Tennessee Information Protection Act (TIPA)
The Tennessee Information Protection Act (HB 1181, effective July 1, 2025) provides comprehensive consumer privacy rights. Applies to entities conducting business in Tennessee that control or process personal data of 175,000+ consumers, or 25,000+ consumers while deriving over 50% of gross revenue from data sales. Notable for affirmative defence for controllers maintaining privacy programs conforming to NIST Privacy Framework.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (23)
Automated Processing
| Code | Title |
|---|---|
| TIPA-12 | Profiling with Significant Effects |
Consumer Choice
| Code | Title |
|---|---|
| TIPA-04 | Opt Out of Targeted Advertising, Sale, and Profiling |
Consumer Rights
| Code | Title |
|---|---|
| CPA-CR-1 | Right to Access |
| CPA-CR-2 | Right to Correction |
| CPA-CR-3 | Right to Deletion |
| CPA-CR-4 | Right to Data Portability |
| CPA-CR-5 | Right to Opt Out |
| CTDPA-3 | Right to Access (Section 4) |
| CTDPA-4 | Right to Correction and Deletion |
| CTDPA-5 | Right to Portability |
| CTDPA-6 | Right to Opt Out |
| FDBR-705 | Consumer Rights (§501.705) |
| FDBR-706 | Controller Response Requirements (§501.706) |
| RIDTPPA-6 | Right to Confirm and Access |
| RIDTPPA-7 | Right to Correct and Delete |
| RIDTPPA-8 | Right to Opt Out |
| TIPA-03 | Consumer Rights Operations |
| TIPA-3 | Right to Access and Confirm |
| TIPA-4 | Right to Delete |
| TIPA-5 | Right to Opt Out |
| WDPA-3 | Right to Access and Confirm |
| WDPA-4 | Right to Portability |
| WDPA-5 | Right to Correction and Deletion |
| WDPA-6 | Right to Opt Out |
| s.6(1) | Right to Deletion |
| s.6(2) | Deletion Request Processing |
| s.6(3) | Right to Withdraw Consent |
| s.7(1) | Data Security Obligations |
Consumer Rights
| Code | Title |
|---|---|
| CPA-CR-1 | Right to Access |
| CPA-CR-2 | Right to Correction |
| CPA-CR-3 | Right to Deletion |
| CPA-CR-4 | Right to Data Portability |
| CPA-CR-5 | Right to Opt Out |
| CTDPA-3 | Right to Access (Section 4) |
| CTDPA-4 | Right to Correction and Deletion |
| CTDPA-5 | Right to Portability |
| CTDPA-6 | Right to Opt Out |
| FDBR-705 | Consumer Rights (§501.705) |
| FDBR-706 | Controller Response Requirements (§501.706) |
| RIDTPPA-6 | Right to Confirm and Access |
| RIDTPPA-7 | Right to Correct and Delete |
| RIDTPPA-8 | Right to Opt Out |
| TIPA-03 | Consumer Rights Operations |
| TIPA-3 | Right to Access and Confirm |
| TIPA-4 | Right to Delete |
| TIPA-5 | Right to Opt Out |
| WDPA-3 | Right to Access and Confirm |
| WDPA-4 | Right to Portability |
| WDPA-5 | Right to Correction and Deletion |
| WDPA-6 | Right to Opt Out |
| s.6(1) | Right to Deletion |
| s.6(2) | Deletion Request Processing |
| s.6(3) | Right to Withdraw Consent |
| s.7(1) | Data Security Obligations |
Controller Obligations
| Code | Title |
|---|---|
| CPA-CO-1 | Privacy Notice Requirements |
| CPA-CO-2 | Purpose Limitation |
| CPA-CO-3 | Data Minimization |
| CPA-CO-4 | Data Security |
| CTDPA-10 | Privacy Notice |
| CTDPA-7 | Data Minimization |
| CTDPA-8 | Security Practices |
| CTDPA-9 | Consent for Sensitive Data |
| LEB-14 | Registration and Licensing |
| LEB-15 | Penalties and Enforcement |
| TIPA-6 | Purpose Limitation |
| TIPA-7 | Privacy Notice |
| TIPA-8 | Sensitive Data Consent |
| TIPA-9 | Response Timeline |
| WDPA-10 | Non-Discrimination |
| WDPA-7 | Data Minimization |
| WDPA-8 | Security Practices |
| WDPA-9 | Privacy Notice |
Data Practices
| Code | Title |
|---|---|
| TIPA-09 | Data Minimisation and Purpose Limitation |
Definitions and Scope (Section 47-18-3201)
| Code | Title |
|---|---|
| TIPA-1 | Definitions |
| TIPA-2 | Applicability Thresholds |
Distinctive Safe Harbour
| Code | Title |
|---|---|
| TIPA-02 | NIST CSF Safe Harbour Alignment |
Documentation
| Code | Title |
|---|---|
| TIPA-18 | Audit and Documentation Retention |
Enforcement
| Code | Title |
|---|---|
| CTDPA-13 | AG Enforcement Authority |
| CTDPA-14 | Cure Period |
| FDBR-720 | Enforcement and Penalties (§501.72) |
| MMCL-Ch13-1 | Penalties |
| MMCL-Ch14-1 | Appeal Procedures |
| PY-11 | Supervisory Authority |
| PY-12 | Penalties |
| TIPA-12 | Profiling with Significant Effects |
| TIPA-13 | Children's and Teen Data Considerations |
Governance
| Code | Title |
|---|---|
| TIPA-16 | Internal Privacy Governance and Accountability |
Human Factors
| Code | Title |
|---|---|
| TIPA-17 | Training and Workforce Awareness |
Incident Management
| Code | Title |
|---|---|
| TIPA-14 | Incident Response and Breach Notification Coordination |
Litigation Readiness
| Code | Title |
|---|---|
| TIPA-11 | Affirmative Defence Documentation Package |
Privacy Program and Affirmative Defense
| Code | Title |
|---|---|
| TIPA-10 | Security Programme Reasonableness |
| TIPA-11 | Affirmative Defence Documentation Package |
Risk Assessment
| Code | Title |
|---|---|
| TIPA-07 | Data Protection Assessments |
Scope
| Code | Title |
|---|---|
| TIPA-01 | Applicability Analysis and Effective Date Readiness |
Security
| Code | Title |
|---|---|
| TIPA-10 | Security Programme Reasonableness |
Sensitive Data
| Code | Title |
|---|---|
| TIPA-06 | Sensitive Data Consent |
Special Categories
| Code | Title |
|---|---|
| TIPA-13 | Children's and Teen Data Considerations |
Technical Controls
| Code | Title |
|---|---|
| TIPA-15 | Universal Opt Out Signal Recognition |
Transparency
| Code | Title |
|---|---|
| TIPA-05 | Privacy Notice and Disclosure Requirements |
Vendor Management
| Code | Title |
|---|---|
| TIPA-08 | Processor Obligations and Contracts |
Your Compliance Coverage
If you comply with Tennessee Information Protection Act (TIPA), you already cover:
FAA Cybersecurity Framework for Aviation
20%
14 controls mapped
Compare →Connecticut Data Privacy Act (CTDPA)
19%
13 controls mapped
Compare →Florida Digital Bill of Rights (SB 262)
19%
13 controls mapped
Compare →+ 612 more: Australia Consumer Data Right — Banking (CDR) (17%), eIDAS 2.0 — EU Digital Identity Regulation (17%)
See all 615 mapped frameworks ↓Maps to 615 other frameworks
Frequently Asked Questions
What is Tennessee Information Protection Act (TIPA)?
Tennessee Information Protection Act (TIPA) is a compliance framework from United States — Tennessee with 23 domains and 74 controls. The Tennessee Information Protection Act (HB 1181, effective July 1, 2025) provides comprehensive consumer privacy rights. Applies to entities conducting business in Tennessee that control or process personal data of 175,000+ consumers, or 25,000+ consumers while deriving over 50% of gross revenue from data sales. Notable for affirmative defence for controllers maintaining privacy programs conforming to NIST Privacy Framework. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Tennessee Information Protection Act (TIPA) have?
Tennessee Information Protection Act (TIPA) has 74 controls organised across 23 domains. The largest domains are Consumer Rights (25 controls), Controller Obligations (18 controls), Enforcement (9 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Tennessee Information Protection Act (TIPA) map to?
Tennessee Information Protection Act (TIPA) maps to 615 other compliance frameworks. The top mapping partners are FAA Cybersecurity Framework for Aviation (20% coverage), Connecticut Data Privacy Act (CTDPA) (19% coverage), Florida Digital Bill of Rights (SB 262) (19% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Tennessee Information Protection Act (TIPA) compliance?
Start your Tennessee Information Protection Act (TIPA) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Tennessee Information Protection Act (TIPA) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 74 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required