Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
Evidence request list. 26 controls, 26 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Consumer Rights
Per RIDTPPA: consumer rights including Right to Access + Correction + Deletion + Portability + Opt Out of sale + targeted advertising + profiling.
- RIDTPPA evidence for RIDTPPA-2
- UOOM recognition + DPIA + cure period workflow partial
DPIA
Per RIDTPPA: DPIA for high-risk processing including sensitive + profiling with significant effects.
- RIDTPPA evidence for RIDTPPA-6
- UOOM recognition + DPIA + cure period workflow partial
Enforcement
Per RIDTPPA: AG enforcement + civil penalties + private right of action + 30 to 60 day cure period in early phase.
- RIDTPPA evidence for RIDTPPA-7
- UOOM recognition + DPIA + cure period workflow partial
Privacy Notice Requirements
Per RIDTPPA: sensitive data including health + biometric + precise geolocation + children + universal opt-out mechanism (GPC + similar).
- RIDTPPA evidence for RIDTPPA-3
- UOOM recognition + DPIA + cure period workflow partial
Per RIDTPPA: privacy notice including categories + purposes + sharing + retention + rights + contact + opt-out mechanism.
- RIDTPPA evidence for RIDTPPA-4
- UOOM recognition + DPIA + cure period workflow partial
Per RIDTPPA: processor + service provider contracts including processing only on instructions + assistance with rights + breach notification.
- RIDTPPA evidence for RIDTPPA-5
- UOOM recognition + DPIA + cure period workflow partial
RIDTPPA: Consumer Rights and Opt-Outs
Provides Rhode Island consumers with rights to access, correct, delete, obtain a copy of personal data, and opt out of targeted advertising, sale of personal data, and certain profiling.
- Consumer rights procedure
- Request intake portal screenshots
- Response timeline metrics
- Appeal handling logs
- Opt-out of profiling not implemented
- Response times exceed statutory window
- Appeals procedure not documented
Controllers shall offer Rhode Island consumers a clear mechanism to opt out of processing of personal data for purposes of targeted advertising.
- Opt-out link or button screenshots
- Opt-out signal propagation logs
- Ad tech vendor instructions
- Compliance with universal opt-out signals
- Opt-out limited to cookies
- Vendor propagation manual and lagging
- Universal opt-out signal not honoured
Controllers shall offer a clear mechanism for consumers to opt out of the sale of personal data, with the definition of sale including disclosures for monetary or other valuable consideration.
- Data sale inventory
- Opt-out routing logs
- Vendor stop sharing confirmations
- Quarterly attestations
- Sale narrowly interpreted
- Vendor cessation not confirmed
- Opt-out not honoured retroactively to prior shares
Controllers shall verify the identity of the consumer making a request to a degree of certainty appropriate to the request, with deletion and access requests requiring higher assurance.
- Verification policy
- Identity proofing flows
- Decline letter templates
- Verification audit logs
- Verification step skipped for low-volume requests
- Decline reasons not documented
- Identity proofing not aligned with NIST 800-63 guidance
RIDTPPA: Controller Duties and Processor Contracts
Controllers shall maintain contracts with processors that contain specified provisions including processing instructions, confidentiality, deletion, audit rights, and subcontractor terms.
- Processor contract register
- Clause coverage matrix
- Subprocessor disclosures
- Audit execution records
- Legacy contracts without required clauses
- Subprocessor lists out of date
- Audit rights never exercised
Controllers shall limit collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the disclosed purposes and shall not process for additional purposes incompatible without consent.
- Data element inventory
- Purpose by element mapping
- Necessity review minutes
- Decommissioning records for obsolete fields
- Inventory not refreshed
- Purposes documented at system level not element level
- No periodic decommissioning
Controllers shall establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of personal data.
- Information security policy
- Risk assessment reports
- Penetration test reports
- Incident response plan
- Safeguards not proportionate to sensitive data volumes
- Risk assessment not refreshed
- Incident response not tested
Controllers shall not discriminate against consumers for exercising rights, including by denying goods or services, charging different prices, or providing a different level of quality, subject to permitted bona fide loyalty programmes.
- Pricing parity analysis
- Loyalty programme terms
- Right exercise outcome metrics
- Internal training on non-discrimination
- Loyalty programme conditioned on selling data
- Right exercise leads to service degradation
- No monitoring of post-exercise treatment
Controllers shall maintain records demonstrating compliance with the Act, including consumer requests received, responses provided, and disclosures made.
- Consumer request register
- Disclosure history
- Document retention schedule referencing RIDTPPA
- Sample exhibit packs for regulator review
- Records spread across teams without central register
- Retention not aligned to statute of limitations
- Exhibit packs not pre-assembled
RIDTPPA: Enforcement
The Rhode Island Attorney General has exclusive enforcement authority and may seek injunctive relief and civil penalties for violations after providing notice and an opportunity to cure where applicable.
- AG correspondence register
- Cure procedure documentation
- Penalty risk register
- Board reporting on enforcement exposure
- No defined owner for AG inquiries
- Cure timelines not tracked
- Board not briefed on enforcement landscape
RIDTPPA: Notice and Third-Party Disclosure
Commercial websites or internet service providers that collect, store, and sell customers' personally identifiable information shall designate categories of information shared and identify all third parties to whom information is sold or may be sold.
- Inventory of third parties receiving personal information
- Data category mapping by third party
- Public disclosure page
- Update procedure on third party changes
- Third parties listed by class only without naming
- Category mapping not updated when new sales occur
- Public disclosure not linked from privacy notice
Controllers shall provide a clear and conspicuous privacy notice describing categories of personal data processed, processing purposes, sharing categories, consumer rights, and contact information.
- Privacy notice URL
- Content matrix versus statute
- Change log
- Accessibility assessment
- Notice copied from other jurisdictions without Rhode Island specifics
- Updates not communicated to consumers
- Conspicuous placement disputed
If a controller sells personal data to third parties or processes personal data for targeted advertising, the controller shall clearly and conspicuously disclose this and the manner in which a consumer may exercise the right to opt out.
- Privacy notice extract
- Third party list
- Opt-out link placement
- Audit trail of disclosure updates
- Sale disclosure buried in generic notice
- Opt-out path more than two clicks
- Third party list missing recent additions
RIDTPPA: Scope, Definitions and Effective Date
Applies to commercial entities that conduct business in Rhode Island or produce products or services targeted to Rhode Island residents and meet defined thresholds for personal data processed or revenue derived from the sale of personal data.
- Applicability analysis memo
- Annual processing volume reports
- Revenue analysis from data sales
- Scoping decision sign-off
- Thresholds not monitored continuously
- Targeting analysis omitted
- Scoping not refreshed after acquisitions
Sets definitions for key terms including controller, processor, personal data, sale of personal data, sensitive data, and third party.
- Internal glossary aligned to statute
- Vendor controller and processor classification
- Sale of data determination matrix
- Internal definitions differ from statute
- Sale interpretation narrow
- Vendor classification inconsistent across business units
The Act takes effect on 1 January 2026 with transitional provisions for existing contracts and pre-existing processing activities, with compliance expected from the effective date.
- Implementation programme charter
- Status dashboards
- Transition plan for legacy contracts
- Go-live readiness sign-off
- Programme started after effective date
- Legacy contracts not amended
- Status dashboards lack independent assurance
RIDTPPA operates alongside other state and federal privacy laws including HIPAA, GLBA, FCRA, COPPA, and other state comprehensive privacy laws, with certain exemptions for regulated data.
- Exemption decision memos
- Cross-state compliance matrix
- Conflict resolution procedure
- Annual interoperability review
- Exemptions claimed without legal opinion
- Cross-state matrix not refreshed
- Conflict resolution undefined
RIDTPPA: Sensitive Data and Assessments
Processing of sensitive data requires opt-in consent of the consumer or, in the case of a known child, processing in accordance with COPPA.
- Sensitive data inventory
- Consent capture records
- COPPA compliance documentation for child data
- Revocation mechanism
- Sensitive data not tagged in systems
- Consent banner not present for sensitive categories
- Revocation not propagated to processors
Controllers shall conduct and document data protection assessments for processing presenting heightened risk, including targeted advertising, sale of personal data, sensitive data processing, and certain profiling.
- DPA template
- Completed assessments by activity
- Risk treatments
- Attorney General disclosure procedure
- DPA limited to new launches
- Heightened risk activities not enumerated
- Risk treatments not actioned
Scope
Per Rhode Island Data Transparency and Privacy Protection Act (effective 2026): scope. Requirements include (a) determine applicability based on thresholds (35K consumers or 10K consumers + 20% revenue from data sales) + (b) apply definitions + (c) document applicability + (d) align with RI AG guidance.
- RIDTPPA evidence for RIDTPPA-1
- UOOM recognition + DPIA + cure period workflow partial
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) framework page.