Tennessee Information Protection Act (TIPA)
Evidence request list. 18 controls, 18 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Assessments and Profiling
Controllers must conduct assessments for processing that presents heightened risk, including targeted advertising, sale, sensitive data, and profiling with significant effects.
- Assessment template anchored to NIST Privacy Framework
- Library of completed assessments
- Trigger criteria for new assessments
- Risk register entries derived from assessments
- Annual refresh schedule
- Assessments completed post launch
- Trigger criteria absent or informal
- Assessments not connected to risk register
Profiling that produces legal or similarly significant effects must be assessed, monitored, and accompanied by safeguards including consumer transparency and opt out.
- Inventory of profiling activities
- Significance assessment record
- Consumer facing explanations
- Human review pathway
- Annual model risk review
- Profiling inventory limited to formal models
- Significance criteria not documented
- Consumer explanations generic
Consumer Rights
Controllers must operate processes for access, correction, deletion, portability, and opt out of targeted advertising, sale, and profiling, within the statutory 45 day window with extension where reasonable.
- Documented rights handling procedure
- Ticketing extract with SLA metrics
- Sample response packs by right
- Appeals workflow and metrics
- Annual review of rights operations
- Appeals workflow missing
- No metric for partial response or denial reasons
- Identity verification too weak for sensitive requests
Controllers must offer accessible opt outs for targeted advertising, sale of personal information, and profiling with significant effects, and propagate the choice to downstream recipients.
- Opt out link inventory by digital surface
- CRM and ad tech suppression evidence
- Universal opt out signal handling design
- Tests of opt out persistence after browser changes
- Annual audit of opt out workflows
- Mobile app omits opt out
- Universal opt out signals not recognised
- Downstream partners not notified of opt outs
Controllers should plan for and implement recognition of widely accepted universal opt out signals, with documented design choices and testing.
- Design document on signal recognition
- Code change records implementing detection
- Test cases verifying signal handling
- Operational dashboards showing signal traffic
- Annual review of supported signals
- Signal recognition limited to web with no mobile coverage
- No tests verifying signal persistence
- Marketing operations unaware of signal volume
Data Minimisation and Security
Controllers must limit collection to what is adequate, relevant, and reasonably necessary for disclosed purposes, and avoid secondary uses that are incompatible without further consent.
- Data inventory with purpose mapping
- Annual minimisation review
- Secondary use approval workflow
- Sunset criteria for unused fields
- Data product owner attestations
- Legacy fields retained without justification
- Secondary use decisions made informally
- No retirement path for unused fields
Controllers must implement reasonable administrative, technical, and physical safeguards appropriate to the volume and nature of personal data, with documented standards and oversight.
- Information security policy
- Control library mapped to NIST CSF or equivalent
- Independent assessment report
- Patch and vulnerability management evidence
- Annual security risk assessment
- Security programme not mapped to a recognised framework
- Independent assessment older than three years
- No risk acceptance log for exceptions
Governance, Training and Records
Controllers must designate privacy programme leadership, allocate resources, and report on programme performance to senior management.
- Privacy programme charter
- Privacy leadership job description
- Quarterly privacy reports to leadership
- Budget allocation records
- Independent review of programme
- Programme leadership role under resourced
- No formal reporting to leadership
- Programme charter not refreshed since enactment
Staff handling personal data must receive privacy training calibrated to their role, refreshed regularly, and supported by awareness campaigns.
- Role based privacy training decks
- LMS completion reports
- Awareness materials such as posters and newsletters
- Knowledge check results
- Annual training plan
- Training not updated for TIPA specifics
- Contractor workforce excluded
- No effectiveness measurement beyond attendance
Controllers must retain assessments, contracts, consent records, and rights handling artefacts in a manner sufficient to support audit and regulatory review.
- Privacy record retention policy
- Centralised assessment library
- Audit ready packs by processing activity
- Sample audit responses to internal or external reviewers
- Access controls limiting record visibility
- Documents scattered across personal drives
- No retention policy for privacy artefacts
- Audit packs created ad hoc each year
Incident Response and Breach Notification
Controllers must integrate Tennessee breach notification rules into incident response, coordinate with the Attorney General when required, and document outcomes.
- Incident response plan with Tennessee annex
- Breach decision tree
- Notification templates by recipient type
- Tabletop exercise results
- Records of past notifications and AG correspondence
- No Tennessee specific annex
- Templates not refreshed since enactment
- Tabletop exercises do not include regulatory engagement
NIST Alignment and Affirmative Defence
TIPA provides an affirmative defence when the controller's privacy programme reasonably conforms to the NIST Privacy Framework, with documented mappings, control implementation, and independent validation.
- Mapping spreadsheet from TIPA obligations to NIST Privacy Framework subcategories
- Control descriptions with owner and evidence pointers
- Independent assessment report aligned to NIST Privacy Framework
- Programme update plan tracking maturity
- Annual reaffirmation by accountable executive
- Mapping treated as a one off paper exercise
- Programme implementation lags behind documented design
- No independent validation to support the safe harbour claim
Controllers seeking to rely on the NIST conformance affirmative defence should maintain a documentation package that can be produced quickly during enforcement or litigation.
- Defence dossier index
- Annual refresh attestation
- Legal review of dossier completeness
- Cross reference between dossier and underlying source artefacts
- Confidentiality controls around the dossier
- No central dossier
- Evidence pointers stale within six months
- Legal review never conducted
Notice and Transparency
Privacy notices must include statutory disclosures, be reasonably accessible, and reflect actual processing, sharing, and consumer rights.
- Master privacy notice with statutory mapping
- Screenshots showing notice access from key consumer surfaces
- Version control log
- Issues log for notice maintenance
- Annual notice review minutes
- Notice not refreshed after vendor or data flow changes
- Notice differs across geographies without justification
- No quick path from notice to opt out
Processors and Contracts
Controllers must bind processors via contract that addresses processing instructions, confidentiality, security, subprocessing, audits, and assistance with consumer rights.
- Standard processor contract aligned to TIPA
- Vendor risk assessment library
- Subprocessor approval log
- Audit reports or attestations
- Annual vendor review minutes
- Older contracts missing required clauses
- Subprocessor changes accepted without review
- Audit rights never exercised even for high risk vendors
Scope and Applicability
Controllers and processors must determine TIPA applicability against the revenue and processing thresholds, with readiness documented in advance of the 1 July 2025 effective date.
- Applicability memo signed by counsel
- Readiness plan with milestones leading to 1 July 2025
- Stakeholder sign off across legal, security, and product
- Annual reassessment after acquisitions or product launches
- Mapping of in scope brands and business units
- Readiness assumed because other state laws were already addressed
- No reassessment after corporate changes
- Subsidiaries excluded without analysis
Sensitive, Children and Teen Data
Processing of sensitive data including racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship status, genetic or biometric data, children's data, and precise geolocation requires consumer consent and additional safeguards.
- Sensitive data inventory by system
- Consent UI evidence
- Consent logs with version and timestamp
- Access restrictions for sensitive datasets
- Annual minimisation review
- Precise geolocation captured in apps without consent
- Sensitive data accessible to broad analyst groups
- Consent withdrawal not honoured promptly
Controllers must respect heightened protections for minors, with age aware experiences and restrictions on targeted advertising and profiling.
- Age screening implementation
- Teen specific marketing restrictions
- Parental consent workflow
- Annual review of minor related controls
- Decision log for borderline cases
- No mechanism to detect minor accounts
- Teen accounts treated identically to adults
- Parental consent procedures manual and inconsistent
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.