Rhode Island Privacy Law Compliance: Data Transparency and Privacy Protection Act Requests on the 45-Day Deadline
Rhode Island wrote the one state privacy law you can be under the size threshold for and still owe something. The rights obligations start at 35,000 residents, but the disclosure rule in the same chapter binds any commercial website that collects, stores, and sells personal information here, and it asks you to name the third parties you have sold data to and the ones you may sell to. There is no cure period to fall back on. Obtainer finds where a person's data lives across your systems, compiles one reviewable manifest, drafts the response, and tracks the 45-day clock.
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
In short
The Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA), codified at R.I. Gen. Laws chapter 6-48.1, took effect January 1, 2026. It passed the General Assembly on June 13, 2024 and became law on June 25, 2024, when Governor Dan McKee transmitted it without his signature. The rights obligations reach for-profit entities doing business in Rhode Island, or targeting products or services to Rhode Island residents, that in the prior calendar year controlled or processed the personal data of at least 35,000 customers, excluding data processed solely to complete a payment transaction, or at least 10,000 customers while deriving more than 20 percent of gross revenue from selling personal data.
Those thresholds sit well below the 100,000 figure Virginia, Texas, Indiana, and Kentucky use, so RIDTPPA reaches mid-market companies that fall outside most other state laws. The bigger departure is a second obligation with no threshold at all. Section 6-48.1-3, headed information sharing practices, requires a commercial website or internet service provider that collects, stores, and sells customers' personally identifiable information to identify, in its customer agreement or another conspicuous place where such notices are customarily posted, every category of personal data it collects and every third party to whom it has sold or may sell that information. No other state asks you to name prospective recipients, and because the section binds any covered website rather than only controllers over the threshold, a company far too small for the rights obligations can still owe a Rhode Island notice.
Customers get the familiar rights: confirm and access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and profiling that produces legal or similarly significant effects. You answer within 45 days, with one 45-day extension if you notify the customer inside the first window, and a denial has to carry an appeal route you resolve in writing within 60 days. Sensitive data needs opt-in consent, assessments apply to processing created or generated on or after January 1, 2026, employment and business-to-business data sit outside the act, and Rhode Island does not require you to honor Global Privacy Control.
Enforcement is where Rhode Island stops being ordinary. A violation is a deceptive trade practice carrying civil penalties of up to $10,000, and intentionally disclosing personal data in violation draws a separate fine of not less than $100 and not more than $500 for each such disclosure. The Attorney General enforces exclusively, there is no private right of action, and there is no right to cure at all, not a sunsetting one like Connecticut had and not a permanent one like Kentucky kept. No statutory window exists in which fixing a problem later makes it go away.
Obtainer covers the operational half. It intakes the request, verifies who is asking, discovers where that person's personal data actually sits across your systems, compiles one source-system manifest a human reviews and redacts, drafts the response, and runs the 45-day and 60-day clocks separately. Nothing is disclosed or erased automatically. Obtainer helps you comply and is not legal advice, so threshold, exemption, and denial calls stay with your team. Self-serve from a planned $49/mo.
Last updated September 2026
Why it fits
Rhode Island businesses, plus out-of-state SaaS, ecommerce, retail, adtech, and B2C firms that reach 35,000 Rhode Island customers or run a commercial website that sells personal information here, and multi-state privacy teams that need the RIDTPPA notice obligation tracked separately from the 45-day request clock.
The threshold does not save you from the notice rule
Most Rhode Island readiness work starts and ends with a headcount question: do we touch 35,000 Rhode Island customers. That question only settles the rights half. Section 6-48.1-3 attaches to commercial websites and internet service providers that collect, store, and sell personal information here, with no consumer count and no revenue floor underneath it. A company that correctly concludes it is under the threshold can still be short a Rhode Island disclosure, and it will find out through an Attorney General inquiry rather than a grace period.
Naming who you may sell to means knowing what you hold
You cannot list the third parties who have received or may receive personal information if you do not know which systems hold it, which vendors read from those systems, and what leaves under what contract. The transparency obligation and the request obligation are the same inventory problem wearing different clothes. Obtainer builds that picture as a by-product of running requests: every discovery pass records which source systems held the person's data and which downstream recipients were in play, so the disclosure you publish is grounded in something you actually checked.
No cure period means the record has to already exist
Fifteen states will give you written notice and 30 or 60 days to fix a violation before enforcement. Rhode Island gives you nothing. There is no window in which producing the right documentation retroactively closes the file, so the only defense is a contemporaneous one: a timestamped record of what was searched, what was found, what was redacted, who approved it, and when it went out. Obtainer keeps that record automatically while the work happens. Self-serve from a planned $49/mo, with no five-figure floor before your first request.
Reference
Where the Rhode Island privacy law departs from the state laws you already handle
Rhode Island borrowed the Connecticut and Virginia rights framework and then bolted on a disclosure regime that behaves nothing like it. The rights, the clocks, and the appeal will look familiar. The differences are concentrated in who is covered, what you have to publish, and what happens when the Attorney General calls. Each row is a place RIDTPPA leaves the template, and what that departure changes in your workflow.
| Requirement | Rhode Island (RIDTPPA) | Typical state law | What it changes for you |
|---|---|---|---|
| Applicability threshold | 35,000 Rhode Island customers, excluding payment-transaction-only data, or 10,000 plus more than 20 percent of gross revenue from selling personal data | Commonly 100,000, with a 25,000 plus 25 or 50 percent revenue prong | A mid-market company outside Virginia, Texas, and Kentucky can be inside Rhode Island. Count customers per state rather than once nationally. |
| Privacy notice obligation | Section 6-48.1-3 binds any commercial website or internet service provider that collects, stores, and sells personal information in Rhode Island, with no threshold at all | The notice duty rides on the same threshold as the rights duties, so under-threshold companies owe nothing | Being under 35,000 does not end the analysis. Check the notice rule separately from the rights rule. |
| Third-party disclosure | Name all third parties to whom you have sold or may sell personally identifiable information | Disclose the categories of third parties that receive personal data | Categories will not satisfy Rhode Island, and the forward-looking half means the list has to be maintained rather than written once. |
| Definition of a sale | Exchange for monetary or other valuable consideration, the broader of the two US formulations | Virginia, Iowa, Utah, Indiana, and Kentucky reach monetary consideration only | A data-for-data swap with an ad partner is a sale in Rhode Island even where it is not one in Kentucky. Scope the opt-out to the broader rule. |
| Universal opt-out signal | Not required | Colorado, Connecticut, Texas, Montana, New Jersey, Delaware, Oregon, Minnesota, and Maryland require honoring an opt-out preference signal | You still need Global Privacy Control handling for the states that mandate it, so build it once and apply it everywhere. |
| Cure period | None. Not a sunsetting cure, not a permanent one | Commonly 30 or 60 days, permanent in seven states and already lapsed in six | There is no window in which fixing it later closes the file. Compare the rest of the country in our rundown of state privacy law cure periods. |
| Penalties | Deceptive trade practice, up to $10,000 per violation, plus $100 to $500 for each intentional disclosure made in violation. AG only, no private right of action | Commonly $7,500 per violation with a cure period in front of it | Two penalty tracks stack, and the per-disclosure fine scales with the number of records rather than the number of failures. |
More use cases
Related features
Questions
Common questions about this
Who has to comply with the Rhode Island Data Transparency and Privacy Protection Act?
Two different groups, and that is the part teams get wrong. The consumer rights obligations apply to for-profit entities that conduct business in Rhode Island or target products or services to Rhode Island residents and, in the prior calendar year, either controlled or processed the personal data of at least 35,000 customers, excluding data processed solely to complete a payment transaction, or controlled or processed the data of at least 10,000 customers while deriving more than 20 percent of gross revenue from selling personal data. Separately, the information sharing rule in section 6-48.1-3 binds any commercial website or internet service provider that collects, stores, and sells personal information in Rhode Island, with no threshold. State agencies, higher education institutions, nonprofits, GLBA financial institutions, and HIPAA covered entities are exempt, and data governed by HIPAA, the Fair Credit Reporting Act, FERPA, and the Driver's Privacy Protection Act is exempt at the data level. If you are unsure which statutes reach you, start with which state privacy laws apply to your business.
When did the Rhode Island privacy law take effect?
January 1, 2026. The General Assembly passed it on June 13, 2024 and it became law on June 25, 2024, when Governor Dan McKee transmitted it without his signature, giving businesses about eighteen months of runway. Rhode Island switched on the same day as the Indiana Consumer Data Protection Act and the Kentucky Consumer Data Protection Act, so a company operating nationally picked up three jurisdictions in one morning. Data protection assessments apply to processing activities created or generated on or after that date.
What is the penalty for violating the Rhode Island privacy law?
Two penalties, and they stack. A violation of the act is a deceptive trade practice under Rhode Island consumer protection law, which carries civil penalties of up to $10,000 per violation. On top of that, an entity that intentionally discloses personal data in violation of the act is subject to a fine of not less than $100 and not more than $500 for each such disclosure. The Attorney General holds exclusive enforcement authority and there is no private right of action, so customers cannot sue you directly.
Does the Rhode Island privacy law have a cure period?
No. RIDTPPA contains no right to cure at all, which makes it unusual even among the states that let theirs lapse. Kentucky, Texas, Virginia, Utah, Iowa, Indiana, and Nebraska all keep a permanent cure period, and Colorado, Connecticut, Delaware, Montana, Minnesota, and New Jersey had one that sunset. Rhode Island never wrote one in. Practically, that means there is no statutory window in which producing documentation after the fact makes a violation go away, so the evidence trail has to be created while you do the work rather than reconstructed afterward.
How long do I have to respond to a Rhode Island data subject request?
Forty-five days from receipt. You may take one additional 45-day extension when reasonably necessary, as long as you tell the customer inside the first 45 days that you are taking it and why. If you decline to act you have to explain the refusal within that same window and tell the customer how to appeal, and you then have 60 days to answer the appeal in writing. Obtainer starts both clocks at intake and works the DSAR process against them. The state-by-state picture is in our guide to data subject request deadlines by state.
What is the Rhode Island third party disclosure requirement?
Section 6-48.1-3 requires a commercial website or internet service provider that collects, stores, and sells customers' personally identifiable information to disclose, in its customer agreement or another conspicuous location where such notices are customarily posted, all categories of personal data it collects and all third parties to whom it has sold or may sell that information. No other state asks you to name specific recipients rather than categories, and none asks for prospective ones. In practice you maintain a named vendor list tied to your actual data flows and revisit it whenever a new sale relationship opens, because a list written once in December 2025 stops being accurate the first time procurement signs a new adtech contract.
Does Rhode Island require honoring Global Privacy Control?
No. RIDTPPA does not require controllers to recognize a universal opt-out mechanism, which puts Rhode Island alongside Virginia, Iowa, Utah, Indiana, and Kentucky. That is the minority position now: Colorado, Connecticut, Texas, Montana, Oregon, Delaware, New Jersey, Minnesota, and Maryland all require it. If you operate nationally, honor the signal everywhere rather than running a state-by-state exception in your consent layer, because maintaining the exception costs more than the compliance does.
Do I need Rhode Island specific software to handle a RIDTPPA request?
No, and buying per state is how privacy budgets get wasted. What you need is one workflow that intakes a request, verifies who is asking, searches every system that could hold that person's data, produces a manifest a human can review and redact, drafts the response, and tracks the statutory clock and any appeal. Rhode Island then becomes configuration: a 45-day timer, a 60-day appeal timer, the broader sale definition applied to your opt-out logic, and a maintained third-party list feeding your published notice. That is what subject access request software is for, and the part that actually takes the time is personal data discovery, which is state agnostic.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.