Privacy Law Library

Tennessee data breach notification law (Release of personal consumer information)

Tenn. Breach Notification

Breach notification · Data security

Requires businesses and government bodies holding computerized personal information of Tennesseans to notify affected residents no later than 45 days after discovering a breach, with a law-enforcement delay. Personal information means name plus SSN, driver license number, or a financial account or card number with its access code. Encrypted data (FIPS 140-2) is covered only if the key is also taken, and large breaches must also be reported to the nationwide credit bureaus.

Where
Tennessee
Citation
Tenn. Code Ann. § 47-18-2107
Status
In force
In force since
2005-07-01
Last amended
2017-04-04
Enforced by
Tennessee Attorney General (a violation of part 21 is a Tennessee Consumer Protection Act violation, § 47-18-2106); private suits by injured customers
People can sue
Yes
Penalties
Injured customers (other than government agencies) may sue for damages and an injunction (§ 47-18-2107(h)). Violations of part 21 are also unfair or deceptive acts under the Tennessee Consumer Protection Act, and part 21 civil penalties (§ 47-18-2105) may apply.
Applies to
  • Any person or business that conducts business in Tennessee, and any state agency or political subdivision, that owns or licenses computerized personal information of Tennessee residents ("information holders")
  • Entities that maintain computerized personal information they do not own
  • Does not apply to information holders subject to GLBA Title V or to HIPAA as expanded by HITECH

Security duties

  • Breach excludes encrypted data (FIPS 140-2) unless the encryption key is also acquired; an employee who obtains data intending unlawful use counts as an unauthorized person.Tenn. Code Ann. § 47-18-2107(a)(1)-(2), (a)(5)

Breach duties

  • Give written or electronic notice, or substitute notice (email, website posting, and statewide media) if costs exceed $250,000, more than 500,000 people are affected, or contact information is insufficient.Tenn. Code Ann. § 47-18-2107(e)
  • An entity that maintains data it does not own must notify the owner or licensee within 45 days of discovery.Tenn. Code Ann. § 47-18-2107(c)
  • Notice may be delayed if law enforcement determines it would impede a criminal investigation, but must go out within 45 days after law enforcement says it will not compromise the investigation.Tenn. Code Ann. § 47-18-2107(d)
  • Notify each Tennessee resident whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person no later than 45 days after discovery or notification of the breach.Tenn. Code Ann. § 47-18-2107(b)
  • If more than 1,000 persons must be notified at one time, also notify all nationwide consumer reporting agencies of the timing, distribution, and content of the notices.Tenn. Code Ann. § 47-18-2107(g) · Only if: More than 1,000 persons notified at one time

Other duties

  • An information holder that follows its own notification procedures in an information security policy consistent with the statute's timing is deemed compliant.Tenn. Code Ann. § 47-18-2107(f)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: No amendments after 2017 appear in the 2025 code history; 2026-session changes were not exhaustively checked. | State agencies are also covered by a separate provision, Tenn. Code Ann. § 8-4-119, which was not reviewed because it binds only government.

Research reference, not legal advice.