Tennessee Information Protection Act (TIPA) Compliance
Pandectes GDPR Compliance helps Shopify stores meet TIPA requirements by managing cookie consent, opt-outs of targeted advertising and sale, and consumer privacy requests.
Start Free
The #1 cookie consent app for Shopify, trusted by 185k stores
What is TIPA?
The Tennessee Information Protection Act (TIPA) is Tennessee’s comprehensive consumer privacy law. It was passed as House Bill 1181 and signed in May 2023, and it is codified at Tennessee Code Annotated § 47-18-3201 and the sections that follow. Like the privacy laws of Virginia and other US states, it gives residents rights over their personal information and sets rules for the businesses that collect it.
Under TIPA, Tennessee consumers have the right to:
- Confirm whether a business processes their personal information and access it
- Correct inaccuracies in their personal information
- Delete personal information provided by or obtained about them
- Obtain a portable copy of the personal information they provided
- Opt out of the sale of their personal information, targeted advertising, and profiling that produces legal or similarly significant effects
TIPA also treats some information as sensitive data, including racial or ethnic origin, religious beliefs, health diagnoses, sexual orientation, citizenship or immigration status, genetic or biometric data used to identify a person, precise geolocation, and personal information collected from a known child.

Who does the TIPA apply to?
TIPA applies to businesses that operate in Tennessee or target products or services to Tennessee residents, have more than $25 million in revenue, and either process the personal information of at least 175,000 Tennessee consumers in a calendar year, or process the personal information of at least 25,000 consumers and derive more than 50% of gross revenue from selling personal information.
Nonprofits, institutions of higher education, financial institutions subject to the Gramm-Leach-Bliley Act, licensed insurance companies, and HIPAA covered entities and business associates are exempt.

What happens if I don’t comply with the TIPA?
The Tennessee Attorney General has exclusive authority to enforce TIPA. The main points are:
- Cure period: before bringing an action, the Attorney General must give written notice and 60 days to cure the violation. This cure period is permanent and does not expire.
- Civil penalties: a court may impose up to $7,500 for each violation.
- Treble damages: for willful or knowing violations, a court may award three times the damages.
- Costs: the Attorney General may recover reasonable attorney fees and investigative costs.
- No private right of action: consumers cannot sue a business directly under TIPA.
TIPA also gives businesses an affirmative defense if they maintain a written privacy program that reasonably conforms to the NIST Privacy Framework or comparable documented standards, keep it updated, and provide consumers the rights the law requires.
When did the TIPA go into effect?
TIPA took effect on July 1, 2025. Businesses that meet its thresholds must comply now.
Complying with the TIPA
If your online store meets TIPA’s thresholds, the work that matters most for cookies and tracking looks like this:
- Offer an opt-out of targeted advertising and sale. Advertising pixels and tags that follow visitors across other websites are typically targeted advertising. TIPA requires you to clearly and conspicuously disclose this processing and how consumers can opt out. A visible opt-out link and a cookie banner with clear choices are the usual way to do this. TIPA does not require businesses to honor universal opt-out signals such as Global Privacy Control.
- Get opt-in consent for sensitive data. You must not process sensitive data, such as precise geolocation, without the consumer’s consent. Data from a known child must be handled under the federal Children’s Online Privacy Protection Act.
- Publish a clear privacy notice. It must list the categories of personal information you process, why you process it, the categories you sell and the third parties you sell to, and how consumers can exercise their rights and appeal your decisions.
- Handle consumer requests on time. Provide at least one secure and reliable way to submit requests, without requiring a new account. Respond within 45 days, extendable once by another 45 days when reasonably necessary, and answer appeals within 60 days.
- Document your privacy program. Aligning it with the NIST Privacy Framework can give you the affirmative defense described above.
To make this easier, consider a Consent Management Platform (CMP) like Pandectes GDPR Compliance. It is built for Shopify stores and provides a cookie banner with opt-out options for US states, a “Do not sell or share my personal information” link, automatic cookie scanning and classification, a cookie declaration, consent logs, and data subject request handling. Region-specific banner settings let you show Tennessee visitors the right experience based on their location.
Every business is different, so review your obligations under TIPA with legal counsel where appropriate.














