iQ Cookie State Law Series
Cookie & Privacy Law in Tennessee
Educational purposes only — not legal advice. This guide is intended to help you understand Tennessee’s data privacy law as it relates to cookie consent and website compliance. Laws change, and your specific situation may vary. Always consult a qualified legal professional before making compliance decisions. iQ Cookie is a technology tool, not a law firm.
The short version
Tennessee’s TIPA took effect July 1, 2025, and it has the narrowest applicability test of any comprehensive state privacy law on this list — a genuine $25 million revenue floor stacked on top of the usual consumer-count thresholds. It also does something no other state does: give businesses a legal defense for maintaining a privacy program aligned with the NIST Privacy Framework.
Tennessee does not have a separate cookie law. Cookie compliance flows from the TIPA itself — its opt-out and sensitive-data rules apply directly to cookies and tracking technology.
Who does it apply to?
The TIPA uses an unusually strict "AND" test. To be covered, a business must conduct business in Tennessee or target Tennessee residents, have more than $25 million in annual revenue, AND meet at least one of these:
Controls or processes personal data of 175,000 or more Tennessee consumers during a calendar year.
Controls or processes data of 25,000 or more consumers AND derives more than 50% of gross revenue from selling personal data.
HIPAA-covered entities, GLBA financial institutions, nonprofits, higher-education institutions, insurers, and state agencies are exempt.
Consumer rights
Tennessee residents whose data is covered by the TIPA can:
Businesses must respond within 45 days, extendable once by 45 more. There is no private right of action — only the Attorney General can enforce.
What makes Tennessee different
The narrowest applicability test in the country. Stacking a $25 million revenue floor on top of consumer-count thresholds means many mid-sized businesses that would be covered elsewhere simply are not covered in Tennessee. Confirm your actual revenue figure before assuming you’re exempt or in scope.
A NIST-alignment affirmative defense — unique among state privacy laws. A controller that maintains a written privacy program reasonably conforming to the NIST Privacy Framework can raise that as an affirmative defense in an enforcement action. No other state privacy law offers this.
The cure period is both long and permanent. Sixty days is longer than the 30-day window most peer states use, and it is written to never sunset — a genuinely durable protection compared to states where cure periods have already expired.
No GPC requirement. Tennessee is one of only seven comprehensive-privacy-law states that does not mandate recognition of Global Privacy Control or any universal opt-out signal.
Willful violations can triple. The standard $7,500-per-violation penalty can reach $22,500 per violation for willful conduct — a meaningful escalation that rewards demonstrable good-faith compliance efforts.
Sensitive data & children
Processing sensitive data requires opt-in consent before any collection begins. Sensitive data includes:
Data from known children under 13 must be processed in accordance with COPPA. For ages 13–17, opt-in consent is required before targeted advertising or sale of that consumer’s data.
What this means for your cookies
| Cookie / data type | Requirement | What to do |
|---|---|---|
| Sensitive data cookies (health, biometric, geolocation) | Opt-in required | Gate these behind affirmative consent before they fire. |
| Sale / targeted advertising cookies | Opt-out required | Provide a clear opt-out mechanism. |
| GPC / universal opt-out signals | Not required | No mandatory GPC recognition under this law — but check other states you operate in. |
| Profiling cookies (legal/significant effects) | Opt-out required | Offer an opt-out for profiling that materially affects consumers. |
| Any cookies — users 13–17 | Opt-in required | No targeted-ad or sale cookies without consent for known minors. |
Enforcement
The Tennessee Attorney General’s Consumer Protection Division has exclusive enforcement authority. Willful violations can be tripled to $22,500 per violation, but the durable 60-day cure period and NIST-alignment defense give compliant businesses meaningfully more protection than most peer states offer.
Your action checklist
Check the full "AND" test, not just consumer count. Even if you process data on 175,000+ Tennessee consumers, you are only in scope if you also clear $25 million in annual revenue.
Consider building toward NIST Privacy Framework alignment. A documented, reasonably conforming privacy program gives you an affirmative legal defense unavailable under any other state’s law.
Audit sensitive data cookies. Health, biometric, and precise geolocation data need opt-in consent before collection.
Gate targeted-ad and sale cookies for ages 13–17. Confirm your age-gating logic covers this full band.
Update your privacy policy. Cover data categories, processing purposes, third-party recipients, and how to exercise every right, including the appeal process.
Document good-faith compliance efforts. With treble damages on the table for willful violations, a clear paper trail of reasonable compliance steps matters.
Review vendor contracts. Any processor handling Tennessee resident data must be covered by a written agreement specifying processing instructions and confidentiality obligations.
iQ Cookie scans your site for compliance gaps and deploys a lightweight US-built consent banner.
iQ Cookie State Law Series · Guide 19 of 25 · Next: Texas →