Does Rhode Island's Data Transparency and Privacy Protection Act apply to your business?
Rhode Island's Data Transparency and Privacy Protection Act, effective January 1, 2026, applies to for-profit businesses operating in Rhode Island or targeting its residents that, in the prior year, controlled or processed personal data of at least 35,000 customers, or 10,000 customers while deriving over 20 percent of revenue from selling data.
Applies to: For-profit businesses that conduct business in Rhode Island or target its residents and meet the 35,000-customer threshold or the 10,000-customer plus over-20-percent-data-sale threshold.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanFounding 30% off with code FOUNDING until 15 August 2026
Rhode Island's Data Transparency and Privacy Protection Act takes effect on January 1, 2026, and it is put together a little differently from most state privacy laws. Two things stand out. It applies to for-profit entities only, and its main volume threshold sits inside the section on controller responsibilities rather than in a separate applicability section. That structure trips people up, so it is worth reading the two operative pieces side by side.
Who the Rhode Island Data Transparency and Privacy Protection Act covers
Section 6-48.1-7 states that the controller duties apply to for-profit entities that conduct business in Rhode Island, or produce products or services targeted to Rhode Island residents, and that during the preceding calendar year controlled or processed the personal data of at least 35,000 customers, excluding data handled solely to complete a payment, or at least 10,000 customers while deriving more than 20 percent of gross revenue from selling personal data. Because the law says for-profit entities, a nonprofit sits outside these controller obligations even at high volume.
The website provision that ignores the thresholds
Rhode Island adds a second layer that many trackers miss. Section 6-48.1-3 requires operators of commercial websites and online services that collect, store, and sell customers' personally identifiable information to post a privacy notice with specific disclosures, including the categories of data collected and the third parties it is shared with. That duty is tied to selling personal information, not to the 35,000 or 10,000 counts, so a smaller online business can still owe the notice. Read both sections before deciding you are clear.
How Rhode Island compares
The 35,000-customer entry point matches Delaware's Personal Data Privacy Act and Maryland's Online Data Privacy Act, and the second branch at 10,000 customers plus more than 20 percent of data-sale revenue is the same figure Delaware and Maryland use. That places Rhode Island in the lower-threshold group, so a business that sits under the 100,000-consumer laws such as Virginia can still be covered here. The privacy thresholds by state comparison shows how the thresholds line up.
Next step
Rhode Island's split structure, a volume threshold in one section and a sale-of-data website rule in another, makes "does it apply?" harder than a single number. The free 2-minute Obligation Scan runs both the Section 6-48.1-7 thresholds and the Section 6-48.1-3 website duty against your business and lists what follows, so you are ready before the January 1, 2026 start.
Compliance checklist
- Confirm you are a for-profit entity that conducts business in Rhode Island or targets its residents.
- Count your Rhode Island customers for the prior year, excluding data used solely to complete a payment, and check whether you reach 35,000.
- If under 35,000, check the second branch: 10,000 customers plus more than 20 percent of gross revenue from selling personal data.
- If you run a commercial website or online service that sells personal information, review the Section 6-48.1-3 privacy-notice duties, which can apply regardless of size.
- If covered, publish a compliant notice and honor customer rights to access, correct, delete, obtain a copy, and opt out of sale, targeted advertising, and profiling.
Sources
- R.I. Gen. Laws Section 6-48.1-7 (Controller and processor responsibilities; 35,000 and 10,000 thresholds), Rhode Island General Assembly
- R.I. Gen. Laws Chapter 6-48.1 (Rhode Island Data Transparency and Privacy Protection Act, index of sections), Rhode Island General Assembly
Last verified: 2026-07-24
Informational, not legal advice.