close
close
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Rhode Island Privacy Law

RI

Rhode Island (RIDTPPA)

Last updated

RIDTPPA Enacted, in effect

Who this affects: This page tracks Rhode Island’s RIDTPPA, which governs controllers and processors.

Who it applies to: For-profit entities that do business in Rhode Island or target its residents, and meet: 35,000+ customers, or 10,000+ customers and more than 20% of gross revenue from selling data; some provisions apply under a separate test (see below).

Content on this page is not legal advice This page aggregates publicly cited regulatory facts for informational purposes only. It is not legal advice, and DataGrail is not responsible for decisions made in reliance on it. Consult qualified counsel for your specific compliance obligations.
Jan 1, 2026
Effective ↗
Attorney General
Enforced by ↗
$10,000
Maximum penalty per violation ↗
None
Private right of action ↗

The law, in plain English

Must · Can’t · Should

RIDTPPA, distilled to what actually changes your week. Read one column to know your floor, your hard limits, and the further obligations and good practices worth planning for.

Must

  • Honor access, correction, deletion and portability requests without undue delay and within 45 days of receipt. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. RI-6-48.1-5 “Confirm whether or not a controller is processing the customer’s personal data and access such personal data, unless such confirmation or access would require the controller to reveal a trade secret” Read the statute RI-6-48.1-5 “Correct inaccuracies in the customer’s personal data and delete personal data provided by, or obtained about, the customer, taking into account the nature of the personal data and the purposes of the processing of the customer’s personal data” Read the statute RI-6-48.1-5 “Obtain a copy of the customer’s personal data processed by the controller, in a portable and, to the extent technically feasible, readily usable format that allows the customer to transmit the data to another controller without undue delay, where the processing is carried out by automated means; provided such controller shall not be required to reveal any trade secret” Read the statute RI-6-48.1-6 “A controller shall respond to the customer without undue delay, but not later than forty-five (45) days after receipt of the request” Read the statute
  • Honor opt-outs of targeted ads, sales, and profiling for solely automated decisions with legal or similarly significant effects. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. RI-6-48.1-5 “Opt out of the processing of the personal data for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the customer” Read the statute
  • When declining a request, give reasons and appeal steps within 45 days, and answer appeals in writing within 60 days. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. RI-6-48.1-6 “the controller shall inform the customer without undue delay, but not later than forty-five (45) days after receipt of the request, of the justification for declining to act and instructions for how to appeal the decision” Read the statute RI-6-48.1-6 “A controller shall establish a process for a customer to appeal the controller’s refusal to take action on a request within a reasonable period of time after the customer’s receipt of the decision” Read the statute RI-6-48.1-6 “Not later than sixty (60) days after receipt of an appeal, a controller shall inform the customer in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decision.” Read the statute

Can't

  • Process sensitive data without consent, or a known child's sensitive data unless consent is obtained and COPPA is followed. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. RI-6-48.1-4 “The controller shall not process sensitive data concerning a customer without obtaining customer consent” Read the statute RI-6-48.1-4 “shall not process sensitive data of a known child unless consent is obtained and the information is processed in accordance with COPPA” Read the statute
  • Deny goods or vary prices or quality for opting out, except bona fide loyalty programs or services needing the opted-out data. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. RI-6-48.1-5 “No controller shall deny goods or services, charge different prices or rates for goods or services, or provide a different level of quality of goods or services to the customer if the customer opts out to use of their data. However, if a customer opts out of data collection, the covered entity is not required to provide a service that requires this data collection. (d) Controllers may provide different prices and levels for goods and services if it is for a bona fide loyalty, rewards, premium features, discount, or club card programs in which customers voluntarily participate” Read the statute
  • Discriminate against customers for exercising their rights, or rely on any waiver of the law, which is void and unenforceable. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. RI-6-48.1-5 “No controller shall discriminate against a customer for exercising their customer rights” Read the statute RI-6-48.1-9 “Any waiver of the provisions of this chapter shall be void and unenforceable” Read the statute

Should

  • Document a data protection assessment for each heightened-risk activity and keep it ready for attorney general investigations. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. RI-6-48.1-7 “A controller shall conduct and document a data protection assessment for each of the controller’s processing activities that presents a heightened risk of harm to a customer” Read the statute RI-6-48.1-7 “The attorney general may require a controller to disclose any data protection assessment that is relevant to an investigation conducted by the attorney general, and the controller shall make the data protection assessment available.” Read the statute
  • Sign a binding processor contract setting instructions, nature and purpose, data type, duration, and both parties' obligations. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. RI-6-48.1-7 “A contract between a controller and a processor shall govern the processor’s data processing procedures with respect to processing performed on behalf of the controller. The contract shall be binding and clearly set forth instructions for processing data; the nature and purpose of processing; the type of data subject to processing; the duration of processing; and the rights and obligations of both parties.” Read the statute
  • Offer a way to grant and revoke consent, suspend processing as soon as practicable, and effectuate revocation within 15 days. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. RI-6-48.1-4 “The controller shall provide customers with a mechanism to grant and revoke consent where consent is required” Read the statute RI-6-48.1-4 “Upon receipt of revocation, the controller shall suspend the processing of data as soon as is practicable” Read the statute RI-6-48.1-4 “The controller shall have no longer than fifteen (15) days from receipt to effectuate the revocation” Read the statute

These are the highlights we judge most important, not everything RIDTPPA requires. The comprehensive law section below covers the full detail, fact by fact, with the statutory text behind every one.

The comprehensive law

Rhode Island Data Transparency and Privacy Protection Act

RIDTPPA (H 7787) is Rhode Island’s comprehensive privacy law. Every fact was extracted from the primary statute by the DataGrail regulation engine and is grounded to the cited source. Scan the facts; the exact statutory text sits one click away on each source link.

Status
Enacted, in effect
Archived excerpt — the text we read § 6-48.1-1. Short title. [Effective January 1, 2026.] This chapter shall be known and may be cited as the “Rhode Island Data Transparency and Privacy Protection Act”. History of Section. P.L. 2024, ch. 430, § 2, effective January 1, 2026; P.L. 2024, ch. 453, § 2, effec… Archived from source — captured 2026-08-03 · snapshot 5c8d890d Verify at the source

Corroborated by Privacy-law tracker

Effective
January 1, 2026
Archived excerpt — the text we read § 6-48.1-1. Short title. [Effective January 1, 2026.] This chapter shall be known and may be cited as the “Rhode Island Data Transparency and Privacy Protection Act”. History of Section. P.L. 2024, ch. 430, § 2, effective January 1, 2026; P.L. 2024, ch. 453, § 2, effective January 1, 2026. Archived from source — captured 2026-08-03 · snapshot 5c8d890d Verify at the source

Corroborated by Privacy-law tracker

Enacted (without Governor's signature)
June 29, 2024
R.I. P.L. 2024, ch. 453 (H 7787) § 1 Archived excerpt — the text we read Chapter 453 2024 -- H 7787 SUBSTITUTE A AS AMENDED Enacted 06/29/2024 A N A C T RELATING TO COMMERCIAL LAW -- GENERAL REGULATORY PROVISIONS -- RHODE ISLAND DATA TRANSPARENCY AND PRIVACY PROTECTION ACT Introduced By: Representatives Shanley, Batista, Donovan, Edwards, Solomon, Voas, Daw… Archived from source — captured 2026-08-14 · snapshot 0d10e605 Verify at the source

Corroborated by Legislative record

Enforced by
Attorney General
Rhode Island Attorney General Archived excerpt — the text we read …; or (2) In violation of any provision of this chapter, that individual or entity shall pay a fine of not less than one hundred dollars ($100) and no more than five hundred dollars ($500) for each such disclosure. (b) The attorney general shall have sole enforcement authority of the provisions of this chapter and may enforce a violation of this chapter pursuant to: (1) The provisions of this section; or (2) General regulatory provisions of commercial law in this title, or both. (c) Nothing in this section shall be constru… Archived from source — captured 2026-08-03 · snapshot cc7a6ccd Verify at the source
Maximum penalty per violation
$10,000
Deceptive trade practice penalties apply, plus $100-$500 per intentional unlawful disclosure (e.g., to a shell company). Source for each figureAdditional $100 to $500 · RI-6-48.1-8 $10,000 · RI-6-13.1-8 $10,000 · RI-6-13.1-5 “Any person who violates the provisions of this chapter shall forfeit and pay to the state a civil penalty of not more than ten thousand dollars ($10,000) per violation.” View the statute
Right to cure
No cure period
Archived excerpt — the text we read …; or (2) In violation of any provision of this chapter, that individual or entity shall pay a fine of not less than one hundred dollars ($100) and no more than five hundred dollars ($500) for each such disclosure. (b) The attorney general shall have sole enforcement authority of the provisions of this chapter and may enforce a violation of this chapter pursuant to: (1) The provisions of this section; or (2) General regulatory provisions of commercial law in this title, or both. (c) Nothing in this section shall be construed to authorize any private right of action to enforce an… Archived from source — captured 2026-08-03 · snapshot cc7a6ccd Verify at the source

Corroborated by Privacy-law tracker

Private right of action
No private right of action.
Archived excerpt — the text we read …hority of the provisions of this chapter and may enforce a violation of this chapter pursuant to: (1) The provisions of this section; or (2) General regulatory provisions of commercial law in this title, or both. (c) Nothing in this section shall be construed to authorize any private right of action to enforce any provision of this chapter, any regulation hereunder, or any other provisions of law. History of Section. P.L. 2024, ch. 430, § 2, effective January 1, 2026; P.L. 2024, ch. 453, § 2, effective January 1, 2026. Archived from source — captured 2026-08-03 · snapshot cc7a6ccd Verify at the source

Corroborated by Privacy-law tracker

Universal opt-out signal
Not required

Corroborated by Privacy-law tracker

Who it applies to

For-profit entities that do business in Rhode Island or target its residents, and meet: 35,000+ customers, or 10,000+ customers and more than 20% of gross revenue from selling data; some provisions apply under a separate test (see full text)

What the law gives consumers

  • Right to access Archived excerpt — the text we read …es and levels for goods and services if it is for a bona fide loyalty, rewards, premium features, discount, or club card programs in which customers voluntarily participate. (e) A customer shall have the right to: (1) Confirm whether or not a controller is processing the customer’s personal data and access such personal data, unless such confirmation or access would require the controller to reveal a trade secret; (2) Correct inaccuracies in the customer’s personal data and delete personal data provided by, or obtained about, the customer, taking into account the nature of the personal data and the purposes of the processing of… Archived from source — captured 2026-08-03 · snapshot b3e3c990 Verify at the source
  • Right to correct Archived excerpt — the text we read …right to: (1) Confirm whether or not a controller is processing the customer’s personal data and access such personal data, unless such confirmation or access would require the controller to reveal a trade secret; (2) Correct inaccuracies in the customer’s personal data and delete personal data provided by, or obtained about, the customer, taking into account the nature of the personal data and the purposes of the processing of the customer’s personal data; (3) Obtain a copy of the customer’s personal data processed by the controller, in a portable and, to the extent technically feasible, readily usable format that allows the customer to transmit the data to another cont… Archived from source — captured 2026-08-03 · snapshot b3e3c990 Verify at the source
  • Right to delete Archived excerpt — the text we read …right to: (1) Confirm whether or not a controller is processing the customer’s personal data and access such personal data, unless such confirmation or access would require the controller to reveal a trade secret; (2) Correct inaccuracies in the customer’s personal data and delete personal data provided by, or obtained about, the customer, taking into account the nature of the personal data and the purposes of the processing of the customer’s personal data; (3) Obtain a copy of the customer’s personal data processed by the controller, in a portable and, to the extent technically feasible, readily usable format that allows the customer to transmit the data to another cont… Archived from source — captured 2026-08-03 · snapshot b3e3c990 Verify at the source
  • Right to data portability Archived excerpt — the text we read …ustomer’s personal data and delete personal data provided by, or obtained about, the customer, taking into account the nature of the personal data and the purposes of the processing of the customer’s personal data; (3) Obtain a copy of the customer’s personal data processed by the controller, in a portable and, to the extent technically feasible, readily usable format that allows the customer to transmit the data to another controller without undue delay, where the processing is carried out by automated means; provided such controller shall not be required to reveal any trade secret; and (4) Opt out of the processing of the personal data for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of solely automated decisions that produce legal or similarly signifi… Archived from source — captured 2026-08-03 · snapshot b3e3c990 Verify at the source
  • Right to opt out of sale Archived excerpt — the text we read …ws the customer to transmit the data to another controller without undue delay, where the processing is carried out by automated means; provided such controller shall not be required to reveal any trade secret; and (4) Opt out of the processing of the personal data for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the customer. (f) A customer may exercise rights under this section by secure and reliable means established by the controller and described to the customer in the controller’s privacy notice. A customer may designate an authorized… Archived from source — captured 2026-08-03 · snapshot b3e3c990 Verify at the source
  • Right to opt out of targeted advertising Archived excerpt — the text we read …ws the customer to transmit the data to another controller without undue delay, where the processing is carried out by automated means; provided such controller shall not be required to reveal any trade secret; and (4) Opt out of the processing of the personal data for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the customer. (f) A customer may exercise rights under this section by secure and reliable means established by the controller and described to the customer in the controller’s privacy notice. A customer may designate an authorized… Archived from source — captured 2026-08-03 · snapshot b3e3c990 Verify at the source
  • Right to opt out of profiling for solely automated significant decisions Archived excerpt — the text we read …ws the customer to transmit the data to another controller without undue delay, where the processing is carried out by automated means; provided such controller shall not be required to reveal any trade secret; and (4) Opt out of the processing of the personal data for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the customer. (f) A customer may exercise rights under this section by secure and reliable means established by the controller and described to the customer in the controller’s privacy notice. A customer may designate an authorized… Archived from source — captured 2026-08-03 · snapshot b3e3c990 Verify at the source
  • Sensitive data: opt-in consent required Archived excerpt — the text we read … (b) The controller shall establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data. (c) The controller shall not process sensitive data concerning a customer without obtaining customer consent and shall not process sensitive data of a known child unless consent is obtained and the information is processed in accordance with COPPA. Controllers and processors that comply with the verifiable parental consent req… Archived from source — captured 2026-08-03 · snapshot b98f77a2 Verify at the source
  • Right to appeal Archived excerpt — the text we read …her purpose pursuant to the provisions of this chapter; or (ii) Opting the customer out of the processing of such personal data for any purpose except for those exempted pursuant to the provisions of this chapter. (6) A controller shall establish a process for a customer to appeal the controller’s refusal to take action on a request within a reasonable period of time after the customer’s receipt of the decision. The appeal process shall be clearly and conspicuously available. Not later than sixty (60) days after receipt of an appeal, a controller shall inform the customer in writing of any action taken or not taken in response … Archived from source — captured 2026-08-03 · snapshot 5f6648ff Verify at the source
  • Right against discrimination Archived excerpt — the text we read …payment transaction. (2) Controlled or processed the personal data of not less than ten thousand (10,000) customers and derived more than twenty percent (20%) of their gross revenue from the sale of personal data. (b) No controller shall discriminate against a customer for exercising their customer rights. (c) No controller shall deny goods or services, charge different prices or rates for goods or services, or provide a different level of quality of goods or services to the customer if the customer opts out to use of th… Archived from source — captured 2026-08-03 · snapshot b3e3c990 Verify at the source
  • Not granted: Private right of action Archived excerpt — the text we read …hority of the provisions of this chapter and may enforce a violation of this chapter pursuant to: (1) The provisions of this section; or (2) General regulatory provisions of commercial law in this title, or both. (c) Nothing in this section shall be construed to authorize any private right of action to enforce any provision of this chapter, any regulation hereunder, or any other provisions of law. History of Section. P.L. 2024, ch. 430, § 2, effective January 1, 2026; P.L. 2024, ch. 453, § 2, effective January 1, 2026. Archived from source — captured 2026-08-03 · snapshot cc7a6ccd Verify at the source

Who the law governs

  • Controllers Archived excerpt — the text we read …ontains descriptions of personal data processing along with other, unrelated information, hovering over, muting, pausing, or closing a given piece of content, or agreement obtained through the use of dark patterns. (7) “Controller” means an individual who, or legal entity that, alone or jointly with others determines the purpose and means of processing personal data. (8) “COPPA” means the Children’s Online Privacy Protection Act of 1998, 15 U.S.C. § 6501 et seq., and the regulations, rules, guidance, and exemptions adopted, pursuant to said act, as said act and such regulations, ru… Archived from source — captured 2026-08-03 · snapshot 28b50951 Verify at the source
  • Processors Archived excerpt — the text we read …or set of operations performed, whether by manual or automated means, on personal data or on sets of personal data, such as the collection, use, storage, disclosure, analysis, deletion, or modification of personal data. “Processor” means an individual who, or legal entity that, processes personal data on behalf of a controller. (21) “Profiling” means any form of automated processing performed on personal data to evaluate, analyze, or predict personal aspects related to an identified or identifiable individual’s economic situation, health, per… Archived from source — captured 2026-08-03 · snapshot 28b50951 Verify at the source

Exemptions

  • State and local government bodies Archived excerpt — the text we read …sclose such processing. (c) Nothing in this chapter shall be construed to authorize the collection, storage, or disclosure of information or data that is otherwise prohibited or restricted by state or federal law. (d) This chapter does not apply to any body, authority, board, bureau, commission, district, or agency of this state, or any political subdivision of this state; nonprofit organization; institution of higher education; national securities association that is registered under 15 U.S.C. § 78o-3 of the Securities Exchange Act of 1934, as amended from time to time; financial instit… Archived from source — captured 2026-08-03 · snapshot 72617356 Verify at the source
  • Nonprofit organizations Archived excerpt — the text we read …erwise prohibited or restricted by state or federal law. (d) This chapter does not apply to any body, authority, board, bureau, commission, district, or agency of this state, or any political subdivision of this state; nonprofit organization; institution of higher education; national securities association that is registered under 15 U.S.C. § 78o-3 of the Securities Exchange Act of 1934, as amended from time to time; financial institution or data subject to Title V of the Gramm-Leach-Blile… Archived from source — captured 2026-08-03 · snapshot 72617356 Verify at the source
  • Institutions of higher education Archived excerpt — the text we read …tricted by state or federal law. (d) This chapter does not apply to any body, authority, board, bureau, commission, district, or agency of this state, or any political subdivision of this state; nonprofit organization; institution of higher education; national securities association that is registered under 15 U.S.C. § 78o-3 of the Securities Exchange Act of 1934, as amended from time to time; financial institution or data subject to Title V of the Gramm-Leach-Bliley Act, 15 U.S.C. § 6801 et seq.; … Archived from source — captured 2026-08-03 · snapshot 72617356 Verify at the source
  • National securities associations registered under securities law Archived excerpt — the text we read … (d) This chapter does not apply to any body, authority, board, bureau, commission, district, or agency of this state, or any political subdivision of this state; nonprofit organization; institution of higher education; national securities association that is registered under 15 U.S.C. § 78o-3 of the Securities Exchange Act of 1934, as amended from time to time; financial institution or data subject to Title V of the Gramm-Leach-Bliley Act, 15 U.S.C. § 6801 et seq.; or covered entity or business associate, as defined in 45 C.F.R. § 160.103. (e) T… Archived from source — captured 2026-08-03 · snapshot 72617356 Verify at the source
  • Financial institutions and data subject to GLBA Title V Affiliates of a financial institution are also exempt. 6-48.1-10(a). Archived excerpt — the text we read …on of this state; nonprofit organization; institution of higher education; national securities association that is registered under 15 U.S.C. § 78o-3 of the Securities Exchange Act of 1934, as amended from time to time; financial institution or data subject to Title V of the Gramm-Leach-Bliley Act, 15 U.S.C. § 6801 et seq.; or covered entity or business associate, as defined in 45 C.F.R. § 160.103. (e) The following information and data are exempt from the provisions of this chapter: (1) Protected health information under HIPAA; (2) Pa… Archived from source — captured 2026-08-03 · snapshot 72617356 Verify at the source
  • HIPAA covered entities and business associates Archived excerpt — the text we read …at is registered under 15 U.S.C. § 78o-3 of the Securities Exchange Act of 1934, as amended from time to time; financial institution or data subject to Title V of the Gramm-Leach-Bliley Act, 15 U.S.C. § 6801 et seq.; or covered entity or business associate, as defined in 45 C.F.R. § 160.103. (e) The following information and data are exempt from the provisions of this chapter: (1) Protected health information under HIPAA; (2) Patient-identifying information for purposes of 42 U.S.C. § 290dd-2; (3) Iden… Archived from source — captured 2026-08-03 · snapshot 72617356 Verify at the source
  • Protected health information under HIPAA Archived excerpt — the text we read … Gramm-Leach-Bliley Act, 15 U.S.C. § 6801 et seq.; or covered entity or business associate, as defined in 45 C.F.R. § 160.103. (e) The following information and data are exempt from the provisions of this chapter: (1) Protected health information under HIPAA; (2) Patient-identifying information for purposes of 42 U.S.C. § 290dd-2; (3) Identifiable private information for purposes of the federal policy for the protection of human research subjects under 45 C.F.R. §§ 46.101… Archived from source — captured 2026-08-03 · snapshot 72617356 Verify at the source
  • Patient-identifying information under 42 U.S.C. 290dd-2 Archived excerpt — the text we read …q.; or covered entity or business associate, as defined in 45 C.F.R. § 160.103. (e) The following information and data are exempt from the provisions of this chapter: (1) Protected health information under HIPAA; (2) Patient-identifying information for purposes of 42 U.S.C. § 290dd-2; (3) Identifiable private information for purposes of the federal policy for the protection of human research subjects under 45 C.F.R. §§ 46.101 through 46.124; (4) Identifiable private information that is otherwise i… Archived from source — captured 2026-08-03 · snapshot 72617356 Verify at the source
  • Human research subjects information Archived excerpt — the text we read ….103. (e) The following information and data are exempt from the provisions of this chapter: (1) Protected health information under HIPAA; (2) Patient-identifying information for purposes of 42 U.S.C. § 290dd-2; (3) Identifiable private information for purposes of the federal policy for the protection of human research subjects under 45 C.F.R. §§ 46.101 through 46.124; (4) Identifiable private information that is otherwise information collected as part of human subjects research pursuant to the good clinical practice guidelines issued by the International Council for Harmonization o… Archived from source — captured 2026-08-03 · snapshot 72617356 Verify at the source
  • Human subjects research under good clinical practice guidelines Archived excerpt — the text we read …ying information for purposes of 42 U.S.C. § 290dd-2; (3) Identifiable private information for purposes of the federal policy for the protection of human research subjects under 45 C.F.R. §§ 46.101 through 46.124; (4) Identifiable private information that is otherwise information collected as part of human subjects research pursuant to the good clinical practice guidelines issued by the International Council for Harmonization of Technical Requirements for Pharmaceuticals for Human Use; (5) The protection of human subjects under 21 C.F.R. Parts 50 and 56, or personal data used or shared in research, as defined in 45 C.F.R. § 164.501 or other research conducted in accordance with applicable law; (6) … Archived from source — captured 2026-08-03 · snapshot 72617356 Verify at the source
  • Human subjects protection under 21 CFR Parts 50 and 56 / research data Archived excerpt — the text we read …tion collected as part of human subjects research pursuant to the good clinical practice guidelines issued by the International Council for Harmonization of Technical Requirements for Pharmaceuticals for Human Use; (5) The protection of human subjects under 21 C.F.R. Parts 50 and 56, or personal data used or shared in research, as defined in 45 C.F.R. § 164.501 or other research conducted in accordance with applicable law; (6) Information and documents created for purposes of the Health Care Quality Improvement Act of 1986, 42 U.S.C. § 11101 et seq.; (7) Patient safety work product for purposes of the Patient Safety and Quality Improve… Archived from source — captured 2026-08-03 · snapshot 72617356 Verify at the source
  • Health Care Quality Improvement Act information Archived excerpt — the text we read …; (5) The protection of human subjects under 21 C.F.R. Parts 50 and 56, or personal data used or shared in research, as defined in 45 C.F.R. § 164.501 or other research conducted in accordance with applicable law; (6) Information and documents created for purposes of the Health Care Quality Improvement Act of 1986, 42 U.S.C. § 11101 et seq.; (7) Patient safety work product for purposes of the Patient Safety and Quality Improvement Act, 42 U.S.C. § 299b-21 et seq., as amended from time to time; (8) Information derived from any of the healthcare-related in… Archived from source — captured 2026-08-03 · snapshot 72617356 Verify at the source
  • Patient Safety and Quality Improvement Act work product Archived excerpt — the text we read … 45 C.F.R. § 164.501 or other research conducted in accordance with applicable law; (6) Information and documents created for purposes of the Health Care Quality Improvement Act of 1986, 42 U.S.C. § 11101 et seq.; (7) Patient safety work product for purposes of the Patient Safety and Quality Improvement Act, 42 U.S.C. § 299b-21 et seq., as amended from time to time; (8) Information derived from any of the healthcare-related information listed in this subsection that is de-identified in accordance with the requirements for de-identification pursuant to HIPAA; (9) Information orig… Archived from source — captured 2026-08-03 · snapshot 72617356 Verify at the source
  • HIPAA de-identified healthcare information Archived excerpt — the text we read …uality Improvement Act of 1986, 42 U.S.C. § 11101 et seq.; (7) Patient safety work product for purposes of the Patient Safety and Quality Improvement Act, 42 U.S.C. § 299b-21 et seq., as amended from time to time; (8) Information derived from any of the healthcare-related information listed in this subsection that is de-identified in accordance with the requirements for de-identification pursuant to HIPAA; (9) Information originating from and intermingled to be indistinguishable with, or information treated in the same manner as, information exempt under this subsection that is maintained by a covered entity or business… Archived from source — captured 2026-08-03 · snapshot 72617356 Verify at the source
  • Information intermingled with exempt covered entity/business associate information Archived excerpt — the text we read …rom time to time; (8) Information derived from any of the healthcare-related information listed in this subsection that is de-identified in accordance with the requirements for de-identification pursuant to HIPAA; (9) Information originating from and intermingled to be indistinguishable with, or information treated in the same manner as, information exempt under this subsection that is maintained by a covered entity or business associate, program, or qualified service organization, as specified in 42 U.S.C. § 290dd-2, as amended from time to time; (10) Information used for public health activities and purposes as authorized by HIPAA, community health activities, and population health activities; (11) The collection, maintenance, d… Archived from source — captured 2026-08-03 · snapshot 72617356 Verify at the source
  • Public health activities information Archived excerpt — the text we read …information exempt under this subsection that is maintained by a covered entity or business associate, program, or qualified service organization, as specified in 42 U.S.C. § 290dd-2, as amended from time to time; (10) Information used for public health activities and purposes as authorized by HIPAA, community health activities, and population health activities; (11) The collection, maintenance, disclosure, sale, communication, or use of any personal information bearing on a customer’s creditworthiness, credit standing, credit capacity, character, general reputation, personal… Archived from source — captured 2026-08-03 · snapshot 72617356 Verify at the source
  • FCRA-regulated data Archived excerpt — the text we read …, character, general reputation, personal characteristics, or mode of living by a customer reporting agency, furnisher, or user that provides information for use in a customer report, and by a user of a customer report, but only to the extent that such activity is regulated by and authorized under the Fair Credit Reporting Act, 15 U.S.C. § 1681 et seq., as amended from time to time; (12) Personal data collected, processed, sold, or disclosed in compliance with the Driver’s Privacy Protection Act of 1994, 18 U.S.C. § 2721 et seq., as amended from time to time; (13) Personal data regulated by the … Archived from source — captured 2026-08-03 · snapshot 72617356 Verify at the source
  • Driver's Privacy Protection Act data Archived excerpt — the text we read …mer report, and by a user of a customer report, but only to the extent that such activity is regulated by and authorized under the Fair Credit Reporting Act, 15 U.S.C. § 1681 et seq., as amended from time to time; (12) Personal data collected, processed, sold, or disclosed in compliance with the Driver’s Privacy Protection Act of 1994, 18 U.S.C. § 2721 et seq., as amended from time to time; (13) Personal data regulated by the Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g et seq., as amended from time to time; (14) Personal data collected, processed, sold, or disclosed in compliance with t… Archived from source — captured 2026-08-03 · snapshot 72617356 Verify at the source
  • FERPA-regulated data Archived excerpt — the text we read …., as amended from time to time; (12) Personal data collected, processed, sold, or disclosed in compliance with the Driver’s Privacy Protection Act of 1994, 18 U.S.C. § 2721 et seq., as amended from time to time; (13) Personal data regulated by the Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g et seq., as amended from time to time; (14) Personal data collected, processed, sold, or disclosed in compliance with the Farm Credit Act, 12 U.S.C. § 2001 et seq., as amended from time to time; (15) Data processed or maintained in the course of an indivi… Archived from source — captured 2026-08-03 · snapshot 72617356 Verify at the source
  • Farm Credit Act data Archived excerpt — the text we read …tection Act of 1994, 18 U.S.C. § 2721 et seq., as amended from time to time; (13) Personal data regulated by the Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g et seq., as amended from time to time; (14) Personal data collected, processed, sold, or disclosed in compliance with the Farm Credit Act, 12 U.S.C. § 2001 et seq., as amended from time to time; (15) Data processed or maintained in the course of an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party, to the extent that the data is col… Archived from source — captured 2026-08-03 · snapshot 72617356 Verify at the source
  • Employment data Archived excerpt — the text we read …20 U.S.C. § 1232g et seq., as amended from time to time; (14) Personal data collected, processed, sold, or disclosed in compliance with the Farm Credit Act, 12 U.S.C. § 2001 et seq., as amended from time to time; (15) Data processed or maintained in the course of an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party, to the extent that the data is collected and used within the context of that role, as the emergency contact information of an individual or that is necessary to retain to administer benefits for another individual relating to the individual who is the subject of the information under this subsection … Archived from source — captured 2026-08-03 · snapshot 72617356 Verify at the source
  • Emergency contact information Archived excerpt — the text we read …e of an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party, to the extent that the data is collected and used within the context of that role, as the emergency contact information of an individual or that is necessary to retain to administer benefits for another individual relating to the individual who is the subject of the information under this subsection and used for the purposes of administering such benefit… Archived from source — captured 2026-08-03 · snapshot 72617356 Verify at the source
  • Benefits administration data Archived excerpt — the text we read … as an agent or independent contractor of a controller, processor, or third party, to the extent that the data is collected and used within the context of that role, as the emergency contact information of an individual or that is necessary to retain to administer benefits for another individual relating to the individual who is the subject of the information under this subsection and used for the purposes of administering such benefits; and (16) Personal data collected, processed, sold, or disclosed in relation to price, route, or service, as such terms are used in the Airline Deregulation Act, 49 U.S.C. § 40101 et seq., as amended from time to time,… Archived from source — captured 2026-08-03 · snapshot 72617356 Verify at the source
  • Airline Deregulation Act price/route/service data held by air carriers To the extent preempted. Archived excerpt — the text we read …ecessary to retain to administer benefits for another individual relating to the individual who is the subject of the information under this subsection and used for the purposes of administering such benefits; and (16) Personal data collected, processed, sold, or disclosed in relation to price, route, or service, as such terms are used in the Airline Deregulation Act, 49 U.S.C. § 40101 et seq., as amended from time to time, by an air carrier subject to said act, to the extent subsections (e)(1) to (e)(11), inclusive, of this section are preempted by the Airline Deregulation Act, 49 U.S.C. § 41713, as amended from time to time. History of Section. P.L. 2024, ch. 430, § 2, effective January 1, 2026; P.L. 2024, ch. 453, § 2, effective January 1, 2026. Archived from source — captured 2026-08-03 · snapshot 72617356 Verify at the source
  • Contractors/subcontractors/agents of state or local government Archived excerpt — the text we read …Gramm-Leach-Bliley Act, 15 U.S.C. § 6801 et seq., and its implementing regulations, or to information or data subject to the Health Insurance Portability and Accountability Act of 1996 (HIPAA), Pub. L. No. 104-191. (b) Nothing in this chapter shall be construed to apply to a contractor, subcontractor, or agent of a state agency or local unit of government when working for that state agency or local unit of government. (c) Nothing in this chapter shall be construed to apply to any entity recognized as a tax-exempt organization under the Internal Revenue Code. (d) Nothing in this chapter shall be construed to mandate and/or require t… Archived from source — captured 2026-08-03 · snapshot 70b1b3af Verify at the source
  • Tax-exempt organizations under Internal Revenue Code Archived excerpt — the text we read …4-191. (b) Nothing in this chapter shall be construed to apply to a contractor, subcontractor, or agent of a state agency or local unit of government when working for that state agency or local unit of government. (c) Nothing in this chapter shall be construed to apply to any entity recognized as a tax-exempt organization under the Internal Revenue Code. (d) Nothing in this chapter shall be construed to mandate and/or require the retention or disclosure of any specific individual’s personally identifiable information. (e) Nothing in this chapter shall prohibit or rest… Archived from source — captured 2026-08-03 · snapshot 70b1b3af Verify at the source
  • Consumer/customer reporting agency data Archived excerpt — the text we read …e) Nothing in this chapter shall prohibit or restrict the dissemination or sale of product sales summaries or statistical information or aggregate customer data that may include personally identifiable information. (f) Nothing in this chapter shall be construed to apply to any personally identifiable information or any other information collected, used, processed, or disclosed by or for a customer reporting agency as defined by 15 U.S.C. § 1681a(f). Provided, further, nothing in this chapter shall be construed to require any entity to collect, store, or sell personally identifiable information, and furthermore, nothing in this chapter shall be construed to require … Archived from source — captured 2026-08-03 · snapshot 70b1b3af Verify at the source
  • Product sales summaries, statistical information or aggregate customer data May include personally identifiable information. 6-48.1-10(e). Archived excerpt — the text we read … organization under the Internal Revenue Code. (d) Nothing in this chapter shall be construed to mandate and/or require the retention or disclosure of any specific individual’s personally identifiable information. (e) Nothing in this chapter shall prohibit or restrict the dissemination or sale of product sales summaries or statistical information or aggregate customer data that may include personally identifiable information. (f) Nothing in this chapter shall be construed to apply to any personally identifiable information or any other information collected, used, processed, or disclosed by or for a customer reporting agency as defined by 1… Archived from source — captured 2026-08-03 · snapshot 70b1b3af Verify at the source
  • Evidentiary privilege (compliance would violate a Rhode Island evidentiary privilege) Archived excerpt — the text we read …that the controller does not collect or maintain. This chapter is intended to apply only to covered entities that choose to collect, store, and sell or otherwise transfer or disclose personally identifiable information. The obligations imposed on controllers or processors under this chapter shall not apply where compliance by the controller or processor with this chapter would violate an evidentiary privilege under the law of this state. Nothing in this chapter shall be construed to prevent a controller or processor from providing personal data concerning a customer to a person covered by an evidentiary privilege under the laws of this state as part of … Archived from source — captured 2026-08-03 · snapshot 70b1b3af Verify at the source
  • Purely personal or household activity Archived excerpt — the text we read …cts the rights or freedoms of any person, including, but not limited to, the rights of any person to freedom of speech or freedom of the press guaranteed in the First Amendment to the United States Constitution; or (2) Apply to any person’s processing of personal data in the course of such person’s purely personal or household activities. (s) Personal data processed by a controller pursuant to this section may be processed to the extent that such processing is reasonably necessary in relation to the purposes for which such data is processed, as disclos… Archived from source — captured 2026-08-03 · snapshot 5eaa7f6f Verify at the source
  • Privileged communications to a person covered by an evidentiary privilege Archived excerpt — the text we read …e obligations imposed on controllers or processors under this chapter shall not apply where compliance by the controller or processor with this chapter would violate an evidentiary privilege under the law of this state. Nothing in this chapter shall be construed to prevent a controller or processor from providing personal data concerning a customer to a person covered by an evidentiary privilege under the laws of this state as part of a privileged communication. History of Section. P.L. 2024, ch. 430, § 2, effective January 1, 2026; P.L. 2024, ch. 453, § 2, effective January 1, 2026. Archived from source — captured 2026-08-03 · snapshot 70b1b3af Verify at the source
  • Rights and freedoms of others, including free speech and press Archived excerpt — the text we read … violation of said sections for the transgressions of the controller or processor from which such third-party controller or processor receives such personal data. (r) Nothing in this chapter shall be construed to: (1) Impose any obligation on a controller or processor that adversely affects the rights or freedoms of any person, including, but not limited to, the rights of any person to freedom of speech or freedom of the press guaranteed in the First Amendment to the United States Constitution; or (2) Apply to any person’s processing of personal data in the course of such person’s purely personal or household activities. (s) Personal data processed by a controller pursuant to this section may be processed t… Archived from source — captured 2026-08-03 · snapshot 5eaa7f6f Verify at the source
  • Financial institutions, their affiliates, GLBA Title V data, and others Entity- and data-level Financial institutions, their affiliates, GLBA Title V data, and information or data subject to HIPAA. Construction clause. Archived excerpt — the text we read § 6-48.1-10. Construction. [Effective January 1, 2026.] (a) Nothing in this chapter shall be deemed to apply in any manner to a financial institution, an affiliate of a financial institution, or data subject to Title V of the federal Gramm-Leach-Bliley Act, 15 U.S.C. § 6801 et seq., and its implementing regulations, or to information or data subject to the Health Insurance Portability and Accountability Act of 1996 (HIPAA), Pub. L. No. 104-191. (b) Nothing in this chapter shall be construed to apply to a contractor, subcontractor, or agent of a state agency or local unit of government when working for that state agency or local unit of government. (c) Nothi… Archived from source — captured 2026-08-03 · snapshot 70b1b3af Verify at the source

Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source.

Timeline

RIDTPPA milestones

This state currently has one dated milestone on the books.

Enforcement January 1, 2026

RIDTPPA took effect

Enforcement began — obligations have been live since this date.

Source: primary citation

Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source. Reference only, not legal advice.

When staying on top of the law isn't enough, DataGrail automates the work.
DSR automation and regulatory tracking — handled by the platform behind this reference.
How DataGrail helps
Back to the Regulations Hub Reference only — not legal advice. Published Sep 29, 2026