Rhode Island Identity Theft Protection Act of 2015 (information security and breach notification)
RI ITPARhode Island's main data security and breach notification statute. It requires businesses and government agencies holding Rhode Island residents' personal information to keep a risk-based information security program, limit retention, destroy data securely and bind vendors by contract to reasonable security. When a breach poses a significant risk of identity theft, affected residents must be notified within 45 days (30 days for agencies), with notice to the Attorney General and credit bureaus if more than 500 residents are affected.
Jurisdiction
Rhode Island
Jurisdiction Type
state
Country
United States
Enforcing Authority
Rhode Island Attorney General
Fines Under This Regulation
0
Total Fine Amount (USD)
--