The Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) is Rhode Island’s first comprehensive consumer privacy statute. It was enacted on June 29, 2024, and—importantly—became law without the governor’s signature. The Act establishes a broad set of rights for Rhode Island residents and imposes significant obligations on businesses that collect, use, or disclose personal data. It takes effect on January 1, 2026.
Rhode Island’s law aligns the state with the growing national trend toward GDPR‑style consumer privacy protections, joining the expanding group of U.S. states with comprehensive privacy frameworks.
Scope and Applicability
The Act applies to controllers—entities that determine the purpose and means of processing personal data—conducting business in Rhode Island or offering products or services to Rhode Island residents.
Like other state privacy laws, it includes exemptions for:
- Data regulated by federal laws (HIPAA, GLBA, FERPA, etc.)
- Certain government entities
- Employment‑related data (depending on context)
Key Consumer Rights
Rhode Island residents gain a suite of rights similar to those in Colorado, Connecticut, and Virginia, including:
- Right to access personal data
- Right to delete personal data
- Right to correct inaccuracies
- Right to data portability
- Right to opt out of:
- Targeted advertising
- Sale of personal data
- Certain types of profiling
These rights reflect the national shift toward giving individuals meaningful control over their personal information.
Controller Obligations
Controllers must implement a range of privacy and governance measures, including:
Transparency
Clear, accessible privacy notices describing:
- Categories of personal data collected
- Purposes of processing
- Consumer rights and how to exercise them
Data Minimization & Purpose Limitation
Controllers may collect only what is reasonably necessary for disclosed purposes.
Security Measures
Reasonable administrative, technical, and physical safeguards must be in place.
Consent for Sensitive Data
Processing sensitive personal information requires opt‑in consent, consistent with other modern state privacy laws.
Data Protection Assessments
High‑risk processing activities—such as targeted advertising, profiling, or processing sensitive data—require documented assessments.
Enforcement
- Enforced exclusively by the Rhode Island Attorney General.
- No private right of action.
- Violations may result in civil penalties, including fines for improper disclosures.
Effective Date
- January 1, 2026 for all covered entities.
Why the Rhode Island Law Matters
The RIDTPPA is significant because it:
- Adds Rhode Island to the growing list of states with full‑spectrum privacy laws
- Aligns closely with the “Colorado/Connecticut model,” making multi‑state compliance more uniform
- Emphasizes transparency, consumer choice, and responsible data governance
- Reflects bipartisan momentum toward comprehensive privacy regulation across the U.S.
