If your business handles personal data from Tennessee residents, this article is for you.
The Tennessee Information Protection Act (TIPA) took effect on July 1, 2025. It is one of the most detailed state privacy laws in the United States, with some features that set it apart from every other state-level regulation currently in force.
This guide covers everything you need to know: who must comply, what the key definitions mean, how consumer rights work, what cookies have to do with all of this, and how to prepare your business for compliance without losing your mind.
TIPA was enacted in May 2023 and took effect on July 1, 2025. Businesses had over two years to prepare.
The Tennessee Information Protection Act (Tenn. Code Ann. § 47-18-3201 et seq.) is a state data privacy law that gives Tennessee residents specific rights over their personal data and imposes clear obligations on businesses that collect and process it.
Think of it as the rules of the road for how companies handle personal information in Tennessee. If you drive in their state, you follow their rules. If you handle data from their residents, you follow TIPA.
TIPA applies to entities that conduct business in Tennessee or produce products or services targeted at Tennessee residents, with annual gross revenue exceeding $25 million, and that during a calendar year meet at least one of the following criteria:
Control or process personal data of at least 175,000 consumers, or
Control or process personal data of at least 25,000 consumers and derive more than 50% of gross revenue from the sale of personal data.
Both conditions must be present: the revenue threshold and at least one of the consumer volume thresholds. This combined filter means smaller businesses with high revenue from data sales are still covered, and large data processors with lower revenue may fall outside the scope.
Several categories of entities and types of data are exempt from TIPA:
State agencies and political subdivisions.
Financial institutions governed by the Gramm-Leach-Bliley Act.
Insurance companies, which is a notable distinction from most other state privacy laws.
Entities governed by HIPAA and HITECH.
Nonprofit organizations.
Institutions of higher education.
De-identified data is explicitly excluded from the definition of personal data under TIPA.
Data processed for journalistic, academic, or literary purposes may also be exempt, recognizing the balance between privacy and freedom of expression.
Any data that can be used on its own or in combination with other data to identify, contact, or locate a person. This includes names, email addresses, phone numbers, IP addresses, and other digital identifiers. The definition is intentionally broad to ensure any information that can trace back to an individual is covered.
A natural person who is a resident of Tennessee acting only in an individual or household context. This definition explicitly excludes individuals acting in a commercial or employment context, which affects how businesses filter incoming requests.
Consent under TIPA must be a clear affirmative act. It cannot be assumed or implied. A user must take a deliberate and unambiguous action, such as clicking an "I agree" button, to indicate they agree to their data being processed. Pre-checked boxes and passive browsing do not qualify.
Sensitive data refers to a specific category of personal information that requires heightened protection due to the risk of harm if misused. Under TIPA, this includes:
Racial or ethnic origin, religious beliefs, mental or physical health diagnoses, sexual orientation or sex life, citizenship or immigration status.
Genetic or biometric data processed to uniquely identify an individual.
Precise geolocation data.
Personal data of a known child under 13.
Financial information, social security numbers, and similar high-risk identifiers.
The main decision-maker regarding personal data. The controller determines the purpose and means of processing. If your company decides what to do with the data it collects, it is a controller under TIPA. This role carries the primary compliance responsibilities.
Any person or entity that processes personal data on behalf of a controller, following their instructions. Processors do not make decisions about how the data is used. A contract between the controller and processor must explicitly define the processor's obligations.
The transfer of personal information to a third party for monetary or other valuable consideration. This definition directly affects businesses that share data with advertising partners, data brokers, or other commercial parties.
Displaying ads customized based on personal data derived from an individual's activities over time and across non-affiliated websites or applications. TIPA requires informed consent for this type of processing and gives consumers the right to opt out of it.
Cookies are small text files placed on a user's device when they visit a website. They power everything from session memory and login persistence to behavioral tracking and personalized advertising.
Under TIPA, cookies that store personal information or enable user identification must be handled with care. Businesses must inform users about the cookies they use and obtain consent before placing non-essential cookies on a visitor's device.
A Consent Management Platform (CMP) is the practical tool for managing this. It displays a cookie notice to visitors, collects and records their preferences, and ensures that no non-essential cookies or trackers are loaded before consent is given.
TIPA also requires businesses to honor the Global Privacy Control (GPC) signal. If a visitor arrives at your site with GPC enabled in their browser, your system must recognize that signal and automatically apply it as an opt-out for targeted advertising and data sales. This is handled at the cookie notice and CMP level.
TIPA grants Tennessee consumers five core rights over their personal data. Any formal request to exercise one of these rights is called a DSAR, or Data Subject Access Request.
Right to confirm and access: Consumers can ask whether a business is processing their data and request a copy of it.
Right to correct: Consumers can request the correction of inaccurate or outdated personal data.
Right to delete: Consumers can request the deletion of personal data provided by them or collected about them, with certain exceptions for legally mandated retention.
Right to data portability: Consumers can request their data in a portable, machine-readable format that allows transfer to another service provider.
Right to opt out: Consumers can opt out of the processing of their data for targeted advertising, the sale of their personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects.
Controllers must respond to authenticated consumer requests within 45 days. This deadline can be extended once by an additional 45 days when reasonably necessary, with written notice to the consumer within the initial period. For appeals of denied requests, the response window is 60 days.
Responses must be provided free of charge at least twice annually per consumer.
If a controller denies a request, the consumer has the right to appeal that decision. The appeal process must be conspicuously available and functionally similar to the original request submission process. If the appeal is denied, the business must provide information on how the consumer can contact the Tennessee Attorney General to file a complaint.
TIPA prohibits businesses from discriminating against consumers who exercise their privacy rights. A business cannot deny goods or services, charge different prices, or provide a lower quality of service to consumers who choose not to share their data or who exercise their TIPA rights.
This is arguably the most distinctive feature of TIPA among all US state privacy laws currently in force.
TIPA allows a business to raise an affirmative defense in an enforcement action if it can demonstrate that it maintains and implements a comprehensive privacy program that reasonably conforms to the NIST Privacy Framework or the ISO 27701 standard.
This is not an exemption from liability. It is a documented risk reduction mechanism. A business with a well-documented, framework-aligned compliance program significantly reduces its regulatory exposure, even if a violation is alleged.
This incentivizes businesses to invest in structured privacy by design practices and maintain documentation that can be presented as evidence of proactive compliance.
Data collected under TIPA can only be used for the specific, explicit, and legitimate purposes for which it was collected. Further processing that is incompatible with those original purposes is prohibited without additional consent.
Controllers must limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the disclosed purposes of processing. Collecting data "just in case" is not compliant.
TIPA requires businesses to implement appropriate technical and organizational security measures to protect personal data against unauthorized access, accidental loss, or unlawful processing. The level of security must be proportional to the volume and sensitivity of the data involved.
Controllers must conduct a Data Protection Assessment before initiating processing activities that present a heightened risk to consumers. This includes processing for targeted advertising, selling personal data, using profiling for significant decisions, and processing sensitive data.
These assessments must identify and weigh the benefits of the processing against the potential risks to consumer rights, and document the safeguards the business will implement to mitigate those risks.
Businesses must provide clear and accessible information about how they process personal data, typically through a privacy policy that is easy to understand and readily available.
When businesses outsource data processing to third parties, binding contracts must define the processor's obligations, the nature and purpose of processing, the types of data involved, and the duration of the arrangement. Understanding the difference between controllers and processors is fundamental to structuring these contracts correctly.
Processing sensitive data requires explicit consent from the consumer before any processing begins. This cannot be bundled with general terms of service or implied through passive behavior.
For data involving known children under 13, additional protections apply, aligned with the federal Children's Online Privacy Protection Act (COPPA).
Managing cookie consent effectively under TIPA involves three things working together:
First, an informed and affirmative consent from users before any non-essential cookies are placed on their device.
Second, clear and accessible information about what cookies are in use, what categories they belong to, and what purposes they serve. Proper tag categorization is what makes this information accurate.
Third, an easy mechanism for users to withdraw consent at any time, as simple as the mechanism used to give it.
A CMP like AdOpt handles all three automatically. It scans the site for active trackers, presents a compliant cookie notice, manages consent preferences, blocks non-consented trackers before they fire, and documents each consent for audit purposes.
Start by understanding what personal data your business collects, where it lives, how it is used, and with whom it is shared. A proper data mapping process is the foundation of every other compliance step.
Your privacy policy must reflect the realities of your data processing. It needs to inform consumers about the categories of data collected, the purposes for processing, how they can exercise their rights, and how long data is retained. Your cookie policy must be specific about each category of tracker and its purpose.
Establish a clear and accessible mechanism for consumers to submit DSARs, track deadlines, and manage responses. A data processing registry makes it operationally possible to respond accurately and within the 45-day window.
Your marketing, legal, and technology teams need to understand what TIPA requires and how their daily processes interact with those requirements. Reviewing high-risk marketing practices is a good starting point.
A CMP is not optional under TIPA. If your site uses any non-essential cookies or trackers, you need a system that collects, records, and enforces user consent. AdOpt handles this automatically, including GPC signal compliance.
To be able to invoke the TIPA affirmative defense, the business needs a documented privacy compliance program aligned to the NIST Privacy Framework or ISO 27701. This means policies, procedures, risk assessments, and ongoing monitoring, not just a privacy policy page.
The Tennessee Attorney General has exclusive authority to enforce TIPA. There is no private right of action.
Before filing an action, the Attorney General must provide written notice of the violation and give the business a 30-day cure period. If the business cures the violation and provides written documentation within that window, no action can be filed for that specific violation.
If the business fails to cure, or if the violation is found to be willful, civil penalties (in Portuguese) can reach up to $7,500 per violation, plus attorney's fees and investigative costs.
The penalty is calculated per violation, not per case. A broken consent system affecting thousands of Tennessee consumers can generate thousands of individual violations.
| Law | State | Revenue Threshold | Consumer Volume | Consent Required | Max Penalty |
|---|---|---|---|---|---|
| TIPA | Tennessee | > $25M | 175K or 25K + 50% revenue | Yes | $7,500/violation |
| TDPSA | Texas | N/A | 25K residents or 50% revenue | Yes | $7,500/violation |
| CCPA | California | > $25M | 50K residents or 50% revenue | Yes | $7,500/violation |
| VCDPA | Virginia | > $25M | 100K residents or 50% revenue | Yes | $7,500/violation |
| MTCDPA | Montana | N/A | 25K residents or 50% revenue | Yes | $7,500/violation |
| CPA | Colorado | > $25M | 100K residents or 25% revenue | Yes | $20,000/violation |
| FDBR | Florida | N/A | 50K residents or 50% revenue | Yes | $5,000/violation |
TIPA stands out from this group in three ways. The combined revenue-plus-volume threshold filters out smaller operators more precisely than laws with no revenue requirement. The explicit inclusion of insurance companies in the entity-level exemptions is unique. And the affirmative defense mechanism tied to recognized international frameworks like NIST and ISO 27701 exists nowhere else in this list.
When compared to the LGPD in Brazil and the GDPR in Europe, TIPA follows the same structural logic: consumer rights, controller obligations, consent requirements, and enforcement with meaningful penalties. The differences are in the thresholds, the specific rights, and the enforcement mechanisms.
AdOpt is the infrastructure that makes compliance operational, not just theoretical.
The automatic site scan identifies every active tracker. The cookie notice collects and records consumer preferences. The platform blocks non-consented trackers before they fire. Every interaction is logged as a consent record that supports your DSAR responses and your affirmative defense documentation.
When a consumer opts out of targeted advertising, the consent management platform propagates that opt-out in real time across all relevant tools. And when the law changes, the platform updates to maintain compliance automatically.
Over 60,000 sites operate with AdOpt. From free plans to enterprise-level operations with global audiences.
Privacy is not a banner. It is a position.
Ready to build a TIPA-compliant data infrastructure? Talk to our team.
Compliance with the TIPA rests on three documents that have to agree with each other: the cookies policy, which declares every tracker and its purpose; the privacy policy, which explains what you do with the data; and the privacy portal, where the consumer exercises their rights and you keep the record of it.
What is TIPA?
The Tennessee Information Protection Act is a state data privacy law that took effect on July 1, 2025. It gives Tennessee consumers rights over their personal data and imposes compliance obligations on businesses that process it.
When does TIPA take effect?
July 1, 2025.
Who must comply with TIPA?
Businesses with annual gross revenue exceeding $25 million that conduct business in Tennessee or target Tennessee residents, and that process data of at least 175,000 consumers or at least 25,000 consumers while deriving more than 50% of gross revenue from data sales.
What rights do consumers have under TIPA?
The right to confirm and access their data, correct inaccuracies, request deletion, obtain a portable copy, and opt out of targeted advertising, data sales, and certain profiling activities.
What is the affirmative defense under TIPA?
A business can raise an affirmative defense in an enforcement action by demonstrating it maintains a comprehensive privacy program aligned with the NIST Privacy Framework or ISO 27701.
What are the penalties for non-compliance?
Up to $7,500 per violation, plus attorney's fees and costs, enforced exclusively by the Tennessee Attorney General. There is no private right of action.
How does TIPA handle cookies?
Cookies that store personal information or enable user identification require informed consent before being placed on a device, except for strictly necessary cookies. The Global Privacy Control signal must also be recognized and honored.
What is sensitive data under TIPA?
Racial or ethnic origin, health and mental health data, sexual orientation, genetic and biometric data, precise geolocation, immigration status, financial identifiers, and personal data of known children under 13.
How does TIPA define consent?
A clear, affirmative, specific, informed, and unambiguous act by the consumer. Implied consent and pre-checked boxes do not qualify.
How does the cure period work?
The Tennessee Attorney General must give the business 30 days written notice before filing an enforcement action. If the violation is cured and documented within that window, no action can be filed for that specific violation.
How does TIPA handle data of minors?
Controllers offering online services to consumers they know or reasonably should know are under 13 must take reasonable care to avoid creating heightened risks of harm to those minors.
How does TIPA compare to other state privacy laws?
TIPA shares the basic structure of CCPA, VCDPA, and TDPSA, but distinguishes itself through the combined revenue and volume threshold, the explicit insurance company exemption, and the unique affirmative defense mechanism tied to recognized compliance frameworks. Learn more in our global privacy law comparison.
Discover the 5 common **cookie consent mistakes** that risk your **compliance** and learn how to avoid heavy **fines**. Simplify your **data privacy** strategy using a reliable **[Cookie notice/banner](https://goadopt.io/en/blog/why-the-cookie-banner/)**.
What the Connecticut CTDPA requires from your Cookies Policy: opt-out link, opt-out preference signal from January 2025, 15-day consent revocation, teen protections, and targeted advertising definition.
Learn the essential steps for creating GDPR-compliant cookie banners in 2025, ensuring user consent and privacy protection.
How does your website handle LGPD? What strategies does it use to comply with the General Data Protection Law? Have you thought about using a cookie notice but don't know if your site has cookies or if it's enough? If you can't answer these questions, be cautious! Your page may be exposed to fines and other sanctions.
LGPD is in effect. Despite that, there are still many companies ignoring it, but is that possible? How long can we ignore LGPD?
How to handle DSARs under the California CCPA/CPRA: 7 consumer rights, 45-day deadline, toll-free number required, 12-month lookback, private right of action for breaches, and CPPA enforcement.
Have you ever thought that your marketing agency could find a great business opportunity in LGPD? Well, unlike what many think, it brings changes that can accelerate the demand for the services of these companies.
Have you ever noticed that every time you sign up for a service to access information or register on a website for purchases, you need to give consent? If you're wondering why you have to give consent on every website you visit, you'll find the answer here.
Learn what your Privacy Policy must contain under the NHDPA. We break down the 8 mandatory elements and how to comply with New Hampshire's data privacy law.
Having a cookie banner on your brand's website has become indispensable for many. However, for e-commerce websites, it has practically become an obligation to have one. This is because this type of website has a technological composition in which cookies are a structural part. Login flow, items in the shopping cart, recommendation showcases, remarketing... Most of them rely on cookies.
California CPRA explained: CCPA vs CPRA timeline and key differences, sensitive personal information, sharing of data, CPPA enforcement, GPC requirement, and tripled penalties for minors.
Find out if the MTCDPA applies to your site, key compliance deadlines, and new rules for cookies and consent in Montana
Iowa ICDPA DSAR guide: 90-day response deadline, 45-day extension, 60-day appeal process, limited deletion scope, opt-out from data sales, targeted advertising disclosure requirement, and 90-day cure period.
Utah UCPA DSAR guide: four consumer rights, limited deletion scope, no right to correct, no formal appeal process, no opt-out of profiling, 45-day deadline, and the guaranteed 30-day cure period.
Learn what your MTCDPA Privacy Policy must include after Montana's SB 297 amendments from the conspicuous "privacy" hyperlink and last-updated date requirements to sale disclosures, minor protections, and how to keep your notice operationally aligned with your stack.
Here is a step-by-step explanation of how consent registration works in AdOpt.
What is a DSAR under NHDPA? Complete guide to consumer rights, response deadlines, and building a compliant Privacy Portal for your site.
Learn how to build a defensible TIPA Cookies Policy for Tennessee compliance covering consent architecture, opt-out requirements, the NIST affirmative defense, and how your cookie banner, privacy notice, and vendor management must work together under the Tennessee Information Protection Act.
The Connecticut Data Privacy Act (CTDPA) is a state regulation designed to protect the privacy of Connecticut residents. It also regards cookies, so in this article we will help you understand all about this new privacy regulation.
Everything you need to know about the Florida Digital Bill of Rights (FDBR): who must comply, the $1 billion threshold, 7 consumer rights, FIPA vs FDBR explained, penalties, and cookies.
What the Colorado CPA requires from your Cookies Policy: mandatory Universal Opt-Out Mechanism from July 2024, targeted advertising definition, dark pattern rules, and the 24-month consent refresh.
Everything about the Oregon OCPA: who must comply, the payment transaction exclusion, 25% revenue threshold, derived data in scope, GPC requirement from January 2026, and elimination of the cure period.
In this article, you will have a great introduction to the topic, as well as various other variations that revolve around the subject: Cookies and LGPD.
What the California CPRA requires from your Privacy Policy: SPI category, two mandatory links, data retention periods, sharing disclosure, right to correct, GPC, and minor protections.
What the Florida FDBR requires from your Cookies Policy: targeted advertising across affiliated sites, opt-out for sensitive data and voice recognition, dark patterns, and tripled penalties.
Google Consent Mode (GCM) is nothing more than a way for you to integrate the consent you collect from your visitors into Google technologies. In this way, upon receiving this consent information, collection can only occur with authorization, thus complying with the legislation and having direct evidence of compliance as defense for both you and Google.
Learn how to build a TIPA-compliant Privacy Portal for Tennessee. Understand DSAR deadlines, consumer rights, opt-out mechanisms, and the affirmative defense that sets TIPA apart from every other US state privacy law.
The Colorado Consumer Privacy Act went into effect July 1, 2023 (CPA). CPA is a vital piece of legislation designed to protect the privacy of residents in Colorado. Understanding its requirements is essential for any business operating in the state. This act is all about giving control back to the consumers regarding their personal data. But what does this mean for you and your business, especially when it comes to managing cookies on your website?
What the Florida FDBR requires from your Privacy Policy: annual updates, 6 mandatory content categories, specific notices for sensitive and biometric data sales, and the 7 consumer rights.
What the California CCPA/CPRA requires from your Privacy Policy: 12-month lookback, annual updates, Do Not Sell link, sensitive PI disclosures, toll-free number, and the 7 consumer rights.
What the Connecticut CTDPA requires from your Privacy Policy: active email contact, opt-out link, 15-day consent revocation, opt-out preference signal from January 2025, and teen protections.
What the Colorado CPA requires from your Privacy Policy: 5 mandatory elements, purpose specification duty, secondary use prohibition, 24-month consent refresh, and Universal Opt-Out Mechanism disclosure.
Utah UCPA explained: the most business-friendly US state privacy law, dual threshold requirement, opt-out for sensitive data, no right to correct, guaranteed 30-day cure period, and key differences from other state laws.
What the Oregon OCPA requires from your Cookies Policy: opt-out link, GPC from January 2026, opt-out without authentication, derived data in scope, teen protections, and the elimination of the cure period.
California CPRA DSAR guide: new rights to correct and limit SPI, opt-out without multiple steps, GPC as valid opt-out, 12-month minor rule, private right of action, and CPPA enforcement.
Your website have users accessing from Texas? So be ready… the Texas Data Privacy and Security Act is here to shake things up. Don't worry; we've got your back. This guide will walk you through everything you need to know to ensure your website complies with the new regulations.
How to handle DSARs under the Virginia VCDPA: consumer rights, 45-day response deadlines, the appeal process, free requests twice per year, and how to build a compliant Privacy Portal.
In this article, we'll explore the GDPR foundations and provide practical insights from the basics to more advanced concepts of its legal basis.
How to handle DSARs under the Florida FDBR: 7 consumer rights, two required submission channels, 45-day deadline with only 15-day extension, tripled penalties for children, and compliance guide.
What the Iowa ICDPA requires from your Cookies Policy: opt-out for data sales and targeted advertising, opt-out model for sensitive data, no GPC requirement, no specific link text required, and the 90-day cure period.
It's time to talk about one of the most impactful tasks, both for the company and for the visitors of your websites: tag categorization. But why is it so impactful? What is the relevance of this configuration and how can it affect us? It is precisely because of these common questions we receive from our clients that we have written this article on best practices in tag categorization.
Rights, Policy and how to understand about the DSAR Montana MTCDPA
Despite cookies being more well-known, what is the main difference between cookies and session storage and local storage? Why choose one over the other? This article will help you with these doubts!
What the California CPRA requires from your Cookies Policy: the sharing concept, GPC as valid opt-out, Do Not Sell or Share link, SPI geolocation, minor protections, and retention periods.
What are the criteria for this choice, and what are the strengths and weaknesses of each option? Well, we're here to help you because this decision needs to be well thought out!
21 Jun 2024
Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819
15 Rue du Général Campredon, 34000 Montpellier, France
207 Rue de Bercy, 75012 Paris, France
EIN: 86-3965064
Phone: +1 (407) 768-3792
AdOpt
Resources
Product
Certifications