# Rhode Island — US state consumer data privacy laws: applicability thresholds by state For Rhode Island, law name and abbreviation is Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA); effective date is January 1, 2026; consumer volume threshold is Controlled or processed the personal data of not less than thirty-five thousand (35,000) customers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; revenue-from-data-sales threshold is Controlled or processed the personal data of not less than ten thousand (10,000) customers and derived more than twenty percent (20%) of their gross revenue from the sale of personal data; threshold combination logic is OR — during the preceding calendar year did any of the following, recorded from its source on 2026-08-12. - **State:** Rhode Island _(our reading, not quoted from the source)_ - **Law name and abbreviation:** Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) - **Effective date:** January 1, 2026 - **Consumer volume threshold:** Controlled or processed the personal data of not less than thirty-five thousand (35,000) customers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction _(verified: appears in the quote below)_ - **Revenue-from-data-sales threshold:** Controlled or processed the personal data of not less than ten thousand (10,000) customers and derived more than twenty percent (20%) of their gross revenue from the sale of personal data _(verified: appears in the quote below)_ - **Threshold combination logic:** OR — during the preceding calendar year did any of the following _(verified: appears in the quote below)_ - **Key exemptions:** State and political subdivision bodies; nonprofit organizations; institutions of higher education; GLBA-regulated financial institutions; HIPAA-covered entities and business associates; national securities associations - **Enforcement mechanism:** Attorney General; no private right of action - **Statute citation:** R.I. Gen. Laws §§ 6-48.1-1 to 6-48.1-14 - **Notes:** Rhode Island uses the term 'customer' rather than 'consumer.' The thresholds (35,000 customers or 10,000 + 20% revenue) are identical to Delaware's and among the lowest in the country. The law applies only to for-profit entities. ## What the source says > entities that conduct business in the state or for-profit entities that produce products or services that are targeted to residents of the state and that during the preceding calendar year did any of the following: (1) Controlled or processed the personal data of not less than thirty-five thousand (35,000) customers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction. (2) Controlled or processed the personal data of not less than ten thousand (10,000) customers and derived more than twenty percent (20%) of their gross revenue from the sale of personal data. ## Source - https://webserver.rilegislature.gov/Statutes/TITLE6/6-48.1/6-48.1-4.htm Last verified: 2026-08-12. Review by: 2026-11-10. Part of [US state consumer data privacy laws: applicability thresholds by state](https://referencesource.org/state-data-privacy-applicability-thresholds/).