Law / United States / Rhode Island

Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA), general applicability

R.I. Gen. Laws ch. 6-48.1, secs. 6-48.1-2, 6-48.1-5, 6-48.1-6

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force 9 months, effective 1 January 2026.

A comprehensive regime rule binding private bodies.

As of 27 August 2026.

What it requires

  • Determine whether you are a for-profit entity conducting business in Rhode Island, or targeting products or services to Rhode Island residents, that controlled or processed personal data of at least 35,000 customers, or 10,000 customers while deriving more than 20 percent of gross revenue from personal-data sales, before relying on any RIDTPPA exemption.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

RIDTPPA applies only to for-profit entities conducting business in Rhode Island, or targeting products or services to Rhode Island residents, that in the preceding calendar year controlled or processed personal data of at least 35,000 customers (excluding payment-only data), or 10,000 customers while deriving more than 20 percent of gross revenue from personal-data sales.

Two companion 2024 bills, H 7787 and S 2500, produced two public laws for the same chapter (P.L. 2024, ch. 430 and ch. 453), both effective January 1, 2026.

When LexLint raises it

  • automated_outreach
  • crawls_web
  • deploys_chatbot
  • processes_biometrics
  • processes_voice
  • trains_models

Read the law

official Rhode Island statute text, R.I. General Laws chapter 6-48.1, Rhode Island General Assembly website

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app