RIDTPPA · Opt-out model

Rhode Island Privacy Law (RIDTPPA): Compliance Guide

The Rhode Island Data Transparency and Privacy Protection Act (H 7787), effective January 15, 2026, is the newest state privacy law on the books, and it puts transparency first: businesses must identify every third party to whom personal data may be sold — by name, not by category. No other state imposes a disclosure duty this specific, and it effectively requires maintaining a public, accurate list of your data buyers. Thresholds are low: 35,000 consumers, or 10,000 with 20% of revenue from data sales.

Effective
January 15, 2026
GPC / universal opt-out
Not required
Required link text
Your Privacy Choices
Handle RIDTPPA compliance free

Last reviewed July 19, 2026 · Rhode Island Data Transparency and Privacy Protection Act (H 7787)

Applicability

Who must comply with the RIDTPPA

The Rhode Island Data Transparency and Privacy Protection Act applies to businesses that meet the following criteria:

  • Controls or processes the personal data of 35,000 or more Rhode Island consumers, or
  • Controls or processes the personal data of 10,000 or more Rhode Island consumers and derives 20% or more of gross revenue from the sale of personal data
  • Notably, there is no revenue-threshold exemption for the “doing business in the state” prong

Consumer rights

What Rhode Island consumers can demand

  • Right to access personal data
  • Right to correct inaccuracies
  • Right to delete personal data
  • Right to data portability
  • Right to opt out of the sale of personal data, targeted advertising, and profiling

Opt-out mechanics

Rhode Island opt-out & GPC requirements

Like every US state privacy law, the RIDTPPA uses an opt-out model: you do not need a GDPR-style cookie banner, but you must provide a clear and conspicuous opt-out link. The accepted text for Rhode Island is Your Privacy Choices.

Global Privacy Control: Not required

The RIDTPPA does not require honoring universal opt-out signals such as Global Privacy Control. The opt-out link remains the required mechanism.

Enforcement

RIDTPPA penalties & enforcement

  • Up to $10,000 per violation

Cure period: Our reference lists no specific cure period for Rhode Island; violations carry up to $10,000 each.

State quirks

What makes Rhode Island different

Rhode Island's signature is radical transparency about data sales. Where every other state lets businesses disclose categories of third parties that may receive sold data, the RIDTPPA requires identifying all of them individually — a standing, public list of data buyers that must be kept accurate as partnerships change. It also skips the revenue-threshold exemption other states offer on the doing-business prong, and it declined to add a GPC mandate. Violations carry up to $10,000 each.

Third-party disclosure by name

Businesses must identify all third parties to whom personal data may be sold — actual names, not just categories of recipients. No other state law goes this far.

Newest law on the books

Took effect January 15, 2026 — the most recent comprehensive state privacy law.

Automation

How ConsentKit handles Rhode Island

  • ConsentKit's widget is served from Cloudflare's edge and receives the visitor's US state server-side, so Rhode Island visitors are identified before any consent UI renders — no client-side geo-lookup delay.
  • Rhode Island visitors see a persistent Your Privacy Choices link — the exact statutory text — available to new and returning visitors alike.
  • Rhode Island does not legally require honoring Global Privacy Control. ConsentKit applies automatic GPC honoring in the 12 states that mandate it; in Rhode Island the opt-out link remains the visitor's control.
  • Every opt-out is recorded server-side with a timestamp and jurisdiction metadata, reviewable and exportable (CSV) from the dashboard — the audit trail regulators ask for.
  • Google Consent Mode v2 stays in sync: analytics and advertising tags update the moment a Rhode Island visitor makes a choice.

Rhode Island's disclosure list lives in your privacy policy; ConsentKit handles the consent side — the opt-out link, instant enforcement, and a recorded, exportable log of every choice.

FAQ

Rhode Island RIDTPPA FAQ

What is Rhode Island's third-party disclosure rule?

The RIDTPPA's signature requirement: businesses must identify all third parties to whom personal data may be sold — actual names, not just categories of recipients. No other state law goes this far, and it effectively requires maintaining a public, accurate list of data buyers.

When does the RIDTPPA take effect, and who is covered?

January 15, 2026 — the newest comprehensive state law. Coverage starts at 35,000 Rhode Island consumers, or 10,000 consumers when 20% or more of gross revenue comes from selling personal data.

Is Global Privacy Control required in Rhode Island?

No. Rhode Island joined Virginia, Utah, Iowa, Indiana, Tennessee, Florida, and Kentucky in declining to mandate universal opt-out signals. The “Your Privacy Choices” link is the required opt-out mechanism.

What are the penalties under the RIDTPPA?

Up to $10,000 per violation. Our reference lists no specific cure period for Rhode Island.

This guide is for informational purposes and is not legal advice. Work with qualified counsel to confirm your obligations under the RIDTPPA.

Comply with Rhode Island's RIDTPPA — and the other 19 state laws

ConsentKit detects each visitor's state at the Cloudflare edge, renders the exact opt-out link their law requires, honors GPC automatically where mandated, and records every choice for your audit trail.