Law / United States / Rhode Island
Identity Theft Protection Act of 2015, risk-based information security program
R.I. Gen. Laws secs. 11-49.3-2, 11-49.3-5
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
Commencement not set.
A security baseline statutes rule binding public and private bodies.
As of 14 September 2026.
What it requires
- This binds a municipal agency, a state agency, or a person, defined broadly to include an individual, sole proprietorship, partnership, association, corporation, joint venture, business, legal entity, trust, estate, cooperative, or other commercial entity, that stores, collects, processes, maintains, acquires, uses, owns, or licenses personal information about a Rhode Island resident.
- Implement and maintain a risk-based information security program with reasonable security procedures and practices appropriate to your size and scope, the nature of the information, and the purpose for which it was collected, to protect the information from unauthorized access, use, modification, destruction, or disclosure and to preserve its confidentiality, integrity, and availability.
- Do not retain personal information longer than reasonably required to provide the requested services, meet the purpose for which it was collected, or comply with a written retention policy or a legal requirement; destroy it securely, for example by shredding, pulverization, incineration, or erasure, regardless of the medium it is stored in.
- If you disclose personal information about a Rhode Island resident to a nonaffiliated third party, require by written contract that the third party implement and maintain reasonable security procedures and practices of the same kind, appropriate to its own size and scope, the nature of the information, and the purpose for which it was collected.
- A reckless violation of this duty is a civil violation of up to $100 per record; a knowing and willful violation is up to $200 per record. Only the Attorney General may bring an action.
If you get it wrong
Criminal exposureNo
Penalty structure
R.I. Gen. Laws sec. 11-49.3-5 sets two tiers per record (mapped here to a person's compromised record): $100 for a reckless violation of the chapter (subsection (a)) and $200 for a knowing and willful violation (subsection (b)), the figure recorded here. The chapter states no aggregate cap.
- Rule
- Per violation only
- As of
- 14 September 2026
- Currency
- USD
- Per violation unit
- Person
- Per violation amount
- 200
Who enforces it
Enforcement body
The Attorney General may bring an action in the name of the state against a business or person believed to have violated this chapter, where proceedings would be in the public interest (R.I. Gen. Laws sec. 11-49.3-5(c)).
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A municipal agency, a state agency, or a person who or that stores, collects, processes, maintains, acquires, uses, owns, or licenses personal information about a Rhode Island resident must implement and maintain a risk-based information security program with reasonable security procedures and practices appropriate to the size and scope of the organization, the nature of the information, and the purpose for which it was collected, to protect the personal information from unauthorized access, use, modification, destruction, or disclosure and to preserve its confidentiality, integrity, and availability.
Personal information may not be retained longer than reasonably required to provide the requested services, meet the purpose for which it was collected, or comply with a written retention policy or legal requirement. It must be destroyed securely, including by shredding, pulverization, incineration, or erasure, regardless of the medium.
A municipal agency, state agency, or person that discloses personal information about a Rhode Island resident to a nonaffiliated third party must require by written contract that the third party implement and maintain the same kind of reasonable security procedures and practices. Sec. 11-49.3-5 makes each reckless violation of the chapter a civil violation of up to $100 per record.
Each knowing and willful violation is a civil violation of up to $200 per record, brought solely by the Attorney General; no private right of action was found in the text read. Both sections originate in P.L. 2015, ch. 138 and P.L. 2015, ch. 148, and neither section's own history note prints a same-page effective date for the 2015 enactment.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product