Privacy
Tennessee Information Protection Act
The law applies only to persons that conduct business in Tennessee producing products or services that target Tennessee residents, exceed $25,000,000 in revenue, and either control or process personal information of at least 175,000 consumers during a calendar year or control or process personal information of at least 25,000 consumers and derive more than 50 percent of gross revenue from the sale of personal information. State agencies, financial institutions subject to the Gramm-Leach-Bliley Act, and HIPAA covered entities are among the exempt entities. Part of the metro is in Kentucky, where the Kentucky Consumer Data Protection Act applies to businesses anywhere that meet its thresholds for Kentucky residents’ data.
What the website needs
- A covered controller must provide a reasonably accessible, clear, and meaningful privacy notice that lists the categories of personal information processed, the purpose of processing, how consumers can exercise their rights and appeal a decision, the categories of personal information the controller sells to third parties, and the categories of third parties to whom it sells personal information.
- A controller that sells personal information or processes it for targeted advertising must clearly and conspicuously disclose that processing and how a consumer can opt out of it.
- A controller must provide, and describe in its privacy notice, one or more secure and reliable means for consumers to submit rights requests, and may not require a consumer to create a new account.
- A controller may not process sensitive data without the consumer's consent, and sensitive data about a known child must be processed in accordance with the federal Children's Online Privacy Protection Act.


