Rhode Island Privacy Law (R.I. Gen. Laws Chapter 6-48.1) state silhouette

Rhode Island Privacy Law (R.I. Gen. Laws Chapter 6-48.1)

Effective Date: 2026-01-01

The Rhode Island Privacy Law, formally the Data Transparency and Privacy Protection Act, has two layers. First, a broad disclosure duty: any commercial website or internet service provider that collects personal information from Rhode Island customers must identify in its privacy policy all categories of personal data collected, all third parties to whom it sells or may sell data, and how to opt out, with no size threshold.

Rhode Island Privacy Law Controller Obligations

Second, full controller obligations apply to businesses processing personal data of at least 35,000 Rhode Island consumers, or 10,000 if more than 20 percent of revenue comes from selling data: access, correction, deletion, and portability rights, consent for sensitive data, and opt-outs for targeted advertising, sale, and profiling.

Enforcement and Penalties

There is no cure period. The Attorney General enforces, with penalties up to $10,000 per violation plus additional penalties for intentional disclosure violations. The universal disclosure layer means even very small sites with Rhode Island visitors should update their privacy policies.

Source: Rhode Island General Assembly: H 7787/S 2500, R.I. Gen. Laws Chapter 6-48.1

Report a violation: If you believe a business is violating this law, you can file a complaint with the Rhode Island Attorney General Consumer Protection Unit.

More Rules & Regulations