Law / United States / Rhode Island

Identity Theft Protection Act of 2015, risk-based information security program

R.I. Gen. Laws secs. 11-49.3-2, 11-49.3-5

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

Commencement not set.

A security baseline statutes rule binding public and private bodies.

As of 14 September 2026.

What it requires

  • This binds a municipal agency, a state agency, or a person, defined broadly to include an individual, sole proprietorship, partnership, association, corporation, joint venture, business, legal entity, trust, estate, cooperative, or other commercial entity, that stores, collects, processes, maintains, acquires, uses, owns, or licenses personal information about a Rhode Island resident.
  • Implement and maintain a risk-based information security program with reasonable security procedures and practices appropriate to your size and scope, the nature of the information, and the purpose for which it was collected, to protect the information from unauthorized access, use, modification, destruction, or disclosure and to preserve its confidentiality, integrity, and availability.
  • Do not retain personal information longer than reasonably required to provide the requested services, meet the purpose for which it was collected, or comply with a written retention policy or a legal requirement; destroy it securely, for example by shredding, pulverization, incineration, or erasure, regardless of the medium it is stored in.
  • If you disclose personal information about a Rhode Island resident to a nonaffiliated third party, require by written contract that the third party implement and maintain reasonable security procedures and practices of the same kind, appropriate to its own size and scope, the nature of the information, and the purpose for which it was collected.
  • A reckless violation of this duty is a civil violation of up to $100 per record; a knowing and willful violation is up to $200 per record. Only the Attorney General may bring an action.

If you get it wrong

Criminal exposureNo

Penalty structure

R.I. Gen. Laws sec. 11-49.3-5 sets two tiers per record (mapped here to a person's compromised record): $100 for a reckless violation of the chapter (subsection (a)) and $200 for a knowing and willful violation (subsection (b)), the figure recorded here. The chapter states no aggregate cap.

Rule
Per violation only
As of
14 September 2026
Currency
USD
Per violation unit
Person
Per violation amount
200

Who enforces it

Enforcement body

The Attorney General may bring an action in the name of the state against a business or person believed to have violated this chapter, where proceedings would be in the public interest (R.I. Gen. Laws sec. 11-49.3-5(c)).

What it reaches

Obligation class

Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A municipal agency, a state agency, or a person who or that stores, collects, processes, maintains, acquires, uses, owns, or licenses personal information about a Rhode Island resident must implement and maintain a risk-based information security program with reasonable security procedures and practices appropriate to the size and scope of the organization, the nature of the information, and the purpose for which it was collected, to protect the personal information from unauthorized access, use, modification, destruction, or disclosure and to preserve its confidentiality, integrity, and availability.

Personal information may not be retained longer than reasonably required to provide the requested services, meet the purpose for which it was collected, or comply with a written retention policy or legal requirement. It must be destroyed securely, including by shredding, pulverization, incineration, or erasure, regardless of the medium.

A municipal agency, state agency, or person that discloses personal information about a Rhode Island resident to a nonaffiliated third party must require by written contract that the third party implement and maintain the same kind of reasonable security procedures and practices. Sec. 11-49.3-5 makes each reckless violation of the chapter a civil violation of up to $100 per record.

Each knowing and willful violation is a civil violation of up to $200 per record, brought solely by the Attorney General; no private right of action was found in the text read. Both sections originate in P.L. 2015, ch. 138 and P.L. 2015, ch. 148, and neither section's own history note prints a same-page effective date for the 2015 enactment.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

official Rhode Island statute text, R.I. General Laws chapter 11-49.3, Rhode Island General Assembly website

Back to the example  ·  Lint your app