What Is the Rhode Island Data Transparency and Privacy Protection Act?
RIDTPPA applies to for-profit entities doing business in Rhode Island or targeting Rhode Island residents that meet either the 35,000-consumer branch or the 10,000-consumer-plus-more-than-20%-sale-revenue branch, subject to exemptions. Rights include access, correction, deletion, portability, and opt-outs from targeted advertising, sale, and certain profiling; controllers generally respond within 45 days, with a possible 45-day extension. Section 6-48.1-3 also requires qualifying commercial websites or internet service providers that collect, store, and sell customers' personally identifiable information to identify data categories, relevant third parties, and a contact mechanism in specified notices. The AG has sole enforcement authority and the chapter creates no private right of action.
At a glance
- Full name
- Rhode Island Data Transparency and Privacy Protection Act
- Short code
- RIDTPPA
- Effective date
- January 1, 2026
- Response reference
- 45 days in this snapshot
- Cure period
- None recorded in this snapshot
- Private right of action
- No
- Enforcement
- Rhode Island Attorney General. Consumer Protection Unit
- Penalty reference
- An intentional disclosure to a shell entity or in violation of the chapter carries a $100–$500 fine per disclosure under R.I. Gen. Laws § 6-48.1-8; other Deceptive Trade Practices Act remedies are not summarized here
- Statutory citation
- R.I. Gen. Laws §§ 6-48.1-1–6-48.1-10.
Who RIDTPPA applies to
A business is covered if it meets the applicability thresholds set out in R.I. Gen. Laws §§ 6-48.1-1–6-48.1-10.. The thresholds listed below are the research record for this law. Whether one or more applies depends on the current statute, its exceptions, and the business's facts; do not assume a universal threshold structure.
- For-profit entity that conducts business in Rhode Island or produces products or services targeted to Rhode Island residents, AND
- Controls or processes personal data of 35,000+ Rhode Island consumers (excluding data processed solely for payment), OR
- Controls or processes personal data of 10,000+ Rhode Island consumers AND derives more than 20% of gross revenue from the sale of personal data
Consumer rights under RIDTPPA
Access, correct, delete, port, and opt out of targeted advertising, sale, and certain profiling
Customer-facing category and third-party disclosure for qualifying commercial websites and ISPs
AG sole enforcement; no private right of action
Notable features (vs. CCPA)
RIDTPPA applies its customer-rights section to covered for-profit entities. Section 6-48.1-3 requires a qualifying commercial website or internet service provider that collects, stores, and sells customers' personally identifiable information to identify the data categories it collects, the third parties to whom it has sold or may sell that information, and a contact method in a customer agreement, addendum, or conspicuous website location. Covered controllers must also disclose sale and targeted-advertising processing.
Enforcement and penalty reference
Enforcing agency: Rhode Island Attorney General. Consumer Protection Unit
Penalty reference: An intentional disclosure to a shell entity or in violation of the chapter carries a $100–$500 fine per disclosure under R.I. Gen. Laws § 6-48.1-8; other Deceptive Trade Practices Act remedies are not summarized here
Cure period: The cited RIDTPPA chapter does not state a general cure period. Section 6-48.1-8 gives the Attorney General sole enforcement authority; any separate procedures or remedies under the general Deceptive Trade Practices Act should be checked independently.
Private right of action: RIDTPPA has no private right of action. Enforcement is exclusive to the Rhode Island Attorney General.
Where to file a complaint: Rhode Island Office of the Attorney General
How to exercise your RIDTPPA rights
- 1
Identify the business that holds your data. OfflistMe can help you review a provider route across 1,034 US/global workflow profiles in the 1,052-record research universe; it does not decide whether a law applies to a specific request.
- 2
Submit a request to the business's designated contact using the provider's current verification instructions. Include only the information reasonably needed to match your record and check the applicable Rhode Island residency, scope, exemption, and verification rules before sending.
- 3
This research snapshot records a 45-day reference window for the modeled request. Confirm the current statute, request type, controller scope, extension rule, and verification date before treating it as a deadline.
- 4
If the provider does not respond or disputes the request, preserve the request and response record, review the applicable exceptions, and consider the Rhode Island Office of the Attorney General complaint route at https://riag.ri.gov/consumer-protection/file-consumer-complaint. A complaint route does not itself guarantee deletion or a particular enforcement result.
Generate requests in under 60 seconds
Generate a RIDTPPA privacy request, $9 one-time
FAQ
What is the data-source disclosure requirement?+
Section 6-48.1-3 applies to a commercial website or internet service provider subject to Rhode Island jurisdiction that collects, stores, and sells customers' personally identifiable information. The required customer agreement, addendum, or conspicuous website notice must identify the categories collected, the third parties to whom the information has been sold or may be sold, and an active contact method; sale and targeted-advertising processing must also be disclosed.
Official sources & citations
Compare with sibling state laws
RIDTPPA is one of 18 comprehensive US state privacy laws. Its closest peers by effective date, useful when tracking how this law influenced or was influenced by neighboring legislation:
