Rhode Island's private-sector security-topic law rests on one enacted safeguards duty, R.I. Gen. Laws sec. 11-49.3-2, a standalone risk-based information security program requirement inside the state's Identity Theft Protection Act of 2015, a chapter separate from and companion to the Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA).
A municipal agency, a state agency, or a person, defined broadly to include an individual, sole proprietorship, partnership, association, corporation, joint venture, business, legal entity, trust, estate, cooperative, or other commercial entity, that stores, collects, processes, maintains, acquires, uses, owns, or licenses personal information about a Rhode Island resident must implement and maintain a risk-based information security program with reasonable security procedures and practices appropriate to the organization's size and scope, the nature of the information, and the purpose for which it was collected; must not retain the information longer than reasonably necessary; must destroy it securely; and must require the same safeguards by written contract of any nonaffiliated third party to whom it discloses the information.
Sec. 11-49.3-5 makes each reckless violation of the chapter, a class that reaches this duty as well as the chapter's own breach-notification duty, a civil violation of up to $100 per record, and each knowing and willful violation up to $200 per record, enforced solely by the Attorney General; no private right of action was found in the text read.
No Rhode Island statute or bill is confirmed to set security requirements a connected device or software product must meet before or after it reaches the market, comparable to California's or Oregon's connected-device statutes or the Cyber Resilience Act; a dedicated search for one located none. Rhode Island has no general private-sector duty to report an exploited vulnerability or a security incident, as distinct from a personal-data breach, to an authority.
One incident-notification duty exists, R.I. Gen. Laws sec. 11-49.3-7, requiring a municipal or state agency that detects a cybersecurity incident to notify the Rhode Island State Police within twenty-four hours, binds only the agency's own systems, the same government information-security-programme shape as FISMA, and is recorded here rather than filed as an instrument.
Two sector regimes reach a class of private licensee no activity in the LexLint vocabulary currently expresses, so both are recorded rather than flagged on a guess: R.I. Gen. Laws sec. 27-1-46 et seq.
(enacted by 2024 H 7281, effective January 1, 2025), modeled on the NAIC Insurance Data Security Model Law, requires a domestic or foreign insurer licensed in Rhode Island to develop a written information security program with named technical and governance controls and to notify the insurance commissioner of a cybersecurity event; and 2025 S.B. 603, effective July 2, 2025 and modeled on the New York Department of Financial Services' 23 NYCRR Part 500, requires a nonbank financial institution licensed by the Department of Business Regulation to maintain a written information security program with named technical controls and to report a security event to the department.
Rhode Island's breach-notification duty, R.I. Gen. Laws secs. 11-49.3-4 and 11-49.3-5, and RIDTPPA's own security-of-processing clause for data a controller processes under this chapter's exemptions, R.I. Gen. Laws sec. 6-48.1-7(s), are already this jurisdiction's privacy-topic rows rather than repeated here.