The Tennessee Information Protection Act (TIPA) took effect on July 1, 2025. Tennessee codified the law at Title 47, Chapter 18, Part 33 of the Tennessee Code, and the Tennessee Attorney General is responsible for enforcement.
The law's headline features are familiar to anyone who has worked with Virginia, Colorado, Connecticut, or Texas privacy laws, but the TIPA also includes two unusual elements that change the calculation: a 25 million dollar annual revenue applicability floor and a voluntary affirmative defense for controllers and processors that maintain a written privacy program reasonably aligned with the NIST Privacy Framework.
This page covers one piece of the picture. For the full scope of the TIPA — who must comply, the thresholds, the consumer rights and the penalties — start with our complete guide to the TIPA and cookies.
This article walks you through the TIPA Privacy Policy from end to end. What it must say. How it must be presented. Where it must live. How to keep it current. How to harmonize it with your CCPA, GDPR, and LGPD obligations. How the NIST aligned defense changes the way you write the notice. How to make the public document match the operational reality of your stack.
If your TIPA Privacy Policy is on your roadmap (and if you process data of Tennessee consumers and meet the thresholds, it is, even if you have not put it there), keep reading. We have been doing this kind of work across jurisdictions for years, and the lessons travel.
Note for readers: this article is a sibling to our TIPA Cookies Policy and TIPA DSAR Policy guides. We will link to those where it helps you assemble the full program.Info
A privacy policy, sometimes called a privacy notice, is the public document a controller publishes to tell consumers what personal information is collected, why, who it is shared with, what rights consumers have, and how those rights are exercised. Under the TIPA Privacy Policy rules, that document is not optional, not generic, and not a single sentence buried in the footer.
The TIPA codifies a clear set of expectations for the privacy notice. Specifically, the privacy notice must include:
If you read those requirements quickly, they sound similar to what other state privacy laws require. They are. The trick of a TIPA Privacy Policy is in the specifics: the appeal mechanism, the clear and conspicuous opt out link, and the fact that everything you say in the notice has to be supported by actual operational behavior, especially if you are leaning on the NIST aligned affirmative defense.
Our explainer on what a privacy policy is is a good companion read for anyone who has never written one before. The structure travels well across regimes, and it makes the TIPA Privacy Policy easier to scaffold.
The Tennessee Information Protection Act is a comprehensive consumer privacy law codified at Title 47, Chapter 18, Part 33 of the Tennessee Code. It took effect on July 1, 2025.
Under the TIPA, Tennessee consumers have a familiar set of rights:
Controllers and processors must provide consumers with reasonably accessible means to exercise these rights. The TIPA also imposes responsibilities on controllers and processors: collect only personal information adequate, relevant, and reasonably necessary for the disclosed purposes, secure that data, contract with processors using terms that satisfy the TIPA's processor contract requirements, conduct data protection assessments where high risk processing is involved, and provide an effective opt out mechanism.
For comparison and context, our piece on the GDPR, LGPD, and CCPA walks through how this family of laws compares. The TIPA Privacy Policy lives in the same neighborhood as those.
The TIPA applies to entities that conduct business in Tennessee or produce products or services targeted to Tennessee residents, and that meet all of the following:
If you fit either of the second criteria and clear the 25 million dollar floor, you need a TIPA Privacy Policy that meets the act's requirements.
This applicability framework is unusual among U.S. state privacy laws. Most states do not have a 25 million dollar revenue floor. The TIPA does, which means many small to mid market companies with Tennessee customers are out of TIPA scope while still being in scope under California, Colorado, Connecticut, or Virginia. Your TIPA Privacy Policy scoping question starts with "is our annual revenue above 25 million dollars?" If the answer is no, the TIPA does not apply.
The TIPA also has a specific list of entity exemptions. Government entities, financial institutions subject to GLBA, covered entities and business associates under HIPAA, nonprofits, higher education institutions, and registered insurance companies are excluded. Some data is also exempted (PHI under HIPAA, consumer reports under FCRA, employment data, and so on).
For a comparison with the LGPD on scope thresholds, our explainer is a useful reference. Like the TIPA, the LGPD scopes by data flow and processing volume, just with different cutoffs.
Let us walk through the components a complete TIPA Privacy Policy should contain. Some are explicitly required by the statute. Others are best practice. We will note which is which.
Open with a short, plain language introduction that names the controller, identifies the scope (the products, services, websites, and apps the policy covers), and gives the date the policy was last updated. While the TIPA does not explicitly require the date of last update the way some other state laws do, including it is best practice. It signals that the document is maintained.
The introduction is also where you tell the consumer what they will find in the document. A short table of contents or list of sections helps.
List the categories of personal information the controller processes. The TIPA requires this. Common categories include:
For each category, the TIPA Privacy Policy should disclose the source of the data (collected from the consumer directly, collected from cookies and similar technologies, received from a third party). Our deep dive on data mapping or data inventory walks through how to discover and document those sources reliably.
Tell the consumer where the data comes from. Direct collection (form fills, account creation, transactions, support interactions). Automated collection (cookies, pixels, SDKs, server side telemetry). Third party sources (data enrichment vendors, identity graphs, partners). Be specific enough to be useful, general enough to remain accurate as your stack evolves.
List the purposes for which each category of personal information is processed. The TIPA expects controllers to limit collection and processing to disclosed purposes. The privacy notice is where those purposes are disclosed.
Common purposes:
Be specific enough that a consumer can match the data they share to a reason that data is being processed. Vague purposes ("for legitimate business reasons") are a hallmark of weak privacy notices and a magnet for regulatory scrutiny.
The TIPA Privacy Policy must disclose the categories of third parties with whom personal information is shared. Common categories:
For each category, identify the purpose of sharing. If the sharing constitutes a sale of personal information or processing for targeted advertising, the TIPA Privacy Policy must clearly and conspicuously say so and pair the disclosure with the opt out link.
For more on the legal shape of those relationships, our primer on controller, processor, and the difference between them sets the foundation.
The TIPA Privacy Policy must include a clear and conspicuous link on the controller's website that allows consumers to opt out of the sale of personal information and processing for targeted advertising.
This is where many privacy notices fail. The disclosure is buried in a long paragraph. The opt out method is on a different page, three clicks away. The "Do Not Sell" link is in 9 point gray text. None of that is clear and conspicuous.
Best practice for the TIPA Privacy Policy:
The disclosure has to be honest. If your audit shows that your ad tags share device identifiers with an audience graph for monetary consideration, that is a sale under TIPA's definition, and your TIPA Privacy Policy has to disclose it.
A small TIPA specific nuance: TIPA's sale definition is narrower than California's because it requires monetary consideration, not just "valuable consideration." Some sharing arrangements that count as sales under California may not count as sales under TIPA. Even so, when in doubt, disclose. A broader disclosure than the legal minimum is more defensible than a narrower one.
Under the TIPA, processing of sensitive data requires consent, defined as a freely given, specific, informed, and unambiguous agreement. Sensitive data includes:
Your TIPA Privacy Policy must:
If you do not process sensitive data, say so affirmatively. Consumers and regulators read the absence of a sensitive data section as either a weakness or an oversight.
For the underlying logic of consent, our piece on consent on websites is a useful primer.
The TIPA requires processing of personal information of a known child to be in accordance with the Children's Online Privacy Protection Act (COPPA). That means the COPPA framework (verifiable parental consent, limited data collection, parental access rights) governs the processing.
Your TIPA Privacy Policy should:
The COPPA layer is well established. The TIPA reference makes the COPPA standard the floor for known children's data under TIPA.
This section is the TIPA Privacy Policy counterpart to the law's grant of rights. It should clearly explain:
For each right, the policy should describe how to exercise it, what identity verification is required, and what timeline applies (the TIPA gives 45 days, with the option of a 45 day extension for complex requests, and the controller must respond to an appeal within 60 days).
The TIPA also requires controllers to establish two or more secure and reliable means for consumers to submit a request to exercise their rights, and to take into account the ways consumers normally interact with the controller. That is a real operational requirement. A privacy email address alone is rarely enough.
Our companion article on the TIPA DSAR Policy goes deep on the rights workflow and how to operate it. The disclosures in the TIPA Privacy Policy must align with the workflow you actually run.
The TIPA gives consumers the right to appeal a denied request. Your TIPA Privacy Policy must describe how to appeal, including the channel and the timeline (within a reasonable time of the original decision). Consumers must also be informed of their right to file a complaint with the Tennessee AG if the appeal is denied.
This is more than legalese. A real appeal process protects consumers and protects the controller from regulatory escalation. Build it. Document it. Disclose it.
For each category of personal information, describe how long it is retained. The TIPA expects retention to be limited to what is necessary for the disclosed purposes. Where exact periods are not feasible, describe the criteria used to determine retention.
A common mistake is to write "as long as necessary" and call it done. Pair that phrase with criteria.
Describe the technical and organizational measures the controller takes to protect personal information. Encryption in transit and at rest. Access controls. Logging and monitoring. Incident response. Staff training.
The TIPA expects controllers to establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal information at issue. The TIPA Privacy Policy should reflect this in plain language. If you have a NIST aligned program, this section can summarize the security controls without disclosing sensitive operational detail.
If personal information flows outside the United States, describe the circumstances and the safeguards. The TIPA does not have a GDPR style transfer regime, but if your audience or your data flows touch the EU, GDPR rules apply on top. The TIPA Privacy Policy should be honest about transfers regardless.
For the GDPR side, our deep dive on GDPR cookies and GDPR legal bases covers the mechanics.
Describe how changes are made and how consumers will be notified. While the TIPA does not explicitly require notification of material changes the way some other laws do, best practice is to notify consumers of meaningful updates. A controller relying on the NIST aligned affirmative defense should, in particular, be able to demonstrate that material changes are communicated.
The companion explainer on user notification of terms changes is useful here.
Provide a way for consumers to contact the controller about privacy. Typically:
Make the contact options easy to find and easy to use. The TIPA requires the rights mechanism to be reasonably accessible. The contact information section is part of that.
For the role of the privacy officer, see our explainer on the responsibilities of a data protection officer and the team that supports them.
This is the part of the TIPA Privacy Policy discussion that is unique to Tennessee. The TIPA includes an affirmative defense for controllers and processors that voluntarily create, maintain, and comply with a written privacy program that reasonably conforms to the NIST Privacy Framework or a comparable framework.
For the privacy notice specifically, the NIST defense changes the game in a few ways:
The notice has to be true. The defense is meaningful only if the program described in the notice is actually operating. A notice that overstates the program is worse than a notice that says less but is honest. The notice has to be supported by documentation. The NIST framework's Identify, Govern, Control, Communicate, and Protect functions each map to the notice in some way.
Identify is the data inventory. Govern is the policies and roles described in the notice. Control is the rights and consent mechanisms. Communicate is the notice itself. Protect is the security section. The notice has to reflect a calibrated program. Smaller controllers can have simpler notices supported by simpler programs. Larger controllers need more.
A notice that is consistent with a documented NIST aligned program is the strongest defense a controller can have under TIPA. It also tends to be a clear, well written notice, because the underlying program forces the discipline.
For more on building a privacy program from the ground up, our piece on privacy by design is a useful starting point.
Tone matters more than people think. A privacy notice that sounds like a contract written by lawyers for lawyers will be ignored. A privacy notice that sounds like a friendly explainer will be read.
For your TIPA Privacy Policy, we recommend:
This is one place where a brand's voice can shine through. The same conversational, no nonsense voice that powers a good cookie banner powers a good TIPA Privacy Policy. For inspiration, our piece on why the cookie banner exists covers the underlying philosophy.
A modern TIPA Privacy Policy is rarely one long document. It is layered.
The first layer is the cookie banner or short privacy summary. It tells the consumer the most important things, gives them a chance to act, and links to deeper content.
The second layer is the main privacy notice. It contains all the elements we listed in the anatomy section. It is the document that satisfies the legal requirements.
The detail layer can include supplemental documents: a separate cookies policy, a CCPA notice (if applicable), a children's privacy notice, a candidate privacy notice for the careers site, and so on. These detail documents do not replace the main notice. They complement it.
The TIPA does not require the layered structure, but it allows it, and it is the structure that performs best.
The TIPA requires the privacy notice to be reasonably accessible. That has practical consequences.
For your TIPA Privacy Policy:
The same accessibility rules apply to your cookie banner and preference center. The notice that governs them has to walk the same talk.
The TIPA does not explicitly require multilingual notices, but if your service is offered in multiple languages, the practical and legal expectation is that the privacy notice is too. Translation should be professional, not machine. Privacy terminology has specific meanings that machine translation often gets wrong. A bad translation creates inconsistency between language versions, and inconsistency is a regulatory and trust problem.
If your audience extends to other languages, translate accordingly. The principle is consistency: every consumer should see the same notice in the language they use to interact with the service.
The TIPA does not specify a particular location for the privacy notice, but it requires the notice to be reasonably accessible. In practice that means:
When the consumer is most likely to ask the question, the answer should be one click away.
The "clear and conspicuous" link to the opt out is a TIPA specific requirement. Make it visible and unambiguous.
While the TIPA does not explicitly require notification of material changes, best practice is to notify consumers of meaningful updates. A material change is a substantive change in the policy: new categories of personal information collected, new purposes of processing, new third party recipients, new opt out mechanisms, new sensitive data, or significant changes to consumer rights or contact methods.
In practice:
A controller relying on the NIST aligned affirmative defense should, in particular, be able to demonstrate that material changes are communicated. This is what the framework's Communicate function expects.
A privacy notice on a website is not a privacy program. The notice is the public artifact. The program is what makes the notice true.
The operational layer for a TIPA Privacy Policy includes:
A complete data inventory that maps personal information through the stack, from collection to processing to sharing to retention to deletion. The notice has to reflect what the inventory shows. The discipline of data mapping is the foundation here.
A vendor management function. Every processor and every recipient must be in a documented relationship. Contracts must satisfy the TIPA's processor contract requirements. Vendor changes must trigger a review of the notice.
A consent management platform that captures, stores, propagates, and respects consent state. The notice describes the consent and opt out mechanisms; the platform makes them real. Our CMP guide walks through what to look for.
A rights workflow that handles access, correction, deletion, portability, and opt out requests, with identity verification, timelines, and appeal channels. The notice describes the workflow; the operational team runs it.
A data protection assessment function for high risk processing. Targeted advertising, sale of personal information, processing of sensitive data, and processing involving known children are all candidates for an assessment. The TIPA explicitly requires assessments for these categories. The assessment is internal documentation that proves the controller thought through the risks.
A training and awareness program. Marketing, product, engineering, customer support, sales, and legal each need to know how the privacy program affects their work.
A monitoring and audit function. Quarterly at minimum, the controller should verify that the notice reflects reality and that the operational layer is doing its job.
When all of these are in place, the TIPA Privacy Policy becomes more than words. It becomes the public face of an actual program, and the foundation of the NIST aligned affirmative defense.
Reading a lot of privacy notices, the same mistakes show up over and over. Here are the most common, with their fixes.
Mistake one: copying a CCPA notice and changing the names. California has its own structure, language, and rights set. Some of the language carries over to Tennessee, but the TIPA Privacy Policy has its own specifics (the appeal mechanism, the clear and conspicuous opt out link, the narrower sale definition). Adapt, do not copy.
Mistake two: vague purposes. "We process personal information for legitimate business purposes" is not a purpose. Be specific.
Mistake three: no rights section. Every required right must be listed, with a description of how to exercise it. Skipping a right is a violation.
Mistake four: opt out hidden. The opt out link must be clear and conspicuous and paired with the disclosure. A footer link in tiny gray is not.
Mistake five: no appeal process. TIPA requires an appeal mechanism. Skipping it is a structural defect.
Mistake six: no NIST alignment. The affirmative defense is voluntary, but for a controller in TIPA scope, declining the defense is leaving real value on the table.
Mistake seven: no accessibility. Screen reader, keyboard navigation, and contrast all matter. A PDF only notice is a problem.
Mistake eight: stale notice. Notices that have not been touched in years almost always misrepresent current practice. Quarterly review at minimum.
Mistake nine: misuse of "necessary" or "legitimate interest." These words have specific meanings and cannot be used to bless any processing the controller wants to do. Map them carefully.
Mistake ten: no operational alignment. The notice describes what the program does. If the program does not do it, the notice is materially false. Build the program first.
The best counter to most of these is a healthy program. Our piece on ignoring the law is a sober reminder of what happens when programs are absent.
The TIPA grants the Tennessee Attorney General exclusive enforcement authority. There is no private right of action.
Enforcement actions can result in:
A few details specific to TIPA:
The 60 day cure period is a meaningful protection. If the AG sends a notice, the controller has 60 days to cure. The cure period is permanent under TIPA, not sunset. The treble damages provision is a real escalation.
Willful violations can be punished at three times the actual damages. The NIST aligned affirmative defense is a real protection. A controller with a documented program that reasonably conforms to NIST has a defense, regardless of whether the violation was technically cured.
For a comparative view of how privacy fines work in practice, our piece on fines under the LGPD is a useful reference.
If you operate at scale, you almost certainly publish more than one privacy notice today. A general privacy notice. A CCPA specific notice (often a separate addendum or page). A GDPR notice for European audiences. An employee or candidate privacy notice. A children's privacy notice if you serve children.
The TIPA Privacy Policy can either be a separate Tennessee specific notice or a section within a larger U.S. or global notice. Both approaches are acceptable as long as the TIPA specific requirements are met.
We generally prefer a single comprehensive notice that includes Tennessee specific disclosures clearly labeled. It is easier for consumers to read, easier for the controller to maintain, and easier to keep consistent.
If you do publish a separate Tennessee notice, link to it from the homepage and from any other place where Tennessee specific disclosures matter. Consistency between the global and the state specific notice is non negotiable.
A defensible TIPA Privacy Policy is the natural output of a privacy by design culture. When privacy is considered at the design phase of every feature, every campaign, and every vendor decision, the privacy notice almost writes itself.
Privacy by design principles applied to the notice:
The teams that approach the TIPA Privacy Policy as a privacy by design exercise tend to produce notices that are shorter, clearer, and easier to defend.
To make this concrete, here is the workflow we use at AdOpt to draft a TIPA Privacy Policy for a client.
Discovery. We sit with the client, walk the product surfaces, identify all the places personal information is collected, and map the categories. We pull from the existing privacy notice, terms of use, vendor list, and tag inventory.
Inventory. We build (or refresh) the data inventory. Categories, sources, purposes, recipients, retention, sensitive data flags, known child flags. The inventory is the source of truth for the notice.
Outline. We draft an outline that covers all the TIPA required elements: rights, appeal, sale and targeted advertising disclosures with paired opt out, sensitive data, children, contact, NIST alignment. We also map each section of the notice to the relevant NIST function so the affirmative defense documentation is integrated.
First draft. We write a plain language draft that follows the outline. Short sentences. Active voice. Concrete examples.
Review. Legal reviews for accuracy and completeness. Marketing reviews for tone. Engineering reviews for technical accuracy. Customer support reviews for usability.
Operational alignment. We confirm that every claim in the draft matches the operational reality. Anything that does not match either changes in the draft or triggers operational work.
Accessibility check. We test with screen readers and keyboard navigation. We check contrast and font size. We make sure the document renders well across devices.
Translation. We translate into every language in which the service is offered. Professional translation, not machine.
Publication. We publish to the site, place a clear and conspicuous link to the opt out, link from the banner and the preference center, and update the "last updated" date.
NIST documentation. We update the affirmative defense documentation to reflect the new notice and the underlying controls.
Audit trail. We document the draft, the reviews, the approvals, and the publication. The next time someone asks how the TIPA Privacy Policy was developed, we have a paper trail.
Cadence. We add the notice to a quarterly review cadence. Anything that changes in the inventory or the operational layer triggers a review.
This workflow takes weeks, not days. That is normal. A real TIPA Privacy Policy is not produced in a sprint.
Imagine a national SaaS company with 75 million dollars in annual revenue, 250,000 Tennessee users, and a typical B2C product. The company runs content marketing, a freemium model, and an ad supported tier. It uses Google Analytics, Mixpanel, Meta Pixel, Google Ads, HubSpot, Intercom, Stripe, Sentry, Hotjar, and a dozen other vendors.
Before TIPA, the company has a generic CCPA notice that mentions Tennessee in a state law section. The notice lists three rights, mentions cookies in passing, and has no explicit opt out for targeted advertising. The "Privacy" link in the footer is small. The notice has not been updated in 18 months. There is no NIST aligned documentation.
Walking through the TIPA Privacy Policy workflow with this company surfaces:
The 250,000 Tennessee users put the company well over the 175,000 consumer threshold. The 75 million dollars in annual revenue clears the 25 million dollar floor. The company is in TIPA scope.
The notice does not include an explicit opt out for targeted advertising paired with a clear and conspicuous link. TIPA requires it. Gap.
The notice does not include an appeal mechanism. TIPA requires it. Gap.
The Meta Pixel and Google Ads integrations result in sale of personal information (where monetary consideration applies) and targeted advertising. The notice does not disclose this clearly and conspicuously. Gap.
The "Privacy" hyperlink in the footer is in 9 point gray text. Not reasonably accessible. Gap.
The notice is not available in Spanish, even though the product is offered in Spanish. Practical gap.
The notice does not address known children, even though the freemium tier has known users in the 13 to 17 range. Gap.
There is no NIST aligned documentation. The affirmative defense is unavailable.
After a four week engagement, the company has a new TIPA Privacy Policy that addresses each gap. The footer link is rebuilt. The Spanish version is published. The opt out for targeted advertising is in line with the disclosure, with a clear and conspicuous link to the preference center. The appeal mechanism is documented and operationalized. The NIST aligned program is documented with controls mapped to each function.
The company is now defensible. Not perfect, because nothing is, but defensible. And the workflow for keeping it that way is documented.
For a story driven take on what happens to companies that skip this kind of work, our piece on a company that got fined is worth a read.
Marketing teams are often nervous about privacy notices because they read like restrictions. The right reading is that the notice is a description of what you can do, written carefully to reflect what you are actually doing. A clean TIPA Privacy Policy removes ambiguity. Marketing knows what is in scope and what is not, and the rest follows.
For a deeper take on adapting marketing under modern privacy law, our explainer on adapting digital marketing covers the operational shifts. The piece on risky processes in marketing lists the specific behaviors that turn into privacy problems.
The TIPA Privacy Policy is also a marketing asset. A clean, well written notice signals to consumers that the brand cares. Trust is a competitive advantage. Brands that have invested in transparent privacy practices have, in study after study, higher engagement and lower churn.
For more on the agency side of marketing under privacy law, our piece on agencies and privacy compliance is a good read.
The TIPA Privacy Policy has to address cookies, but it does not have to do it alone. A common pattern is to have a dedicated cookies policy (linked from the privacy notice and from the cookie banner) that handles the granular detail, while the privacy notice covers the conceptual framing.
Both documents are subject to the TIPA's requirements. The privacy notice is the umbrella. The cookies policy is the specific application of the umbrella to cookies and similar technologies.
If you want the deep dive on cookies under Tennessee law, our companion article on the TIPA Cookies Policy walks through every detail.
For broader context on cookies and privacy law, our deep dive on cookies and privacy and on the cookie banner cover the underlying ideas.
The TIPA grants consumers rights to access, correct, delete, port, and opt out of certain processing. The TIPA Privacy Policy must describe these rights and how to exercise them. The actual handling of the requests is a workflow, not a document.
Our companion article on the TIPA DSAR Policy walks through the workflow in detail. A few highlights for the privacy notice:
The notice and the workflow have to match. A notice that promises a 30 day response while the workflow takes 60 is non compliant by misrepresentation.
For more on the DPO and team that operates the rights workflow, our explainer is useful.
The TIPA does not have a GDPR style "records of processing activities" obligation by name, but it expects controllers to be able to demonstrate compliance, conduct data protection assessments for high risk processing, and document the operations of the program. The NIST aligned affirmative defense, in particular, is built on documentation.
The internal records that support the TIPA Privacy Policy typically include:
For a primer on the discipline of records of processing, our piece on ROPA for LGPD is a good cross reference.
The TIPA does not have a regulatory body the way the LGPD has the ANPD or the GDPR has the EDPB. Enforcement comes from the Tennessee Attorney General. The Tennessee AG's Office has issued some guidance and tips for businesses and consumers on the TIPA, but there is no formal guidance issuing body that publishes opinions on cookies, privacy notices, and DSARs.
That said, controllers can still draw on guidance from analogous regulators when designing the TIPA Privacy Policy. The ANPD has published orientative guidance on cookies and personal data protection that the Tennessee AG would likely consider sensible. The European Data Protection Board has published similar guidance for the GDPR. Building toward that bar is a way to future proof the TIPA Privacy Policy against tighter U.S. interpretations down the road.
To make this practical, here are a few plain language examples of how sections of a TIPA Privacy Policy can read.
Example: introduction.
"This notice describes how [Company] collects and uses personal information when you visit our website, use our app, or interact with us. It applies to consumers in the United States, including residents of Tennessee. We last updated this notice on [date]. If you only want the highlights, the summary at the top of this page covers them. If you want the full picture, read on."Info
Example: rights.
Example: targeted advertising disclosure.
"We use cookies, pixels, and similar technologies that allow third party advertising partners to show you ads on other websites based on your activity on ours. The Tennessee Information Protection Act calls this 'targeted advertising,' and you have the right to opt out. To opt out, [click here] or use the preference center. If you visit from a browser that sends a Global Privacy Control signal, we will treat that as an opt out automatically."Info
These examples are short, plain, and concrete. A reader knows what is happening and what they can do about it. That is the bar.
The TIPA expects controllers to conduct data protection assessments for processing activities that present a heightened risk of harm. The categories that trigger an assessment include processing for targeted advertising, sale of personal information, processing of sensitive data, and processing of personal information for purposes of profiling that presents a reasonably foreseeable risk of unfair or deceptive treatment, financial or physical injury, or other substantial injury.
The assessment itself is an internal document. The TIPA Privacy Policy does not need to publish the contents of the assessment, but the notice should reflect the conclusions. If the assessment determines that a particular processing activity should be opt in rather than opt out, the notice has to describe that opt in mechanism. If the assessment identifies safeguards, the notice has to describe those safeguards.
The TIPA AG can request a copy of an assessment in connection with an investigation. That is another reason to keep the assessments well documented and aligned with the notice.
For more on the discipline of risk assessments and the data protection officer that oversees them, our explainer on the responsibilities of a DPO is a useful starting point.
A small but valuable practice: maintain a change log for the TIPA Privacy Policy. Each material change gets a dated entry that summarizes the change, the reason, and the effective date. The change log can live at the bottom of the notice or on a separate page linked from the notice.
The change log serves three purposes. First, it provides a clean record for consumers to understand what changed. Second, it gives regulators (and your own legal team) a clear paper trail of how the notice has evolved. Third, it ties into the NIST framework's Communicate function as evidence of the controller's commitment to transparency.
For high traffic sites, we recommend keeping the last several versions of the notice in an archive. If a consumer signed up under an earlier version and is asking about their rights at that time, you have the answer.
The TIPA includes inferences within the broad understanding of personal information. An inference is a derived data point, drawn from observed behavior, that says something about the consumer (interests, propensity to buy, demographic segment, lookalike score, lifetime value prediction).
For your TIPA Privacy Policy, inferences require their own attention:
Inferences are personal information and need the same disclosure as raw data. The notice should call them out as a category. Inferences feed targeted advertising, profiling, and personalization. The notice should describe how inferences are used in each of these activities. Inferences are subject to the same rights as raw data. If a consumer requests deletion, the inferences derived from their data should also be deleted (or at least disconnected from them).
The inference category is one of the most underdisclosed pieces of typical privacy notices. Cleaning it up under the TIPA Privacy Policy is a useful forcing function for the rest of the program.
Many controllers run identity resolution systems that match consumers across devices, sessions, and channels. These systems often use first party data (login state, email address, phone number) to maintain a unified identity. The TIPA does not prohibit identity resolution, but it does expect honest disclosure.
Your TIPA Privacy Policy should describe:
That the controller maintains a unified identity for each consumer (where it does). The categories of data used to resolve the identity. The purposes for which the unified identity is used (analytics, personalization, advertising, customer service). The consumer rights that apply to the unified identity (access to the merged record, correction, deletion, opt out).
This area gets technical fast. Engineering teams often think of identity resolution as plumbing. From a privacy perspective, it is also a substantive data flow.
The TIPA defines "consumer" in a way that excludes individuals acting in a commercial or employment context. That means a B2B contact (a buyer at a customer organization) is not a consumer for TIPA purposes. An employee or contractor is also not a consumer for TIPA purposes.
Practically, this matters for SaaS companies and services with mixed audiences. If your service has both consumer users and B2B users, the TIPA Privacy Policy should be clear about which protections apply to which group. A common pattern is to publish a comprehensive notice that addresses consumer rights, with a separate note explaining that B2B contacts and employees are scoped under different documents.
Be careful with the line between B2B and consumer. A solo professional who buys a product for personal and business use blurs the line. The conservative posture is to treat the data as consumer data unless the context is unambiguously commercial.
We will close with a brief tour of how AdOpt works with clients on the TIPA Privacy Policy specifically.
We start with a discovery sprint. Two to four weeks, depending on complexity. We map the data, inventory the cookies and vendors, review the existing notice, and identify gaps against the TIPA requirements.
We draft the notice. Plain language, structured the way consumers actually read, with the TIPA specific elements clearly addressed. We work with your legal team to validate the disclosures and with your marketing team to validate the tone.
We deploy the technical layer. The CMP, the preference center, the rights workflow, the consent state propagation, the universal opt out detection (best practice). The notice describes what the technical layer does. The technical layer makes the notice true.
We build the NIST aligned documentation. Each function (Identify, Govern, Control, Communicate, Protect) is mapped to your program with evidence of operation. This is what gives you the affirmative defense.
We train the team. Marketing, product, engineering, customer support, sales, and legal each get a briefing tailored to their role.
We set up the maintenance cadence. Quarterly review, material change triggers, and an audit calendar.
The clients who work with us tend to find that the TIPA rollout is less painful than they expected, mostly because we have done it before. The work scales. The framework holds up across other state laws. The investment pays back.
To make this fully concrete, here is a skeleton outline that a TIPA Privacy Policy can follow. Use it as a starting point and adapt to your stack.
This outline is more comprehensive than a minimum compliance notice, but it sets you up for cross state durability and consumer readability. The TIPA Privacy Policy sections (or addendum, if you go that route) can plug into this skeleton without rewriting the whole document.
Most U.S. businesses cannot afford to maintain a separate privacy program for every state. The smart pattern is to harmonize across the comprehensive consumer privacy law family and treat state specifics as deltas on top of a shared baseline.
For your TIPA Privacy Policy, the harmonization approach looks like this:
Build the baseline notice using the strongest set of expectations across the comprehensive state laws. That usually means honoring the most demanding right (often access or portability), the broadest sensitive data category, the strictest minor protection, and the most prominent opt out display. Add state specific deltas where the law diverges.
Tennessee's revenue floor and NIST aligned defense are deltas. California's "Do Not Sell or Share My Personal Information" and "Limit Use of Sensitive Personal Information" are deltas. Colorado's universal opt out signal mandate is a delta. Maintain a single internal source of truth (the data inventory and the program documentation) so the deltas can be derived rather than maintained by hand.
This approach scales. Each new state law is an incremental delta, not a from scratch rebuild. The TIPA Privacy Policy plugs into the same framework that handles California, Colorado, Connecticut, Virginia, Texas, Montana, Oregon, Delaware, and the rest of the patchwork.
For a comparative read on the key differences between LGPD and GDPR, our explainer is a good model. The same exercise applied to U.S. state laws produces a manageable list of deltas.
There is a piece of all this we have only touched on indirectly: customer trust. Privacy notices are not just compliance artifacts. They are signals to the consumer about the brand's posture. Brands that publish honest, plain language privacy notices earn more trust, and trust is a hard to fake competitive advantage.
The TIPA Privacy Policy is, in this sense, a marketing document as much as a legal document. It is read by potential customers, by procurement teams at enterprise prospects, by journalists writing about the brand, by competitors looking for weakness, and by regulators looking for liability.
Brands that get this right tend to invest in the notice the way they invest in the homepage. Plain language. Real examples. Visual structure. Tone that matches the brand. The result is a notice that consumers actually read and respect.
Brands that get this wrong copy a template, paste it into a footer link, and forget about it. The notice contradicts the product. The product contradicts the promise. The promise erodes trust. And eventually, a regulator notices.
Investing in the notice is not a charity. It is a return on investment.
A defensible TIPA Privacy Policy is the work of more than one team. The notice describes what the program does, and the program is operated by people across the organization.
The privacy officer or DPO owns the notice content, the legal interpretation, and the alignment with regulatory obligations. They write or review the draft, approve material changes, and sign off on the final version.
The legal team reviews the notice for accuracy and consistency with contracts, terms of use, and regulatory positions.
The marketing team reviews the notice for tone, for alignment with marketing operations, and for clarity of disclosures around advertising and analytics.
The engineering team validates that the technical layer (CMP, tag manager, rights workflow, consent state propagation) supports the notice's claims.
The product team validates that the user experience reflected in the notice is what the product actually delivers.
The customer support team validates that the contact and rights mechanisms described in the notice are what they actually handle.
The security team validates the security claims in the notice.
When all of these are aligned, the TIPA Privacy Policy is defensible. When they are not, the notice contains claims that nobody operationally supports, and that is where compliance failures hide.
For more on the DPO and the team that supports them, our explainer is a useful reference.
The first version of a TIPA Privacy Policy does not have to be perfect. It has to be honest, complete, and aligned with the operational program. Once it is published, the next steps are iteration: testing readability with real consumers, cleaning up areas where the language is fuzzy, adjusting as the program evolves.
Treat the privacy notice the way a product team treats a landing page. Measure how consumers interact with it. Measure how often consumers contact privacy support. Measure DSAR volume and nature. Where the data shows misunderstanding, refine the notice. Where the data shows the program needs adjustment, adjust the program.
The TIPA Privacy Policy is a living document. The teams that treat it that way build trust over time. The teams that treat it as a one time deliverable lose ground. The discipline pays back.
A defensible TIPA Privacy Policy is not a single document. It is a discipline. It pairs honest disclosures with an operational program that makes the disclosures true. It updates on a cadence. It aligns with the NIST Privacy Framework so the affirmative defense is real. It listens to the consumer. It survives regulatory scrutiny because it has nothing to hide.
The teams that build this kind of policy find that the work pays back across the entire privacy program. The work done for Tennessee flows into California, Colorado, Connecticut, Virginia, Texas, Montana, and the rest of the patchwork. The work done for the U.S. flows into the EU and Brazil. Privacy compliance is not a state by state expense; it is a portfolio investment.
If you are starting fresh or refreshing a stale notice, the AdOpt team has done this hundreds of times. We bring the templates, the workflows, the technology, and the patience to do it well. We would love to help.
Yes, but only if you exceed 25 million dollars in annual revenue and meet one of the consumer thresholds (175,000 Tennessee consumers in a calendar year, or 25,000 Tennessee consumers plus more than 50 percent of gross revenue from sale of personal information).
The TIPA applies to entities that conduct business in Tennessee or produce products or services targeted to Tennessee residents who meet those criteria. A physical Tennessee office is not required. The 25 million dollar revenue floor is the most important filter; many smaller companies are out of TIPA scope even if they are in scope under California or Colorado.
The TIPA includes a unique provision: controllers and processors that voluntarily create, maintain, and comply with a written privacy program reasonably aligned with the NIST Privacy Framework (or a comparable framework) can use that program as an affirmative defense in a TIPA enforcement action.
It is voluntary. But for a controller that is in TIPA scope, the defense is a meaningful strategic asset. We recommend aligning with NIST and documenting the alignment. The work also strengthens your posture across other state laws and global regimes.
The TIPA gives consumers the right to appeal a denied request. Your privacy notice must describe the appeal channel and the timeline. The controller must respond to the appeal within 60 days of receipt, and if the appeal is denied, the controller must inform the consumer of how to file a complaint with the Tennessee Attorney General. A real appeal process is not a formality; it is the safety valve that keeps the program honest.
The TIPA's definition of "sale of personal information" requires monetary consideration, not the broader "valuable consideration" used in California. That means some sharing arrangements that count as sales under California may not count as sales under TIPA.
In practice, the safe path is to disclose all sharing that involves any value exchange, even if it does not technically meet the TIPA's monetary threshold. A broader disclosure than the legal minimum is more defensible than a narrower one, and it protects you across multiple state laws at once.
That is a structural compliance problem. The notice is supposed to describe what the program does. If the program is doing something different (sharing more data than disclosed, retaining longer than disclosed, using sensitive data without consent), the notice is materially false.
The Tennessee AG can pursue civil penalties up to 7,500 dollars per violation, plus treble damages for willful violations, plus injunctive relief and attorney fees. The 60 day cure period is available for fixable violations, but a pattern of misrepresentation is unlikely to be cured by a quick edit. The fix is to keep the notice and the program aligned through quarterly review and a clear material change notification process.
If you got this far, you have a sense of what a real TIPA Privacy Policy looks like. It is not a paragraph in the footer.
It is the public face of a working privacy program, anchored in honest disclosures, supported by an operational layer, refreshed on a cadence, and aligned with the NIST Privacy Framework so the affirmative defense is real. It takes work to build. It pays back across every other state law and every other jurisdiction your business touches.
AdOpt builds and maintains this kind of program for hundreds of brands across the U.S., Brazil, and Europe. We bring the templates, the technology, and the team. We adapt to your stack, your audience, and your timeline.
Schedule a demo with the AdOpt team and we will walk through your current privacy notice, your data inventory, and your Tennessee exposure. You will leave with a clear plan, with or without us. Better to know than to guess. The Tennessee AG is not in the guessing business, and neither should you be.
Discover the 5 common **cookie consent mistakes** that risk your **compliance** and learn how to avoid heavy **fines**. Simplify your **data privacy** strategy using a reliable **[Cookie notice/banner](https://goadopt.io/en/blog/why-the-cookie-banner/)**.
What the Connecticut CTDPA requires from your Cookies Policy: opt-out link, opt-out preference signal from January 2025, 15-day consent revocation, teen protections, and targeted advertising definition.
How does your website handle LGPD? What strategies does it use to comply with the General Data Protection Law? Have you thought about using a cookie notice but don't know if your site has cookies or if it's enough? If you can't answer these questions, be cautious! Your page may be exposed to fines and other sanctions.
LGPD is in effect. Despite that, there are still many companies ignoring it, but is that possible? How long can we ignore LGPD?
How to handle DSARs under the California CCPA/CPRA: 7 consumer rights, 45-day deadline, toll-free number required, 12-month lookback, private right of action for breaches, and CPPA enforcement.
Have you ever noticed that every time you sign up for a service to access information or register on a website for purchases, you need to give consent? If you're wondering why you have to give consent on every website you visit, you'll find the answer here.
Learn what your Privacy Policy must contain under the NHDPA. We break down the 8 mandatory elements and how to comply with New Hampshire's data privacy law.
Having a cookie banner on your brand's website has become indispensable for many. However, for e-commerce websites, it has practically become an obligation to have one. This is because this type of website has a technological composition in which cookies are a structural part. Login flow, items in the shopping cart, recommendation showcases, remarketing... Most of them rely on cookies.
California CPRA explained: CCPA vs CPRA timeline and key differences, sensitive personal information, sharing of data, CPPA enforcement, GPC requirement, and tripled penalties for minors.
Find out if the MTCDPA applies to your site, key compliance deadlines, and new rules for cookies and consent in Montana
Iowa ICDPA DSAR guide: 90-day response deadline, 45-day extension, 60-day appeal process, limited deletion scope, opt-out from data sales, targeted advertising disclosure requirement, and 90-day cure period.
Utah UCPA DSAR guide: four consumer rights, limited deletion scope, no right to correct, no formal appeal process, no opt-out of profiling, 45-day deadline, and the guaranteed 30-day cure period.
Learn what your MTCDPA Privacy Policy must include after Montana's SB 297 amendments from the conspicuous "privacy" hyperlink and last-updated date requirements to sale disclosures, minor protections, and how to keep your notice operationally aligned with your stack.
A privacy policy is a document that outlines how an organization collects, uses, discloses, and manages a customer's data. It's essential for building trust with users and complying with legal requirements. However, if you're not familiar with it, don't worry as we're here to help you.
Here is a step-by-step explanation of how consent registration works in AdOpt.
The Texas Data Privacy and Security Act (TDPSA) introduces sweeping changes to how businesses collect, use, and disclose personal data—and your privacy policy is now a frontline compliance tool. This article is a comprehensive guide for any company serving Texas residents, explaining how to align your privacy practices with the new legal standards.
What is a DSAR under NHDPA? Complete guide to consumer rights, response deadlines, and building a compliant Privacy Portal for your site.
Learn how to build a defensible TIPA Cookies Policy for Tennessee compliance covering consent architecture, opt-out requirements, the NIST affirmative defense, and how your cookie banner, privacy notice, and vendor management must work together under the Tennessee Information Protection Act.
The Connecticut Data Privacy Act (CTDPA) is a state regulation designed to protect the privacy of Connecticut residents. It also regards cookies, so in this article we will help you understand all about this new privacy regulation.
Everything you need to know about the Florida Digital Bill of Rights (FDBR): who must comply, the $1 billion threshold, 7 consumer rights, FIPA vs FDBR explained, penalties, and cookies.
What the Colorado CPA requires from your Cookies Policy: mandatory Universal Opt-Out Mechanism from July 2024, targeted advertising definition, dark pattern rules, and the 24-month consent refresh.
Everything about the Oregon OCPA: who must comply, the payment transaction exclusion, 25% revenue threshold, derived data in scope, GPC requirement from January 2026, and elimination of the cure period.
What the California CPRA requires from your Privacy Policy: SPI category, two mandatory links, data retention periods, sharing disclosure, right to correct, GPC, and minor protections.
What the Florida FDBR requires from your Cookies Policy: targeted advertising across affiliated sites, opt-out for sensitive data and voice recognition, dark patterns, and tripled penalties.
Google Consent Mode (GCM) is nothing more than a way for you to integrate the consent you collect from your visitors into Google technologies. In this way, upon receiving this consent information, collection can only occur with authorization, thus complying with the legislation and having direct evidence of compliance as defense for both you and Google.
Learn how to build a TIPA-compliant Privacy Portal for Tennessee. Understand DSAR deadlines, consumer rights, opt-out mechanisms, and the affirmative defense that sets TIPA apart from every other US state privacy law.
The Colorado Consumer Privacy Act went into effect July 1, 2023 (CPA). CPA is a vital piece of legislation designed to protect the privacy of residents in Colorado. Understanding its requirements is essential for any business operating in the state. This act is all about giving control back to the consumers regarding their personal data. But what does this mean for you and your business, especially when it comes to managing cookies on your website?
What the Florida FDBR requires from your Privacy Policy: annual updates, 6 mandatory content categories, specific notices for sensitive and biometric data sales, and the 7 consumer rights.
What the California CCPA/CPRA requires from your Privacy Policy: 12-month lookback, annual updates, Do Not Sell link, sensitive PI disclosures, toll-free number, and the 7 consumer rights.
What the Connecticut CTDPA requires from your Privacy Policy: active email contact, opt-out link, 15-day consent revocation, opt-out preference signal from January 2025, and teen protections.
What the Colorado CPA requires from your Privacy Policy: 5 mandatory elements, purpose specification duty, secondary use prohibition, 24-month consent refresh, and Universal Opt-Out Mechanism disclosure.
Utah UCPA explained: the most business-friendly US state privacy law, dual threshold requirement, opt-out for sensitive data, no right to correct, guaranteed 30-day cure period, and key differences from other state laws.
What the Oregon OCPA requires from your Cookies Policy: opt-out link, GPC from January 2026, opt-out without authentication, derived data in scope, teen protections, and the elimination of the cure period.
California CPRA DSAR guide: new rights to correct and limit SPI, opt-out without multiple steps, GPC as valid opt-out, 12-month minor rule, private right of action, and CPPA enforcement.
Your website have users accessing from Texas? So be ready… the Texas Data Privacy and Security Act is here to shake things up. Don't worry; we've got your back. This guide will walk you through everything you need to know to ensure your website complies with the new regulations.
How to handle DSARs under the Virginia VCDPA: consumer rights, 45-day response deadlines, the appeal process, free requests twice per year, and how to build a compliant Privacy Portal.
How to handle DSARs under the Florida FDBR: 7 consumer rights, two required submission channels, 45-day deadline with only 15-day extension, tripled penalties for children, and compliance guide.
What the Iowa ICDPA requires from your Cookies Policy: opt-out for data sales and targeted advertising, opt-out model for sensitive data, no GPC requirement, no specific link text required, and the 90-day cure period.
It's time to talk about one of the most impactful tasks, both for the company and for the visitors of your websites: tag categorization. But why is it so impactful? What is the relevance of this configuration and how can it affect us? It is precisely because of these common questions we receive from our clients that we have written this article on best practices in tag categorization.
Rights, Policy and how to understand about the DSAR Montana MTCDPA
What the California CPRA requires from your Cookies Policy: the sharing concept, GPC as valid opt-out, Do Not Sell or Share link, SPI geolocation, minor protections, and retention periods.
What are the criteria for this choice, and what are the strengths and weaknesses of each option? Well, we're here to help you because this decision needs to be well thought out!
Cookies Policy under NHDPA explained. Discover what's mandatory, dark patterns to avoid, and how to implement legal cookie consent.
Everything you need to know about the Virginia Consumer Data Protection Act (VCDPA): who must comply, consumer rights, cookie requirements, penalties, and how to get your site in compliance.
What the Utah UCPA requires from your Privacy Policy: five mandatory elements, opt-out model for sensitive data, no retention periods required, no active contact channel mandate, and the guaranteed 30-day cure period.
27 Apr 2026
Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819
15 Rue du Général Campredon, 34000 Montpellier, France
207 Rue de Bercy, 75012 Paris, France
EIN: 86-3965064
Phone: +1 (407) 768-3792
AdOpt
Resources
Product
Certifications