Law / United States /
Rhode Island
Rhode Island Data Transparency and Privacy Protection Act, customer rights
R.I. Gen. Laws secs. 6-48.1-5, 6-48.1-6
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force 9 months, effective 1 January 2026.
A data subject rights rule binding private bodies.
As of 27 August 2026.
What it requires
- Give a Rhode Island customer a means to confirm whether you process their personal data, access it, correct it, delete it, and receive a portable copy.
- Offer a Rhode Island customer an opt-out of targeted advertising, the sale of personal data, and significant-effect profiling.
- Respond to a customer rights request without undue delay and not later than 45 days after receipt, with one 45-day extension available, and decide an appeal within 60 days of receipt.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
RIDTPPA gives a Rhode Island customer the right to confirm and access their personal data, correct inaccuracies, delete data, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and significant-effect profiling. A controller must respond without undue delay and not later than 45 days after receipt, with one 45-day extension available, and must decide an appeal within 60 days, after which the customer may complain to the Attorney General.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisions
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.