Tennessee Information Protection Act (TIPA)

· About Tennessee Information Protection Act (TIPA)

Key Takeaways

  • TIPA applies to for-profit controllers doing business in Tennessee or targeting Tennessee residents if they meet the law’s revenue-and-volume thresholds, and it also reaches some controllers outside Tennessee through their consumer-facing activities. [2][4][5]
  • The law gives Tennessee consumers rights to access, correct, delete, obtain a copy of, and opt out of certain processing, including targeted advertising, sale of personal data, and profiling in furtherance of decisions with legal or similarly significant effects. [2][5]
  • TIPA is enforced exclusively by the Tennessee Attorney General and Reporter, and the law provides a 60-day cure period after written notice; there is no private right of action. [2][5]
  • TIPA took effect on 1 July 2025, while data-protection assessment requirements for new processing activities had a phase-in date of 1 July 2024 for activities created or generated on or after that date. [2][3][5]
  • The statute has not been publicly identified in the gathered sources as having 2025–2026 amendments delaying the operative date, and available official and secondary summaries continue to describe the law as effective and in force on 1 July 2025. [2][3][5]
  • A controller that violates the Act can face civil penalties of up to $7,500 per violation, plus injunctive relief and enforcement costs under Tennessee consumer protection enforcement authority. [2][5]

What It Is

The Tennessee Information Protection Act (TIPA) is Tennessee’s comprehensive consumer privacy law, codified at Tenn. Code Ann. §§ 47-18-3301 et seq., and it regulates how covered controllers process personal information of Tennessee consumers. [2][5][12]

The law is enforced by the Tennessee Attorney General and Reporter, who has exclusive civil enforcement authority and may issue civil investigative demands and seek relief after notice and an opportunity to cure. [2][5]

TIPA was adopted on 11 May 2023 when Governor Bill Lee signed HB 1181 / Public Chapter 408; the law was set to become effective on 1 July 2025. [2][11][12]

A key phase-in date is 1 July 2024, when the law’s data protection assessment requirements began applying to new processing activities created or generated on or after that date. [2][3][5]

The operative law is described in current official and practice materials as effective 1 July 2025, and no source gathered here indicates a later statewide delay or repeal as of 6 September 2026. [2][3][5][10]

Who Must Comply

TIPA applies to a person that conducts business in Tennessee or produces products or services targeted to Tennessee residents and that is not a governmental entity, while also meeting the law’s size-and-processing thresholds. [5][6]

A covered controller generally must, during a calendar year, either control or process the personal information of at least 175,000 consumers or control or process the personal information of at least 25,000 consumers and derive more than 50% of gross revenue from the sale of personal information, with an additional revenue threshold reflected in secondary summaries. [5][6]

The law has extraterritorial reach to the extent a controller outside Tennessee targets Tennessee residents or otherwise falls within the statutory business-activity standard and thresholds. [5][6]

TIPA includes a broad list of entity exemptions and data-level exemptions, including many nonprofit, governmental, and sector-specific carveouts; a 2025 public chapter reportedly broadened the nonprofit/public-utility language so the exemption can cover a public utility regulated under Tennessee law, not only one organized under Tennessee law. [4][5][11]

The law does not create a private right of action, so consumer complaints are routed through the Attorney General rather than individual lawsuits under TIPA itself. [2][5]

Core Requirements

  1. Provide a privacy notice. Covered controllers must disclose the categories of personal data processed, the purposes for processing, how consumers may exercise rights, categories of data shared with third parties, and how to appeal a denial. [2][5]
  1. Honor consumer rights. Controllers must provide a process for consumers to confirm whether their data is being processed and to access, correct, delete, and obtain a portable copy of that data. [2][5]
  1. Enable opt-outs. Controllers must allow consumers to opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions producing legal or similarly significant effects. [2][5]
  1. Limit processing to disclosed purposes. Controllers must not process personal data for purposes that are neither reasonably necessary nor disclosed, and they must follow data minimization and purpose-limitation principles. [2][5]
  1. Conduct data protection assessments. Controllers must perform assessments for processing that presents heightened risk, including targeted advertising, sale of personal data, profiling, sensitive data processing, and certain other high-risk uses. [2][3][5]
  1. Protect sensitive data. Controllers must obtain consent before processing sensitive data, which in Tennessee privacy statutes generally includes precise geolocation and biometric or similar sensitive categories defined by the Act. [2][5]
  1. Respond within the statutory timeline. Controllers must respond to authenticated consumer requests within 45 days, with a possible 45-day extension when reasonably necessary and properly communicated. [2][5][15]
  1. Maintain contracts and oversight. Controllers must use written contracts with processors imposing confidentiality, deletion/return, assistance, and audit-related obligations aligned to the statutory processor framework. [2][5]

Deadlines and Penalties

| milestone | date | what applies | |---|---:|---| | Data protection assessment phase-in | 1 July 2024 | New processing activities created or generated on or after this date are subject to assessment requirements. [2][3][5] | | TIPA effective date | 1 July 2025 | Full operative consumer privacy rights and controller obligations apply. [2][3][5][12] | | Cure period after notice | ongoing | The Attorney General must give 60 days’ written notice before filing an action, and the controller may cure the violation if possible. [2][5] |

Maximum civil penalties under Tennessee consumer protection enforcement are up to $7,500 per violation, with the Attorney General also able to seek injunctive relief and recover enforcement costs in appropriate cases. [2][5]

Other sanctions include civil investigative demands, compliance orders through enforcement, and mandatory corrective action, but the statute does not provide consumer statutory damages or a private lawsuit path. [2][5]

How to Comply

  1. Map your data and determine applicability. Confirm whether your organization meets the Tennessee threshold, whether you target Tennessee residents, and whether any exemptions apply. Use this as the gatekeeper for the rest of the program. [5][6]
  1. Build a TIPA-specific data inventory. Align your recordkeeping with ISO 27001 asset management and data-classification practices so you can locate personal data, sensitive data, processors, and sharing paths quickly. [2][5]
  1. Create consumer rights workflows. Implement intake, identity verification, request tracking, and appeal handling for access, correction, deletion, portability, and opt-out requests, and make sure deadlines are measured in 45-day cycles. [2][5]
  1. Update notices and preference controls. Review privacy notices, cookie banners, and global privacy control handling so opt-outs for targeted advertising, sale, and profiling are honored consistently. Map this to NIST CSF 2.0 governance, identity, and privacy-related controls. [2][5]
  1. Run and document data protection assessments. Use a repeatable risk-assessment method for high-risk processing, especially targeted advertising, sale, profiling, and sensitive-data processing. ISO 42001 can help structure AI-related governance where profiling or automated decisioning is involved. [2][3][5]
  1. Tighten processor contracts. Review controller-processor agreements for confidentiality, deletion/return, subprocessor oversight, audit support, and incident/reporting terms that match the statute’s outsourcing model. [2][5]
  1. Train customer-facing and engineering teams. Ensure privacy, marketing, and product teams understand what counts as a sale, targeted advertising, profiling, and sensitive data so they do not accidentally route requests or processing incorrectly. [2][5]
  1. Prepare an AG-response package. Keep assessments, notices, policies, and request logs organized so you can respond promptly if the Attorney General issues a civil investigative demand or notice of alleged violation. [2][5]

Related Regulations

Virginia Consumer Data Protection Act (VCDPA): Tennessee’s law is structurally similar, especially on consumer rights, assessments, and opt-outs, but the threshold tests and some exemptions differ. [5]

Connecticut Data Privacy Act (CTDPA): Connecticut overlaps on consumer rights and controller duties, but it uses its own enforcement architecture and threshold framework, so a multi-state program should not treat the laws as interchangeable. [5]

Colorado Privacy Act (CPA): Colorado’s law also requires opt-outs and assessments, but Colorado’s rulemaking and universal opt-out mechanics differ, so cookie and ad-tech programs need state-specific controls. [5]

California Consumer Privacy Act as amended by CPRA: California is broader in operational scope and has a different enforcement landscape, including a dedicated privacy regulator, so TIPA compliance does not substitute for California readiness. [5]

Tennessee Consumer Protection Act: TIPA is enforced through Tennessee’s consumer protection enforcement system, so general unfair-or-deceptive-practice exposure can overlap with privacy compliance failures. [2][5]

FAQ

Does TIPA apply to companies outside Tennessee?

Yes, if the company does business in Tennessee or produces products or services targeted to Tennessee residents and meets the statutory thresholds. The law is not limited to Tennessee-incorporated entities. [5][6]

When did TIPA actually start applying?

The law’s main operative date is 1 July 2025. Data protection assessment obligations for certain new processing activities began earlier, on 1 July 2024. [2][3][5]

Does TIPA let consumers sue directly?

No. Enforcement is vested exclusively in the Tennessee Attorney General and Reporter, and the statute does not create a private right of action. [2][5]

What consumer rights does TIPA cover?

TIPA covers access, correction, deletion, portability, and opt-out rights for targeted advertising, sale of personal data, and certain profiling. Controllers must also respond to verified requests within 45 days, subject to a limited extension. [2][5][15]

Are nonprofits exempt?

Many nonprofit organizations are exempt, but the exemptions are specific and should be tested carefully against the statutory text. Secondary 2025 materials also note a public-utility related clarification affecting nonprofit/public-utility coverage. [4][5][11]

Are there 2025–2026 amendments or delays?

The gathered official and secondary sources continue to describe TIPA as effective on 1 July 2025, and no gathered source shows a later delay or rollback. A 2025 public chapter appears to have made a narrow exemption clarification, but it did not change the law’s operative date. [2][3][4][5][11]

Sources

Put it into practice

More compliance guides