Law note · Rhode Island

Identity Theft Protection Act of 2015, notification of breach

cite R.I. Gen. Laws secs. 11-49.3-4, 11-49.3-5 stage IMMINENT commencement not set reviewed 2026-08-27

Any municipal agency, state agency, or person that stores, owns, collects, processes, maintains, acquires, uses, or licenses data including personal information must notify affected Rhode Island residents of a breach that poses a significant risk of identity theft, within 30 days of confirmation for a state or municipal agency and within 45 days for any other person, with Attorney General and consumer-reporting-agency notice required once more than 500 residents are affected.

Reckless violations carry a penalty of up to $100 per record and knowing and willful violations up to $200 per record, brought by the Attorney General; no private right of action was found in the text read. Sections 11-49.3-4 and 11-49.3-5 both originate in P.L. 2015, ch. 138 and ch. 148; sec. 11-49.3-4's notice duty was last amended by P.L. 2023, ch. 375, sec. 1, effective June 27, 2023, while sec. 11-49.3-5's penalty provisions carry no amendment since 2015.

Neither section's own history note prints a same-page effective date for the original 2015 enactment, so no single effective_date is recorded for this citation's combined range.

What it asks of an app

  • Notify affected Rhode Island residents of a breach posing a significant risk of identity theft within 45 days of confirming the breach, or within 30 days if you are a state or municipal agency.
  • Notify the Attorney General and consumer reporting agencies once more than 500 Rhode Island residents are affected, without delaying notice to residents.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach

Primary source: official Rhode Island statute text, R.I. General Laws chapter 11-49.3, Rhode Island General Assembly website

← Back to the example  ·  Lint your app →