Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
The Rhode Island Data Transparency and Privacy Protection Act (H 6096), signed into law in June 2024 and effective January 1, 2026, establishes consumer data privacy rights for Rhode Island residents. It applies to controllers conducting business in Rhode Island that process personal data of 35,000+ consumers, or 10,000+ consumers while deriving 20%+ revenue from data sales. Follows the Connecticut/Virginia model with universal opt-out mechanism requirements.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (22)
Assessments
| Code | Title |
|---|---|
| RIDTPPA-09 | Data Protection Assessment |
Consumer Rights
| Code | Title |
|---|---|
| CPA-CR-1 | Right to Access |
| CPA-CR-2 | Right to Correction |
| CPA-CR-3 | Right to Deletion |
| CPA-CR-4 | Right to Data Portability |
| CPA-CR-5 | Right to Opt Out |
| CTDPA-3 | Right to Access (Section 4) |
| CTDPA-4 | Right to Correction and Deletion |
| CTDPA-5 | Right to Portability |
| CTDPA-6 | Right to Opt Out |
| FDBR-705 | Consumer Rights (§501.705) |
| FDBR-706 | Controller Response Requirements (§501.706) |
| RIDTPPA-03 | Consumer Rights |
| RIDTPPA-6 | Right to Confirm and Access |
| RIDTPPA-7 | Right to Correct and Delete |
| RIDTPPA-8 | Right to Opt Out |
| TIPA-3 | Right to Access and Confirm |
| TIPA-4 | Right to Delete |
| TIPA-5 | Right to Opt Out |
| WDPA-3 | Right to Access and Confirm |
| WDPA-4 | Right to Portability |
| WDPA-5 | Right to Correction and Deletion |
| WDPA-6 | Right to Opt Out |
| s.6(1) | Right to Deletion |
| s.6(2) | Deletion Request Processing |
| s.6(3) | Right to Withdraw Consent |
| s.7(1) | Data Security Obligations |
Consumer Rights
| Code | Title |
|---|---|
| CPA-CR-1 | Right to Access |
| CPA-CR-2 | Right to Correction |
| CPA-CR-3 | Right to Deletion |
| CPA-CR-4 | Right to Data Portability |
| CPA-CR-5 | Right to Opt Out |
| CTDPA-3 | Right to Access (Section 4) |
| CTDPA-4 | Right to Correction and Deletion |
| CTDPA-5 | Right to Portability |
| CTDPA-6 | Right to Opt Out |
| FDBR-705 | Consumer Rights (§501.705) |
| FDBR-706 | Controller Response Requirements (§501.706) |
| RIDTPPA-03 | Consumer Rights |
| RIDTPPA-6 | Right to Confirm and Access |
| RIDTPPA-7 | Right to Correct and Delete |
| RIDTPPA-8 | Right to Opt Out |
| TIPA-3 | Right to Access and Confirm |
| TIPA-4 | Right to Delete |
| TIPA-5 | Right to Opt Out |
| WDPA-3 | Right to Access and Confirm |
| WDPA-4 | Right to Portability |
| WDPA-5 | Right to Correction and Deletion |
| WDPA-6 | Right to Opt Out |
| s.6(1) | Right to Deletion |
| s.6(2) | Deletion Request Processing |
| s.6(3) | Right to Withdraw Consent |
| s.7(1) | Data Security Obligations |
Data Minimisation
| Code | Title |
|---|---|
| RIDTPPA-11 | Data Minimisation and Purpose Limitation |
Definitions
| Code | Title |
|---|---|
| RIDTPPA-02 | Definitions |
Definitions and Applicability
| Code | Title |
|---|---|
| FDBR-701 | Short Title (§501.701) |
| FDBR-702 | Definitions (§501.702) |
| FDBR-703 | Applicability (§501.703) |
| FDBR-704 | Exemptions (§501.704) |
| RIDTPPA-1 | Definitions |
| RIDTPPA-2 | Applicability Thresholds |
| WDPA-1 | Definitions |
| WDPA-2 | Applicability Thresholds |
Disclosure
| Code | Title |
|---|---|
| RIDTPPA-04 | Customer Information Disclosure Requirement |
Enforcement
| Code | Title |
|---|---|
| RIDTPPA-17 | Enforcement by the Attorney General |
Enforcement and Penalties
CRTC enforcement, private right of action, and penalties
| Code | Title |
|---|---|
| BSA-ENF-1 | Anti-Structuring Prohibition |
| BSA-ENF-2 | Civil Money Penalties |
| BSA-ENF-3 | Criminal Penalties |
| CASL-ENF-01 | Administrative Monetary Penalties |
| CASL-ENF-02 | Compliance and Due Diligence |
| CASL-ENF-03 | Address Harvesting |
| ENF-1 | EPA Inspection Authority |
| ENF-2 | Civil Penalties |
| ENF-3 | Enforcement Actions |
| ENF-4 | Technical Assistance |
| RA10175-S10 | Law Enforcement Authority |
| RA10175-S21 | Jurisdiction |
| RA10175-S8 | Penalties |
| RIDTPPA-10 | Controller and Processor Contracts |
| RIDTPPA-11 | Data Minimisation and Purpose Limitation |
| RIDTPPA-9 | AG Enforcement |
| UKTSA-ENF-01 | Ofcom Information Powers |
| UKTSA-ENF-02 | Ofcom Inspection Powers |
| UKTSA-ENF-03 | Enforcement Notices |
| UKTSA-ENF-04 | Financial Penalties |
| UKTSA-ENF-05 | Security Breach Notification |
| ZMDPA-ENF-01 | Data Protection Commissioner Powers |
| ZMDPA-ENF-02 | Penalties for Non-Compliance |
| s.11 | Consent, Justification and Objection |
| s.5 | Notice to Data Principal |
| s.7 | Certain Legitimate Uses |
| s.8 | Accountability |
Identity Verification
| Code | Title |
|---|---|
| RIDTPPA-15 | Verification of Consumer Requests |
Implementation
| Code | Title |
|---|---|
| RIDTPPA-18 | Effective Date and Transition |
Interoperability
| Code | Title |
|---|---|
| RIDTPPA-19 | Interplay with Other Privacy Laws |
Non-Discrimination
| Code | Title |
|---|---|
| RIDTPPA-13 | Non-Discrimination |
Opt-Out
| Code | Title |
|---|---|
| RIDTPPA-06 | Opt-Out of Targeted Advertising |
| RIDTPPA-07 | Opt-Out of Sale of Personal Data |
Privacy Notice
| Code | Title |
|---|---|
| RIDTPPA-05 | Privacy Notice Requirements |
Privacy Notice Requirements
| Code | Title |
|---|---|
| RIDTPPA-3 | Conspicuous Privacy Notice |
| RIDTPPA-4 | Sale and Advertising Disclosure |
| RIDTPPA-5 | Contact Mechanism |
Recordkeeping
| Code | Title |
|---|---|
| RIDTPPA-16 | Recordkeeping |
Scope
| Code | Title |
|---|---|
| RIDTPPA-01 | Applicability and Thresholds |
Security
| Code | Title |
|---|---|
| RIDTPPA-12 | Security Safeguards |
Sensitive Data
| Code | Title |
|---|---|
| RIDTPPA-08 | Sensitive Data Consent |
Transparency
| Code | Title |
|---|---|
| RIDTPPA-14 | Disclosure of Third Parties to Whom Data Is Sold |
Vendor Contracts
| Code | Title |
|---|---|
| RIDTPPA-10 | Controller and Processor Contracts |
Your Compliance Coverage
If you comply with Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA), you already cover:
FAA Cybersecurity Framework for Aviation
16%
13 controls mapped
Compare →FTC GLBA Safeguards Rule (16 CFR Part 314)
15%
12 controls mapped
Compare →Florida Digital Bill of Rights (SB 262)
15%
12 controls mapped
Compare →+ 623 more: CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 (14%), NIS2 Directive (14%)
See all 626 mapped frameworks ↓Maps to 626 other frameworks
Frequently Asked Questions
What is Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)?
Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) is a compliance framework from United States — Rhode Island with 22 domains and 82 controls. The Rhode Island Data Transparency and Privacy Protection Act (H 6096), signed into law in June 2024 and effective January 1, 2026, establishes consumer data privacy rights for Rhode Island residents. It applies to controllers conducting business in Rhode Island that process personal data of 35,000+ consumers, or 10,000+ consumers while deriving 20%+ revenue from data sales. Follows the Connecticut/Virginia model with universal opt-out mechanism requirements. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) have?
Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) has 82 controls organised across 22 domains. The largest domains are Enforcement and Penalties (27 controls), Consumer Rights (25 controls), Definitions and Applicability (8 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) map to?
Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) maps to 626 other compliance frameworks. The top mapping partners are FAA Cybersecurity Framework for Aviation (16% coverage), FTC GLBA Safeguards Rule (16 CFR Part 314) (15% coverage), Florida Digital Bill of Rights (SB 262) (15% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) compliance?
Start your Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 82 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required