{
 "jurisdiction_id": "US-TN",
 "jurisdiction": "United States – Tennessee",
 "url": "https://dataprotection.gi/jurisdictions/united-states-tennessee/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-06",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 40,
  "sub_modules": 57,
  "source_register": 18
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-tennessee/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "TIPA is confirmed in force via multiple corroborating secondary sources, but the primary Tennessee Code codification was not independently fetched (allowlist gap), and the injected seed's factual premise conflicts with research findings, warranting operator verification before treating detailed thresholds as final.",
   "claims": [
    {
     "statement": "The Tennessee Information Protection Act (TIPA), enacted 11 May 2023 as Public Chapter 408 (HB 1181, substituted for companion SB 0073), entered into force on 1 July 2025.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/tennessee-tipa-published-secretary-state",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Enforcement of TIPA is managed exclusively by the Tennessee Attorney General, with no private data-protection regulator or agency established by the statute.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/tennessee-information-protection-act-comprehensive",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "TIPA's applicability thresholds require an entity to make more than USD 25 million in annual revenue while controlling or processing personal data of 25,000 or more consumers and deriving over 50% of revenue from the sale of personal data, or otherwise controlling/processing data at higher consumer-volume levels reported in the range of 175,000 consumers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/two-for-one-special-montana-tennessee-comprehensive-privacy-bills-clear-legislatures",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "TIPA defines 'personal data' as information linked or reasonably linkable to an identified or identifiable individual, expressly excluding de-identified data, aggregate data, and publicly available information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/tennessee-information-protection-act-comprehensive",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Tennessee's coverage thresholds for regulated entities under TIPA are reported as narrower than those of any other US state comprehensive privacy law in effect at the time of passage.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/two-for-one-special-montana-tennessee-comprehensive-privacy-bills-clear-legislatures",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "No general controller registration or pre-filing obligation with the Tennessee Attorney General was identified under TIPA.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/tennessee-information-protection-act-comprehensive",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Tennessee's general data-breach notification statute (Tenn. Code Ann. §47-18-2107) defines 'breach of system security' as unauthorized acquisition of unencrypted computerized personal information, or encrypted data together with the encryption key, that materially compromises security, confidentiality, or integrity.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "State of Tennessee",
     "source_url": "https://www.dataguidance.com/sites/default/files/47-18-2107_tennessee_code_.pdf",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "In the absence of sector-specific coverage, the FTC's general Section 5 unfair-or-deceptive-practices authority operates nationally, including in Tennessee, as a reactive federal privacy-enforcement baseline.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-tennessee/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Core categories (sensitive data, biometric data, consent) are corroborated by multiple secondary sources, but exact statutory mechanics were not independently verified against primary Tennessee Code text.",
   "claims": [
    {
     "statement": "TIPA follows a disclosed-purpose/opt-out processing model rather than an enumerated lawful-bases framework, granting consumers rights to opt out of the sale of personal data and processing for targeted advertising.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/tennessee-bill-information-protection-act-introduced",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "TIPA contains a statutory definition of 'consent' among its enumerated defined terms.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/tennessee-information-protection-act-comprehensive",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Tennessee was among the states whose 2023 comprehensive privacy bills included a right requiring opt-in consumer consent before a controller may process sensitive data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/indiana-governor-signs-a-comprehensive-privacy-act-into-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "TIPA is grouped among US state privacy laws (with Indiana, Iowa, Kentucky, Minnesota, Montana, Nebraska, Texas, and Virginia) that define 'consumer health data' narrowly as limited to a health diagnosis rather than broader health status or condition.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/is-a-hipaa-style-de-identification-standard-emerging-in-us-state-laws-",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "TIPA excludes de-identified data and aggregate data from the scope of 'personal data,' functioning as a de-identification carve-out.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/tennessee-information-protection-act-comprehensive",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-tennessee/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Core rights and response deadline are corroborated across multiple independent secondary sources.",
   "claims": [
    {
     "statement": "TIPA grants Tennessee consumers a right to access personal data held about them by a controller.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/tennessee-information-protection-act-comprehensive",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "TIPA grants consumers rights to correct inaccurate personal data and to delete personal data held by a controller.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/tennessee-information-protection-act-comprehensive",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "TIPA grants consumers the right to opt out of the processing of their personal data for targeted advertising and the sale of personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/tennessee-bill-information-protection-act-introduced",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "TIPA's originating legislation grants consumers a data portability right.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/tennessee-bill-information-protection-act-introduced",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "TIPA requires controllers to respond to consumer data subject requests within a 45-day window.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/two-for-one-special-montana-tennessee-comprehensive-privacy-bills-clear-legislatures",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-tennessee/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Core accountability and breach-notification duties are well corroborated; DPO, ROPA, joint-controller, and retention-limit provisions could not be confirmed from available sources.",
   "claims": [
    {
     "statement": "TIPA requires controllers to conduct Data Protection Assessments (DPAs) as part of their accountability obligations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/tennessee-information-protection-act-comprehensive",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "No provision requiring appointment of a Data Protection Officer was identified under TIPA.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/tennessee-information-protection-act-comprehensive",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "No GDPR Art.30-style formal records-of-processing-activities obligation was identified under TIPA.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/tennessee-information-protection-act-comprehensive",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "TIPA requires processors to adhere to controller instructions when processing personal data on the controller's behalf.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/tennessee-information-protection-act-comprehensive",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "TIPA requires controllers to ensure the security of personal data they process.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/tennessee-information-protection-act-comprehensive",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Tenn. Code Ann. §47-18-2107 requires notification following a breach of system security that materially compromises the security, confidentiality, or integrity of personal consumer information, whether the compromised data was encrypted or unencrypted.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "State of Tennessee",
     "source_url": "https://www.dataguidance.com/sites/default/files/47-18-2107_tennessee_code_.pdf",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "No specific statutory data-retention-limitation or disposal-duty provision was identified under TIPA or Tennessee's breach-notification statute.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/tennessee-information-protection-act-comprehensive",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "red",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-tennessee/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "No cross-border transfer mechanism, adequacy framework, or localisation rule exists under TIPA or Tennessee sectoral law; this reflects the genuine absence of such a regime rather than incomplete research.",
   "claims": [
    {
     "statement": "TIPA governs data transfers to third-party processors indirectly through its requirement that processors adhere to controller instructions, rather than through a dedicated cross-border transfer mechanism.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/tennessee-information-protection-act-comprehensive",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-tennessee/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "One sector overlay (insurance data security) is confirmed via primary statutory text; other sectoral exemptions (GLBA/HIPAA/FERPA/FCRA/employment) are inferred from cross-state legislative pattern only, not independently confirmed for Tennessee.",
   "claims": [
    {
     "statement": "GLBA-regulated financial institutions and GLBA-covered personal data are likely exempted from TIPA, consistent with the standard carve-out pattern in peer Virginia-model state privacy laws.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/tennessee-information-protection-act-comprehensive",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "HIPAA-covered entities and HIPAA-regulated protected health information are likely exempted from TIPA, consistent with peer state-law patterns, while TIPA separately treats non-HIPAA consumer health diagnosis data as 'sensitive data.'",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/is-a-hipaa-style-de-identification-standard-emerging-in-us-state-laws-",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Employment/HR-related personal data is likely excluded from TIPA's definition of regulated 'consumer' data, consistent with peer Virginia-model laws.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/tennessee-information-protection-act-comprehensive",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "FCRA-regulated consumer report data is likely exempted from TIPA, consistent with peer state-law patterns.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/tennessee-information-protection-act-comprehensive",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Tennessee enacted an Insurance Data Security Law (Public Chapter 345, House Bill 766) amending Tennessee Code Annotated Title 56, Chapter 2, to impose data-security obligations on licensed insurers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "State of Tennessee",
     "source_url": "https://www.dataguidance.com/sites/default/files/pc0345-insurance-data-security.pdf",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-tennessee/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "The core opt-out right is corroborated; several sub-modules common to more prescriptive state laws (dark patterns, universal opt-out signals, clean rooms) are unconfirmed gaps for Tennessee specifically.",
   "claims": [
    {
     "statement": "TIPA's opt-out right over processing for targeted advertising functions as the statute's principal mechanism for consumer control over tracking-based adtech, absent a dedicated cookie-consent regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/tennessee-bill-information-protection-act-introduced",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "No evidence was found that TIPA mandates recognition of a universal opt-out mechanism (e.g., Global Privacy Control) as a method of exercising consumer opt-out rights, distinguishing it from Colorado and Montana's laws.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/two-for-one-special-montana-tennessee-comprehensive-privacy-bills-clear-legislatures",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "TIPA grants consumers a right to opt out of the sale of personal data to third parties and of processing for targeted advertising.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/tennessee-bill-information-protection-act-introduced",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-tennessee/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Biometric data category is corroborated; ADM transparency, AI risk assessment, genetic data, and surveillance carve-out sub-modules lack direct confirming evidence.",
   "claims": [
    {
     "statement": "TIPA defines 'biometric data' as an enumerated data category subject to the statute's sensitive-data protections.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/tennessee-information-protection-act-comprehensive",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "red",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-tennessee/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "No TIPA-specific children/vulnerable-groups provisions were confirmed beyond the general federal COPPA baseline; explicit absence is recorded rather than silently omitted.",
   "claims": [
    {
     "statement": "Federal COPPA imposes verifiable-parental-consent requirements on operators of websites or online services directed to children under 13, or with actual knowledge of collecting personal information from children under 13, applicable in Tennessee as elsewhere in the US.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/legal-library/browse/rules/childrens-online-privacy-protection-rule-coppa",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-tennessee/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Statutory enforcement architecture (AG-exclusive, 60-day cure, NIST affirmative defense) is well corroborated; actual enforcement track record and regulator capacity signals are unconfirmed gaps just over one year after the law's effective date.",
   "claims": [
    {
     "statement": "TIPA grants covered entities a nonsunsetting 60-day right to cure alleged violations before the Attorney General may initiate an enforcement action.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/two-for-one-special-montana-tennessee-comprehensive-privacy-bills-clear-legislatures",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "TIPA offers an affirmative defense against enforcement actions to controllers/processors that maintain a privacy program reasonably conforming to recognized standards, including the NIST Privacy Framework, the APEC Cross-Border Privacy Rules, and the APEC Privacy Recognition for Processors System.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/state-privacy-dispatch-the-floodgates-are-open",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The Tennessee Attorney General published compliance guidance related to TIPA in advance of the statute's effective date.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/tennessee-ag-provides-guidelines-tipa",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "TIPA does not create a private right of action for consumers; enforcement is exclusive to the Tennessee Attorney General.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/two-for-one-special-montana-tennessee-comprehensive-privacy-bills-clear-legislatures",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  }
 ]
}