Key Takeaways
- TIPA has been in effect since July 1, 2025. It applies to businesses that exceed $25 million in annual revenue and either process data on 175,000+ Tennessee consumers, or 25,000+ consumers while getting more than half their revenue from selling personal information.
- Violations can cost up to $7,500 per violation, and courts can triple that to $22,500 per violation for willful or knowing conduct.
- Businesses get a 60-day cure period before the Attorney General can bring an enforcement action, and unlike some other states, this right does not have a sunset date.
- TIPA offers a rare affirmative defense: businesses with a written privacy program that reasonably conforms to the NIST Privacy Framework can use that as a legal defense if they're investigated.
- Consumers get the standard set of rights (know, access, correct, delete, port, opt out), and businesses have 45 days to respond, extendable by another 45.
The Tennessee Information Protection Act (TIPA) is Tennessee's comprehensive consumer data privacy law. Signed on May 11, 2023, it took effect on July 1, 2025 and now governs how qualifying businesses collect, process, and sell Tennessee residents' personal data. This checklist covers who the law applies to, what it requires, the penalties for getting it wrong, and the compliance steps to work through in order.
Secure Privacy is a cookie and consent management platform built to help businesses meet requirements like TIPA's consent, opt-out, and data protection assessment rules without building the infrastructure from scratch.
What Is the Tennessee Information Protection Act?
TIPA is Tennessee's state-level consumer privacy law, following the pattern set by other US states that passed comprehensive privacy legislation before it. It gives Tennessee consumers rights over their personal data and imposes obligations on the businesses that collect it.
TIPA sits closer to the more business-friendly end of the state privacy law spectrum. It's structurally similar to Virginia's Consumer Data Protection Act and to laws like Utah's and Iowa's, and it's less consumer-protective than the California Consumer Privacy Act, Colorado's Privacy Act, or Indiana's Consumer Data Protection Act. It's also considerably less strict than the EU's GDPR or Brazil's LGPD. TIPA's standout feature, not found in most other US state laws, is its NIST-framework affirmative defense, covered in the enforcement section below.
Who Does TIPA Apply To?
TIPA applies to any business that conducts business in Tennessee, or produces products or services targeted to Tennessee residents, and meets both of these conditions:
- Revenue threshold: Exceeds $25 million in annual revenue.
- Data volume threshold (either one):
- Controls or processes the personal information of at least 175,000 Tennessee consumers during a calendar year, or
- Controls or processes the personal information of at least 25,000 Tennessee consumers and derives more than 50% of gross revenue from selling personal information.
If your business doesn't clear the revenue threshold, TIPA doesn't apply, regardless of how much data you handle. This two-part test is why some large data processors fall outside TIPA's scope while smaller, data-sale-dependent businesses can fall inside it.
Exemptions
TIPA exempts certain organizations entirely:
- Government entities
- Nonprofit organizations
- Higher education institutions (public or private)
- Entities covered by HIPAA and HITECH
- Financial institutions regulated under the Gramm-Leach-Bliley Act
- Insurance companies licensed under state law
It also exempts specific categories of data, including information already regulated under HIPAA, GLBA, the Fair Credit Reporting Act, FERPA, and the federal Farm Credit Act, along with research data collected in the public interest, employment records, and personal motor vehicle records.
What Counts as Personal Data Under TIPA?
Personal data under TIPA is any information that identifies an individual, directly or indirectly. That covers obvious identifiers like name, Social Security number, and phone number, as well as less obvious ones: IP addresses, browsing history, purchase history, fitness-tracker health data, and precise geolocation.
TIPA singles out a narrower category, sensitive data, for stricter treatment:
- Data revealing racial or ethnic origin, sexual orientation, citizenship or immigration status, or a health diagnosis
- A child's data
- Precise geolocation data
- Genetic or biometric data used to identify a person
- Personal information collected from a known child
You can't collect sensitive data without consent, and processing it usually triggers a required data protection assessment (covered below).
What Businesses Must Do to Comply
TIPA distinguishes a controller (decides why and how data is processed) from a processor (processes data on the controller's behalf). If you run Google Analytics on your site, you're the controller; Google is your processor.
Every controller or processor also has to create, maintain, and follow a written privacy program that reasonably conforms to the NIST Privacy Framework or a comparable documented set of policies and procedures. This isn't optional groundwork: it's also the basis of TIPA's affirmative defense, covered under Enforcement below.
Data Processing Agreements
TIPA requires processors to handle data only under a written contract with the controller. At minimum, this data processing agreement needs to include:
- The identity of both parties
- The nature and purpose of the processing
- The categories of personal data involved
- How long the processing will last
- Both parties' rights and duties, including confidentiality terms
- A requirement to delete data on the controller's request
- A requirement that the processor prove compliance to the controller on request
- Terms covering the use of subcontractors
Processing data without this written contract in place is itself a violation.
Privacy Notice
Your privacy notice (or privacy policy) needs to disclose, at minimum:
- Why you process personal data
- What categories of data you process
- What categories of data you sell, if any
- What categories of third parties you sell data to, if any
- How consumers can exercise their rights
You can include more than this, but these five elements are the floor, not a suggestion.
Consent for Sensitive Data
You need explicit, freely given, specific, informed, and unambiguous consent before processing sensitive data. This requirement applies only to sensitive data, not to personal data generally. If you're processing a known child's data, TIPA lets you rely on the parental consent standards already set out in COPPA instead of building a separate consent mechanism.
Universal Opt-Out Mechanisms
TIPA doesn't require you to honor universal opt-out signals (like Global Privacy Control). It's silent on the topic entirely. You still have to give consumers a way to opt out through methods you designate and disclose, just not through a universal browser-level signal.
Data Protection Assessments
A data protection assessment is where you document the risks a specific processing activity poses to consumers, and what you're doing to mitigate them. TIPA requires one for:
- Selling personal data
- Processing sensitive data
- Processing data for targeted advertising
- Processing data for profiling
- Any other processing that poses a heightened risk to consumers
What Rights Do Tennessee Consumers Have?
TIPA gives Tennessee residents the right to:
- Confirm whether a business is processing their data
- Access their personal data
- Correct inaccuracies in their data
- Delete their data
- Obtain a portable copy of their data
- Opt out of targeted advertising, profiling, and the sale of their personal information
Consumers submit these requests through whatever channel your privacy notice designates. You have 45 days to respond, and you can extend that by another 45 days for more complex requests, as long as you notify the consumer of the extension.
Enforcement and Penalties
The Tennessee Attorney General has exclusive authority to enforce TIPA. There's no private right of action: individual consumers can't sue your business directly, only the Attorney General can bring an action.
Cure period: Before pursuing enforcement, the Attorney General must give written notice and 60 days to fix the violation. This is one of the longest cure periods among US state privacy laws, and unlike some other states' time-limited cure rights, TIPA's does not currently carry a sunset date. Submit written confirmation within the 60 days that the violation is cured and won't recur, and the Attorney General can't move forward on it.
Penalties: Violations that aren't cured in time can draw civil penalties of up to $7,500 per violation. For willful or knowing violations, a court can award treble damages, tripling the exposure to as much as $22,500 per violation. The Attorney General can also recover attorney's fees and investigative costs.
NIST affirmative defense: TIPA includes a defense that most other state privacy laws don't offer. If your business is investigated, you have an affirmative defense available if you maintain a written privacy program that reasonably conforms to the NIST Privacy Framework, "A Tool for Improving Privacy through Enterprise Risk Management, Version 1.0," or another documented set of policies, standards, and procedures designed to safeguard consumer privacy. In practice, this makes a documented, NIST-aligned privacy program worth building well before you're ever investigated, not after.
TIPA Compliance Checklist
Work through this in order:
- Confirm applicability against the revenue and consumer-count thresholds above.
- Classify your data into ordinary personal data and sensitive data.
- Update your privacy notice with the five required disclosures.
- Sign written data processing agreements with every processor you use.
- Set up consent capture for sensitive data and known children's data.
- Build opt-out mechanisms for targeted advertising, profiling, and data sales.
- Run and document data protection assessments for sensitive-data processing, sales, targeted advertising, profiling, and other high-risk activity.
- Build a rights-request process that can confirm, access, correct, delete, and port data within 45 days (with a process for the 45-day extension).
- Write and maintain a NIST-aligned privacy program, both to reduce risk and preserve the affirmative defense.
- Document your cure-period response process so a notice from the Attorney General doesn't catch you scrambling.
FAQ
Is TIPA in effect right now?
Yes. TIPA took effect on July 1, 2025, after being signed into law on May 11, 2023. It has been enforceable for over a year.
Who does TIPA apply to?
Businesses that conduct business in Tennessee or target Tennessee residents, exceed $25 million in annual revenue, and either process 175,000+ Tennessee consumers' data or 25,000+ consumers' data while getting more than half their revenue from selling personal information.
How much can a TIPA violation cost?
Up to $7,500 per violation, or up to $22,500 per violation if a court finds the violation was willful or knowing and awards treble damages.
Does TIPA have a cure period?
Yes, 60 days from written notice of the alleged violation. If the business confirms in writing that it fixed the issue within that window, the Attorney General can't bring an enforcement action over it. This cure right does not currently have a sunset date.
What is the NIST affirmative defense under TIPA?
A business investigated for a TIPA violation can raise an affirmative defense if it maintains a written privacy program that reasonably conforms to the NIST Privacy Framework or a comparable documented set of privacy policies and procedures. Few other state privacy laws offer anything like it.
Can individual consumers sue a business under TIPA?
No. TIPA doesn't include a private right of action. Only the Tennessee Attorney General can bring an enforcement action.
How long do businesses have to respond to a consumer rights request?
45 days, extendable by another 45 days for more complex requests, as long as the business notifies the consumer of the extension.
Sources
- Tennessee Code, Title 47, Chapter 18, Part 33, Tennessee Information Protection Act (Justia)
- Tennessee Information Protection Act (TIPA): What to Know, Osano
- Tennessee Information Protection Act Is Signed Into Law, Davis Wright Tremaine
- Tennessee Information Protection Act: What Businesses Need to Know, Akin



