Every time a Tennessee resident sends a data request to your business, a clock starts ticking.
This page covers one piece of the picture. For the full scope of the TIPA — who must comply, the thresholds, the consumer rights and the penalties — start with our complete guide to the TIPA and cookies.
45 days.
That's what the Tennessee Information Protection Act (TIPA), in effect since July 1, 2025, gives you to respond to a Data Subject Access Request, commonly known as a DSAR.
One missed deadline. One unanswered request. One absent appeal process. Any of these can put your business in front of the Tennessee Attorney General.
This article breaks down what DSARs look like under TIPA, what a Privacy Portal needs to have to support them, and how to build a workflow that is both compliant and operationally sustainable.
The Tennessee Information Protection Act (Tenn. Code Ann. § 47-18-3201 et seq.) was enacted in May 2023 and took effect on July 1, 2025. It applies to entities that conduct business in Tennessee or produce products or services targeted at Tennessee residents, with annual gross revenue exceeding $25 million, and that during a calendar year:
Control or process personal data of at least 175,000 consumers, or
Control or process personal data of at least 25,000 consumers and derive more than 50% of gross revenue from the sale of personal data.
There are entity-level exemptions for state agencies, financial institutions governed by the Gramm-Leach-Bliley Act, insurance companies, entities governed by HIPAA and HITECH, nonprofits, and institutions of higher education.
One notable distinction: TIPA explicitly includes insurance companies in its entity-level exemptions, which sets it apart from most other state privacy laws.
A "consumer" under TIPA is a natural person who is a Tennessee resident acting only in an individual or household context. This definition explicitly excludes individuals acting in a commercial or employment context, which affects how businesses filter and prioritize incoming DSARs.
A Data Subject Access Request is any formal request submitted by a consumer to exercise the rights guaranteed by TIPA over the personal data a business holds about them.
TIPA grants Tennessee consumers the following rights:
The right to confirm whether a controller is processing their personal data and to access it.
The right to correct inaccuracies in their personal data.
The right to delete personal data provided by or obtained about the consumer.
The right to obtain a copy of their personal data in a portable, readily usable format.
The right to opt out of the processing of their personal data for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects.
These rights mirror the structure established by the LGPD (in Portuguese) in Brazil and other modern global privacy regulations. The core logic is the same: receive, verify, respond, document.
TIPA does not use the term "Privacy Portal" explicitly. But it requires controllers to provide clear and conspicuous mechanisms for consumers to exercise their rights.
A Privacy Portal is the most efficient way to fulfill that requirement. It is a centralized interface, typically a dedicated page on the business website, where consumers can:
Learn about the rights they hold under TIPA.
Submit access, correction, deletion, and portability requests securely.
Exercise opt-out of targeted advertising and data sales.
Track the status of their requests.
Revoke previously given consents.
The cookie banner and the Privacy Portal need to be connected. When a user clicks "manage preferences" on the cookie notice, the Portal is the natural destination for the full exercise of their rights.
TIPA requires controllers to offer clear mechanisms for consumers to submit requests. Best practice is to provide at least two channels, such as an online form combined with a dedicated privacy email address.
The business cannot require consumers to create a new account to submit a request. It may, however, require the use of an existing account for identity verification purposes.
TIPA allows a controller to decline a request if it cannot verify the consumer's identity using commercially reasonable efforts. But the verification process cannot be designed as a barrier.
The level of verification should be proportional to the sensitivity of the data involved. For access or portability requests involving sensitive data, stronger authentication makes sense. For opt-out requests, a simpler process is appropriate.
A well-maintained data mapping inventory is what makes verification operationally effective. Without knowing where data lives across all systems, verifying identity does not help you respond within 45 days.
The Portal needs to explain in plain language what each right means in practice. Consumers need to understand what they are requesting before they submit a request.
Under TIPA, transparency is not just a principle. It is a compliance requirement. This converges with what the LGPD (in Portuguese) establishes in Art. 9: information must be made available in a clear, adequate, and accessible manner.
TIPA guarantees the right to opt out of targeted advertising and data sales. The Portal needs to make this opt-out easy to find and simple to use.
Targeted advertising under TIPA means displaying ads selected based on personal data obtained from a consumer's activities over time and across non-affiliated websites or applications. If your site uses tools like the Meta Pixel, Google Ads, or TikTok Pixel, you are running targeted advertising under this definition.
The opt-out needs to work in practice. When a consumer disables targeted advertising, the corresponding tags and trackers need to be blocked in real time. A consent management platform properly configured handles this automatically.
TIPA requires controllers to recognize and comply with the Global Privacy Control (GPC) signal. This means if a consumer visits your site with GPC enabled in their browser, your system must automatically respect that signal as an opt-out request for targeted advertising and data sales.
This is an operational requirement that needs to be handled at the cookie notice and CMP level, not manually.
TIPA requires controllers to establish a process for consumers to appeal a decision to deny their request. This process must be conspicuously available and functionally similar to the original request submission process.
If a consumer submits a request via an online form, the appeal process must also be available via a form, not buried in a PDF or hidden in a terms and conditions page.
The appeal process must be described in the Privacy Portal. Consumers need to know it exists and how to use it before they need to invoke it.
TIPA includes specific obligations regarding minors under 13. Controllers offering online services to consumers they know or willfully disregard to be minors must take reasonable care to avoid a heightened risk of harm to those minors.
The Privacy Portal should include a clear statement about how minors' data is handled, whether the site does not intentionally collect data from children or how parental consent is obtained when applicable.
The clock starts the moment a valid, authenticated request is received. From that point, the controller has 45 days to respond.
The deadline can be extended once by an additional 45 days when reasonably necessary, considering the complexity and number of requests. But the consumer must be informed of the extension within the initial 45-day period, along with the reason for the extension.
The response must be provided free of charge at least twice annually per consumer. If a request is manifestly unfounded, excessive, or repetitive, the controller may charge a reasonable administrative fee to cover the costs of compliance or may decline to act on the request. The controller bears the burden of demonstrating the request falls into that exception.
If the controller declines a request, it must inform the consumer within the 45-day window, provide the reason, and give instructions on how to appeal.
Missing this deadline is a violation. And violations under TIPA (in Portuguese) can reach up to $7,500 per violation, with enforcement exclusively by the Tennessee Attorney General.
Step 1: Intake. The request arrives through the form or dedicated email. The system logs the date, request type, and consumer information, starting the 45-day clock.
Step 2: Immediate Confirmation. The consumer receives an acknowledgment with the expected response timeline. This stops the anxiety of waiting and creates a timestamp that documents when the clock started.
Step 3: Identity Verification. The team authenticates the request using methods proportional to the sensitivity of the data involved. If unable to verify, the consumer is notified and asked for additional information.
Step 4: Data Search. The ticket is routed to the teams responsible for the relevant data. An updated data processing registry is the map that makes this search efficient.
Step 5: Decision and Execution. The controller decides to fulfill, partially fulfill, or deny. For fulfillment, the action is executed: access, correction, deletion, portability, or opt-out. For denial, the justification and appeal instructions are prepared.
Step 6: Delivery to Consumer. The response is sent securely via the consumer's chosen channel, with delivery confirmation recorded in the system.
Step 7: Documentation. The full request record, authentication evidence, action taken, and communication sent are archived. This documentation is the business's defense in any investigation by the Tennessee Attorney General.
The consumer wants to know if the business has their data and wants to see it.
The workflow verifies identity, searches all relevant systems, compiles the information, and delivers it in a readable format within 45 days.
This is the most operationally demanding right because it requires complete coverage. A search that misses a secondary system delivers a partial, inaccurate response. A well-maintained data inventory prevents those gaps.
The consumer found an inaccuracy and wants it fixed.
The team verifies identity, evaluates whether the correction is warranted based on the nature of the data and the purpose of processing, executes the correction, and propagates it across all integrated systems.
If the correction is not made in all systems, the next marketing campaign may still use the wrong data.
The consumer wants their data erased.
The team identifies all storage locations, checks for legal retention obligations that may prevent immediate deletion, executes the deletion for everything that can be removed, and maintains a minimal deletion record to ensure the data does not re-enter the database.
This parallels what the LGPD (in Portuguese) establishes in Art. 18, IV and VI, with the same exceptions for legally mandated retention.
The consumer wants a copy of their data in a format they can use elsewhere.
The team compiles the data in a machine-readable, structured, and portable format, such as CSV or JSON, and delivers it securely. A static PDF is not sufficient.
The consumer does not want their behavioral data used to serve personalized ads across different websites.
The system processes the opt-out and blocks the relevant advertising trackers in real time. The cookie notice must be configured so that this opt-out reflects immediately in how the site's trackers behave.
The consumer does not want their data sold to third parties for monetary or other valuable consideration.
The system processes the opt-out and ensures that data sharing pipelines with commercial partners reflect the consumer's choice. This directly impacts digital marketing operations that depend on purchased or sold data sets.
The consumer can refuse the use of their data in automated decision-making processes that produce legal or similarly significant effects concerning them, such as credit, employment, or access to essential services.
If any of the above rights is denied, the consumer can appeal. The appeal process must be as easy to use as the original request process, with a 60-day response window.
TIPA is one of the few state privacy laws in the United States that allows controllers to raise an affirmative defense in an enforcement action.
If a business can demonstrate that it maintains and implements a comprehensive privacy program that reasonably conforms to the NIST Privacy Framework or the ISO 27701 standard, it can use that as a defense against a claim of non-compliance.
This is not an exemption. It is a risk reduction mechanism. A documented compliance program aligned with recognized international frameworks significantly reduces regulatory exposure.
Privacy by design applied from the ground up, with documented processes, regular data protection assessments, and a functioning consent management infrastructure, is the foundation that makes this defense credible.
Consumer data is often distributed across multiple third-party vendors: email platforms, CRMs, analytics tools, payment processors, and more.
When a deletion or opt-out DSAR arrives, the controller needs to propagate that request to all relevant processors. TIPA requires that contracts between controllers and processors explicitly outline the processor's obligations in supporting consumer rights requests.
Understanding the clear boundary between controllers and processors determines who is responsible for what when a DSAR touches multiple systems.
A processor that fails to execute a deletion on time is not just an operational problem. It can be the link that creates a compliance gap in an otherwise solid program.
The Tennessee Attorney General has exclusive authority to enforce TIPA. There is no private right of action, meaning individual consumers cannot sue businesses directly under this law.
Before filing an action, the Attorney General must give the business written notice of the violation and provide a 30-day window to cure. If the business cures the violation and provides written documentation of the cure within that window, no action can be filed.
If the business fails to cure, or if the violation is determined to be willful, civil penalties (in Portuguese) can reach up to $7,500 per violation, plus attorney's fees and investigative costs.
The penalty is per violation, not per case. An absent or broken DSAR process affecting thousands of Tennessee consumers can generate thousands of individual violations.
Businesses have two main options for managing DSARs at scale: build a custom internal system or use a purpose-built compliance platform.
Building internally gives full control over the workflow but requires significant development time, ongoing maintenance, and updates every time a regulation changes.
Using a platform like AdOpt handles the cookie consent, consent logging, tracker blocking, and opt-out propagation automatically, leaving your team to focus on the portions of the DSAR process that require human judgment.
The 80/20 principle applies here. A well-configured consent management platform handles most of the compliance infrastructure, so your internal team focuses on what technology cannot automate.
AdOpt logs every consent interaction with the cookie notice on your site. This creates the audit trail that supports DSAR responses and provides documented evidence of a functioning compliance program for the affirmative defense.
When a consumer opts out of targeted advertising, the platform blocks the corresponding trackers automatically. The opt-out is real, immediate, and traceable.
The automatic site scan identifies all active tracking technologies, feeding an accurate picture of what data is being collected and from which sources. This directly supports access and portability requests.
And when regulations change, as they will, the platform updates to maintain compliance without requiring a full reconfiguration.
Over 60,000 sites already operate with AdOpt. From free plans to enterprise-level operations.
Privacy is not a banner. It is a position.
Ready to build a Privacy Portal that actually works under TIPA? Talk to our team.
Two or more secure channels for submitting requests, such as an online form plus a dedicated privacy email address.
Identity verification mechanism proportional to the sensitivity of the data involved in the request.
Plain-language description of each TIPA right, accessible to a consumer with no legal background.
Opt-out mechanism for targeted advertising, integrated with the site's tracker management system.
Opt-out mechanism for data sales, with propagation to partner and integrated systems.
GPC signal compliance, handled at the CMP and cookie notice level.
45-day response deadline monitored and alerted automatically by the system.
Conspicuously available appeal process, with a 60-day response window and information on how to contact the Tennessee Attorney General.
No requirement to create a new account to exercise rights, per TIPA.
Documented record of every DSAR, including authentication evidence, action taken, and response delivered.
Clear statement on minors' data, either that no children's data is intentionally collected or how parental consent is obtained.
Non-discrimination commitment visible to consumers exercising their rights.
Free response guarantee for at least two requests per consumer per year, with documented exception process for excessive requests.
Link to Privacy Portal in the site footer and within the cookie notice.
Documented compliance program aligned with NIST Privacy Framework or ISO 27701 to support the affirmative defense.
1. Does TIPA require a dedicated Privacy Portal?
Not by name. TIPA requires controllers to provide clear and conspicuous mechanisms for consumers to exercise their rights. A dedicated Privacy Portal is the most efficient way to meet this requirement. A combination of a functional privacy email, an online form, and a visible link from the cookie notice can be sufficient for smaller operations.
2. What is the affirmative defense under TIPA and how does it work?
If the business maintains a comprehensive privacy program reasonably conforming to the NIST Privacy Framework or ISO 27701, it can raise that as an affirmative defense in an enforcement action by the Tennessee Attorney General. It does not eliminate liability but significantly reduces regulatory risk.
3. How long does the business have to respond to a DSAR under TIPA?
45 days from receipt of the authenticated request. The deadline can be extended once by 45 additional days when reasonably necessary, with written notice to the consumer. For appeals of denied requests, the window is 60 days.
4. Does TIPA apply to businesses outside Tennessee or outside the United States?
If the business produces products or services targeted at Tennessee residents and meets the volume or revenue thresholds defined by the law, TIPA applies regardless of where the business is incorporated or physically located. The same extraterritorial logic applies to the LGPD (in Portuguese) in Brazil and the GDPR in Europe.
5. What makes TIPA different from other state privacy laws?
Three things stand out. First, the affirmative defense mechanism tied to recognized compliance frameworks like NIST and ISO 27701 is unique among US state privacy laws. Second, TIPA explicitly includes insurance companies in its entity-level exemptions, which sets it apart. Third, the revenue threshold requirement of annual gross revenue exceeding $25 million is combined with the consumer volume thresholds, creating a combined filter that other laws like MTCDPA do not apply.
Privacy is not a banner. It is a position.
A working DSAR process is not just about avoiding fines. It is the system that tells a Tennessee consumer: your data belongs to you. And when you want to know what we have, correct it, or delete it entirely, we will respond. Within the deadline. Without friction.
Ready to structure your Privacy Portal for TIPA compliance? Talk to our team.
What the California CCPA/CPRA requires from your Privacy Policy: 12-month lookback, annual updates, Do Not Sell link, sensitive PI disclosures, toll-free number, and the 7 consumer rights.
What the California CCPA/CPRA requires from your Cookies Policy: Do Not Sell or Share link, GPC compliance, sale vs sharing distinction, sensitive PI opt-out, and annual updates.
What the Connecticut CTDPA requires from your Privacy Policy: active email contact, opt-out link, 15-day consent revocation, opt-out preference signal from January 2025, and teen protections.
Is there an ideal and _foolproof_ Privacy Policy? This is one of the most difficult questions to answer nowadays. Especially considering all the jurisprudence already established in Europe with the GDPR, the extensive history of cases, and the numerous tips we see in the market. Not to mention the judicial decisions that are already emerging in Brazil with the LGPD.
What the Colorado CPA requires from your Privacy Policy: 5 mandatory elements, purpose specification duty, secondary use prohibition, 24-month consent refresh, and Universal Opt-Out Mechanism disclosure.
What the Virginia VCDPA requires from your Privacy Policy: the 5 mandatory content categories, sensitive data obligations, targeted advertising disclosure, and the appeal process explained.
Utah UCPA explained: the most business-friendly US state privacy law, dual threshold requirement, opt-out for sensitive data, no right to correct, guaranteed 30-day cure period, and key differences from other state laws.
What the Oregon OCPA requires from your Cookies Policy: opt-out link, GPC from January 2026, opt-out without authentication, derived data in scope, teen protections, and the elimination of the cure period.
California CPRA DSAR guide: new rights to correct and limit SPI, opt-out without multiple steps, GPC as valid opt-out, 12-month minor rule, private right of action, and CPPA enforcement.
Discover the 5 common **cookie consent mistakes** that risk your **compliance** and learn how to avoid heavy **fines**. Simplify your **data privacy** strategy using a reliable **[Cookie notice/banner](https://goadopt.io/en/blog/why-the-cookie-banner/)**.
Your website have users accessing from Texas? So be ready… the Texas Data Privacy and Security Act is here to shake things up. Don't worry; we've got your back. This guide will walk you through everything you need to know to ensure your website complies with the new regulations.
The Data Protection Officer, or DPO, is a new position that emerged all over the globe with the new privacy regulations, and more recently at the LGPD. Although it already existed in other international legislations, such as the EU's GDPR, it is still a novelty here since 2020. Along with it comes the possibility of outsourcing, known as DPO as a Service (DPOaaS).
What the Connecticut CTDPA requires from your Cookies Policy: opt-out link, opt-out preference signal from January 2025, 15-day consent revocation, teen protections, and targeted advertising definition.
How to handle DSARs under the Virginia VCDPA: consumer rights, 45-day response deadlines, the appeal process, free requests twice per year, and how to build a compliant Privacy Portal.
How to handle DSARs under the Florida FDBR: 7 consumer rights, two required submission channels, 45-day deadline with only 15-day extension, tripled penalties for children, and compliance guide.
What the Iowa ICDPA requires from your Cookies Policy: opt-out for data sales and targeted advertising, opt-out model for sensitive data, no GPC requirement, no specific link text required, and the 90-day cure period.
Rights, Policy and how to understand about the DSAR Montana MTCDPA
Now that we have the data flow within your company, we need to highlight 2 aspects of LGPD that will help you determine the extent of your responsibility in relation to the many points listed in the company. I'm talking about the difference between Data Controller and Data Processor.
Cookies Policy under NHDPA explained. Discover what's mandatory, dark patterns to avoid, and how to implement legal cookie consent.
Everything you need to know about the Virginia Consumer Data Protection Act (VCDPA): who must comply, consumer rights, cookie requirements, penalties, and how to get your site in compliance.
Learn what your TIPA Privacy Policy must include to comply with the Tennessee Information Protection Act from consumer rights and targeted advertising disclosures to the NIST affirmative defense, appeal mechanisms, and how to keep your notice aligned with your operational program.
What the Utah UCPA requires from your Privacy Policy: five mandatory elements, opt-out model for sensitive data, no retention periods required, no active contact channel mandate, and the guaranteed 30-day cure period.
Brazilian LGPD - General Data Protection Law brought with it several acronyms and specific terms. Many of them are imported from other countries and regulations. One of them is ROPA (Record Of Processing Activities), adapted in Brazil to Registros das Atividades de Tratamento. An essential document for any DPO, Data Processor.
How to handle DSARs under the California CCPA/CPRA: 7 consumer rights, 45-day deadline, toll-free number required, 12-month lookback, private right of action for breaches, and CPPA enforcement.
Have you ever noticed that every time you sign up for a service to access information or register on a website for purchases, you need to give consent? If you're wondering why you have to give consent on every website you visit, you'll find the answer here.
Learn what your Privacy Policy must contain under the NHDPA. We break down the 8 mandatory elements and how to comply with New Hampshire's data privacy law.
What the Iowa ICDPA requires from your Privacy Policy: five mandatory elements, 90-day response deadline, 60-day appeal process, opt-out for sensitive data, no retention periods required, and the 90-day cure period.
California CPRA explained: CCPA vs CPRA timeline and key differences, sensitive personal information, sharing of data, CPPA enforcement, GPC requirement, and tripled penalties for minors.
Find out if the MTCDPA applies to your site, key compliance deadlines, and new rules for cookies and consent in Montana
Iowa ICDPA DSAR guide: 90-day response deadline, 45-day extension, 60-day appeal process, limited deletion scope, opt-out from data sales, targeted advertising disclosure requirement, and 90-day cure period.
Utah UCPA DSAR guide: four consumer rights, limited deletion scope, no right to correct, no formal appeal process, no opt-out of profiling, 45-day deadline, and the guaranteed 30-day cure period.
Discover what the New Hampshire Privacy Act (NHDPA) means for your business. Learn about compliance steps, consumer rights, penalties, and how to simplify it all with AdOpt, a Google-certified CMP.
Learn what your MTCDPA Privacy Policy must include after Montana's SB 297 amendments from the conspicuous "privacy" hyperlink and last-updated date requirements to sale disclosures, minor protections, and how to keep your notice operationally aligned with your stack.
What the Oregon OCPA requires from your Privacy Policy: actively monitored contact channel, detailed third-party descriptions, derived data in scope, GPC from January 2026, and the elimination of the cure period.
A privacy policy is a document that outlines how an organization collects, uses, discloses, and manages a customer's data. It's essential for building trust with users and complying with legal requirements. However, if you're not familiar with it, don't worry as we're here to help you.
AdOpt CMP: Google-certified consent platform with prior blocking, granular choices, encrypted logs, and GTM/Consent Mode
If you're looking to understand how this law impacts businesses in Tennessee, especially those dealing with digital cookies, you're in the right place. This article will simplify the complexities of compliance and make them easy to grasp, even if you're just starting to learn about data privacy.
The Texas Data Privacy and Security Act (TDPSA) introduces sweeping changes to how businesses collect, use, and disclose personal data—and your privacy policy is now a frontline compliance tool. This article is a comprehensive guide for any company serving Texas residents, explaining how to align your privacy practices with the new legal standards.
What is a DSAR under NHDPA? Complete guide to consumer rights, response deadlines, and building a compliant Privacy Portal for your site.
What the Virginia VCDPA requires from your Cookies Policy: targeted advertising disclosure, consent standards, tracker categories, opt-out mechanisms, and the 30-day cure period explained.
How to handle DSARs under the Colorado CPA: 5 consumer rights, portability limited to twice per year, Universal Opt-Out Mechanism, 24-month record retention, and District Attorney enforcement.
The Connecticut Data Privacy Act (CTDPA) is a state regulation designed to protect the privacy of Connecticut residents. It also regards cookies, so in this article we will help you understand all about this new privacy regulation.
Everything you need to know about the Florida Digital Bill of Rights (FDBR): who must comply, the $1 billion threshold, 7 consumer rights, FIPA vs FDBR explained, penalties, and cookies.
What the Colorado CPA requires from your Cookies Policy: mandatory Universal Opt-Out Mechanism from July 2024, targeted advertising definition, dark pattern rules, and the 24-month consent refresh.
How do you deal with a profession that didn't even exist a few years ago and is now mandatory in companies? That's precisely the question that arises when we think of the figure of the Data Protection Officer or DPO.
18 May 2026
Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819
15 Rue du Général Campredon, 34000 Montpellier, France
207 Rue de Bercy, 75012 Paris, France
EIN: 86-3965064
Phone: +1 (407) 768-3792
AdOpt
Resources
Product
Certifications