Privacy
Rhode Island Data Transparency and Privacy Protection Act
Sections 6-48.1-4 through 6-48.1-7, which cover sensitive-data consent, consumer rights, request handling, and assessments, apply to for-profit entities that conduct business in Rhode Island or target its residents and that, in the preceding calendar year, controlled or processed personal data of at least 35,000 customers, not counting payment-only data. They also apply to for-profit entities that controlled or processed personal data of at least 10,000 customers and derived more than 20 percent of gross revenue from the sale of personal data. Section 6-48.1-3 on information sharing practices states no numeric threshold and instead covers any commercial website or internet service provider that conducts business in Rhode Island, has customers in Rhode Island, or is otherwise subject to Rhode Island jurisdiction. The chapter exempts state and local government bodies, nonprofit organizations, institutions of higher education, registered national securities associations, financial institutions and data subject to the Gramm-Leach-Bliley Act, and HIPAA covered entities and business associates.
What the website needs
- Under § 6-48.1-3, any commercial website or internet service provider within its reach must designate a controller.
- If the commercial website or internet service provider collects, stores, and sells customers' personally identifiable information, the controller must, in its customer agreement or an incorporated addendum or in another conspicuous place on its website where similar notices are usually posted, identify all categories of personal data it collects through the website, identify all third parties to which it has sold or may sell customers' personally identifiable information, and give an active email address or other online contact method.
- A controller that sells personal data or processes it for targeted advertising must clearly and conspicuously disclose that processing.
- A covered entity that meets the thresholds may not process sensitive data without customer consent, must provide a way to grant and revoke consent, and must carry out a revocation within 15 days.


