Skip to content

Evidence request lists

Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)

Evidence request list. 26 controls, 26 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Consumer Rights

RIDTPPA-2
Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)

Per RIDTPPA: consumer rights including Right to Access + Correction + Deletion + Portability + Opt Out of sale + targeted advertising + profiling.

Artefacts an auditor will ask for
  • RIDTPPA evidence for RIDTPPA-2
Where this commonly fails
  • UOOM recognition + DPIA + cure period workflow partial

DPIA

RIDTPPA-6
Data Protection Impact Assessment

Per RIDTPPA: DPIA for high-risk processing including sensitive + profiling with significant effects.

Artefacts an auditor will ask for
  • RIDTPPA evidence for RIDTPPA-6
Where this commonly fails
  • UOOM recognition + DPIA + cure period workflow partial

Enforcement

RIDTPPA-7
Enforcement and Penalties

Per RIDTPPA: AG enforcement + civil penalties + private right of action + 30 to 60 day cure period in early phase.

Artefacts an auditor will ask for
  • RIDTPPA evidence for RIDTPPA-7
Where this commonly fails
  • UOOM recognition + DPIA + cure period workflow partial

Privacy Notice Requirements

RIDTPPA-3
Sensitive Data, Children, Universal Opt-Out Mechanism

Per RIDTPPA: sensitive data including health + biometric + precise geolocation + children + universal opt-out mechanism (GPC + similar).

Artefacts an auditor will ask for
  • RIDTPPA evidence for RIDTPPA-3
Where this commonly fails
  • UOOM recognition + DPIA + cure period workflow partial
RIDTPPA-4
Privacy Notice and Transparency

Per RIDTPPA: privacy notice including categories + purposes + sharing + retention + rights + contact + opt-out mechanism.

Artefacts an auditor will ask for
  • RIDTPPA evidence for RIDTPPA-4
Where this commonly fails
  • UOOM recognition + DPIA + cure period workflow partial
RIDTPPA-5
Data Processing Agreements, Service Providers

Per RIDTPPA: processor + service provider contracts including processing only on instructions + assistance with rights + breach notification.

Artefacts an auditor will ask for
  • RIDTPPA evidence for RIDTPPA-5
Where this commonly fails
  • UOOM recognition + DPIA + cure period workflow partial

RIDTPPA: Consumer Rights and Opt-Outs

RIDTPPA-03
Consumer Rights

Provides Rhode Island consumers with rights to access, correct, delete, obtain a copy of personal data, and opt out of targeted advertising, sale of personal data, and certain profiling.

Artefacts an auditor will ask for
  • Consumer rights procedure
  • Request intake portal screenshots
  • Response timeline metrics
  • Appeal handling logs
Where this commonly fails
  • Opt-out of profiling not implemented
  • Response times exceed statutory window
  • Appeals procedure not documented
RIDTPPA-06
Opt-Out of Targeted Advertising

Controllers shall offer Rhode Island consumers a clear mechanism to opt out of processing of personal data for purposes of targeted advertising.

Artefacts an auditor will ask for
  • Opt-out link or button screenshots
  • Opt-out signal propagation logs
  • Ad tech vendor instructions
  • Compliance with universal opt-out signals
Where this commonly fails
  • Opt-out limited to cookies
  • Vendor propagation manual and lagging
  • Universal opt-out signal not honoured
RIDTPPA-07
Opt-Out of Sale of Personal Data

Controllers shall offer a clear mechanism for consumers to opt out of the sale of personal data, with the definition of sale including disclosures for monetary or other valuable consideration.

Artefacts an auditor will ask for
  • Data sale inventory
  • Opt-out routing logs
  • Vendor stop sharing confirmations
  • Quarterly attestations
Where this commonly fails
  • Sale narrowly interpreted
  • Vendor cessation not confirmed
  • Opt-out not honoured retroactively to prior shares
RIDTPPA-15
Verification of Consumer Requests

Controllers shall verify the identity of the consumer making a request to a degree of certainty appropriate to the request, with deletion and access requests requiring higher assurance.

Artefacts an auditor will ask for
  • Verification policy
  • Identity proofing flows
  • Decline letter templates
  • Verification audit logs
Where this commonly fails
  • Verification step skipped for low-volume requests
  • Decline reasons not documented
  • Identity proofing not aligned with NIST 800-63 guidance

RIDTPPA: Controller Duties and Processor Contracts

RIDTPPA-10
Controller and Processor Contracts

Controllers shall maintain contracts with processors that contain specified provisions including processing instructions, confidentiality, deletion, audit rights, and subcontractor terms.

Artefacts an auditor will ask for
  • Processor contract register
  • Clause coverage matrix
  • Subprocessor disclosures
  • Audit execution records
Where this commonly fails
  • Legacy contracts without required clauses
  • Subprocessor lists out of date
  • Audit rights never exercised
RIDTPPA-11
Data Minimisation and Purpose Limitation

Controllers shall limit collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the disclosed purposes and shall not process for additional purposes incompatible without consent.

Artefacts an auditor will ask for
  • Data element inventory
  • Purpose by element mapping
  • Necessity review minutes
  • Decommissioning records for obsolete fields
Where this commonly fails
  • Inventory not refreshed
  • Purposes documented at system level not element level
  • No periodic decommissioning
RIDTPPA-12
Security Safeguards

Controllers shall establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of personal data.

Artefacts an auditor will ask for
  • Information security policy
  • Risk assessment reports
  • Penetration test reports
  • Incident response plan
Where this commonly fails
  • Safeguards not proportionate to sensitive data volumes
  • Risk assessment not refreshed
  • Incident response not tested
RIDTPPA-13
Non-Discrimination

Controllers shall not discriminate against consumers for exercising rights, including by denying goods or services, charging different prices, or providing a different level of quality, subject to permitted bona fide loyalty programmes.

Artefacts an auditor will ask for
  • Pricing parity analysis
  • Loyalty programme terms
  • Right exercise outcome metrics
  • Internal training on non-discrimination
Where this commonly fails
  • Loyalty programme conditioned on selling data
  • Right exercise leads to service degradation
  • No monitoring of post-exercise treatment
RIDTPPA-16
Recordkeeping

Controllers shall maintain records demonstrating compliance with the Act, including consumer requests received, responses provided, and disclosures made.

Artefacts an auditor will ask for
  • Consumer request register
  • Disclosure history
  • Document retention schedule referencing RIDTPPA
  • Sample exhibit packs for regulator review
Where this commonly fails
  • Records spread across teams without central register
  • Retention not aligned to statute of limitations
  • Exhibit packs not pre-assembled

RIDTPPA: Enforcement

RIDTPPA-17
Enforcement by the Attorney General

The Rhode Island Attorney General has exclusive enforcement authority and may seek injunctive relief and civil penalties for violations after providing notice and an opportunity to cure where applicable.

Artefacts an auditor will ask for
  • AG correspondence register
  • Cure procedure documentation
  • Penalty risk register
  • Board reporting on enforcement exposure
Where this commonly fails
  • No defined owner for AG inquiries
  • Cure timelines not tracked
  • Board not briefed on enforcement landscape

RIDTPPA: Notice and Third-Party Disclosure

RIDTPPA-04
Customer Information Disclosure Requirement

Commercial websites or internet service providers that collect, store, and sell customers' personally identifiable information shall designate categories of information shared and identify all third parties to whom information is sold or may be sold.

Artefacts an auditor will ask for
  • Inventory of third parties receiving personal information
  • Data category mapping by third party
  • Public disclosure page
  • Update procedure on third party changes
Where this commonly fails
  • Third parties listed by class only without naming
  • Category mapping not updated when new sales occur
  • Public disclosure not linked from privacy notice
RIDTPPA-05
Privacy Notice Requirements

Controllers shall provide a clear and conspicuous privacy notice describing categories of personal data processed, processing purposes, sharing categories, consumer rights, and contact information.

Artefacts an auditor will ask for
  • Privacy notice URL
  • Content matrix versus statute
  • Change log
  • Accessibility assessment
Where this commonly fails
  • Notice copied from other jurisdictions without Rhode Island specifics
  • Updates not communicated to consumers
  • Conspicuous placement disputed
RIDTPPA-14
Disclosure of Third Parties to Whom Data Is Sold

If a controller sells personal data to third parties or processes personal data for targeted advertising, the controller shall clearly and conspicuously disclose this and the manner in which a consumer may exercise the right to opt out.

Artefacts an auditor will ask for
  • Privacy notice extract
  • Third party list
  • Opt-out link placement
  • Audit trail of disclosure updates
Where this commonly fails
  • Sale disclosure buried in generic notice
  • Opt-out path more than two clicks
  • Third party list missing recent additions

RIDTPPA: Scope, Definitions and Effective Date

RIDTPPA-01
Applicability and Thresholds

Applies to commercial entities that conduct business in Rhode Island or produce products or services targeted to Rhode Island residents and meet defined thresholds for personal data processed or revenue derived from the sale of personal data.

Artefacts an auditor will ask for
  • Applicability analysis memo
  • Annual processing volume reports
  • Revenue analysis from data sales
  • Scoping decision sign-off
Where this commonly fails
  • Thresholds not monitored continuously
  • Targeting analysis omitted
  • Scoping not refreshed after acquisitions
RIDTPPA-02
Definitions

Sets definitions for key terms including controller, processor, personal data, sale of personal data, sensitive data, and third party.

Artefacts an auditor will ask for
  • Internal glossary aligned to statute
  • Vendor controller and processor classification
  • Sale of data determination matrix
Where this commonly fails
  • Internal definitions differ from statute
  • Sale interpretation narrow
  • Vendor classification inconsistent across business units
RIDTPPA-18
Effective Date and Transition

The Act takes effect on 1 January 2026 with transitional provisions for existing contracts and pre-existing processing activities, with compliance expected from the effective date.

Artefacts an auditor will ask for
  • Implementation programme charter
  • Status dashboards
  • Transition plan for legacy contracts
  • Go-live readiness sign-off
Where this commonly fails
  • Programme started after effective date
  • Legacy contracts not amended
  • Status dashboards lack independent assurance
RIDTPPA-19
Interplay with Other Privacy Laws

RIDTPPA operates alongside other state and federal privacy laws including HIPAA, GLBA, FCRA, COPPA, and other state comprehensive privacy laws, with certain exemptions for regulated data.

Artefacts an auditor will ask for
  • Exemption decision memos
  • Cross-state compliance matrix
  • Conflict resolution procedure
  • Annual interoperability review
Where this commonly fails
  • Exemptions claimed without legal opinion
  • Cross-state matrix not refreshed
  • Conflict resolution undefined

RIDTPPA: Sensitive Data and Assessments

RIDTPPA-08
Sensitive Data Consent

Processing of sensitive data requires opt-in consent of the consumer or, in the case of a known child, processing in accordance with COPPA.

Artefacts an auditor will ask for
  • Sensitive data inventory
  • Consent capture records
  • COPPA compliance documentation for child data
  • Revocation mechanism
Where this commonly fails
  • Sensitive data not tagged in systems
  • Consent banner not present for sensitive categories
  • Revocation not propagated to processors
RIDTPPA-09
Data Protection Assessment

Controllers shall conduct and document data protection assessments for processing presenting heightened risk, including targeted advertising, sale of personal data, sensitive data processing, and certain profiling.

Artefacts an auditor will ask for
  • DPA template
  • Completed assessments by activity
  • Risk treatments
  • Attorney General disclosure procedure
Where this commonly fails
  • DPA limited to new launches
  • Heightened risk activities not enumerated
  • Risk treatments not actioned

Scope

RIDTPPA-1
Scope, Applicability, Definitions

Per Rhode Island Data Transparency and Privacy Protection Act (effective 2026): scope. Requirements include (a) determine applicability based on thresholds (35K consumers or 10K consumers + 20% revenue from data sales) + (b) apply definitions + (c) document applicability + (d) align with RI AG guidance.

Artefacts an auditor will ask for
  • RIDTPPA evidence for RIDTPPA-1
Where this commonly fails
  • UOOM recognition + DPIA + cure period workflow partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) framework page.