🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-TN · run data-protection-2026-08-06 v13-gdpri-1.0.0
content: ai_generated 18 sources retrieved model claude-sonnet-5 ·

United States – Tennessee

US-TN schema gdpri-v2 trajectory: not recordedhybrid regimeoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 40 claims · 18 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
40Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

TIPA is confirmed in force via multiple corroborating secondary sources, but the primary Tennessee Code codification was not independently fetched (allowlist gap), and the injected seed's factual premise conflicts with research findings, warranting operator verification before treating detailed thresholds as final.

Primary frameworkTennessee Information Protection Act (TIPA), 2023 Pub. Ch. 408 (HB 1181/SB 0073), effective 1 July 2025; Tenn. Code Ann. §47-18-2107 (breach notification); FTC Act §5 (federal baseline)
Traffic-light rationale — AmberTIPA is confirmed in force via multiple corroborating secondary sources, but the primary Tennessee Code codification was not independently fetched (allowlist gap), and the injected seed's factual premise conflicts with research findings, warranting operator verification before treating detailed thresholds as final.

Sub-modules (5)

Regulator And AuthorityAmber

TIPA enforcement is exclusive to the Tennessee Attorney General; there is no private data-protection authority and no rulemaking agency distinct from the AG's office.

Claims (1):

  • Enforcement of TIPA is managed exclusively by the Tennessee Attorney General, with no private data-protection regulator or agency established by the statute.

Act And InstrumentsGreen

Primary instruments are TIPA (comprehensive, in force 1 July 2025) and the pre-existing breach-notification statute at Tenn. Code Ann. §47-18-2107; federal FTC Act §5 operates as a general backstop.

Claims (3):

  • The Tennessee Information Protection Act (TIPA), enacted 11 May 2023 as Public Chapter 408 (HB 1181, substituted for companion SB 0073), entered into force on 1 July 2025.
  • Tennessee's general data-breach notification statute (Tenn. Code Ann. §47-18-2107) defines 'breach of system security' as unauthorized acquisition of unencrypted computerized personal information, or encrypted data together with the encryption key, that materially compromises security, confidentiality, or integrity.
  • In the absence of sector-specific coverage, the FTC's general Section 5 unfair-or-deceptive-practices authority operates nationally, including in Tennessee, as a reactive federal privacy-enforcement baseline.

Material ScopeAmber

TIPA covers 'personal data' linked/linkable to identifiable Tennessee consumers, excluding de-identified, aggregate, and publicly available information; coverage is gated by revenue-plus-volume thresholds rather than a flat consumer-count test.

Claims (2):

  • TIPA's applicability thresholds require an entity to make more than USD 25 million in annual revenue while controlling or processing personal data of 25,000 or more consumers and deriving over 50% of revenue from the sale of personal data, or otherwise controlling/processing data at higher consumer-volume levels reported in the range of 175,000 consumers.
  • TIPA defines 'personal data' as information linked or reasonably linkable to an identified or identifiable individual, expressly excluding de-identified data, aggregate data, and publicly available information.

Territorial ScopeAmber

TIPA applies to entities conducting business in Tennessee or targeting products/services to Tennessee residents that meet the statute's narrow multi-part thresholds, reported as among the narrowest of any US state comprehensive privacy law.

Claims (1):

  • Tennessee's coverage thresholds for regulated entities under TIPA are reported as narrower than those of any other US state comprehensive privacy law in effect at the time of passage.

Regulator Registration And FilingRed

No evidence was found of a controller registration, filing, or notification-to-regulator regime under TIPA (unlike EU-style DPA registration models).

Claims (1):

  • No general controller registration or pre-filing obligation with the Tennessee Attorney General was identified under TIPA.
Category narrative109 words

CRITICAL CORRECTION TO INJECTED SEED: the seed's disambiguation stating Tennessee has NO comprehensive consumer-privacy statute is STALE. Research confirms the Tennessee Information Protection Act (TIPA), enacted 2023 as Public Chapter 408 (HB 1181/SB 0073), entered into force on 1 July 2025 and is a comprehensive omnibus consumer-privacy statute of the Virginia/Utah lineage, now layered atop Tennessee's pre-existing breach-notification statute (Tenn. Code Ann. §47-18-2107) and the federal sectoral/FTC Section 5 baseline. Jurisdiction is accordingly classified 'hybrid' (state omnibus + federal sectoral overlay), not 'regulated_sectoral' as the seed's caution flags would imply. Enforcement is vested exclusively in the Tennessee Attorney General and Reporter; no dedicated data-protection authority or registration regime exists.

Sources and claims (8)
  1. ConfirmedDataGuidanceThe Tennessee Information Protection Act (TIPA), enacted 11 May 2023 as Public Chapter 408 (HB 1181, substituted for companion SB 0073), entered into force on 1 July 2025.observed
  2. ConfirmedDataGuidanceEnforcement of TIPA is managed exclusively by the Tennessee Attorney General, with no private data-protection regulator or agency established by the statute.observed
  3. ProbableIAPPTIPA's applicability thresholds require an entity to make more than USD 25 million in annual revenue while controlling or processing personal data of 25,000 or more consumers and deriving over 50% of revenue from the sale of personal data, or otherwise controlling/processing data at higher consumer-volume levels reported in the range of 175,000 consumers.observed
  4. ProbableDataGuidanceTIPA defines 'personal data' as information linked or reasonably linkable to an identified or identifiable individual, expressly excluding de-identified data, aggregate data, and publicly available information.observed
  5. ProbableIAPPTennessee's coverage thresholds for regulated entities under TIPA are reported as narrower than those of any other US state comprehensive privacy law in effect at the time of passage.observed
  6. UncertainDataGuidanceNo general controller registration or pre-filing obligation with the Tennessee Attorney General was identified under TIPA.observed
  7. ConfirmedState of TennesseeTennessee's general data-breach notification statute (Tenn. Code Ann. §47-18-2107) defines 'breach of system security' as unauthorized acquisition of unencrypted computerized personal information, or encrypted data together with the encryption key, that materially compromises security, confidentiality, or integrity.observed
  8. ConfirmedFTCIn the absence of sector-specific coverage, the FTC's general Section 5 unfair-or-deceptive-practices authority operates nationally, including in Tennessee, as a reactive federal privacy-enforcement baseline.observed

#

Core categories (sensitive data, biometric data, consent) are corroborated by multiple secondary sources, but exact statutory mechanics were not independently verified against primary Tennessee Code text.

Primary frameworkTennessee Information Protection Act (TIPA)
Traffic-light rationale — AmberCore categories (sensitive data, biometric data, consent) are corroborated by multiple secondary sources, but exact statutory mechanics were not independently verified against primary Tennessee Code text.

Sub-modules (4)

Lawful BasesAmber

TIPA has no GDPR Art.6-style enumerated lawful-bases list; general processing is permitted on a disclosed-purpose basis subject to consumer opt-out rights for targeted advertising, sale, and (per typical Virginia-model structure) profiling.

Claims (1):

  • TIPA follows a disclosed-purpose/opt-out processing model rather than an enumerated lawful-bases framework, granting consumers rights to opt out of the sale of personal data and processing for targeted advertising.

Special CategoriesAmber

TIPA defines 'sensitive data' and 'biometric data' as distinct categories; Tennessee is reported among the 2023 wave of states whose bills included an opt-in consent right for sensitive-data processing, and TIPA is grouped among states that narrowly define consumer health data as limited to a health diagnosis (rather than broader health status/condition).

Claims (2):

  • Tennessee was among the states whose 2023 comprehensive privacy bills included a right requiring opt-in consumer consent before a controller may process sensitive data.
  • TIPA is grouped among US state privacy laws (with Indiana, Iowa, Kentucky, Minnesota, Montana, Nebraska, Texas, and Virginia) that define 'consumer health data' narrowly as limited to a health diagnosis rather than broader health status or condition.

Pseudonymisation And AnonymisationAmber

TIPA's 'personal data' definition excludes de-identified and aggregate data, implying a de-identification safe harbour, but the statutory de-identification standard (e.g., reasonable-linkability test, contractual commitments) was not independently confirmed.

Claims (1):

  • TIPA excludes de-identified data and aggregate data from the scope of 'personal data,' functioning as a de-identification carve-out.
Category narrative65 words

TIPA does not adopt a GDPR-style enumerated lawful-bases model; instead it follows the US 'notice-and-choice plus opt-out' structure common to Virginia-lineage state laws, layering an opt-in consent requirement onto a defined 'sensitive data' category (including biometric data) while general processing proceeds on a disclosed-purpose/opt-out basis. Several sub-module details (precise consent mechanics, pseudonymisation safe harbours) rely on secondary legislative-tracking sources rather than fetched primary statutory text.

Sources and claims (5)
  1. ProbableDataGuidanceTIPA follows a disclosed-purpose/opt-out processing model rather than an enumerated lawful-bases framework, granting consumers rights to opt out of the sale of personal data and processing for targeted advertising.observed
  2. ProbableDataGuidanceTIPA contains a statutory definition of 'consent' among its enumerated defined terms.observed
  3. ProbableIAPPTennessee was among the states whose 2023 comprehensive privacy bills included a right requiring opt-in consumer consent before a controller may process sensitive data.observed
  4. ProbableIAPPTIPA is grouped among US state privacy laws (with Indiana, Iowa, Kentucky, Minnesota, Montana, Nebraska, Texas, and Virginia) that define 'consumer health data' narrowly as limited to a health diagnosis rather than broader health status or condition.observed
  5. ProbableDataGuidanceTIPA excludes de-identified data and aggregate data from the scope of 'personal data,' functioning as a de-identification carve-out.observed

#

Core rights and response deadline are corroborated across multiple independent secondary sources.

Primary frameworkTennessee Information Protection Act (TIPA)
Traffic-light rationale — GreenCore rights and response deadline are corroborated across multiple independent secondary sources.

Sub-modules (5)

Access RightGreen

TIPA grants consumers a right of access to their personal data held by controllers.

Claims (1):

  • TIPA grants Tennessee consumers a right to access personal data held about them by a controller.

Rectification And ErasureGreen

TIPA grants consumers rights to correct inaccuracies and to delete personal data.

Claims (1):

  • TIPA grants consumers rights to correct inaccurate personal data and to delete personal data held by a controller.

Restriction And ObjectionAmber

TIPA's opt-out rights over targeted advertising and sale of personal data function as the statute's restriction/objection mechanism; explicit profiling opt-out was not independently confirmed.

Claims (1):

  • TIPA grants consumers the right to opt out of the processing of their personal data for targeted advertising and the sale of personal data.

Data PortabilityAmber

TIPA's originating bill (SB 0073) description included a data portability right for consumers.

Claims (1):

  • TIPA's originating legislation grants consumers a data portability right.

Deadlines And Response WindowsGreen

Controllers must respond to consumer rights requests within a 45-day window, consistent with the Virginia/Colorado/Connecticut model.

Claims (1):

  • TIPA requires controllers to respond to consumer data subject requests within a 45-day window.
Category narrative38 words

TIPA grants Tennessee consumers a standard Virginia-model rights package: access, correction, deletion, data portability, and opt-out of targeted advertising/sale/(typically) profiling, with a 45-day controller response window. Exact appeal-process and extension mechanics were not independently verified against primary text.

Sources and claims (5)
  1. ConfirmedDataGuidanceTIPA grants Tennessee consumers a right to access personal data held about them by a controller.observed
  2. ConfirmedDataGuidanceTIPA grants consumers rights to correct inaccurate personal data and to delete personal data held by a controller.observed
  3. ProbableDataGuidanceTIPA grants consumers the right to opt out of the processing of their personal data for targeted advertising and the sale of personal data.observed
  4. ProbableDataGuidanceTIPA's originating legislation grants consumers a data portability right.observed
  5. ConfirmedIAPPTIPA requires controllers to respond to consumer data subject requests within a 45-day window.observed

#

Core accountability and breach-notification duties are well corroborated; DPO, ROPA, joint-controller, and retention-limit provisions could not be confirmed from available sources.

Primary frameworkTennessee Information Protection Act (TIPA); Tenn. Code Ann. §47-18-2107
Traffic-light rationale — AmberCore accountability and breach-notification duties are well corroborated; DPO, ROPA, joint-controller, and retention-limit provisions could not be confirmed from available sources.

Sub-modules (7)

Accountability And DpiaGreen

Controllers must conduct Data Protection Assessments (DPAs) for certain higher-risk processing activities, TIPA's functional equivalent to GDPR Art.35 DPIAs.

Claims (1):

  • TIPA requires controllers to conduct Data Protection Assessments (DPAs) as part of their accountability obligations.

Dpo RequirementsRed

No standalone Data Protection Officer appointment or independence requirement was identified under TIPA.

Claims (1):

  • No provision requiring appointment of a Data Protection Officer was identified under TIPA.

Ropa RequirementsRed

No explicit records-of-processing-activities obligation analogous to GDPR Art.30 was identified; DPAs may partially substitute but are not equivalent in scope.

Claims (1):

  • No GDPR Art.30-style formal records-of-processing-activities obligation was identified under TIPA.

Joint Controller ArrangementsAmber

TIPA requires processors to adhere to controller instructions, implying a contractual controller-processor relationship, but no distinct 'joint controller' regime was identified.

Claims (1):

  • TIPA requires processors to adhere to controller instructions when processing personal data on the controller's behalf.

Security MeasuresAmber

Controllers must ensure data security, though the specific 'reasonable administrative, technical, and physical' security standard language was not independently confirmed for TIPA.

Claims (1):

  • TIPA requires controllers to ensure the security of personal data they process.

Breach NotificationGreen

Tenn. Code Ann. §47-18-2107 requires notification of a breach of system security involving personal consumer information; TIPA does not appear to separately restate breach-notification duties.

Claims (1):

  • Tenn. Code Ann. §47-18-2107 requires notification following a breach of system security that materially compromises the security, confidentiality, or integrity of personal consumer information, whether the compromised data was encrypted or unencrypted.

Retention And DisposalRed

No specific data-retention limitation or disposal-duty provision was identified in TIPA or the breach statute during this research pass.

Claims (1):

  • No specific statutory data-retention-limitation or disposal-duty provision was identified under TIPA or Tennessee's breach-notification statute.
Category narrative49 words

TIPA imposes accountability obligations including mandatory Data Protection Assessments (DPAs), a general data-security duty on controllers, and contractual constraints on processors, plus separate breach-notification duties under Tenn. Code Ann. §47-18-2107. GDPR-style DPO appointment and formal Records-of-Processing (ROPA) obligations were not identified in retrieved sources and are treated as gaps.

Sources and claims (7)
  1. ConfirmedDataGuidanceTIPA requires controllers to conduct Data Protection Assessments (DPAs) as part of their accountability obligations.observed
  2. UncertainDataGuidanceNo provision requiring appointment of a Data Protection Officer was identified under TIPA.observed
  3. UncertainDataGuidanceNo GDPR Art.30-style formal records-of-processing-activities obligation was identified under TIPA.observed
  4. ProbableDataGuidanceTIPA requires processors to adhere to controller instructions when processing personal data on the controller's behalf.observed
  5. ProbableDataGuidanceTIPA requires controllers to ensure the security of personal data they process.observed
  6. ConfirmedState of TennesseeTenn. Code Ann. §47-18-2107 requires notification following a breach of system security that materially compromises the security, confidentiality, or integrity of personal consumer information, whether the compromised data was encrypted or unencrypted.observed
  7. UncertainDataGuidanceNo specific statutory data-retention-limitation or disposal-duty provision was identified under TIPA or Tennessee's breach-notification statute.observed

#

No cross-border transfer mechanism, adequacy framework, or localisation rule exists under TIPA or Tennessee sectoral law; this reflects the genuine absence of such a regime rather than incomplete research.

Primary frameworkTennessee Information Protection Act (TIPA)
Traffic-light rationale — RedNo cross-border transfer mechanism, adequacy framework, or localisation rule exists under TIPA or Tennessee sectoral law; this reflects the genuine absence of such a regime rather than incomplete research.

Sub-modules (6)

Transfer MechanismsAmber

No dedicated cross-border transfer mechanism exists under TIPA; onward transfer to processors relies on the general controller-processor instruction/contract requirement.

Claims (1):

  • TIPA governs data transfers to third-party processors indirectly through its requirement that processors adhere to controller instructions, rather than through a dedicated cross-border transfer mechanism.

Adequacy ReceivedRed

Not applicable — US states do not receive adequacy decisions from foreign regimes.

Absence provenance: not recorded. Searched: not recorded.

Adequacy GrantedRed

Not applicable — Tennessee, as a US state, does not issue adequacy determinations regarding foreign jurisdictions.

Absence provenance: not recorded. Searched: not recorded.

Sccs And BcrsRed

TIPA contains no SCC or BCR mechanism; such instruments are not part of the US state comprehensive-privacy-law model.

Absence provenance: not recorded. Searched: not recorded.

Transfer Impact AssessmentRed

No transfer-impact-assessment requirement was identified under TIPA.

Absence provenance: not recorded. Searched: not recorded.

Data LocalisationRed

No data-localisation mandate was identified under Tennessee law.

Absence provenance: not recorded. Searched: not recorded.

Category narrative58 words

TIPA, consistent with the US state comprehensive-privacy-law model, contains no EU-style cross-border transfer regime: there are no adequacy decisions (received or granted), no SCC/BCR mechanisms, no transfer-impact-assessment requirement, and no data-localisation mandate. Transfers to processors are governed indirectly through the controller-processor contractual instruction requirement. This is an explicit structural gap relative to GDPR-style regimes, not a silent omission.

Sources and claims (1)
  1. UncertainDataGuidanceTIPA governs data transfers to third-party processors indirectly through its requirement that processors adhere to controller instructions, rather than through a dedicated cross-border transfer mechanism.observed

#

One sector overlay (insurance data security) is confirmed via primary statutory text; other sectoral exemptions (GLBA/HIPAA/FERPA/FCRA/employment) are inferred from cross-state legislative pattern only, not independently confirmed for Tennessee.

Primary frameworkTennessee Information Protection Act (TIPA); Tennessee Insurance Data Security Law (Pub. Ch. 345)
Traffic-light rationale — AmberOne sector overlay (insurance data security) is confirmed via primary statutory text; other sectoral exemptions (GLBA/HIPAA/FERPA/FCRA/employment) are inferred from cross-state legislative pattern only, not independently confirmed for Tennessee.

Sub-modules (7)

Financial Sector OverlayAmber

GLBA-regulated financial institutions and GLBA-covered data are commonly exempted from Virginia-model state privacy laws; a Tennessee-specific exemption clause was not independently confirmed.

Claims (1):

  • GLBA-regulated financial institutions and GLBA-covered personal data are likely exempted from TIPA, consistent with the standard carve-out pattern in peer Virginia-model state privacy laws.

Health Sector OverlayAmber

HIPAA-covered entities/data are commonly exempted under Virginia-model laws; TIPA additionally uses a narrow diagnosis-only definition of consumer health data as sensitive data.

Claims (1):

  • HIPAA-covered entities and HIPAA-regulated protected health information are likely exempted from TIPA, consistent with peer state-law patterns, while TIPA separately treats non-HIPAA consumer health diagnosis data as 'sensitive data.'

Telecoms And EprivacyRed

No Tennessee-specific ePrivacy/cookie-consent statute distinct from TIPA's general opt-out rights was identified.

Absence provenance: not recorded. Searched: not recorded.

Employment DataAmber

Virginia-model laws typically exclude employment/HR data from the 'consumer' definition; a Tennessee-specific carve-out was not independently confirmed.

Claims (1):

  • Employment/HR-related personal data is likely excluded from TIPA's definition of regulated 'consumer' data, consistent with peer Virginia-model laws.

Credit And ScoringAmber

FCRA-regulated credit data is commonly exempted under peer state laws; a Tennessee-specific exemption was not independently confirmed.

Claims (1):

  • FCRA-regulated consumer report data is likely exempted from TIPA, consistent with peer state-law patterns.

EducationRed

FERPA operates as the federal baseline for education records; no Tennessee-specific education-sector data-protection overlay beyond TIPA's general exemptions was identified.

Absence provenance: not recorded. Searched: not recorded.

InsuranceGreen

Tennessee enacted a dedicated Insurance Data Security Law (Public Chapter 345, HB 766) amending Tenn. Code Ann. Title 56, Chapter 2, layering sector-specific data-security duties on licensed insurers.

Claims (1):

  • Tennessee enacted an Insurance Data Security Law (Public Chapter 345, House Bill 766) amending Tennessee Code Annotated Title 56, Chapter 2, to impose data-security obligations on licensed insurers.
Category narrative74 words

As with peer Virginia-lineage state laws, TIPA is expected to carry standard sectoral carve-outs (GLBA-regulated financial data, HIPAA-regulated health data, FERPA-regulated education data, FCRA-regulated credit data, and employment/HR data), but the Tennessee-specific exemption clauses were not independently retrieved from primary text in this pass and are flagged as inferred-by-pattern rather than confirmed. A confirmed, TIPA-independent sector overlay is Tennessee's separate insurance-sector data-security law (Public Chapter 345, amending Tenn. Code Ann. Title 56, Chapter 2).

Sources and claims (5)
  1. UncertainDataGuidanceGLBA-regulated financial institutions and GLBA-covered personal data are likely exempted from TIPA, consistent with the standard carve-out pattern in peer Virginia-model state privacy laws.observed
  2. UncertainIAPPHIPAA-covered entities and HIPAA-regulated protected health information are likely exempted from TIPA, consistent with peer state-law patterns, while TIPA separately treats non-HIPAA consumer health diagnosis data as 'sensitive data.'observed
  3. UncertainDataGuidanceEmployment/HR-related personal data is likely excluded from TIPA's definition of regulated 'consumer' data, consistent with peer Virginia-model laws.observed
  4. UncertainDataGuidanceFCRA-regulated consumer report data is likely exempted from TIPA, consistent with peer state-law patterns.observed
  5. ConfirmedState of TennesseeTennessee enacted an Insurance Data Security Law (Public Chapter 345, House Bill 766) amending Tennessee Code Annotated Title 56, Chapter 2, to impose data-security obligations on licensed insurers.observed

#

The core opt-out right is corroborated; several sub-modules common to more prescriptive state laws (dark patterns, universal opt-out signals, clean rooms) are unconfirmed gaps for Tennessee specifically.

Primary frameworkTennessee Information Protection Act (TIPA)
Traffic-light rationale — AmberThe core opt-out right is corroborated; several sub-modules common to more prescriptive state laws (dark patterns, universal opt-out signals, clean rooms) are unconfirmed gaps for Tennessee specifically.

Sub-modules (6)

Cookies And TrackersAmber

No EU-style cookie-consent regime exists; the functional equivalent is TIPA's opt-out right for targeted-advertising-related tracking.

Claims (1):

  • TIPA's opt-out right over processing for targeted advertising functions as the statute's principal mechanism for consumer control over tracking-based adtech, absent a dedicated cookie-consent regime.

Dark PatternsRed

No Tennessee-specific dark-pattern prohibition (unlike Connecticut/California) was identified under TIPA.

Absence provenance: not recorded. Searched: not recorded.

Opt Out SignalsRed

No confirmation was found that TIPA requires or recognizes universal opt-out mechanisms (e.g., Global Privacy Control), unlike Colorado, Montana, and California.

Claims (1):

  • No evidence was found that TIPA mandates recognition of a universal opt-out mechanism (e.g., Global Privacy Control) as a method of exercising consumer opt-out rights, distinguishing it from Colorado and Montana's laws.

Clean Rooms And DcrRed

No clean-room or data-collaboration-room-specific rule was identified under Tennessee law.

Absence provenance: not recorded. Searched: not recorded.

Cross Context AdvertisingAmber

TIPA provides consumers a right to opt out of the sale of personal data and processing for targeted advertising, TIPA's analogue to CPRA's 'sale'/'share' opt-out.

Claims (1):

  • TIPA grants consumers a right to opt out of the sale of personal data to third parties and of processing for targeted advertising.

Direct MarketingAmber

No Tennessee-specific direct-marketing consent/suppression statute distinct from TIPA's general opt-out right was identified.

Claims (1):

  • TIPA grants consumers a right to opt out of the sale of personal data to third parties and of processing for targeted advertising.
Category narrative38 words

TIPA's principal adtech-relevant mechanism is the consumer opt-out right over targeted advertising and sale of personal data. No Tennessee-specific cookie-consent statute, dark-pattern prohibition, universal opt-out signal (e.g., GPC) recognition, or clean-room/data-collaboration rule was identified in this research pass.

Sources and claims (3)
  1. ProbableDataGuidanceTIPA's opt-out right over processing for targeted advertising functions as the statute's principal mechanism for consumer control over tracking-based adtech, absent a dedicated cookie-consent regime.observed
  2. UncertainIAPPNo evidence was found that TIPA mandates recognition of a universal opt-out mechanism (e.g., Global Privacy Control) as a method of exercising consumer opt-out rights, distinguishing it from Colorado and Montana's laws.observed
  3. ProbableDataGuidanceTIPA grants consumers a right to opt out of the sale of personal data to third parties and of processing for targeted advertising.observed

#

Biometric data category is corroborated; ADM transparency, AI risk assessment, genetic data, and surveillance carve-out sub-modules lack direct confirming evidence.

Primary frameworkTennessee Information Protection Act (TIPA)
Traffic-light rationale — AmberBiometric data category is corroborated; ADM transparency, AI risk assessment, genetic data, and surveillance carve-out sub-modules lack direct confirming evidence.

Sub-modules (6)

Profiling RestrictionsRed

No TIPA-specific profiling-restriction or profiling opt-out clause was independently confirmed, though such a right is common in peer Virginia-model laws.

Absence provenance: not recorded. Searched: not recorded.

Automated Decision Making TransparencyRed

No ADM transparency or explanation right under TIPA was identified.

Absence provenance: not recorded. Searched: not recorded.

Ai Risk AssessmentsRed

No TIPA-specific AI risk-assessment obligation (distinct from general DPAs) was identified in this research pass.

Absence provenance: not recorded. Searched: not recorded.

Biometric RegimeAmber

TIPA defines 'biometric data' as an enumerated category, treated among the statute's sensitive-data types requiring heightened protection.

Claims (1):

  • TIPA defines 'biometric data' as an enumerated data category subject to the statute's sensitive-data protections.

Genetic DataRed

No standalone genetic-data-specific regime distinct from the general 'sensitive data' category was confirmed.

Absence provenance: not recorded. Searched: not recorded.

State Surveillance CarveoutsRed

No Tennessee-specific national-security or government-surveillance carve-out clause under TIPA was independently confirmed, though such carve-outs (excluding government entities from 'controller' status) are typical of peer state laws.

Absence provenance: not recorded. Searched: not recorded.

Category narrative44 words

TIPA defines 'biometric data' as a distinct, likely sensitive-data category subject to opt-in consent. Automated-decision-making transparency rights, AI-specific risk-assessment obligations, genetic-data-specific rules, and government/national-security carve-outs were not independently confirmed for Tennessee in this research pass and are flagged as gaps rather than silently omitted.

Sources and claims (1)
  1. ProbableDataGuidanceTIPA defines 'biometric data' as an enumerated data category subject to the statute's sensitive-data protections.observed

#

No TIPA-specific children/vulnerable-groups provisions were confirmed beyond the general federal COPPA baseline; explicit absence is recorded rather than silently omitted.

Primary frameworkChildren's Online Privacy Protection Act (COPPA) [federal baseline]; Tennessee Information Protection Act (TIPA) [state overlay, unconfirmed provisions]
Traffic-light rationale — RedNo TIPA-specific children/vulnerable-groups provisions were confirmed beyond the general federal COPPA baseline; explicit absence is recorded rather than silently omitted.

Sub-modules (5)

Age VerificationRed

No Tennessee-specific age-verification mandate under TIPA was identified.

Absence provenance: not recorded. Searched: not recorded.

Minor Profiling BansRed

No minor-specific profiling ban under TIPA was identified.

Absence provenance: not recorded. Searched: not recorded.

Education SettingsRed

No Tennessee-specific education-setting data-protection rule beyond the federal FERPA baseline was identified.

Absence provenance: not recorded. Searched: not recorded.

Dependent AdultsRed

No dependent-adult/elderly-specific data-protection provision was identified under Tennessee law.

Absence provenance: not recorded. Searched: not recorded.

Category narrative41 words

No Tennessee-specific age-verification, parental-consent mechanics, minor-profiling ban, education-setting rule, or dependent-adult protection was independently confirmed for TIPA in this research pass; federal COPPA operates as the baseline for children under 13. This module is a significant research gap requiring primary-source escalation.

Sources and claims (1)
  1. ConfirmedFTCFederal COPPA imposes verifiable-parental-consent requirements on operators of websites or online services directed to children under 13, or with actual knowledge of collecting personal information from children under 13, applicable in Tennessee as elsewhere in the US.observed

#

Statutory enforcement architecture (AG-exclusive, 60-day cure, NIST affirmative defense) is well corroborated; actual enforcement track record and regulator capacity signals are unconfirmed gaps just over one year after the law's effective date.

Primary frameworkTennessee Information Protection Act (TIPA)
Traffic-light rationale — AmberStatutory enforcement architecture (AG-exclusive, 60-day cure, NIST affirmative defense) is well corroborated; actual enforcement track record and regulator capacity signals are unconfirmed gaps just over one year after the law's effective date.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The Attorney General has exclusive enforcement authority and must provide a nonsunsetting 60-day cure period before initiating an enforcement action; TIPA also grants an affirmative defense to entities whose privacy programs reasonably conform to recognized standards such as the NIST Privacy Framework.

Claims (2):

  • TIPA grants covered entities a nonsunsetting 60-day right to cure alleged violations before the Attorney General may initiate an enforcement action.
  • TIPA offers an affirmative defense against enforcement actions to controllers/processors that maintain a privacy program reasonably conforming to recognized standards, including the NIST Privacy Framework, the APEC Cross-Border Privacy Rules, and the APEC Privacy Recognition for Processors System.

Enforcement Activity IndexAmber

The Tennessee Attorney General issued compliance guidance ahead of TIPA's 1 July 2025 effective date, but no confirmed enforcement actions, fines, or settlements under TIPA were identified in this research pass.

Claims (1):

  • The Tennessee Attorney General published compliance guidance related to TIPA in advance of the statute's effective date.

Regulator Funding And CapacityRed

No specific data on the Attorney General's privacy-enforcement staffing, budget, or headcount was identified.

Absence provenance: not recorded. Searched: not recorded.

Collective Redress And Class ActionsAmber

TIPA provides no private right of action or class-action mechanism for consumers; redress runs solely through Attorney General enforcement.

Claims (1):

  • TIPA does not create a private right of action for consumers; enforcement is exclusive to the Tennessee Attorney General.

Private Right Of ActionAmber

TIPA does not create a private right of action; enforcement is exclusively vested in the Attorney General.

Claims (1):

  • TIPA does not create a private right of action for consumers; enforcement is exclusive to the Tennessee Attorney General.

Recent Developments 180DRed

No material TIPA amendments, new implementing guidance, litigation, or enforcement developments within the last 180 days (approx. February-August 2026) were identified in this research pass.

Absence provenance: not recorded. Searched: not recorded.

Category narrative86 words

TIPA enforcement is vested exclusively in the Tennessee Attorney General, who must afford covered entities a nonsunsetting 60-day cure period before initiating an action; the statute offers an unusual affirmative defense to enforcement where a controller/processor maintains a privacy program reasonably conforming to the NIST Privacy Framework, ISO 31700, or APEC CBPR/PRP standards. TIPA provides no private right of action. No confirmed TIPA enforcement actions, fines, or settlements were identified as of the dispatch date, and no material developments in the last 180 days were found.

Sources and claims (4)
  1. ConfirmedIAPPTIPA grants covered entities a nonsunsetting 60-day right to cure alleged violations before the Attorney General may initiate an enforcement action.observed
  2. ConfirmedIAPPTIPA offers an affirmative defense against enforcement actions to controllers/processors that maintain a privacy program reasonably conforming to recognized standards, including the NIST Privacy Framework, the APEC Cross-Border Privacy Rules, and the APEC Privacy Recognition for Processors System.observed
  3. UncertainDataGuidanceThe Tennessee Attorney General published compliance guidance related to TIPA in advance of the statute's effective date.observed
  4. ConfirmedIAPPTIPA does not create a private right of action for consumers; enforcement is exclusive to the Tennessee Attorney General.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Tennessee
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 40 claim(s), 18 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiessecurity measures
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacyadequacy granted
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacysccs and bcrs
Art. 49Cross-Border & Adequacytransfer impact assessment
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redresscollective redress and class actions
Art. 80Enforcement & Redressprivate right of action
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, data_subject_rights, and the enforcement_and_redress core (AG-exclusive enforcement, 60-day cure, NIST affirmative defense, no private right of action) rest on T2/T3 secondary reporting (DataGuidance, IAPP) corroborated across multiple independent outlets, plus one directly-retrieved T1 primary text (Tenn. Code Ann. §47-18-2107 breach statute, and the Insurance Data Security Law Public Chapter 345). controller_processor_duties is partially T1/T3 (breach notice confirmed T1; DPA/security duties T3) with DPO, ROPA, and retention sub-modules unconfirmed (T4-equivalent gaps). lawful_processing_and_special_data and sectoral_watch rely heavily on cross-state pattern inference (T3/Uncertain) rather than TN-specific primary text for GLBA/HIPAA/FERPA/FCRA/employment carve-outs. cross_border_and_adequacy, algorithmic_biometric_and_surveillance_governance, and children_and_vulnerable_groups are the weakest modules, largely populated with explicit absent_field_provenance gap narratives rather than confirmed claims, reflecting both genuine regime gaps (no EU-style transfer regime exists) and research-access limits (no primary TIPA statutory text was directly fetched; only secondary legislative-tracking summaries).

Unresolved questions (7):

  • The injected seed's disambiguation stated Tennessee has NO comprehensive consumer-privacy statute; research found this to be stale as of the 2026-08-06 dispatch date given TIPA's 1 July 2025 effective date. Operator should confirm whether the seed corpus requires a refresh cycle for US-TN.
  • Exact codification (Tennessee Code Annotated title/chapter/section numbers) for TIPA's substantive provisions was not independently verified against primary code text; only secondary summaries were available.
  • Precise numeric applicability thresholds (25,000 vs 175,000 consumers, 50% revenue-from-sale test) were reported with some internal inconsistency across secondary sources and should be verified against the enrolled bill/codified statute.
  • Whether TIPA contains explicit GLBA/HIPAA/FERPA/FCRA/employment-data exemption clauses (assumed by pattern from peer Virginia-model laws) requires primary-text confirmation.
  • Whether TIPA includes a distinct profiling opt-out right and/or a children's-data consent provision cross-referencing COPPA was not confirmed from retrieved sources.
  • No TIPA enforcement actions, settlements, or fines were located as of dispatch date (13 months post-effective-date); unclear whether this reflects true regulatory quiescence or a research-access gap.
  • The seed-provided regulator URL (naag.org) is the national multistate-AG coordination body, not a Tennessee-specific Attorney General consumer-protection webpage; the correct dedicated TN AG consumer-protection/privacy enforcement URL should be sourced and substituted.

Escalate to primary-source review: yes