Tennessee Information Protection Act (TIPA) Compliance: The NIST Safe Harbor, 175,000 Consumers, and a Permanent 60-Day Cure
Tennessee is the only state that lets you build a defense. Every other US privacy law measures you against the statute alone, but TIPA says a written privacy program that reasonably conforms to the NIST Privacy Framework is an affirmative defense you can assert if you are sued. That makes documented, repeatable request handling worth more in Tennessee than anywhere else. Obtainer finds where a person's data lives across your systems, compiles one reviewable manifest, drafts the response, and keeps an audit trail on the 45-day clock.
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
In short
The Tennessee Information Protection Act (TIPA) took effect on July 1, 2025, and it is the only comprehensive US state privacy law that offers an affirmative defense for having a good privacy program. TIPA applies only to a business that clears both halves of a conjunctive test: more than $25,000,000 in annual revenue, AND either controlling or processing the personal data of 175,000 or more Tennessee consumers in a calendar year, or the data of 25,000 or more consumers while deriving more than 50 percent of gross revenue from the sale of personal information. That 175,000-consumer trigger is the highest volume threshold in the country, and pairing it with a revenue floor makes TIPA one of the narrowest state laws in scope, narrower than Colorado or Texas and closer to Utah. Tennessee consumers can confirm whether you process their personal data and access it, correct inaccuracies, delete it, obtain a portable copy, and opt out of the sale of personal data, targeted advertising, and profiling that produces legal or similarly significant effects. You must respond within 45 days of a request, extendable once by another 45 days when reasonably necessary if you notify the consumer, and you must offer an appeal process, with 60 days to answer an appeal. The defining feature is in the enforcement section: a controller or processor that creates, maintains, and complies with a written privacy program that reasonably conforms to the NIST Privacy Framework, or to other documented policies and procedures designed to safeguard consumer privacy, may assert that program as an affirmative defense to a TIPA claim. The program has to be scaled to the size and complexity of your business and the volume and sensitivity of the data you handle, so it is not a checkbox, and it is a defense rather than an exemption. Enforcement rests exclusively with the Tennessee Attorney General, who must give written notice and a 60-day opportunity to cure that has no sunset date, making it one of the most generous cure periods in the country. Civil penalties reach $7,500 per violation, with treble damages available for willful or knowing violations, so as much as $22,500. There is no private right of action. Obtainer handles the operational side: intake, discovery of where the person's data lives, a source-system manifest, a drafted deadline-safe response, 45-day tracking, and the documented, repeatable record that a NIST-aligned program needs as evidence. Nothing is disclosed or erased automatically; a human reviews, redacts, and approves. Obtainer helps you comply. It is not legal advice, so whether your program conforms to the NIST Privacy Framework is a judgment for your team and counsel. Self-serve from $49/mo.
Why it fits
Tennessee businesses and out-of-state companies above the $25 million revenue floor that reach 175,000 Tennessee consumers, plus multi-state privacy teams that want the documented, auditable request trail a NIST Privacy Framework program defense depends on.
The only state where a documented program is a legal defense
TIPA lets you assert a written privacy program that reasonably conforms to the NIST Privacy Framework as an affirmative defense to a claim. No other US state privacy law has an analog. The practical consequence is that evidence matters: you need to show not just a policy document but that you actually followed it, request by request. Every request Obtainer handles leaves a timestamped record of what was searched, what was found, who reviewed it, what was redacted, and when it went out, which is the kind of proof a program defense rests on.
A conjunctive test with the highest consumer threshold in the country
TIPA is the only state law combining a $25,000,000 revenue floor with a 175,000-consumer trigger, and you have to clear both to be covered. Most states catch you at 100,000 consumers with no revenue test at all, and Delaware at 35,000. So a company squarely covered by Colorado, Connecticut, or Texas can be entirely out of scope in Tennessee. Knowing which of your incoming requests are actually TIPA requests changes what you owe and which clock you are on.
A permanent 60-day cure, but treble damages if you ignore it
The Tennessee Attorney General must give you written notice and 60 days to fix an alleged violation before filing, and unlike Colorado, Connecticut, or Delaware that right has no sunset date. It is a real safety net. What removes the net is willfulness: penalties run to $7,500 per violation and treble to $22,500 for knowing or willful violations. A backlog you knew about and did not work is a different category of exposure from an honest miss.
More use cases
Related features
Questions
Common questions about this
Who has to comply with the Tennessee Information Protection Act?
A business that conducts business in Tennessee or produces products or services targeted to Tennessee residents, exceeds $25,000,000 in annual revenue, and also either controls or processes the personal data of 175,000 or more Tennessee consumers in a calendar year, or the data of 25,000 or more consumers while deriving more than 50 percent of gross revenue from selling personal information. Both the revenue test and one volume test must be met. That conjunctive structure and the 175,000 figure, the highest in the country, make TIPA narrower in scope than most state privacy laws.
What is the NIST Privacy Framework affirmative defense under TIPA?
TIPA is the only US state privacy law that lets you assert your privacy program as a defense. A controller or processor that creates, maintains, and complies with a written privacy program reasonably conforming to the NIST Privacy Framework, or to other documented policies and procedures designed to safeguard consumer privacy, may raise it as an affirmative defense to a TIPA claim. The program must be scaled to your size, complexity, and the sensitivity of the data you process. It is a defense you have to prove, not an exemption from the law.
How long do I have to respond to a Tennessee data subject request?
Forty-five days from receipt of the request, extendable once by another 45 days when reasonably necessary if you notify the consumer of the extension and the reason inside the original window. That matches the 45-plus-45 standard used by eighteen of the twenty comprehensive state laws; only Iowa (90 days) and Florida (45 plus 15) differ. If you deny a request you must provide an appeal process, and you have 60 days to respond to an appeal.
What are the penalties for violating TIPA?
Civil penalties reach $7,500 per violation, and a court may award treble damages, up to $22,500 per violation, for a willful or knowing violation. The Tennessee Attorney General has exclusive enforcement authority and must first give written notice and a 60-day opportunity to cure, which has no sunset date. There is no private right of action, so consumers cannot sue you directly under TIPA.
Does TIPA have a cure period?
Yes, and it is one of the most generous in the country. The Tennessee Attorney General must provide written notice of an alleged violation and give you 60 days to cure it before bringing an enforcement action. Unlike the cure periods in Colorado, Connecticut, Delaware, and New Jersey, which have all expired or sunset, Tennessee's 60 days is permanent with no end date written into the statute.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.