Does the Tennessee Information Protection Act apply to your business?
The Tennessee Information Protection Act, effective July 1, 2025, applies only to businesses that exceed $25 million in revenue and either control or process personal information of at least 175,000 consumers in a year, or 25,000 consumers while deriving more than 50 percent of gross revenue from selling personal information.
Applies to: Businesses that exceed $25 million in revenue and also meet the 175,000-consumer threshold or the 25,000-consumer plus over-50-percent-data-sale threshold, and that operate in or target Tennessee.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanFounding 30% off with code FOUNDING until 15 August 2026
The Tennessee Information Protection Act took effect on July 1, 2025, and it reaches far fewer businesses than most state privacy laws. The reason is a revenue gate. Unlike Virginia or Colorado, where a smaller company can be covered on consumer count alone, Tennessee does not apply at all unless your revenue exceeds $25 million. Check that number first, because if you are under it, the rest of the test does not matter.
Who the Tennessee Information Protection Act covers
Under Tennessee Code Annotated Section 47-18-3202, the law applies to persons that conduct business in Tennessee, or produce products or services targeting Tennessee residents, and that exceed $25 million in revenue, and that also, during a calendar year, control or process the personal information of at least 175,000 consumers, or of at least 25,000 consumers while deriving more than 50 percent of gross revenue from selling personal information. The revenue gate and a volume trigger both have to be met, which is why the law is narrow.
Why the $25 million gate matters so much
Because the revenue figure is a required condition rather than an alternative, a business under $25 million is outside TIPA no matter how much data it handles. Watch the wording carefully: the as-introduced version of the bill did not include the revenue gate and set a lower 100,000-consumer trigger, but the enacted law added the $25 million floor and raised the volume figure to 175,000. Anyone relying on an early summary can reach the wrong answer. The verified numbers here come from the enacted text.
How Tennessee compares
Tennessee's revenue gate puts it in the narrow-scope group alongside Utah's UCPA, which also requires $25 million in revenue before its consumer thresholds apply. That is a very different design from Texas's TDPSA, which drops numeric thresholds entirely in favor of a small-business test. To see how Tennessee's high figures sit against every other state on one page, use the privacy thresholds by state comparison. TIPA also stands out for its affirmative defense: a controller that maintains a written privacy program conforming to the NIST Privacy Framework can raise it against a claim. The US state privacy laws hub shows how the models differ.
Next step
Tennessee's revenue gate means many businesses can stop after one question, while larger data-heavy companies need to check both triggers and consider the NIST-based defense. The free 2-minute Obligation Scan runs the Section 47-18-3202 test against your business and lists the duties that follow if you are covered, so you know where you stand rather than guessing from an outdated summary.
Compliance checklist
- First check the revenue gate: TIPA only reaches businesses that exceed $25 million in revenue, so confirm this before anything else.
- If you clear $25 million, check the volume triggers: 175,000 consumers, or 25,000 consumers plus more than 50 percent of gross revenue from selling personal information.
- Confirm you conduct business in Tennessee or target its residents, and review the Section 47-18-3210 exemptions.
- If covered, publish a privacy notice and honor rights to access, correct, delete, obtain a copy, and opt out of sale, targeted advertising, and profiling.
- Consider building a written privacy program aligned to the NIST Privacy Framework to claim TIPA's affirmative defense.
Sources
- Tenn. Code Ann. Section 47-18-3202 (Scope), enacted text via House Commerce Amendment 1 to HB 1181 (Public Chapter 408), Tennessee General Assembly
- Tennessee Information Protection Act, Public Chapter 408 (2023), Tennessee Secretary of State
Last verified: 2026-08-04
Informational, not legal advice.