Pandectes GDPR Compliance - 3,000+ Verified ⭐⭐⭐⭐⭐ 5/5 Reviews Worldwide - #1 on Shopify 🏅

Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) Compliance

Pandectes GDPR Compliance helps Shopify stores meet RIDTPPA requirements by managing cookie consent, offering clear opt-outs and handling consumer privacy requests.

Start Free
RIDTPPA Rhode Island

The #1 cookie consent app for Shopify, trusted by 185k stores

  • Nike Strength
  • Reebok
  • Ted Baker
  • Juicy Couture
  • Aje
  • Casely
  • Oracle Red Bull Racing
  • KFC
  • Flying Tiger Copenhagen
  • Sennheiser
  • Susanne Kaufmann
  • Aldo
  • Victoria Beckham
  • Scalpers
  • UGREEN

What is RIDTPPA?

The Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) is Rhode Island’s comprehensive consumer privacy law. It gives Rhode Island residents rights over their personal data and sets obligations for the businesses that collect and process it. The law closely follows the model used by states such as Connecticut and Virginia.

Under the RIDTPPA, Rhode Island residents have the right to:

  • Confirm whether a business processes their personal data, and access that data
  • Correct inaccurate personal data
  • Delete personal data
  • Obtain a portable copy of their personal data
  • Opt out of targeted advertising, the sale of their personal data, and profiling used for solely automated decisions with legal or similarly significant effects

Businesses must also obtain consent before processing sensitive data, such as health data, precise geolocation, biometric data, data revealing racial or ethnic origin, or data collected from a known child.

The law places particular weight on transparency. Websites that collect and sell the personal data of Rhode Island customers must publish a privacy notice that describes the categories of personal data collected, and identifies the third parties to which that data has been or may be sold. This notice requirement is written more broadly than the rest of the law, so it may apply even to websites that fall below the thresholds below.

Who does the RIDTPPA apply to?

The RIDTPPA applies to for-profit businesses that operate in Rhode Island or offer products or services targeted to Rhode Island residents, and that in the previous calendar year controlled or processed the personal data of at least 35,000 Rhode Island customers (not counting data used only to complete a payment), or of at least 10,000 customers while earning more than 20% of gross revenue from selling personal data. Nonprofits and certain regulated entities and data types are exempt.

What happens if I don’t comply with the RIDTPPA?

A violation of the RIDTPPA is treated as a deceptive trade practice under Rhode Island law. Key points about enforcement:

  • The Rhode Island Attorney General has exclusive authority to enforce the law.
  • Violations can lead to civil penalties under Rhode Island’s deceptive trade practices law, which can reach $10,000 per violation.
  • Anyone who intentionally discloses personal data in violation of the law can also be fined between $100 and $500 for each disclosure.
  • The law does not include a cure period, so businesses are not guaranteed a chance to fix a problem before enforcement begins.
  • There is no private right of action, so consumers cannot sue businesses directly under the law.

When did the RIDTPPA go into effect?

The RIDTPPA took effect on January 1, 2026. Businesses that meet the thresholds should already be in compliance.

Complying with the RIDTPPA

If your online store sells to Rhode Island residents, most of your practical work involves cookies and tracking. Marketing pixels, analytics tags, and advertising cookies often count as targeted advertising or a “sale” of personal data under state privacy laws, so they need to respect each visitor’s choices.

Practical steps for a Shopify store include:

  • Offer a clear opt-out. Give visitors an easy way to opt out of targeted advertising and the sale of their personal data, such as a “Do not sell or share my personal information” link, and make sure tracking stops once they do.
  • Consider honoring Global Privacy Control. Unlike several other states, the RIDTPPA does not specifically require businesses to recognize universal opt-out signals. Treating a Global Privacy Control (GPC) signal as an opt-out is still a sensible way to respect visitor choices consistently across states.
  • Get consent for sensitive data. Do not process sensitive data without the consumer’s consent, and review your apps and forms for anything that collects it.
  • Update your privacy notice. Describe the personal data you collect, why you collect it, how consumers can exercise their rights, and the third parties to which personal data has been or may be sold. Your cookie list is a good starting point for identifying advertising and analytics partners.
  • Handle consumer requests. Set up a reliable way for customers to request access, correction, deletion, or a copy of their data, and respond within the required timeframe.

A consent management platform makes these steps much easier to maintain. Pandectes GDPR Compliance is built for Shopify stores and provides a cookie banner with opt-out options for US states, a “Do not sell or share my personal information” link, and support for the Global Privacy Control signal. It automatically scans and classifies the cookies on your store, generates a cookie declaration, keeps consent logs, and helps you handle data subject requests. Region-specific banner settings use geolocation to show the right experience to visitors from Rhode Island and other states.

Privacy laws differ in their details and continue to change, so review your setup with legal counsel where appropriate.

Make your Shopify Store's use of cookies and online tracking compliant today

Try for free