Tennessee Information Protection Act (HB 1181) state silhouette

Tennessee Information Protection Act (HB 1181)

Effective Date: 2025-07-01

The Tennessee Information Protection Act applies only to businesses exceeding $25 million in annual revenue that also control or process personal data of at least 175,000 Tennessee consumers, or 25,000 consumers if the business derives more than half its revenue from selling personal data, making it one of the narrower state laws.

What the Tennessee Information Protection Act Requires

Covered businesses must post a privacy notice, honor access, correction, deletion, and portability rights, obtain consent for sensitive data, and offer opt-outs for targeted advertising, sale, and significant profiling. TIPA’s unique feature is a formal affirmative defense: businesses that maintain a written privacy program reasonably conforming to the NIST Privacy Framework can use it as a defense against enforcement.

Enforcement and Penalties

The Attorney General enforces exclusively, with a 60-day cure period, penalties up to $7,500 per violation, and treble damages for willful violations. There is no universal opt-out signal requirement, and the NIST safe harbor makes a documented privacy program the smartest investment for covered companies.

Source: Tennessee General Assembly: HB 1181/SB 73, Tenn. Code 47-18-3201 et seq.

Report a violation: If you believe a business is violating this law, you can file a complaint with the Tennessee Attorney General Division of Consumer Affairs.

More Rules & Regulations