Rhode Island Identity Theft Protection Act of 2015 (information security and breach notification)

RI ITPA
active

Rhode Island's main data security and breach notification statute. It requires businesses and government agencies holding Rhode Island residents' personal information to keep a risk-based information security program, limit retention, destroy data securely and bind vendors by contract to reasonable security. When a breach poses a significant risk of identity theft, affected residents must be notified within 45 days (30 days for agencies), with notice to the Attorney General and credit bureaus if more than 500 residents are affected.

Jurisdiction

Rhode Island

Jurisdiction Type

state

Country

United States

Enforcing Authority

Rhode Island Attorney General

Fines Under This Regulation

0

Total Fine Amount (USD)

--