Law / Rhode Island

Rhode Island

age

Rhode Island has not enacted any age-gating or age-verification statute in any of the four families as of July 15, 2026.

Bills have been introduced in recent sessions but none has passed either chamber: the Social Media Regulation Act (2026 H7953 and S2968), which would require parental consent for minors' social media accounts and age verification of users, was held for further study by the House Innovation and Senate Artificial Intelligence committees in April 2026, and an Age-Appropriate Design Code bill (2025 H5830) was held for further study in March 2025.

Perennial proposals to make internet providers filter sexual content unless a user verifies age have also never advanced, and no app store age verification bill has advanced.

privacy

Rhode Island's comprehensive privacy law, the Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA, R.I. Gen. Laws ch. 6-48.1), took effect January 1, 2026 from two companion 2024 bills, H 7787 and S 2500.

It applies only to for-profit entities that controlled or processed personal data of at least 35,000 customers, or 10,000 customers while deriving more than 20 percent of gross revenue from personal-data sales, a lower sale-revenue threshold than New Hampshire's or Kentucky's near-identical statutes.

RIDTPPA requires opt-in consent for sensitive data, including biometric data processed to uniquely identify a person, and gives customers access, correction, deletion, portability, and opt-out rights, enforced solely by the Attorney General with no mandatory cure period and no private right of action.

A separate breach-notification statute, the Identity Theft Protection Act of 2015 (R.I. Gen. Laws sec. 11-49.3-4), covers municipal and state agencies as well as private persons, and no private right of action was found in either statute's enforcement text.

13 instruments named 5 researched in detail As of 2026-08-27

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

Identity Theft Protection Act of 2015, notification of breach

cite R.I. Gen. Laws secs. 11-49.3-4, 11-49.3-5 stage IMMINENT commencement not set source official Rhode Island statute text, R.I. General Laws chapter 11-49.3, Rhode Island General Assembly website

Any municipal agency, state agency, or person that stores, owns, collects, processes, maintains, acquires, uses, or licenses data including personal information must notify affected Rhode Island residents of a breach that poses a significant risk of identity theft, within 30 days of confirmation for a state or municipal agency and within 45 days for any other person, with Attorney General and consumer-reporting-agency notice required once more than 500 residents are affected.

Reckless violations carry a penalty of up to $100 per record and knowing and willful violations up to $200 per record, brought by the Attorney General; no private right of action was found in the text read. Sections 11-49.3-4 and 11-49.3-5 both originate in P.L. 2015, ch. 138 and ch. 148; sec. 11-49.3-4's notice duty was last amended by P.L. 2023, ch. 375, sec. 1, effective June 27, 2023, while sec. 11-49.3-5's penalty provisions carry no amendment since 2015.

Neither section's own history note prints a same-page effective date for the original 2015 enactment, so no single effective_date is recorded for this citation's combined range.

What it asks of an app

Comprehensive regime

Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA), general applicability

cite R.I. Gen. Laws ch. 6-48.1, secs. 6-48.1-2, 6-48.1-5, 6-48.1-6 stage RECENT in force 8 months effective 2026-01-01 source official Rhode Island statute text, R.I. General Laws chapter 6-48.1, Rhode Island General Assembly website

RIDTPPA applies only to for-profit entities conducting business in Rhode Island, or targeting products or services to Rhode Island residents, that in the preceding calendar year controlled or processed personal data of at least 35,000 customers (excluding payment-only data), or 10,000 customers while deriving more than 20 percent of gross revenue from personal-data sales.

Two companion 2024 bills, H 7787 and S 2500, produced two public laws for the same chapter (P.L. 2024, ch. 430 and ch. 453), both effective January 1, 2026.

What it asks of an app

Data subject rights

Rhode Island Data Transparency and Privacy Protection Act, customer rights

cite R.I. Gen. Laws secs. 6-48.1-5, 6-48.1-6 stage RECENT in force 8 months effective 2026-01-01 source official Rhode Island statute text, R.I. General Laws chapter 6-48.1, Rhode Island General Assembly website

RIDTPPA gives a Rhode Island customer the right to confirm and access their personal data, correct inaccuracies, delete data, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and significant-effect profiling. A controller must respond without undue delay and not later than 45 days after receipt, with one 45-day extension available, and must decide an appeal within 60 days, after which the customer may complain to the Attorney General.

What it asks of an app

Enforcement supervision

Rhode Island Data Transparency and Privacy Protection Act, enforcement

cite R.I. Gen. Laws sec. 6-48.1-8 stage RECENT in force 8 months effective 2026-01-01 source official Rhode Island statute text, R.I. General Laws chapter 6-48.1, Rhode Island General Assembly website

A violation of RIDTPPA is a deceptive trade practice, and intentional disclosure of personal data to a shell company or otherwise in violation of the chapter carries a fine of $100 to $500 per disclosure. The Attorney General has sole enforcement authority, and unlike New Hampshire's and Kentucky's near-identical statutes, no mandatory or discretionary cure period appears in the enforcement section as read. The chapter creates no private right of action.

What it asks of an app

Sensitive categories

Rhode Island Data Transparency and Privacy Protection Act, sensitive data and biometric data definitions

cite R.I. Gen. Laws sec. 6-48.1-2(26), (3) stage RECENT in force 8 months effective 2026-01-01 source official Rhode Island statute text, R.I. General Laws chapter 6-48.1, Rhode Island General Assembly website

RIDTPPA classifies genetic or biometric data processed to uniquely identify a person, along with racial or ethnic origin, religious belief, health condition, sex life, sexual orientation, citizenship or immigration status, a known child's data, and precise geolocation, as sensitive data.

"Biometric data" is textually identical to New Hampshire's and Kentucky's definitions: it means data from automatic measurement of a biological characteristic, such as a fingerprint, voiceprint, or eye retina or iris, used to identify a specific individual, and excludes a photograph or recording, or data generated from one, only until that data is generated to identify a specific individual.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.