iQ Cookie  State Law Series

State 18 of 25 · Rhode Island

Cookie & Privacy Law in Rhode Island

Published August 2026
Law in effect
No cure period, ever

Educational purposes only — not legal advice. This guide is intended to help you understand Rhode Island’s data privacy law as it relates to cookie consent and website compliance. Laws change, and your specific situation may vary. Always consult a qualified legal professional before making compliance decisions. iQ Cookie is a technology tool, not a law firm.

LAW
RIDTPPA
R.I. Gen. Laws Ch. 6-48.1
SIGNED
Jun 29, 2024
Effective Jan 1, 2026
CURE PERIOD
None
No grace period at all
STATE RANK
#19
To enact a law

The short version

Rhode Island’s RIDTPPA is the newest law in this series to take effect, arriving January 1, 2026. It skipped two features almost every peer state includes: there was never a cure period at all, and it does not require businesses to honor Global Privacy Control or any other universal opt-out signal. What it adds instead is a privacy-notice disclosure requirement stricter than almost anything else in the series.

Rhode Island does not have a separate cookie law. Cookie compliance flows from the RIDTPPA itself — its opt-out and sensitive-data rules apply directly to cookies and tracking technology.

Rhode Island General Assembly — Official Text
Data Transparency and Privacy Protection Act — R.I. Gen. Laws § 6-48.1

Who does it apply to?

The RIDTPPA covers for-profit entities that conduct business in Rhode Island or target Rhode Island residents, and meet at least one of these thresholds:

THRESHOLD 1

Controls or processes personal data of 35,000 or more Rhode Island residents during a calendar year.

THRESHOLD 2

Controls or processes data of 10,000 or more residents AND derives more than 20% of gross revenue from selling personal data.

GLBA financial institutions, HIPAA-covered entities, nonprofits, government entities, higher-education institutions, and several federally regulated data categories (FERPA, FCRA, DPPA) are exempt.

Consumer rights

Rhode Island residents whose data is covered by the RIDTPPA can:

Access
Confirm processing and receive a copy of their data
Correct
Fix inaccurate personal data
Delete
Request removal of personal data
Portability
Receive data in a usable, portable format
Opt out of sale
Stop the sale of personal data to third parties
Opt out of profiling
Stop targeted ads and significant automated profiling

Businesses must respond within 45 days, extendable once by 45 more. There is no private right of action — only the Attorney General can enforce.

What makes Rhode Island different

Never had a cure period — not sunset, never existed. Unlike states where a cure window ran out on a fixed date, Rhode Island’s law was written without one from the start. Enforcement can proceed straight to action from day one of the law’s effective date.

You must name specific third parties — including ones you might sell to in the future. The privacy notice must list every third party you have sold data to, or may sell data to. That "may sell" language is unusually forward-looking and harder to satisfy than a simple current-recipients list.

No GPC requirement at all. Rhode Island does not mandate recognition of Global Privacy Control or any universal opt-out mechanism — a departure from the majority of states in this series.

A separate penalty layer for intentional disclosure. Beyond the standard $10,000-per-violation civil penalty, the law adds a $100–$500 per-violation penalty specifically when personal information is intentionally disclosed in violation of the Act.

For-profit scoping is explicit. The threshold language specifically targets for-profit entities, reinforcing the nonprofit exemption in a way some peer states leave more ambiguous.

Sensitive data & children

Processing sensitive data requires opt-in consent before any collection begins. Sensitive data includes:

Racial / ethnic origin
Religious beliefs
Mental / physical health
Sex life / sexual orientation
Citizenship / immigration status
Genetic / biometric data
Precise geolocation
Children’s data (under 13)

Data from known children under 13 requires COPPA-compliant parental consent. The RIDTPPA does not layer on the broader 13–16 opt-in bands some peer states use — its minors’ protection tracks the federal COPPA standard directly.

What this means for your cookies

Cookie / data typeRequirementWhat to do
Sensitive data cookies (health, biometric, geolocation)Opt-in requiredGate these behind affirmative consent before they fire.
Sale / targeted advertising cookiesOpt-out requiredProvide a clear opt-out mechanism.
GPC / universal opt-out signalsNot requiredNo mandatory GPC recognition under this law — but check other states you operate in.
Third-party sale disclosureName current AND potential recipientsList every party you sell to or may sell to in your privacy notice.
Any cookies — known children under 13COPPA-aligned consentVerifiable parental consent required.

Enforcement

$10,000
Max civil penalty per violation
None
No cure period, ever
AG only
No private right of action

The Rhode Island Attorney General has exclusive enforcement authority, with civil penalties up to $10,000 per violation as a deceptive trade practice, plus a separate $100–$500 per-violation penalty for intentional disclosures. With no cure period at any point in the law’s history, businesses should treat compliance gaps as immediately actionable risk.

Your action checklist

With no cure period ever available, these need to be handled now:

1

Check your thresholds. Do you process data on 35,000+ Rhode Island residents, or 10,000+ while earning over a fifth of your revenue from data sales? If yes, you are in scope.

2

Rebuild your third-party disclosure list. Name every party you currently sell data to AND every party you may sell to in the future — a genuinely unusual requirement worth a dedicated review.

3

Don’t assume GPC covers you here. Even if your consent tool already honors universal opt-out signals for other states, Rhode Island doesn’t require it — but you still need standalone opt-out mechanisms.

4

Audit sensitive data cookies. Health, biometric, and precise geolocation data need opt-in consent before collection.

5

Complete data protection assessments for targeted advertising, data sales, risky profiling, and sensitive data processing before January 1, 2026.

6

Update your privacy policy. Cover data categories, processing purposes, the full third-party recipient list, and how to exercise every right.

7

Review vendor contracts. Any processor handling Rhode Island resident data must be covered by a written agreement specifying processing instructions and confidentiality obligations.

Not sure where your site stands with Rhode Island?

iQ Cookie scans your site for compliance gaps and deploys a lightweight US-built consent banner.

iQ Cookie State Law Series  ·  Guide 18 of 25  ·  Next: Tennessee →