Effective January 1, 2026

Rhode Island Data Transparency and Privacy Protection Act (RIDPA)

A practical compliance guide for website owners. Learn what Rhode Island's privacy law requires and how to implement it on your site.

Who Must Comply

Conducts business in Rhode Island or targets Rhode Island residents AND controls/processes personal data of 35K+ consumers (excl. payment transactions), OR controls/processes data of 10K+ consumers and derives 20%+ of gross revenue from selling personal data

Consent model: Opt-outSensitive data: Opt-in required

What Your Website Must Do

RequirementStatus
Cookie consent bannerRecommended
Do Not Sell linkRequired
Do Not Share linkRequired
Honor GPC browser signalsRecommended
Universal opt-out mechanismNot required
Sensitive data opt-in consentRequired

Checked against the RIDPA on August 29, 2026. Read the source This is a summary, not legal advice.

Required Links & Notices

The RIDPA requires the following links or notices to be visible on your website:

  • 1Do Not Sell or Share My Personal Data
  • 2Privacy Policy

Enforcement & Penalties

Enforcement Body
Rhode Island Attorney General
Maximum Penalty
$10,000 per violation. No cure period.

Key Things to Know

The Rhode Island Data Transparency and Privacy Protection Act (RIDPA) has applied in Rhode Island since January 1, 2026.

Who it covers: Conducts business in Rhode Island or targets Rhode Island residents AND controls/processes personal data of 35K+ consumers (excl. payment transactions), OR controls/processes data of 10K+ consumers and derives 20%+ of gross revenue from selling personal data.

Do Not Sell and opt-out rights: residents may opt out of the sale of their personal data and opt out of targeted advertising. RIDPA expects the choice to be reachable from your site under the heading “Do Not Sell or Share My Personal Data”, and you may not degrade the service of someone who exercises it.

Global Privacy Control: RIDPA does not oblige you to honour a browser opt-out signal. Honouring GPC anyway is the simpler engineering choice, because twelve other states do require it and the signal does not say which state the visitor is in.

Cookie banner: RIDPA is an opt-out law, so it does not require the opt-in banner the GDPR does. What it does require is that the tracking you run for advertising can be switched off on request, which in practice means a preference control that actually blocks tags rather than a notice that only records a click. Sensitive data is the exception: that needs consent before you process it.

Enforcement: $10,000 per violation. No cure period. Enforced by the Rhode Island Attorney General.

How to Configure LegalBanner for RIDPA

  1. 1

    Create your site

    Sign up for free and add your website domain in the dashboard.

  2. 2

    Set consent mode to "Opt-out"

    In Settings, select the consent mode that matches Rhode Island's requirements.

  3. 3

    Install the snippet

    Add the one-line script tag to your website. The banner, opt-out links, and GPC support are automatic.

  4. 4

    Generate your Privacy Policy

    Use the built-in policy wizard to generate a RIDPA-compliant privacy policy.

Set up RIDPA compliance in 5 minutes

LegalBanner handles Rhode Island privacy requirements automatically — cookie banner, opt-out links, and GPC support included.

Frequently Asked Questions

When does the Rhode Island RIDPA take effect?

The RIDPA takes effect January 1, 2026. Businesses should begin preparing now.

Does Rhode Island have a cure period?

No. Rhode Island is one of only two states (along with Maryland) with no cure period. The AG can take immediate enforcement action for violations.

What are the thresholds for the Rhode Island law?

35,000+ consumers (excluding payment transactions) or 10,000+ consumers with 20%+ revenue from data sales — among the lowest thresholds nationally.

Does Rhode Island require data security measures?

Yes. Rhode Island uniquely requires businesses to implement and maintain reasonable security practices to protect personal data, in addition to standard privacy requirements.

What are the penalties for RIDPA violations?

Up to $10,000 per violation with no cure period. The AG can pursue immediate enforcement.

Disclaimer: This page provides practical implementation guidance only. It does not constitute legal advice. The information is current as of the most recent review date but privacy laws change frequently. Consult a qualified attorney for legal advice specific to your situation. LegalBanner provides compliance tools, not legal counsel.