Tennessee — Comprehensive Law

Tennessee Privacy Law

Tennessee’s comprehensive privacy statute contains a device no other state has enacted: a complete affirmative defense to any cause of action under the Act for a controller or processor that maintains a written privacy policy reasonably conforming to the NIST Privacy Framework. That single provision reorients the statute from a rule-compliance regime toward a standards-adoption one. Around it sits the narrowest applicability test in the country — $25 million in revenue plus 175,000 Tennessee consumers — and a penalty provision that pairs $7,500 per violation with discretionary treble damages for wilful conduct. The breach statute runs on a different logic entirely: it names FIPS 140-2 as the encryption benchmark, defines an unauthorized person to include a rogue employee, imposes no Attorney General notice duty at all, and gives injured customers a private right of action the privacy Act expressly denies.

The Tennessee Information Protection Act (TIPA)

TIPA was enacted as House Bill 1181, substituted for Senate Bill 73, and became Public Chapter No. 408 of the 113th General Assembly. Section 47-18-3202 sets a conjunctive applicability test that produces the highest consumer threshold of any state privacy law: the part applies to persons conducting business in Tennessee producing products or services targeting Tennessee residents that exceed twenty-five million dollars in revenue and either control or process the personal information of at least 25,000 consumers while deriving more than fifty percent of gross revenue from the sale of personal information, or during a calendar year control or process the personal information of at least 175,000 consumers. Section 47-18-3203 grants the standard suite — confirmation and access, correction, deletion, a portable copy, and an opt-out of targeted advertising, profiling, or the sale of personal information — exercisable by a known child’s parent or legal guardian on the child’s behalf, with a forty-five-day response window. Section 47-18-3212(e) forecloses private enforcement in unusually explicit terms, providing that a violation “shall not serve as the basis for, or be subject to, a private right of action, including a class action lawsuit, under this part or other law”. Section 6 of the public chapter set the effective date at July 1, 2025, “the public welfare requiring it”.

Effective dateJuly 1, 2025
CitationTenn. Code Ann. § 47-18-3201 et seq.
Enforced byTennessee Attorney General and Reporter
Maximum penaltyUp to $7,500 per violation under Tenn. Code Ann. § 47-18-3212(d)(1), plus discretionary treble damages for a wilful or knowing violation
Private right of actionNo, enforcement by the state only
Right to cure60 days (permanent)

Who Must Comply

The TIPA applies where a business has exceeds $25,000,000 in revenue, and controls or processes the personal information of at least 25,000 consumers and derives more than 50% of gross revenue from the sale of personal information, or during a calendar year, controls or processes the personal information of at least 175,000 consumers.

Section 47-18-3213 gives a controller or processor an affirmative defense to a cause of action under the part where it creates, maintains and complies with a written privacy policy that reasonably conforms to the NIST Privacy Framework, keeps pace with subsequent revisions, and provides the substantive rights the part requires. No other state privacy statute contains an equivalent, and none pairs a per-violation penalty with a treble-damages multiplier as § 47-18-3212(d)(2) does

Consumer Rights Under the TIPA

Residents of Tennessee can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.

Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.

Sector-Specific Privacy Laws in Tennessee

Release of personal consumer information (Tenn. Code Ann. § 47-18-2107)

Tennessee’s breach statute, rewritten in full by Senate Bill 547 of the 110th General Assembly, differs from its neighbours in four respects. The trigger is qualified: a “breach of system security” is acquisition of computerized data by an unauthorized person that materially compromises the security, confidentiality or integrity of personal information maintained by the information holder. The encryption safe harbor names a federal standard rather than describing one — personal information does not include information encrypted in accordance with the current version of the Federal Information Processing Standard (FIPS) 140-2 if the encryption key has not been acquired by an unauthorized person. “Unauthorized person” is defined to include an employee of the information holder who is discovered by the holder to have obtained personal information for an unlawful purpose, closing the insider gap most statutes leave open through their good-faith-employee carve-outs. And the deadline is a hard forty-five days: subsection (b) requires disclosure no later than forty-five days from the discovery or notification of the breach unless a longer period is required by the legitimate needs of law enforcement, subsection (c) applies the same forty-five days to an information holder notifying an owner of data it does not own, and subsection (d) restarts the forty-five days from the date law enforcement determines that notification will not compromise an investigation. Substitute notice becomes available where the cost would exceed $250,000, the affected class exceeds 500,000 persons, or contact information is insufficient. The data elements are narrow — a name with a Social Security number, driver licence number, or account, credit or debit card number with its security or access code — and the section does not apply to holders subject to Title V of the Gramm-Leach-Bliley Act or to HIPAA as expanded by the HITECH Act.

Tennessee Consumer Protection Act (Tenn. Code Ann. § 47-18-101 et seq.)

TIPA was drafted as a new part of title 47, chapter 18 — the Consumer Protection Act — rather than as a freestanding chapter, which is why the enforcing official is the “attorney general and reporter” throughout and why the Act’s remedies read like consumer-protection remedies. Section 47-18-3212(c) lists what the office may seek once a cure period lapses: a declaratory judgment that the act or practice violates the chapter; injunctive relief, preliminary and permanent, to prevent an additional violation and compel compliance; civil penalties; reasonable attorney’s fees and investigative costs; and other relief the court determines appropriate. Subsection (f) separately allows recovery of reasonable expenses incurred in investigating and preparing the case, including attorney fees, in any action initiated under the part.

Voluntary privacy program affirmative defense (Tenn. Code Ann. § 47-18-3213)

Section 47-18-3213 is Tennessee’s signature provision and operates as a substantive defense rather than as a mitigating factor. Subsection (a) gives a controller or processor an affirmative defense to a cause of action for a violation of the part where it creates, maintains and complies with a written privacy policy that reasonably conforms to the NIST privacy framework entitled “A Tool for Improving Privacy through Enterprise Risk Management Version 1.0”, or to other documented policies, standards and procedures designed to safeguard consumer privacy; that is updated to reasonably conform with a subsequent revision to the NIST or comparable framework within two years of that revision’s publication date; and that provides a person with the substantive rights the part requires. Subsection (b) makes the scale and scope of the program appropriate where it is based on five factors: the size and complexity of the business, the nature and scope of its activities, the sensitivity of the personal information processed, the cost and availability of tools to improve privacy protections and data governance, and compliance with a comparable state or federal law. Subsection (c) adds that a controller may be certified under the Asia Pacific Economic Cooperation’s Cross Border Privacy Rules system.

Data Breach Notification in Tennessee

Section 47-18-2107 is one of the few state breach statutes that never routes notice to a regulator. Its obligations run to residents and, where the information holder does not own the data, to the owner or licensee — both within forty-five days of discovery or notification. What it provides instead of an agency filing is a private remedy: subsection (h) states that any customer of an information holder who is a person or business entity, but not an agency of the state or a political subdivision, and who is injured by a violation of the section, may institute a civil action to recover damages and to enjoin the information holder from further action in violation of the section, with those rights and remedies cumulative to each other and to any others available under law. That is the opposite of the arrangement in TIPA, where § 47-18-3212(e) bars any private action including a class action. The definitional architecture is equally distinctive. A breach requires acquisition that materially compromises security, confidentiality or integrity. Encrypted information falls outside the definition of personal information only where the encryption conforms to the current version of FIPS 140-2 and the key has not been acquired — a named federal benchmark rather than a general reasonableness test. And “unauthorized person” expressly includes an employee of the information holder discovered to have obtained personal information for an unlawful purpose.

Residents must be notified no later than forty-five days from the discovery or notification of the breach of system security. Section 47-18-2107 imposes no notice duty to the Attorney General or any other state agency. Complaints are taken by the Tennessee Attorney General and Reporter, which enforces the statute.

How the TIPA Is Enforced

Sixty days to cure, with the office setting its own reasonable cause. Section 47-18-3212(a) gives the attorney general and reporter exclusive authority to enforce the part. Subsection (b) provides that the office may develop reasonable cause to believe a controller or processor is in violation based on its own inquiry or on consumer or public complaints, and requires sixty days’ written notice identifying the specific provisions alleged to have been violated before any action is initiated. If the controller or processor cures the noticed violation within the sixty-day period and provides an express written statement that the alleged violations have been cured and that no further violations shall occur, the office shall not initiate an action. Subsection (c) permits action where violations continue after the cure period or the written statement is breached.

The office published its reading of the Act before it took effect. On April 30, 2025 the Attorney General’s office issued guidance for businesses and consumers on the Tennessee Information Protection Act, two months before the July 1, 2025 effective date. It set out the applicability thresholds — more than $25 million in annual revenue plus either 25,000 Tennessee consumers with fifty percent of gross annual revenue from the sale of that information, or 175,000 Tennessee consumers in a calendar year — the consumer rights and the forty-five-day response window, the NIST affirmative defense with its two-year update requirement, and the sixty-day right to cure that precedes any enforcement action.

Recent Enforcement in Tennessee

Marriott International — $52 million multistate settlement, $919,043 to Tennessee. On October 9, 2024 the Attorney General announced a $52 million multistate settlement with Marriott International over the breach of the Starwood guest reservation database, with Tennessee receiving $919,043.00. The breach ran from July 2014 to September 2018 and involved 131.5 million guest records in the United States; intruders remained undetected in the system for more than four years. The states alleged that Marriott failed to implement reasonable data security measures and did not remediate security deficiencies when integrating the acquired Starwood systems, with inadequate oversight of the acquired network. The injunctive terms are among the most detailed in any state data-security settlement: implementation of zero-trust principles and a comprehensive security program with executive-level reporting; data minimisation requiring less consumer information to be collected and retained; encryption, network segmentation, patch management and intrusion detection; multi-factor authentication options for loyalty accounts with suspicious activity reviews; consumer data deletion rights even where not legally required; risk-based security assessments addressing potential consumer harm; third-party security audits every two years for twenty years; and enhanced security review of future acquisitions before network integration.

23andMe — $348,687 to Tennessee in the multistate genetic data settlement. On July 14, 2026 the Attorney General announced that Tennessee had joined a coalition of forty-three attorneys general in a settlement with the bankruptcy trustee of 23andMe, resolving the states’ claims arising from the 2023 breach that exposed the genetic and personal information of 6.9 million customers worldwide, including 116,395 Tennesseans. The states recover $18 million in available funds, of which Tennessee expects $348,687. The multistate investigation found that the company failed to implement reasonable safeguards, including protections against credential stuffing attacks, adequate monitoring for suspicious activity, and timely responses to known security vulnerabilities.

Pending Privacy Legislation

Tennessee’s privacy framework arrived in a single piece and has not been amended since. House Bill 1181, sponsored by Representatives Garrett, Zachary, Towns, Haston, Howell, Moody, Williams, Tim Hicks, Todd and Clemmons and substituted for Senate Bill 73 by Senators Watson, Stevens, Campbell, Lowe and Reeves, became Public Chapter No. 408 of the 113th General Assembly and took effect July 1, 2025 under section 6 of the chapter. The breach statute was last rewritten by Senate Bill 547 of the 110th General Assembly, sponsored by Senator Ketron with House Bill 545 by Representative Rogers, which replaced § 47-18-2107 in its entirety and set the forty-five-day clock and the FIPS 140-2 safe harbor now in force. In April 2025 the Attorney General’s office published guidance for businesses and consumers on TIPA ahead of the effective date.

Federal Privacy Laws That Apply in Tennessee

Federal privacy law applies in Tennessee by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The TIPA sits alongside those rules rather than displacing them: the Tennessee Attorney General and Reporter enforce the state law, while the federal regulators continue to reach the sectors and activities they cover. The state-law counterpart to section 5 is the Tennessee Consumer Protection Act (Tenn. Code Ann. § 47-18-101 et seq.), which the Tennessee Attorney General and Reporter enforces against businesses whose stated data practices differ from their actual ones.

Tennessee Privacy Law FAQ

What is Tennessee’s NIST affirmative defense?
Section 47-18-3213(a) gives a controller or processor a complete affirmative defense to a cause of action for a violation of the Tennessee Information Protection Act where it creates, maintains and complies with a written privacy policy that reasonably conforms to the NIST privacy framework “A Tool for Improving Privacy through Enterprise Risk Management Version 1.0”, or to other documented policies, standards and procedures designed to safeguard consumer privacy; that is updated to reasonably conform with a subsequent revision within two years of that revision’s publication date; and that provides a person with the substantive rights the part requires. No other state comprehensive privacy statute contains an equivalent provision.
How large must a company be before TIPA applies?
Larger than under any other state privacy law. Section 47-18-3202 requires revenue exceeding twenty-five million dollars and one of two data thresholds: personal information of at least 25,000 consumers together with more than fifty percent of gross revenue from the sale of personal information, or personal information of at least 175,000 consumers during a calendar year. The 175,000 figure is well above the 100,000 that Virginia, Colorado, Iowa and most other states use, and the conjunctive revenue floor means a data-intensive company below $25 million falls outside the part entirely.
Can a Tennessean sue over a privacy violation or a data breach?
Over a breach, yes; over a TIPA violation, no. Section 47-18-2107(h) provides that any customer of an information holder who is injured by a violation of the breach section may institute a civil action to recover damages and to enjoin further violating conduct, with those rights cumulative to any others available under law. Section 47-18-3212(e) takes the opposite position for the privacy Act: a violation “shall not serve as the basis for, or be subject to, a private right of action, including a class action lawsuit, under this part or other law”.
Does Tennessee require breach notice to a state agency?
No. Section 47-18-2107 sets duties running to affected residents and, for an information holder that does not own the data, to the owner or licensee — both on the forty-five-day clock — but it contains no provision requiring notice to the Attorney General and Reporter, to a state agency, or to the consumer reporting agencies. That makes Tennessee one of the small group of states where a breach can be fully worked through without any regulator filing under the breach statute itself.
What encryption standard does Tennessee’s breach law recognise?
FIPS 140-2 by name. Section 47-18-2107(a)(4)(B)(ii) excludes from “personal information” any information that has been encrypted in accordance with the current version of the Federal Information Processing Standard (FIPS) 140-2 “if the encryption key has not been acquired by an unauthorized person”. The section separately defines encryption at subsection (a)(2) as rendering data unusable, unreadable or indecipherable through a security technology or methodology generally accepted in the field of information security, but it is the FIPS reference that governs the safe harbor.
Does a rogue employee count as an unauthorized person in Tennessee?
Yes, and the statute says so rather than leaving it to inference. Section 47-18-2107(a)(5) provides that “unauthorized person” includes an employee of the information holder who is discovered by the information holder to have obtained personal information for an unlawful purpose. Most state statutes address the same ground from the other direction, by carving good-faith employee acquisition out of the breach definition; Tennessee does both, so an insider acting for an unlawful purpose is inside the definition rather than merely outside the carve-out.
What penalties can the Tennessee Attorney General seek under TIPA?
Section 47-18-3212(d)(1) allows a court to impose a civil penalty of up to seven thousand five hundred dollars for each violation of the part. Subsection (d)(2) adds a multiplier that is unusual in state privacy law: if the court finds the controller or processor wilfully or knowingly violated the part, the court may, in its discretion, award treble damages. The office may also obtain a declaratory judgment, preliminary and permanent injunctive relief, reasonable attorney’s fees and investigative costs, and other relief the court determines appropriate, and may recover its investigation and preparation expenses under subsection (f).
Has Tennessee recovered anything in a privacy or data-security matter?
Yes, principally through multistate work. On October 9, 2024 the office announced a $52 million multistate settlement with Marriott International over the Starwood guest reservation database breach, with Tennessee receiving $919,043.00; 131.5 million United States guest records were involved and intruders had remained undetected from July 2014 to September 2018. On July 14, 2026 the office announced a settlement with the bankruptcy trustee of 23andMe as part of a coalition of forty-three attorneys general, with Tennessee expecting $348,687 of the $18 million recovered on behalf of 116,395 affected Tennesseans.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.