Skip to content

Evidence request lists

Tennessee Information Protection Act (TIPA)

Evidence request list. 18 controls, 18 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Assessments and Profiling

TIPA-07
Data Protection Assessments

Controllers must conduct assessments for processing that presents heightened risk, including targeted advertising, sale, sensitive data, and profiling with significant effects.

Artefacts an auditor will ask for
  • Assessment template anchored to NIST Privacy Framework
  • Library of completed assessments
  • Trigger criteria for new assessments
  • Risk register entries derived from assessments
  • Annual refresh schedule
Where this commonly fails
  • Assessments completed post launch
  • Trigger criteria absent or informal
  • Assessments not connected to risk register
TIPA-12
Profiling with Significant Effects

Profiling that produces legal or similarly significant effects must be assessed, monitored, and accompanied by safeguards including consumer transparency and opt out.

Artefacts an auditor will ask for
  • Inventory of profiling activities
  • Significance assessment record
  • Consumer facing explanations
  • Human review pathway
  • Annual model risk review
Where this commonly fails
  • Profiling inventory limited to formal models
  • Significance criteria not documented
  • Consumer explanations generic

Consumer Rights

TIPA-03
Consumer Rights Operations

Controllers must operate processes for access, correction, deletion, portability, and opt out of targeted advertising, sale, and profiling, within the statutory 45 day window with extension where reasonable.

Artefacts an auditor will ask for
  • Documented rights handling procedure
  • Ticketing extract with SLA metrics
  • Sample response packs by right
  • Appeals workflow and metrics
  • Annual review of rights operations
Where this commonly fails
  • Appeals workflow missing
  • No metric for partial response or denial reasons
  • Identity verification too weak for sensitive requests
TIPA-04
Opt Out of Targeted Advertising, Sale, and Profiling

Controllers must offer accessible opt outs for targeted advertising, sale of personal information, and profiling with significant effects, and propagate the choice to downstream recipients.

Artefacts an auditor will ask for
  • Opt out link inventory by digital surface
  • CRM and ad tech suppression evidence
  • Universal opt out signal handling design
  • Tests of opt out persistence after browser changes
  • Annual audit of opt out workflows
Where this commonly fails
  • Mobile app omits opt out
  • Universal opt out signals not recognised
  • Downstream partners not notified of opt outs
TIPA-15
Universal Opt Out Signal Recognition

Controllers should plan for and implement recognition of widely accepted universal opt out signals, with documented design choices and testing.

Artefacts an auditor will ask for
  • Design document on signal recognition
  • Code change records implementing detection
  • Test cases verifying signal handling
  • Operational dashboards showing signal traffic
  • Annual review of supported signals
Where this commonly fails
  • Signal recognition limited to web with no mobile coverage
  • No tests verifying signal persistence
  • Marketing operations unaware of signal volume

Data Minimisation and Security

TIPA-09
Data Minimisation and Purpose Limitation

Controllers must limit collection to what is adequate, relevant, and reasonably necessary for disclosed purposes, and avoid secondary uses that are incompatible without further consent.

Artefacts an auditor will ask for
  • Data inventory with purpose mapping
  • Annual minimisation review
  • Secondary use approval workflow
  • Sunset criteria for unused fields
  • Data product owner attestations
Where this commonly fails
  • Legacy fields retained without justification
  • Secondary use decisions made informally
  • No retirement path for unused fields
TIPA-10
Security Programme Reasonableness

Controllers must implement reasonable administrative, technical, and physical safeguards appropriate to the volume and nature of personal data, with documented standards and oversight.

Artefacts an auditor will ask for
  • Information security policy
  • Control library mapped to NIST CSF or equivalent
  • Independent assessment report
  • Patch and vulnerability management evidence
  • Annual security risk assessment
Where this commonly fails
  • Security programme not mapped to a recognised framework
  • Independent assessment older than three years
  • No risk acceptance log for exceptions

Governance, Training and Records

TIPA-16
Internal Privacy Governance and Accountability

Controllers must designate privacy programme leadership, allocate resources, and report on programme performance to senior management.

Artefacts an auditor will ask for
  • Privacy programme charter
  • Privacy leadership job description
  • Quarterly privacy reports to leadership
  • Budget allocation records
  • Independent review of programme
Where this commonly fails
  • Programme leadership role under resourced
  • No formal reporting to leadership
  • Programme charter not refreshed since enactment
TIPA-17
Training and Workforce Awareness

Staff handling personal data must receive privacy training calibrated to their role, refreshed regularly, and supported by awareness campaigns.

Artefacts an auditor will ask for
  • Role based privacy training decks
  • LMS completion reports
  • Awareness materials such as posters and newsletters
  • Knowledge check results
  • Annual training plan
Where this commonly fails
  • Training not updated for TIPA specifics
  • Contractor workforce excluded
  • No effectiveness measurement beyond attendance
TIPA-18
Audit and Documentation Retention

Controllers must retain assessments, contracts, consent records, and rights handling artefacts in a manner sufficient to support audit and regulatory review.

Artefacts an auditor will ask for
  • Privacy record retention policy
  • Centralised assessment library
  • Audit ready packs by processing activity
  • Sample audit responses to internal or external reviewers
  • Access controls limiting record visibility
Where this commonly fails
  • Documents scattered across personal drives
  • No retention policy for privacy artefacts
  • Audit packs created ad hoc each year

Incident Response and Breach Notification

TIPA-14
Incident Response and Breach Notification Coordination

Controllers must integrate Tennessee breach notification rules into incident response, coordinate with the Attorney General when required, and document outcomes.

Artefacts an auditor will ask for
  • Incident response plan with Tennessee annex
  • Breach decision tree
  • Notification templates by recipient type
  • Tabletop exercise results
  • Records of past notifications and AG correspondence
Where this commonly fails
  • No Tennessee specific annex
  • Templates not refreshed since enactment
  • Tabletop exercises do not include regulatory engagement

NIST Alignment and Affirmative Defence

TIPA-02
NIST CSF Safe Harbour Alignment

TIPA provides an affirmative defence when the controller's privacy programme reasonably conforms to the NIST Privacy Framework, with documented mappings, control implementation, and independent validation.

Artefacts an auditor will ask for
  • Mapping spreadsheet from TIPA obligations to NIST Privacy Framework subcategories
  • Control descriptions with owner and evidence pointers
  • Independent assessment report aligned to NIST Privacy Framework
  • Programme update plan tracking maturity
  • Annual reaffirmation by accountable executive
Where this commonly fails
  • Mapping treated as a one off paper exercise
  • Programme implementation lags behind documented design
  • No independent validation to support the safe harbour claim
TIPA-11
Affirmative Defence Documentation Package

Controllers seeking to rely on the NIST conformance affirmative defence should maintain a documentation package that can be produced quickly during enforcement or litigation.

Artefacts an auditor will ask for
  • Defence dossier index
  • Annual refresh attestation
  • Legal review of dossier completeness
  • Cross reference between dossier and underlying source artefacts
  • Confidentiality controls around the dossier
Where this commonly fails
  • No central dossier
  • Evidence pointers stale within six months
  • Legal review never conducted

Notice and Transparency

TIPA-05
Privacy Notice and Disclosure Requirements

Privacy notices must include statutory disclosures, be reasonably accessible, and reflect actual processing, sharing, and consumer rights.

Artefacts an auditor will ask for
  • Master privacy notice with statutory mapping
  • Screenshots showing notice access from key consumer surfaces
  • Version control log
  • Issues log for notice maintenance
  • Annual notice review minutes
Where this commonly fails
  • Notice not refreshed after vendor or data flow changes
  • Notice differs across geographies without justification
  • No quick path from notice to opt out

Processors and Contracts

TIPA-08
Processor Obligations and Contracts

Controllers must bind processors via contract that addresses processing instructions, confidentiality, security, subprocessing, audits, and assistance with consumer rights.

Artefacts an auditor will ask for
  • Standard processor contract aligned to TIPA
  • Vendor risk assessment library
  • Subprocessor approval log
  • Audit reports or attestations
  • Annual vendor review minutes
Where this commonly fails
  • Older contracts missing required clauses
  • Subprocessor changes accepted without review
  • Audit rights never exercised even for high risk vendors

Scope and Applicability

TIPA-01
Applicability Analysis and Effective Date Readiness

Controllers and processors must determine TIPA applicability against the revenue and processing thresholds, with readiness documented in advance of the 1 July 2025 effective date.

Artefacts an auditor will ask for
  • Applicability memo signed by counsel
  • Readiness plan with milestones leading to 1 July 2025
  • Stakeholder sign off across legal, security, and product
  • Annual reassessment after acquisitions or product launches
  • Mapping of in scope brands and business units
Where this commonly fails
  • Readiness assumed because other state laws were already addressed
  • No reassessment after corporate changes
  • Subsidiaries excluded without analysis

Sensitive, Children and Teen Data

TIPA-06
Sensitive Data Consent

Processing of sensitive data including racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship status, genetic or biometric data, children's data, and precise geolocation requires consumer consent and additional safeguards.

Artefacts an auditor will ask for
  • Sensitive data inventory by system
  • Consent UI evidence
  • Consent logs with version and timestamp
  • Access restrictions for sensitive datasets
  • Annual minimisation review
Where this commonly fails
  • Precise geolocation captured in apps without consent
  • Sensitive data accessible to broad analyst groups
  • Consent withdrawal not honoured promptly
TIPA-13
Children's and Teen Data Considerations

Controllers must respect heightened protections for minors, with age aware experiences and restrictions on targeted advertising and profiling.

Artefacts an auditor will ask for
  • Age screening implementation
  • Teen specific marketing restrictions
  • Parental consent workflow
  • Annual review of minor related controls
  • Decision log for borderline cases
Where this commonly fails
  • No mechanism to detect minor accounts
  • Teen accounts treated identically to adults
  • Parental consent procedures manual and inconsistent
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.