US State Privacy Law

RI Data

Rhode Island's privacy law (Jan 2026) requires naming every third party you sell data to. No cure period, up to $10,000 per violation.

RI Data requirements

Rhode Island's law took effect January 1, 2026 at a 35,000-consumer threshold and contains a disclosure requirement found nowhere else: the privacy notice must identify all third parties to whom the controller has sold or may sell personal data. For a website running dozens of advertising and analytics tags, that is a vendor inventory requirement in disguise, and it has to be accurate. Consumers may opt out of targeted advertising, sale, and profiling, and sensitive data requires opt-in consent. The Attorney General enforces as a deceptive trade practice, with no cure period, penalties of up to $10,000 per violation, and a separate fine of $100 to $500 for each intentional disclosure of personal data in violation of the chapter. Rhode Island is the clearest example of a state law that cannot be satisfied with policy text alone, because the text must list the vendors that are actually receiving data.

See what your sites and apps actually send

Get a free site analysis: every tracker, mapped to the laws that apply to it.