Law note · Rhode Island
Identity Theft Protection Act of 2015, notification of breach
Any municipal agency, state agency, or person that stores, owns, collects, processes, maintains, acquires, uses, or licenses data including personal information must notify affected Rhode Island residents of a breach that poses a significant risk of identity theft, within 30 days of confirmation for a state or municipal agency and within 45 days for any other person, with Attorney General and consumer-reporting-agency notice required once more than 500 residents are affected.
Reckless violations carry a penalty of up to $100 per record and knowing and willful violations up to $200 per record, brought by the Attorney General; no private right of action was found in the text read. Sections 11-49.3-4 and 11-49.3-5 both originate in P.L. 2015, ch. 138 and ch. 148; sec. 11-49.3-4's notice duty was last amended by P.L. 2023, ch. 375, sec. 1, effective June 27, 2023, while sec. 11-49.3-5's penalty provisions carry no amendment since 2015.
Neither section's own history note prints a same-page effective date for the original 2015 enactment, so no single effective_date is recorded for this citation's combined range.
What it asks of an app
- Notify affected Rhode Island residents of a breach posing a significant risk of identity theft within 45 days of confirming the breach, or within 30 days if you are a state or municipal agency.
- Notify the Attorney General and consumer reporting agencies once more than 500 Rhode Island residents are affected, without delaying notice to residents.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach
Primary source: official Rhode Island statute text, R.I. General Laws chapter 11-49.3, Rhode Island General Assembly website