Tennessee
Tennessee Information Protection Act (TIPA)
- Effective date
- July 1, 2025
- Enacted
- May 11, 2023
- Enforcement
- Tennessee Attorney General
- Last reviewed
- October 3, 2026
Overview
At a Glance
Effective Date
July 1, 2025
Enforcement Authority
Tennessee Attorney General
Consumer Request Deadline
45 days; one additional 45-day extension when reasonably necessary.
Cure Period
60-day cure period.
60-day cure period.
Universal Opt-Out / GPC
No
Private Right of Action
No
Sensitive Data Consent
Yes
Opt-in consent required
Appeals Process
Yes
Applicability
Who Does This Law Apply To?
Applies to qualifying persons doing business in Tennessee or targeting Tennessee residents when revenue and processing thresholds are met.
General Coverage Thresholds
- Annual revenue
- Over $25 million (required in addition to a volume threshold)
- Consumer volume
- 175,000+ Tennessee consumers per year
- Data sales
- Or 25,000+ consumers and over 50% of gross revenue from selling personal data
- Special provisions
- Affirmative defense for a privacy program aligned with the NIST Privacy Framework
Rights
Consumer Rights
Right to Opt Out of Sale
Opt out of sale of covered personal data as defined by the statute.
Right to Access
Confirm processing and access covered personal data, subject to statutory limits.
Right to Delete
Request deletion of covered personal data, subject to exceptions.
Right to Opt Out of Profiling
Opt out of qualifying profiling or solely automated decisions where provided.
Right to Correct
Request correction of inaccuracies in covered personal data.
Right to Data Portability
Obtain covered personal data in a portable format where the statute provides.
Right to Opt Out of Targeted Advertising
Opt out of covered targeted or cross-context behavioral advertising.
Obligations
Business Obligations
- AppealsRequiredInternal appeal process for denied rights requests.
- Data securityRequiredMaintain reasonable administrative, technical, and physical safeguards as required by the statute.
- Privacy noticeRequiredProvide required privacy disclosures/notices.
- Sensitive dataState-specificOpt-in consent is generally required before processing sensitive data, subject to statutory exceptions.
- Data minimizationRequired / state-specificLimit or govern collection/use consistent with the statute's duties and disclosed purposes.
- Universal opt outNot requiredNo general universal opt-out mechanism requirement in the current omnibus law.
- Processor contractsRequiredUse contracts governing processors/service providers as required.
- Consumer request processRequiredProvide methods for consumers to exercise statutory rights.
- Data protection assessmentRequiredConduct assessments for specified higher-risk processing.
Exemptions
Common Exemptions
Exemptions are state-specific and may apply at the entity level, data level, or both. Verify the official statute before relying on an exemption. Treatment commonly varies for government, regulated financial/health information, higher education, nonprofits, employment data, and B2B data.
This list is not exhaustive.
Enforcement
Enforcement & Penalties
Authority: Tennessee Attorney General
Up to $7,500 per violation; treble damages may be available in specified willful/knowing enforcement circumstances.
Self-check
Could This Law Apply to My Business?
Your result
Answer the 4 questions to see a general, educational indication.
Sources
Sources & Verification
- View source
Tennessee Information Protection Act (statute)
State legislature
- View source
iapp.org
Secondary reference
- View source
ncsl.org
Secondary reference
- View source
privacylawnetwork.com
Secondary reference
- View source
ketch.com
Secondary reference
Last reviewed: October 3, 2026· Verified against official sources
From understanding to action
Digital Data Rights helps you understand the privacy landscape.
DataRightsOS helps businesses put privacy processes into operation.
Educational information only, not legal advice. Summaries may omit details; verify against the statute, regulations and official guidance.