← All jurisdictions
RI · data breach notification

Rhode Island

med

R.I. Gen. Laws §§11-49.3-1–6

Individual deadline
45 days
Trigger standard
Risk of harm
AG / regulator
Required
Notice to individuals45 calendar days from discovery
Risk-of-harm standardnotice where risk of identity theft
Encryption safe harborYes, encrypted data (key not compromised) generally exempt.
Regulator noticeRhode Island Attorney General, required above 500 residents; concurrent with individual notice
Written notice to AG + CRAs
Credit reporting agenciesNotify CRAs above 500 residents.
Substitute noticeTypically available above $250,000 cost / 500,000 affected (verify).
Private right of actionNo, enforcement by the state.
PenaltiesUp to $100 per record (reckless) / $200 (knowing-willful)
Notable PI definitionsIncludes biometric, credentials.

Rule last verified July 10, 2026 · confidence med. This is a reference summary, not legal advice; verify against the current statute. How we compile this →

Is a Rhode Island breach part of a multi-state incident?

See every jurisdiction at once, with letters and filing packets generated.

Run the calculator →