Rhode Island Privacy Law (RIDTPPA): Compliance Guide
The Rhode Island Data Transparency and Privacy Protection Act (H 7787), effective January 15, 2026, is the newest state privacy law on the books, and it puts transparency first: businesses must identify every third party to whom personal data may be sold — by name, not by category. No other state imposes a disclosure duty this specific, and it effectively requires maintaining a public, accurate list of your data buyers. Thresholds are low: 35,000 consumers, or 10,000 with 20% of revenue from data sales.
- Effective
- January 15, 2026
- GPC / universal opt-out
- Not required
- Required link text
- “Your Privacy Choices”
Last reviewed July 19, 2026 · Rhode Island Data Transparency and Privacy Protection Act (H 7787)
Applicability
Who must comply with the RIDTPPA
The Rhode Island Data Transparency and Privacy Protection Act applies to businesses that meet the following criteria:
- Controls or processes the personal data of 35,000 or more Rhode Island consumers, or
- Controls or processes the personal data of 10,000 or more Rhode Island consumers and derives 20% or more of gross revenue from the sale of personal data
- Notably, there is no revenue-threshold exemption for the “doing business in the state” prong
Consumer rights
What Rhode Island consumers can demand
- Right to access personal data
- Right to correct inaccuracies
- Right to delete personal data
- Right to data portability
- Right to opt out of the sale of personal data, targeted advertising, and profiling
Opt-out mechanics
Rhode Island opt-out & GPC requirements
Like every US state privacy law, the RIDTPPA uses an opt-out model: you do not need a GDPR-style cookie banner, but you must provide a clear and conspicuous opt-out link. The accepted text for Rhode Island is “Your Privacy Choices”.
Global Privacy Control: Not required
The RIDTPPA does not require honoring universal opt-out signals such as Global Privacy Control. The opt-out link remains the required mechanism.
Enforcement
RIDTPPA penalties & enforcement
- Up to $10,000 per violation
Cure period: Our reference lists no specific cure period for Rhode Island; violations carry up to $10,000 each.
State quirks
What makes Rhode Island different
Rhode Island's signature is radical transparency about data sales. Where every other state lets businesses disclose categories of third parties that may receive sold data, the RIDTPPA requires identifying all of them individually — a standing, public list of data buyers that must be kept accurate as partnerships change. It also skips the revenue-threshold exemption other states offer on the doing-business prong, and it declined to add a GPC mandate. Violations carry up to $10,000 each.
Third-party disclosure by name
Businesses must identify all third parties to whom personal data may be sold — actual names, not just categories of recipients. No other state law goes this far.
Newest law on the books
Took effect January 15, 2026 — the most recent comprehensive state privacy law.
Automation
How ConsentKit handles Rhode Island
- ConsentKit's widget is served from Cloudflare's edge and receives the visitor's US state server-side, so Rhode Island visitors are identified before any consent UI renders — no client-side geo-lookup delay.
- Rhode Island visitors see a persistent “Your Privacy Choices” link — the exact statutory text — available to new and returning visitors alike.
- Rhode Island does not legally require honoring Global Privacy Control. ConsentKit applies automatic GPC honoring in the 12 states that mandate it; in Rhode Island the opt-out link remains the visitor's control.
- Every opt-out is recorded server-side with a timestamp and jurisdiction metadata, reviewable and exportable (CSV) from the dashboard — the audit trail regulators ask for.
- Google Consent Mode v2 stays in sync: analytics and advertising tags update the moment a Rhode Island visitor makes a choice.
Rhode Island's disclosure list lives in your privacy policy; ConsentKit handles the consent side — the opt-out link, instant enforcement, and a recorded, exportable log of every choice.
FAQ
Rhode Island RIDTPPA FAQ
What is Rhode Island's third-party disclosure rule?
The RIDTPPA's signature requirement: businesses must identify all third parties to whom personal data may be sold — actual names, not just categories of recipients. No other state law goes this far, and it effectively requires maintaining a public, accurate list of data buyers.
When does the RIDTPPA take effect, and who is covered?
January 15, 2026 — the newest comprehensive state law. Coverage starts at 35,000 Rhode Island consumers, or 10,000 consumers when 20% or more of gross revenue comes from selling personal data.
Is Global Privacy Control required in Rhode Island?
No. Rhode Island joined Virginia, Utah, Iowa, Indiana, Tennessee, Florida, and Kentucky in declining to mandate universal opt-out signals. The “Your Privacy Choices” link is the required opt-out mechanism.
What are the penalties under the RIDTPPA?
Up to $10,000 per violation. Our reference lists no specific cure period for Rhode Island.
This guide is for informational purposes and is not legal advice. Work with qualified counsel to confirm your obligations under the RIDTPPA.
Comply with Rhode Island's RIDTPPA — and the other 19 state laws
ConsentKit detects each visitor's state at the Cloudflare edge, renders the exact opt-out link their law requires, honors GPC automatically where mandated, and records every choice for your audit trail.