Rhode Island Identity Theft Protection Act

· About Rhode Island Identity Theft Protection Act

Key Takeaways

  • The Rhode Island Identity Theft Protection Act of 2015 regulates breach notification and data security for entities that own or license Rhode Island residents’ personal data and for state and municipal agencies.
  • The law currently requires a risk-based information security program and prompt consumer notice after a breach, and the 2026 amendment package would modernize the statute by replacing “personal information” with “personally identifiable information” and tying security controls to recognized cybersecurity frameworks[1][2].
  • A 2025 Rhode Island bill would impose fixed breach-notice deadlines of 30 days for state and municipal agencies and 45 days for businesses, replacing the older “most expedient time possible” standard for those covered by the amendment[11].
  • The 2026 amendment package would keep the existing penalties for reckless and knowing and willful violations and add authority for additional court sanctions in appropriate cases[1][4].
  • As of 6 September 2026, the 2026 bills were reported and amended in the legislature, but this guide treats the 2025–2026 changes as proposed unless and until enacted[1][4][6].

What It Is

The Rhode Island Identity Theft Protection Act is Rhode Island’s core data-breach and information-security statute, codified in Chapter 11-49.3 of the General Laws. It applies to entities that maintain Rhode Island residents’ covered information and to state and municipal agencies, and it is enforced through Rhode Island’s civil and criminal penalty framework rather than a standalone privacy regulator[12][13].

The original public laws in 2015 included delayed effective dates, with the statute taking effect one year after passage for the enacted 2015 measures[12][13]. The current legislative record in 2026 shows an active modernization effort through S 2638 / H 7509, which would update definitions, reporting, and penalties, but the available sources identify these as bills and amendments rather than finalized enacted text[1][2][3][4].

The 2026 bill materials describe three key policy changes: replacing “personal information” with personally identifiable information, aligning security-program expectations with an industry-recognized cybersecurity framework, and adding notification to Rhode Island’s Division of Enterprise Technology Strategy and Services (ETSS) for certain breaches[1][2][4]. The bills also point to a July 2026 effective date in bill text, but because the available materials are legislative documents and press releases rather than an enrolled act, that date should be treated as proposed unless confirmed in enacted law[3][14].

Who Must Comply

The statute reaches businesses and public entities that own or license resident data containing the statutorily covered information, and it also covers state agencies and municipalities that experience a breach[11][12]. The 2026 modernization bills indicate the legislature intended to broaden the definition from “personal information” to personally identifiable information, which would expand the operational scope if enacted[1][2].

The law has extraterritorial reach in the practical sense that it applies when an entity holds covered information about Rhode Island residents, regardless of where the entity is located, so long as the entity falls within the statute’s covered categories. That means out-of-state companies with Rhode Island customer data should treat the act as applicable if they maintain the relevant data set[11][12].

The current public materials do not show a broad commercial exemption for small businesses, nonprofits, or sector-specific entities; instead, compliance turns on whether the entity possesses the covered data and whether a breach triggers notice duties. Sectoral federal laws such as HIPAA, GLBA, and FCRA may still affect how a particular entity fulfills its obligations, but they do not eliminate the need to analyze Rhode Island breach notice duties separately[11][12].

Core Requirements

  1. Maintain a written, risk-based security program. Entities handling covered data must implement and maintain an information-security program designed to protect the information, and the 2026 bill materials say the program should satisfy current best practices in an industry-recognized cybersecurity framework[1][2].
  1. Restrict access to covered data. The modernization materials specifically call for controls that restrict and manage access to the protected data, which means role-based access, least privilege, and access review processes should be part of the program design if the amendment is enacted[1][4].
  1. Notify affected Rhode Island residents after a breach. The statute requires breach notification to consumers when covered information is acquired in an unauthorized way, and the 2025 amendment text would tighten the timing to fixed outer limits for agencies and businesses[11][12].
  1. Notify state authorities for government and business breaches when required. The 2026 press materials say the amendment would add timely notice to ETSS when a breach occurs, which would create an additional reporting path beyond consumer notification[1][6].
  1. Treat unencrypted data exposure seriously. The Rhode Island materials repeatedly frame breach obligations around unauthorized acquisition of unencrypted covered data, so encryption and key-management decisions directly affect the notification analysis and residual risk exposure[11][15].
  1. Preserve documentation and decision records. Because the statute turns on breach discovery, scope, and notice timing, entities should document incident response decisions, legal analysis, and notice timing to defend the reasonableness of their process under enforcement review.

Deadlines and Penalties

| milestone | date | what applies | |---|---:|---| | Original enactment effective date | one year after 2015 passage | Baseline Identity Theft Protection Act provisions became operative[12][13] | | 2025 amendment proposal | proposed 2025 effective schedule | Would set 30-day agency notice and 45-day business notice deadlines[11] | | 2026 modernization bill text | proposed July 2026 effective date | Would update definitions, security-program standards, and ETSS reporting[3][14] |

The existing penalty structure referenced in the 2026 legislative materials preserves penalties for reckless and knowing and willful violations, and the amendment would authorize additional court sanctions where warranted[1][4]. The materials available here do not provide a definitive, finalized post-amendment fine schedule, so any monetary exposure beyond the existing penalty framework should be treated as uncertain until enacted text is confirmed[1][4].

Other sanctions can include injunctive relief, court-imposed compliance orders, and reputational harm from public breach disclosure. Because the statute is framed as a privacy-and-security enforcement law, remediation costs, forensic review, consumer notice, and identity-theft mitigation are also practical consequences even when no separate administrative agency fine is imposed[11][12].

How to Comply

  1. Map data and classify it. Build a data inventory for Rhode Island resident information, identify where it is stored, and determine which systems process data that could fall within the statute’s covered categories.
  1. Align the security program to ISO 27001 and NIST CSF 2.0. ISO 27001 maps well to governance, risk assessment, access control, supplier management, and auditability, while NIST CSF 2.0 maps well to identify-protect-detect-respond-recover functions and incident workflows.
  1. Use ISO 42001 where AI systems touch covered data. If an organization uses AI for customer support, fraud detection, or security analytics involving covered data, ISO 42001 helps structure AI governance, oversight, logging, and risk controls.
  1. Implement breach response playbooks with state-specific timers. Define when legal, privacy, security, and communications teams must decide whether Rhode Island notice is required, and build timer-based workflows for the proposed 30-day and 45-day deadlines.
  1. Encrypt sensitive data and manage keys separately. Strong encryption materially reduces breach exposure and should be paired with sound key management, so that unauthorized acquisition does not automatically translate into a reportable incident.
  1. Limit access and log privileged activity. Apply least privilege, multi-factor authentication, periodic access review, and monitoring for anomalous activity across systems that store Rhode Island resident data.
  1. Test vendor and incident clauses. Contracts with processors, MSPs, and cloud providers should require prompt breach reporting, cooperation on forensic investigation, and support for state-specific notice obligations.
  1. Keep a compliance file. Retain policies, risk assessments, tabletop results, breach determinations, legal conclusions, and notice copies so that the organization can show the basis for its actions if challenged.

Related Regulations

  • Rhode Island breach-notification statutes outside Chapter 11-49.3 can overlap with this law when a specific incident also implicates other Rhode Island disclosure duties.
  • HIPAA may conflict on timing and content where a covered entity or business associate handles protected health information, so the shorter or more specific notice rule should be reconciled with both regimes.
  • GLBA can affect financial institutions’ safeguard obligations, but it does not remove the need to analyze Rhode Island resident-data breach duties for applicable records.
  • FCRA may be relevant when the breach concerns consumer-report information or identity-theft protection services, creating parallel notice and remediation expectations.
  • Rhode Island public-records and government-security rules can overlap for agencies, especially where incident reporting, preservation, and disclosure duties are triggered at the same time.

FAQ

Does the Rhode Island Identity Theft Protection Act apply to companies outside Rhode Island?

Yes, if the company owns or licenses covered information about Rhode Island residents and otherwise falls within the statute’s scope. The operative question is not corporate headquarters but whether the entity handles protected resident data[11][12].

Does the law require notice for every data incident?

No, the notice obligation is tied to unauthorized acquisition of covered data and the applicable statutory thresholds. The 2025 and 2026 materials also show that Rhode Island is moving toward tighter, more prescriptive timing rules, but the basic trigger remains a qualifying breach[11][12].

Are there fixed breach-notice deadlines today?

The current statute materials show a prompt-notice standard, while the 2025 amendment text would impose 30-day and 45-day deadlines for government and business entities respectively[11][12]. Until enacted text is confirmed, those fixed deadlines should be treated as proposed rather than settled law[11].

What security framework should a compliance team use?

The bill materials expressly point toward an industry-recognized cybersecurity framework, which makes ISO 27001 and the NIST CSF 2.0 natural implementation choices[1][4]. If AI systems are involved, ISO 42001 is also a useful governance layer because it addresses AI-specific risk management and accountability.

Did Rhode Island change the penalty scheme in 2026?

The 2026 amendment materials say the existing penalties for reckless and knowing-and-willful violations would remain, while courts would gain authority to impose additional sanctions in appropriate cases[1][4]. Because the accessible materials are legislative proposals and summaries, the final penalty effect should be confirmed against enacted text before relying on it.

Sources

Put it into practice

More compliance guides