Law / United States / Rhode Island

Rhode Island Data Transparency and Privacy Protection Act, enforcement

R.I. Gen. Laws sec. 6-48.1-8

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force 9 months, effective 1 January 2026.

An enforcement supervision rule binding private bodies.

As of 27 August 2026.

What it requires

  • Expect RIDTPPA violations to be enforced exclusively by the Rhode Island Attorney General, never by a private plaintiff.
  • Do not rely on a notice-and-cure opportunity before an Attorney General action. Unlike New Hampshire and Kentucky, Rhode Island's enforcement section contains no cure period.
  • Avoid intentionally disclosing personal data to a shell company or otherwise in violation of the chapter. Each such disclosure carries a fine of $100 to $500.

If you get it wrong

Private right of actionNo

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A violation of RIDTPPA is a deceptive trade practice, and intentional disclosure of personal data to a shell company or otherwise in violation of the chapter carries a fine of $100 to $500 per disclosure. The Attorney General has sole enforcement authority, and unlike New Hampshire's and Kentucky's near-identical statutes, no mandatory or discretionary cure period appears in the enforcement section as read. The chapter creates no private right of action.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach

Read the law

official Rhode Island statute text, R.I. General Laws chapter 6-48.1, Rhode Island General Assembly website

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app