iQ Cookie State Law Series
Cookie & Privacy Law in Rhode Island
Educational purposes only — not legal advice. This guide is intended to help you understand Rhode Island’s data privacy law as it relates to cookie consent and website compliance. Laws change, and your specific situation may vary. Always consult a qualified legal professional before making compliance decisions. iQ Cookie is a technology tool, not a law firm.
The short version
Rhode Island’s RIDTPPA is the newest law in this series to take effect, arriving January 1, 2026. It skipped two features almost every peer state includes: there was never a cure period at all, and it does not require businesses to honor Global Privacy Control or any other universal opt-out signal. What it adds instead is a privacy-notice disclosure requirement stricter than almost anything else in the series.
Rhode Island does not have a separate cookie law. Cookie compliance flows from the RIDTPPA itself — its opt-out and sensitive-data rules apply directly to cookies and tracking technology.
Who does it apply to?
The RIDTPPA covers for-profit entities that conduct business in Rhode Island or target Rhode Island residents, and meet at least one of these thresholds:
Controls or processes personal data of 35,000 or more Rhode Island residents during a calendar year.
Controls or processes data of 10,000 or more residents AND derives more than 20% of gross revenue from selling personal data.
GLBA financial institutions, HIPAA-covered entities, nonprofits, government entities, higher-education institutions, and several federally regulated data categories (FERPA, FCRA, DPPA) are exempt.
Consumer rights
Rhode Island residents whose data is covered by the RIDTPPA can:
Businesses must respond within 45 days, extendable once by 45 more. There is no private right of action — only the Attorney General can enforce.
What makes Rhode Island different
Never had a cure period — not sunset, never existed. Unlike states where a cure window ran out on a fixed date, Rhode Island’s law was written without one from the start. Enforcement can proceed straight to action from day one of the law’s effective date.
You must name specific third parties — including ones you might sell to in the future. The privacy notice must list every third party you have sold data to, or may sell data to. That "may sell" language is unusually forward-looking and harder to satisfy than a simple current-recipients list.
No GPC requirement at all. Rhode Island does not mandate recognition of Global Privacy Control or any universal opt-out mechanism — a departure from the majority of states in this series.
A separate penalty layer for intentional disclosure. Beyond the standard $10,000-per-violation civil penalty, the law adds a $100–$500 per-violation penalty specifically when personal information is intentionally disclosed in violation of the Act.
For-profit scoping is explicit. The threshold language specifically targets for-profit entities, reinforcing the nonprofit exemption in a way some peer states leave more ambiguous.
Sensitive data & children
Processing sensitive data requires opt-in consent before any collection begins. Sensitive data includes:
Data from known children under 13 requires COPPA-compliant parental consent. The RIDTPPA does not layer on the broader 13–16 opt-in bands some peer states use — its minors’ protection tracks the federal COPPA standard directly.
What this means for your cookies
| Cookie / data type | Requirement | What to do |
|---|---|---|
| Sensitive data cookies (health, biometric, geolocation) | Opt-in required | Gate these behind affirmative consent before they fire. |
| Sale / targeted advertising cookies | Opt-out required | Provide a clear opt-out mechanism. |
| GPC / universal opt-out signals | Not required | No mandatory GPC recognition under this law — but check other states you operate in. |
| Third-party sale disclosure | Name current AND potential recipients | List every party you sell to or may sell to in your privacy notice. |
| Any cookies — known children under 13 | COPPA-aligned consent | Verifiable parental consent required. |
Enforcement
The Rhode Island Attorney General has exclusive enforcement authority, with civil penalties up to $10,000 per violation as a deceptive trade practice, plus a separate $100–$500 per-violation penalty for intentional disclosures. With no cure period at any point in the law’s history, businesses should treat compliance gaps as immediately actionable risk.
Your action checklist
With no cure period ever available, these need to be handled now:
Check your thresholds. Do you process data on 35,000+ Rhode Island residents, or 10,000+ while earning over a fifth of your revenue from data sales? If yes, you are in scope.
Rebuild your third-party disclosure list. Name every party you currently sell data to AND every party you may sell to in the future — a genuinely unusual requirement worth a dedicated review.
Don’t assume GPC covers you here. Even if your consent tool already honors universal opt-out signals for other states, Rhode Island doesn’t require it — but you still need standalone opt-out mechanisms.
Audit sensitive data cookies. Health, biometric, and precise geolocation data need opt-in consent before collection.
Complete data protection assessments for targeted advertising, data sales, risky profiling, and sensitive data processing before January 1, 2026.
Update your privacy policy. Cover data categories, processing purposes, the full third-party recipient list, and how to exercise every right.
Review vendor contracts. Any processor handling Rhode Island resident data must be covered by a written agreement specifying processing instructions and confidentiality obligations.
iQ Cookie scans your site for compliance gaps and deploys a lightweight US-built consent banner.
iQ Cookie State Law Series · Guide 18 of 25 · Next: Tennessee →