gen. Laws ch. 6-48.1
Enforced byRhode Island Attorney General
Maximum penalty$100 to $500 for each intentional disclosure under § 6-48.1-8(a)(2); other violations are deceptive trade practices carrying up to $10,000 per violation under § 6-13.1-8
Private right of actionNo, enforcement by the state only
Right to cureNone — the chapter provides no right to cure

Who Must Comply

The RIDTPPA applies to a any commercial website or internet service provider doing business in Rhode Island or with Rhode Island customers must designate a controller and make the § 6-48.1-3 disclosures — no threshold applies, and the § 6-48.1-4 processing obligations apply to for-profit entities that during the preceding calendar year controlled or processed the personal data of not less than 35,000 customers, excluding data processed solely to complete a payment transaction, or controlled or processed the personal data of not less than 10,000 customers and derived more than 20% of gross revenue from the sale of personal data.

The disclosure duty in § 6-48.1-3 attaches to any commercial website with no threshold, the processing obligations in § 6-48.1-4 reach only for-profit entities above the thresholds, and the chapter names shell companies formed to circumvent it as a distinct violation.

Consumer Rights Under the RIDTPPA

Residents of Rhode Island can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.

Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.

Sector-Specific Privacy Laws in Rhode Island

Deceptive Trade Practices Act (R.I. Gen. Laws ch. 6-13.1)

Chapter 6-13.1 is where the privacy chapter’s remedies actually come from. Section 6-48.1-8(a) provides that a violation of the privacy chapter constitutes a violation of the general regulatory provisions of commercial law in title 6 and “shall constitute a deceptive trade practice in violation of chapter 13.1 of this title”. Section 6-13.1-5(a) then allows the Attorney General, on reason to believe that a person is using, has used or is about to use a method, act or practice declared unlawful by § 6-13.1-2, and that proceedings would be in the public interest, to bring an action in the name of the state to restrain the practice by temporary or permanent injunction upon appropriate notice and to seek any other appropriate relief. Subsection (b) fixes venue in the superior court of the county where the person dwells, is found or has a principal place of business, with alternatives for nonresidents. Section 6-13.1-8 supplies the money: “Any person who violates the provisions of this chapter shall forfeit and pay to the state a civil penalty of not more than ten thousand dollars ($10,000) per violation”, recoverable on the Attorney General’s petition in the name of the state.

Identity Theft Protection Act of 2015 (R.I. Gen. Laws ch. 11-49.3)

Beyond the notification section, chapter 11-49.3 carries the state’s data-security and identity-theft framework across seven sections, from § 11-49.3-1 through § 11-49.3-7. Its placement in title 11, the criminal offences title, rather than in title 6 with the commercial and privacy chapters, is itself a drafting choice that separates Rhode Island from the states around it: Connecticut’s breach statute sits in the banking title at § 36a-701b, Delaware’s in the commerce title at ch. 12B, and New Hampshire’s in the Right to Privacy chapter at RSA 359-C:20. The notification section’s prescribed contents at § 11-49.3-4(d) require the notice to point the consumer toward remediation service providers, the Attorney General, and the mechanics of obtaining a police report and a security freeze.

Data Breach Notification in Rhode Island

The Identity Theft Protection Act of 2015 at chapter 11-49.3 sits in the criminal title rather than the commercial one, and it sets two different clocks. Section 11-49.3-4(a)(1) applies to any municipal agency, state agency or person that stores, owns, collects, processes, maintains, acquires, uses or licenses data including personal information, and requires notification of any disclosure of personal information or breach of the security of the system “that poses a significant risk of identity theft” to any Rhode Island resident whose personal information was or is reasonably believed to have been acquired by an unauthorized person or entity. Under subsection (a)(2)(i), state and municipal agencies have no later than thirty calendar days after confirmation of the breach and the ability to ascertain the information required for the notice; under subsection (a)(2)(ii), every other person has forty-five calendar days measured from the same point. Both clocks run from confirmation of the breach and the ability to ascertain the required contents, not from first suspicion. Where more than five hundred Rhode Island residents are to be notified, both subparagraphs require notice to the Attorney General and to the major credit reporting agencies of the timing, content and distribution of the notices and the approximate number of affected individuals, and both provide that this notice “shall be made without delaying notice to affected Rhode Island residents”. Subsection (b) permits delay where a federal, state or local law enforcement agency so determines. Subsection (d) prescribes the contents of the notice, including a clear and concise description of the consumer’s ability to file or obtain a police report, how to request a security freeze and what information must be supplied when requesting one, and that fees may be payable to the consumer reporting agencies.

Residents must be notified in the most expedient time possible and not later than 45 calendar days after confirmation of the breach for private entities; 30 days for state and municipal agencies. Notify the Attorney General and the major credit reporting agencies where more than 500 Rhode Island residents are to be notified. Complaints are taken by the Rhode Island Attorney General, which enforces the statute.

How the RIDTPPA Is Enforced

Shell companies named as a distinct violation. Section 6-48.1-8(a) sets out two consequences rather than one. The first is categorical: a violation of the chapter constitutes a violation of the general regulatory provisions of commercial law in title 6 and a deceptive trade practice under chapter 6-13.1, which carries the civil penalty of up to $10,000 per violation in § 6-13.1-8. The second is specific to disclosure. Where an individual or entity intentionally discloses personal data either to “a shell company or any entity that has been formed or established solely, or in part, for the purposes of circumventing the intent of this chapter”, or in violation of any provision of the chapter, that individual or entity “shall pay a fine of not less than one hundred dollars ($100) and no more than five hundred dollars ($500) for each such disclosure”. Subsection (b) gives the Attorney General sole enforcement authority, exercisable under either that section or the general regulatory provisions of commercial law, or both. Subsection (c) provides that nothing in the section authorises a private right of action to enforce the chapter, any regulation under it, or any other provision of law.

Recent Enforcement in Rhode Island

The Attorney General’s public breach registry. The Office of the Attorney General publishes the breach notifications submitted to it. Its Data Breach Notifications page states the standing rule — “[u]nder state law, any time a data breach results in personal data of more than 500 Rhode Islanders being leaked, the Rhode Island Attorney General’s Office must be notified within 45 days” — and then lists every notification the office has received since 2025 by date and by notifying entity. The list runs from the first weeks of 2025 onward and covers a cross-section of the economy: retail and direct sales, health plans and community health centres, dental and medical billing, education technology, school districts, law firms, landscaping and manufacturing businesses, background-screening providers and, in the case of the January 14, 2025 RIBridges entry, the state’s own public benefits system. Because the registry is published rather than held internally, the record of who notified and when is a matter of public inspection.

Multistate challenge to federal student-data collection, March 2026. The Attorney General announced on March 11, 2026 that he had joined a coalition of attorneys general suing to stop what the office describes as an unlawful data demand to colleges and universities. The suit challenges United States Department of Education requirements, finalised on December 18, 2025 after a notice and comment period in which coalition members filed opposing comments, that institutions report data through the Integrated Postsecondary Education Data System disaggregated by race and sex and retroactively report seven years of such data, with a March 18, 2026 compliance deadline. The office states that the coalition argues the department failed to define critical terms, leaving universities to guess what to report under threat of severe financial penalties, and that the new demands “jeopardize student privacy and could lead to individuals being easily identified” while institutions carry their own data protection obligations to students. The attorneys general plead that the actions are contrary to law, fail to observe required procedure and are arbitrary and capricious. Rhode Island was joined by the attorneys general of California, Colorado, Connecticut, Delaware, Hawai’i, Illinois, Maryland, Massachusetts, Nevada, New Jersey, New York, Oregon, Vermont, Virginia, Wisconsin and Washington.

Pending Privacy Legislation

Chapter 6-48.1 was enacted twice over in the 2024 session — by P.L. 2024, ch. 430, § 2 and by P.L. 2024, ch. 453, § 2, companion measures that each carry the same January 1, 2026 effective date, which is why every section of the chapter is annotated to both. Nothing has amended the chapter since, and the operative sections still bear the “[Effective January 1, 2026]” notation the enacting acts gave them. The chapter as enacted contains no cure period, no rulemaking authority, no universal opt-out preference signal provision and no data protection assessment requirement, and no subsequent act has supplied any of them. The Identity Theft Protection Act of 2015 at chapter 11-49.3 remains in force alongside it, as does the Deceptive Trade Practices Act at chapter 6-13.1, whose civil penalty provision at § 6-13.1-8 was last amended by P.L. 2021, chs. 206 and 329.

Federal Privacy Laws That Apply in Rhode Island

Federal privacy law applies in Rhode Island by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The RIDTPPA sits alongside those rules rather than displacing them: the Rhode Island Attorney General enforces the state law, while the federal regulators continue to reach the sectors and activities they cover. The state-law counterpart to section 5 is the Deceptive Trade Practices Act (R.I. Gen. Laws ch. 6-13.1), which the Rhode Island Attorney General enforces against businesses whose stated data practices differ from their actual ones.

Rhode Island Privacy Law FAQ

Which Rhode Island businesses have privacy duties regardless of size?
Any commercial website or internet service provider. Section 6-48.1-3(a) requires any such business conducting business in Rhode Island, with customers in Rhode Island, or otherwise subject to Rhode Island jurisdiction to designate a controller, without reference to any threshold. Where the business collects, stores and sells customers’ personally identifiable information, the controller must identify all categories of personal data collected, identify all third parties to whom it has sold or may sell that information, and identify an active electronic mail address or other online mechanism for customer contact. The entity exemptions in subsection (d) still apply.
Does Rhode Island’s privacy law have a right to cure?
No provision of chapter 6-48.1 creates one. Section 6-48.1-8 sets out the consequences of a violation without any antecedent notice-and-cure step, in contrast to the thirty-day periods in Indiana, Kentucky, Minnesota and Nebraska and the sixty-day periods that ran in Connecticut, Delaware and New Hampshire. Section 6-48.1-8(b) gives the Attorney General sole enforcement authority; subsection (c) provides that nothing in the section authorises a private right of action.
What is the penalty for an intentional disclosure in Rhode Island?
Section 6-48.1-8(a) provides that where an individual or entity intentionally discloses personal data to a shell company or any entity formed or established solely or in part to circumvent the intent of the chapter, or in violation of any provision of the chapter, it “shall pay a fine of not less than one hundred dollars ($100) and no more than five hundred dollars ($500) for each such disclosure”. That is separate from the deceptive-trade-practice route in the same subsection, under which R.I. Gen. Laws § 6-13.1-8 supplies a civil penalty of not more than $10,000 per violation.
How long does a Rhode Island business have to report a breach?
Section 11-49.3-4(a)(2)(ii) gives a person other than a state or municipal agency no later than forty-five calendar days after confirmation of the breach and the ability to ascertain the information required for the notice. State and municipal agencies have thirty calendar days under subparagraph (i). Both clocks are subject to the legitimate needs of law enforcement under subsection (b), and both require notice to the Attorney General and the major credit reporting agencies where more than five hundred Rhode Island residents are to be notified — notice that must be made without delaying notice to the residents themselves.
What triggers a Rhode Island breach notification?
Section 11-49.3-4(a)(1) frames the trigger as a risk rather than as the fact of acquisition. It requires notification of any disclosure of personal information, or any breach of the security of the system, “that poses a significant risk of identity theft” to any Rhode Island resident whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person or entity. The duty falls on any municipal agency, state agency, or person who or that stores, owns, collects, processes, maintains, acquires, uses or licenses data that includes personal information.
Are nonprofits and universities covered by the RIDTPPA?
No. Section 6-48.1-3(d) provides that the chapter does not apply to any body, authority, board, bureau, commission, district or agency of the state or a political subdivision; nonprofit organizations; institutions of higher education; national securities associations registered under 15 U.S.C. § 78o-3; financial institutions or data subject to Title V of the Gramm-Leach-Bliley Act; or covered entities and business associates as defined in 45 C.F.R. § 160.103. The processing obligations in § 6-48.1-4(a) separately reach only for-profit entities.
Can a Rhode Island customer agree to waive the chapter’s protections?
Section 6-48.1-9 provides that “[a]ny waiver of the provisions of this chapter shall be void and unenforceable.” The same section makes the chapter severable, so that if any provision or its application is held invalid the invalidity does not affect other provisions or applications that can be given effect without it.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.