TIPA is confirmed in force via multiple corroborating secondary sources, but the primary Tennessee Code codification was not independently fetched (allowlist gap), and the injected seed's factual premise conflicts with research findings, warranting operator verification before treating detailed thresholds as final.
Primary frameworkTennessee Information Protection Act (TIPA), 2023 Pub. Ch. 408 (HB 1181/SB 0073), effective 1 July 2025; Tenn. Code Ann. §47-18-2107 (breach notification); FTC Act §5 (federal baseline)
Traffic-light rationale — AmberTIPA is confirmed in force via multiple corroborating secondary sources, but the primary Tennessee Code codification was not independently fetched (allowlist gap), and the injected seed's factual premise conflicts with research findings, warranting operator verification before treating detailed thresholds as final.
Sub-modules (5)
Regulator And AuthorityAmber
TIPA enforcement is exclusive to the Tennessee Attorney General; there is no private data-protection authority and no rulemaking agency distinct from the AG's office.
Claims (1):
Enforcement of TIPA is managed exclusively by the Tennessee Attorney General, with no private data-protection regulator or agency established by the statute.
Act And InstrumentsGreen
Primary instruments are TIPA (comprehensive, in force 1 July 2025) and the pre-existing breach-notification statute at Tenn. Code Ann. §47-18-2107; federal FTC Act §5 operates as a general backstop.
Claims (3):
The Tennessee Information Protection Act (TIPA), enacted 11 May 2023 as Public Chapter 408 (HB 1181, substituted for companion SB 0073), entered into force on 1 July 2025.
Tennessee's general data-breach notification statute (Tenn. Code Ann. §47-18-2107) defines 'breach of system security' as unauthorized acquisition of unencrypted computerized personal information, or encrypted data together with the encryption key, that materially compromises security, confidentiality, or integrity.
In the absence of sector-specific coverage, the FTC's general Section 5 unfair-or-deceptive-practices authority operates nationally, including in Tennessee, as a reactive federal privacy-enforcement baseline.
Material ScopeAmber
TIPA covers 'personal data' linked/linkable to identifiable Tennessee consumers, excluding de-identified, aggregate, and publicly available information; coverage is gated by revenue-plus-volume thresholds rather than a flat consumer-count test.
Claims (2):
TIPA's applicability thresholds require an entity to make more than USD 25 million in annual revenue while controlling or processing personal data of 25,000 or more consumers and deriving over 50% of revenue from the sale of personal data, or otherwise controlling/processing data at higher consumer-volume levels reported in the range of 175,000 consumers.
TIPA defines 'personal data' as information linked or reasonably linkable to an identified or identifiable individual, expressly excluding de-identified data, aggregate data, and publicly available information.
Territorial ScopeAmber
TIPA applies to entities conducting business in Tennessee or targeting products/services to Tennessee residents that meet the statute's narrow multi-part thresholds, reported as among the narrowest of any US state comprehensive privacy law.
Claims (1):
Tennessee's coverage thresholds for regulated entities under TIPA are reported as narrower than those of any other US state comprehensive privacy law in effect at the time of passage.
Regulator Registration And FilingRed
No evidence was found of a controller registration, filing, or notification-to-regulator regime under TIPA (unlike EU-style DPA registration models).
Claims (1):
No general controller registration or pre-filing obligation with the Tennessee Attorney General was identified under TIPA.
Category narrative109 words
CRITICAL CORRECTION TO INJECTED SEED: the seed's disambiguation stating Tennessee has NO comprehensive consumer-privacy statute is STALE. Research confirms the Tennessee Information Protection Act (TIPA), enacted 2023 as Public Chapter 408 (HB 1181/SB 0073), entered into force on 1 July 2025 and is a comprehensive omnibus consumer-privacy statute of the Virginia/Utah lineage, now layered atop Tennessee's pre-existing breach-notification statute (Tenn. Code Ann. §47-18-2107) and the federal sectoral/FTC Section 5 baseline. Jurisdiction is accordingly classified 'hybrid' (state omnibus + federal sectoral overlay), not 'regulated_sectoral' as the seed's caution flags would imply. Enforcement is vested exclusively in the Tennessee Attorney General and Reporter; no dedicated data-protection authority or registration regime exists.
Sources and claims (8)
ConfirmedDataGuidance — The Tennessee Information Protection Act (TIPA), enacted 11 May 2023 as Public Chapter 408 (HB 1181, substituted for companion SB 0073), entered into force on 1 July 2025.observed
ConfirmedDataGuidance — Enforcement of TIPA is managed exclusively by the Tennessee Attorney General, with no private data-protection regulator or agency established by the statute.observed
ProbableIAPP — TIPA's applicability thresholds require an entity to make more than USD 25 million in annual revenue while controlling or processing personal data of 25,000 or more consumers and deriving over 50% of revenue from the sale of personal data, or otherwise controlling/processing data at higher consumer-volume levels reported in the range of 175,000 consumers.observed
ProbableDataGuidance — TIPA defines 'personal data' as information linked or reasonably linkable to an identified or identifiable individual, expressly excluding de-identified data, aggregate data, and publicly available information.observed
ProbableIAPP — Tennessee's coverage thresholds for regulated entities under TIPA are reported as narrower than those of any other US state comprehensive privacy law in effect at the time of passage.observed
UncertainDataGuidance — No general controller registration or pre-filing obligation with the Tennessee Attorney General was identified under TIPA.observed
ConfirmedState of Tennessee — Tennessee's general data-breach notification statute (Tenn. Code Ann. §47-18-2107) defines 'breach of system security' as unauthorized acquisition of unencrypted computerized personal information, or encrypted data together with the encryption key, that materially compromises security, confidentiality, or integrity.observed
ConfirmedFTC — In the absence of sector-specific coverage, the FTC's general Section 5 unfair-or-deceptive-practices authority operates nationally, including in Tennessee, as a reactive federal privacy-enforcement baseline.observed
Core categories (sensitive data, biometric data, consent) are corroborated by multiple secondary sources, but exact statutory mechanics were not independently verified against primary Tennessee Code text.
Primary frameworkTennessee Information Protection Act (TIPA)
Traffic-light rationale — AmberCore categories (sensitive data, biometric data, consent) are corroborated by multiple secondary sources, but exact statutory mechanics were not independently verified against primary Tennessee Code text.
Sub-modules (4)
Lawful BasesAmber
TIPA has no GDPR Art.6-style enumerated lawful-bases list; general processing is permitted on a disclosed-purpose basis subject to consumer opt-out rights for targeted advertising, sale, and (per typical Virginia-model structure) profiling.
Claims (1):
TIPA follows a disclosed-purpose/opt-out processing model rather than an enumerated lawful-bases framework, granting consumers rights to opt out of the sale of personal data and processing for targeted advertising.
Consent ThresholdsAmber
TIPA contains a statutory definition of 'consent' as a defined term, consistent with other Virginia-lineage state laws, though the precise freely-given/informed/revocable standard text was not independently retrieved.
Claims (1):
TIPA contains a statutory definition of 'consent' among its enumerated defined terms.
Special CategoriesAmber
TIPA defines 'sensitive data' and 'biometric data' as distinct categories; Tennessee is reported among the 2023 wave of states whose bills included an opt-in consent right for sensitive-data processing, and TIPA is grouped among states that narrowly define consumer health data as limited to a health diagnosis (rather than broader health status/condition).
Claims (2):
Tennessee was among the states whose 2023 comprehensive privacy bills included a right requiring opt-in consumer consent before a controller may process sensitive data.
TIPA is grouped among US state privacy laws (with Indiana, Iowa, Kentucky, Minnesota, Montana, Nebraska, Texas, and Virginia) that define 'consumer health data' narrowly as limited to a health diagnosis rather than broader health status or condition.
Pseudonymisation And AnonymisationAmber
TIPA's 'personal data' definition excludes de-identified and aggregate data, implying a de-identification safe harbour, but the statutory de-identification standard (e.g., reasonable-linkability test, contractual commitments) was not independently confirmed.
Claims (1):
TIPA excludes de-identified data and aggregate data from the scope of 'personal data,' functioning as a de-identification carve-out.
Category narrative65 words
TIPA does not adopt a GDPR-style enumerated lawful-bases model; instead it follows the US 'notice-and-choice plus opt-out' structure common to Virginia-lineage state laws, layering an opt-in consent requirement onto a defined 'sensitive data' category (including biometric data) while general processing proceeds on a disclosed-purpose/opt-out basis. Several sub-module details (precise consent mechanics, pseudonymisation safe harbours) rely on secondary legislative-tracking sources rather than fetched primary statutory text.
Sources and claims (5)
ProbableDataGuidance — TIPA follows a disclosed-purpose/opt-out processing model rather than an enumerated lawful-bases framework, granting consumers rights to opt out of the sale of personal data and processing for targeted advertising.observed
ProbableDataGuidance — TIPA contains a statutory definition of 'consent' among its enumerated defined terms.observed
ProbableIAPP — Tennessee was among the states whose 2023 comprehensive privacy bills included a right requiring opt-in consumer consent before a controller may process sensitive data.observed
ProbableIAPP — TIPA is grouped among US state privacy laws (with Indiana, Iowa, Kentucky, Minnesota, Montana, Nebraska, Texas, and Virginia) that define 'consumer health data' narrowly as limited to a health diagnosis rather than broader health status or condition.observed
ProbableDataGuidance — TIPA excludes de-identified data and aggregate data from the scope of 'personal data,' functioning as a de-identification carve-out.observed
Traffic-light rationale — GreenCore rights and response deadline are corroborated across multiple independent secondary sources.
Sub-modules (5)
Access RightGreen
TIPA grants consumers a right of access to their personal data held by controllers.
Claims (1):
TIPA grants Tennessee consumers a right to access personal data held about them by a controller.
Rectification And ErasureGreen
TIPA grants consumers rights to correct inaccuracies and to delete personal data.
Claims (1):
TIPA grants consumers rights to correct inaccurate personal data and to delete personal data held by a controller.
Restriction And ObjectionAmber
TIPA's opt-out rights over targeted advertising and sale of personal data function as the statute's restriction/objection mechanism; explicit profiling opt-out was not independently confirmed.
Claims (1):
TIPA grants consumers the right to opt out of the processing of their personal data for targeted advertising and the sale of personal data.
Data PortabilityAmber
TIPA's originating bill (SB 0073) description included a data portability right for consumers.
Claims (1):
TIPA's originating legislation grants consumers a data portability right.
Deadlines And Response WindowsGreen
Controllers must respond to consumer rights requests within a 45-day window, consistent with the Virginia/Colorado/Connecticut model.
Claims (1):
TIPA requires controllers to respond to consumer data subject requests within a 45-day window.
Category narrative38 words
TIPA grants Tennessee consumers a standard Virginia-model rights package: access, correction, deletion, data portability, and opt-out of targeted advertising/sale/(typically) profiling, with a 45-day controller response window. Exact appeal-process and extension mechanics were not independently verified against primary text.
Sources and claims (5)
ConfirmedDataGuidance — TIPA grants Tennessee consumers a right to access personal data held about them by a controller.observed
ConfirmedDataGuidance — TIPA grants consumers rights to correct inaccurate personal data and to delete personal data held by a controller.observed
ProbableDataGuidance — TIPA grants consumers the right to opt out of the processing of their personal data for targeted advertising and the sale of personal data.observed
ProbableDataGuidance — TIPA's originating legislation grants consumers a data portability right.observed
ConfirmedIAPP — TIPA requires controllers to respond to consumer data subject requests within a 45-day window.observed
Core accountability and breach-notification duties are well corroborated; DPO, ROPA, joint-controller, and retention-limit provisions could not be confirmed from available sources.
Primary frameworkTennessee Information Protection Act (TIPA); Tenn. Code Ann. §47-18-2107
Traffic-light rationale — AmberCore accountability and breach-notification duties are well corroborated; DPO, ROPA, joint-controller, and retention-limit provisions could not be confirmed from available sources.
Sub-modules (7)
Accountability And DpiaGreen
Controllers must conduct Data Protection Assessments (DPAs) for certain higher-risk processing activities, TIPA's functional equivalent to GDPR Art.35 DPIAs.
Claims (1):
TIPA requires controllers to conduct Data Protection Assessments (DPAs) as part of their accountability obligations.
Dpo RequirementsRed
No standalone Data Protection Officer appointment or independence requirement was identified under TIPA.
Claims (1):
No provision requiring appointment of a Data Protection Officer was identified under TIPA.
Ropa RequirementsRed
No explicit records-of-processing-activities obligation analogous to GDPR Art.30 was identified; DPAs may partially substitute but are not equivalent in scope.
Claims (1):
No GDPR Art.30-style formal records-of-processing-activities obligation was identified under TIPA.
Joint Controller ArrangementsAmber
TIPA requires processors to adhere to controller instructions, implying a contractual controller-processor relationship, but no distinct 'joint controller' regime was identified.
Claims (1):
TIPA requires processors to adhere to controller instructions when processing personal data on the controller's behalf.
Security MeasuresAmber
Controllers must ensure data security, though the specific 'reasonable administrative, technical, and physical' security standard language was not independently confirmed for TIPA.
Claims (1):
TIPA requires controllers to ensure the security of personal data they process.
Breach NotificationGreen
Tenn. Code Ann. §47-18-2107 requires notification of a breach of system security involving personal consumer information; TIPA does not appear to separately restate breach-notification duties.
Claims (1):
Tenn. Code Ann. §47-18-2107 requires notification following a breach of system security that materially compromises the security, confidentiality, or integrity of personal consumer information, whether the compromised data was encrypted or unencrypted.
Retention And DisposalRed
No specific data-retention limitation or disposal-duty provision was identified in TIPA or the breach statute during this research pass.
Claims (1):
No specific statutory data-retention-limitation or disposal-duty provision was identified under TIPA or Tennessee's breach-notification statute.
Category narrative49 words
TIPA imposes accountability obligations including mandatory Data Protection Assessments (DPAs), a general data-security duty on controllers, and contractual constraints on processors, plus separate breach-notification duties under Tenn. Code Ann. §47-18-2107. GDPR-style DPO appointment and formal Records-of-Processing (ROPA) obligations were not identified in retrieved sources and are treated as gaps.
Sources and claims (7)
ConfirmedDataGuidance — TIPA requires controllers to conduct Data Protection Assessments (DPAs) as part of their accountability obligations.observed
UncertainDataGuidance — No provision requiring appointment of a Data Protection Officer was identified under TIPA.observed
UncertainDataGuidance — No GDPR Art.30-style formal records-of-processing-activities obligation was identified under TIPA.observed
ProbableDataGuidance — TIPA requires processors to adhere to controller instructions when processing personal data on the controller's behalf.observed
ProbableDataGuidance — TIPA requires controllers to ensure the security of personal data they process.observed
ConfirmedState of Tennessee — Tenn. Code Ann. §47-18-2107 requires notification following a breach of system security that materially compromises the security, confidentiality, or integrity of personal consumer information, whether the compromised data was encrypted or unencrypted.observed
UncertainDataGuidance — No specific statutory data-retention-limitation or disposal-duty provision was identified under TIPA or Tennessee's breach-notification statute.observed
No cross-border transfer mechanism, adequacy framework, or localisation rule exists under TIPA or Tennessee sectoral law; this reflects the genuine absence of such a regime rather than incomplete research.
Primary frameworkTennessee Information Protection Act (TIPA)
Traffic-light rationale — RedNo cross-border transfer mechanism, adequacy framework, or localisation rule exists under TIPA or Tennessee sectoral law; this reflects the genuine absence of such a regime rather than incomplete research.
Sub-modules (6)
Transfer MechanismsAmber
No dedicated cross-border transfer mechanism exists under TIPA; onward transfer to processors relies on the general controller-processor instruction/contract requirement.
Claims (1):
TIPA governs data transfers to third-party processors indirectly through its requirement that processors adhere to controller instructions, rather than through a dedicated cross-border transfer mechanism.
Adequacy ReceivedRed
Not applicable — US states do not receive adequacy decisions from foreign regimes.
Absence provenance: not recorded. Searched: not recorded.
Adequacy GrantedRed
Not applicable — Tennessee, as a US state, does not issue adequacy determinations regarding foreign jurisdictions.
Absence provenance: not recorded. Searched: not recorded.
Sccs And BcrsRed
TIPA contains no SCC or BCR mechanism; such instruments are not part of the US state comprehensive-privacy-law model.
Absence provenance: not recorded. Searched: not recorded.
Transfer Impact AssessmentRed
No transfer-impact-assessment requirement was identified under TIPA.
Absence provenance: not recorded. Searched: not recorded.
Data LocalisationRed
No data-localisation mandate was identified under Tennessee law.
Absence provenance: not recorded. Searched: not recorded.
Category narrative58 words
TIPA, consistent with the US state comprehensive-privacy-law model, contains no EU-style cross-border transfer regime: there are no adequacy decisions (received or granted), no SCC/BCR mechanisms, no transfer-impact-assessment requirement, and no data-localisation mandate. Transfers to processors are governed indirectly through the controller-processor contractual instruction requirement. This is an explicit structural gap relative to GDPR-style regimes, not a silent omission.
Sources and claims (1)
UncertainDataGuidance — TIPA governs data transfers to third-party processors indirectly through its requirement that processors adhere to controller instructions, rather than through a dedicated cross-border transfer mechanism.observed
One sector overlay (insurance data security) is confirmed via primary statutory text; other sectoral exemptions (GLBA/HIPAA/FERPA/FCRA/employment) are inferred from cross-state legislative pattern only, not independently confirmed for Tennessee.
Primary frameworkTennessee Information Protection Act (TIPA); Tennessee Insurance Data Security Law (Pub. Ch. 345)
Traffic-light rationale — AmberOne sector overlay (insurance data security) is confirmed via primary statutory text; other sectoral exemptions (GLBA/HIPAA/FERPA/FCRA/employment) are inferred from cross-state legislative pattern only, not independently confirmed for Tennessee.
Sub-modules (7)
Financial Sector OverlayAmber
GLBA-regulated financial institutions and GLBA-covered data are commonly exempted from Virginia-model state privacy laws; a Tennessee-specific exemption clause was not independently confirmed.
Claims (1):
GLBA-regulated financial institutions and GLBA-covered personal data are likely exempted from TIPA, consistent with the standard carve-out pattern in peer Virginia-model state privacy laws.
Health Sector OverlayAmber
HIPAA-covered entities/data are commonly exempted under Virginia-model laws; TIPA additionally uses a narrow diagnosis-only definition of consumer health data as sensitive data.
Claims (1):
HIPAA-covered entities and HIPAA-regulated protected health information are likely exempted from TIPA, consistent with peer state-law patterns, while TIPA separately treats non-HIPAA consumer health diagnosis data as 'sensitive data.'
Telecoms And EprivacyRed
No Tennessee-specific ePrivacy/cookie-consent statute distinct from TIPA's general opt-out rights was identified.
Absence provenance: not recorded. Searched: not recorded.
Employment DataAmber
Virginia-model laws typically exclude employment/HR data from the 'consumer' definition; a Tennessee-specific carve-out was not independently confirmed.
Claims (1):
Employment/HR-related personal data is likely excluded from TIPA's definition of regulated 'consumer' data, consistent with peer Virginia-model laws.
Credit And ScoringAmber
FCRA-regulated credit data is commonly exempted under peer state laws; a Tennessee-specific exemption was not independently confirmed.
Claims (1):
FCRA-regulated consumer report data is likely exempted from TIPA, consistent with peer state-law patterns.
EducationRed
FERPA operates as the federal baseline for education records; no Tennessee-specific education-sector data-protection overlay beyond TIPA's general exemptions was identified.
Absence provenance: not recorded. Searched: not recorded.
InsuranceGreen
Tennessee enacted a dedicated Insurance Data Security Law (Public Chapter 345, HB 766) amending Tenn. Code Ann. Title 56, Chapter 2, layering sector-specific data-security duties on licensed insurers.
Claims (1):
Tennessee enacted an Insurance Data Security Law (Public Chapter 345, House Bill 766) amending Tennessee Code Annotated Title 56, Chapter 2, to impose data-security obligations on licensed insurers.
Category narrative74 words
As with peer Virginia-lineage state laws, TIPA is expected to carry standard sectoral carve-outs (GLBA-regulated financial data, HIPAA-regulated health data, FERPA-regulated education data, FCRA-regulated credit data, and employment/HR data), but the Tennessee-specific exemption clauses were not independently retrieved from primary text in this pass and are flagged as inferred-by-pattern rather than confirmed. A confirmed, TIPA-independent sector overlay is Tennessee's separate insurance-sector data-security law (Public Chapter 345, amending Tenn. Code Ann. Title 56, Chapter 2).
Sources and claims (5)
UncertainDataGuidance — GLBA-regulated financial institutions and GLBA-covered personal data are likely exempted from TIPA, consistent with the standard carve-out pattern in peer Virginia-model state privacy laws.observed
UncertainIAPP — HIPAA-covered entities and HIPAA-regulated protected health information are likely exempted from TIPA, consistent with peer state-law patterns, while TIPA separately treats non-HIPAA consumer health diagnosis data as 'sensitive data.'observed
UncertainDataGuidance — Employment/HR-related personal data is likely excluded from TIPA's definition of regulated 'consumer' data, consistent with peer Virginia-model laws.observed
UncertainDataGuidance — FCRA-regulated consumer report data is likely exempted from TIPA, consistent with peer state-law patterns.observed
ConfirmedState of Tennessee — Tennessee enacted an Insurance Data Security Law (Public Chapter 345, House Bill 766) amending Tennessee Code Annotated Title 56, Chapter 2, to impose data-security obligations on licensed insurers.observed
The core opt-out right is corroborated; several sub-modules common to more prescriptive state laws (dark patterns, universal opt-out signals, clean rooms) are unconfirmed gaps for Tennessee specifically.
Primary frameworkTennessee Information Protection Act (TIPA)
Traffic-light rationale — AmberThe core opt-out right is corroborated; several sub-modules common to more prescriptive state laws (dark patterns, universal opt-out signals, clean rooms) are unconfirmed gaps for Tennessee specifically.
Sub-modules (6)
Cookies And TrackersAmber
No EU-style cookie-consent regime exists; the functional equivalent is TIPA's opt-out right for targeted-advertising-related tracking.
Claims (1):
TIPA's opt-out right over processing for targeted advertising functions as the statute's principal mechanism for consumer control over tracking-based adtech, absent a dedicated cookie-consent regime.
Dark PatternsRed
No Tennessee-specific dark-pattern prohibition (unlike Connecticut/California) was identified under TIPA.
Absence provenance: not recorded. Searched: not recorded.
Opt Out SignalsRed
No confirmation was found that TIPA requires or recognizes universal opt-out mechanisms (e.g., Global Privacy Control), unlike Colorado, Montana, and California.
Claims (1):
No evidence was found that TIPA mandates recognition of a universal opt-out mechanism (e.g., Global Privacy Control) as a method of exercising consumer opt-out rights, distinguishing it from Colorado and Montana's laws.
Clean Rooms And DcrRed
No clean-room or data-collaboration-room-specific rule was identified under Tennessee law.
Absence provenance: not recorded. Searched: not recorded.
Cross Context AdvertisingAmber
TIPA provides consumers a right to opt out of the sale of personal data and processing for targeted advertising, TIPA's analogue to CPRA's 'sale'/'share' opt-out.
Claims (1):
TIPA grants consumers a right to opt out of the sale of personal data to third parties and of processing for targeted advertising.
Direct MarketingAmber
No Tennessee-specific direct-marketing consent/suppression statute distinct from TIPA's general opt-out right was identified.
Claims (1):
TIPA grants consumers a right to opt out of the sale of personal data to third parties and of processing for targeted advertising.
Category narrative38 words
TIPA's principal adtech-relevant mechanism is the consumer opt-out right over targeted advertising and sale of personal data. No Tennessee-specific cookie-consent statute, dark-pattern prohibition, universal opt-out signal (e.g., GPC) recognition, or clean-room/data-collaboration rule was identified in this research pass.
Sources and claims (3)
ProbableDataGuidance — TIPA's opt-out right over processing for targeted advertising functions as the statute's principal mechanism for consumer control over tracking-based adtech, absent a dedicated cookie-consent regime.observed
UncertainIAPP — No evidence was found that TIPA mandates recognition of a universal opt-out mechanism (e.g., Global Privacy Control) as a method of exercising consumer opt-out rights, distinguishing it from Colorado and Montana's laws.observed
ProbableDataGuidance — TIPA grants consumers a right to opt out of the sale of personal data to third parties and of processing for targeted advertising.observed
Biometric data category is corroborated; ADM transparency, AI risk assessment, genetic data, and surveillance carve-out sub-modules lack direct confirming evidence.
Primary frameworkTennessee Information Protection Act (TIPA)
Traffic-light rationale — AmberBiometric data category is corroborated; ADM transparency, AI risk assessment, genetic data, and surveillance carve-out sub-modules lack direct confirming evidence.
Sub-modules (6)
Profiling RestrictionsRed
No TIPA-specific profiling-restriction or profiling opt-out clause was independently confirmed, though such a right is common in peer Virginia-model laws.
Absence provenance: not recorded. Searched: not recorded.
Automated Decision Making TransparencyRed
No ADM transparency or explanation right under TIPA was identified.
Absence provenance: not recorded. Searched: not recorded.
Ai Risk AssessmentsRed
No TIPA-specific AI risk-assessment obligation (distinct from general DPAs) was identified in this research pass.
Absence provenance: not recorded. Searched: not recorded.
Biometric RegimeAmber
TIPA defines 'biometric data' as an enumerated category, treated among the statute's sensitive-data types requiring heightened protection.
Claims (1):
TIPA defines 'biometric data' as an enumerated data category subject to the statute's sensitive-data protections.
Genetic DataRed
No standalone genetic-data-specific regime distinct from the general 'sensitive data' category was confirmed.
Absence provenance: not recorded. Searched: not recorded.
State Surveillance CarveoutsRed
No Tennessee-specific national-security or government-surveillance carve-out clause under TIPA was independently confirmed, though such carve-outs (excluding government entities from 'controller' status) are typical of peer state laws.
Absence provenance: not recorded. Searched: not recorded.
Category narrative44 words
TIPA defines 'biometric data' as a distinct, likely sensitive-data category subject to opt-in consent. Automated-decision-making transparency rights, AI-specific risk-assessment obligations, genetic-data-specific rules, and government/national-security carve-outs were not independently confirmed for Tennessee in this research pass and are flagged as gaps rather than silently omitted.
Sources and claims (1)
ProbableDataGuidance — TIPA defines 'biometric data' as an enumerated data category subject to the statute's sensitive-data protections.observed
No TIPA-specific children/vulnerable-groups provisions were confirmed beyond the general federal COPPA baseline; explicit absence is recorded rather than silently omitted.
Traffic-light rationale — RedNo TIPA-specific children/vulnerable-groups provisions were confirmed beyond the general federal COPPA baseline; explicit absence is recorded rather than silently omitted.
Sub-modules (5)
Age VerificationRed
No Tennessee-specific age-verification mandate under TIPA was identified.
Absence provenance: not recorded. Searched: not recorded.
Parental ConsentAmber
Federal COPPA requires verifiable parental consent for processing personal information of children under 13; a TIPA-specific cross-reference to COPPA (common in peer Virginia-model laws) was not independently confirmed for Tennessee.
Claims (1):
Federal COPPA imposes verifiable-parental-consent requirements on operators of websites or online services directed to children under 13, or with actual knowledge of collecting personal information from children under 13, applicable in Tennessee as elsewhere in the US.
Minor Profiling BansRed
No minor-specific profiling ban under TIPA was identified.
Absence provenance: not recorded. Searched: not recorded.
Education SettingsRed
No Tennessee-specific education-setting data-protection rule beyond the federal FERPA baseline was identified.
Absence provenance: not recorded. Searched: not recorded.
Dependent AdultsRed
No dependent-adult/elderly-specific data-protection provision was identified under Tennessee law.
Absence provenance: not recorded. Searched: not recorded.
Category narrative41 words
No Tennessee-specific age-verification, parental-consent mechanics, minor-profiling ban, education-setting rule, or dependent-adult protection was independently confirmed for TIPA in this research pass; federal COPPA operates as the baseline for children under 13. This module is a significant research gap requiring primary-source escalation.
Sources and claims (1)
ConfirmedFTC — Federal COPPA imposes verifiable-parental-consent requirements on operators of websites or online services directed to children under 13, or with actual knowledge of collecting personal information from children under 13, applicable in Tennessee as elsewhere in the US.observed
Statutory enforcement architecture (AG-exclusive, 60-day cure, NIST affirmative defense) is well corroborated; actual enforcement track record and regulator capacity signals are unconfirmed gaps just over one year after the law's effective date.
Primary frameworkTennessee Information Protection Act (TIPA)
Traffic-light rationale — AmberStatutory enforcement architecture (AG-exclusive, 60-day cure, NIST affirmative defense) is well corroborated; actual enforcement track record and regulator capacity signals are unconfirmed gaps just over one year after the law's effective date.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
The Attorney General has exclusive enforcement authority and must provide a nonsunsetting 60-day cure period before initiating an enforcement action; TIPA also grants an affirmative defense to entities whose privacy programs reasonably conform to recognized standards such as the NIST Privacy Framework.
Claims (2):
TIPA grants covered entities a nonsunsetting 60-day right to cure alleged violations before the Attorney General may initiate an enforcement action.
TIPA offers an affirmative defense against enforcement actions to controllers/processors that maintain a privacy program reasonably conforming to recognized standards, including the NIST Privacy Framework, the APEC Cross-Border Privacy Rules, and the APEC Privacy Recognition for Processors System.
Enforcement Activity IndexAmber
The Tennessee Attorney General issued compliance guidance ahead of TIPA's 1 July 2025 effective date, but no confirmed enforcement actions, fines, or settlements under TIPA were identified in this research pass.
Claims (1):
The Tennessee Attorney General published compliance guidance related to TIPA in advance of the statute's effective date.
Regulator Funding And CapacityRed
No specific data on the Attorney General's privacy-enforcement staffing, budget, or headcount was identified.
Absence provenance: not recorded. Searched: not recorded.
Collective Redress And Class ActionsAmber
TIPA provides no private right of action or class-action mechanism for consumers; redress runs solely through Attorney General enforcement.
Claims (1):
TIPA does not create a private right of action for consumers; enforcement is exclusive to the Tennessee Attorney General.
Private Right Of ActionAmber
TIPA does not create a private right of action; enforcement is exclusively vested in the Attorney General.
Claims (1):
TIPA does not create a private right of action for consumers; enforcement is exclusive to the Tennessee Attorney General.
Recent Developments 180DRed
No material TIPA amendments, new implementing guidance, litigation, or enforcement developments within the last 180 days (approx. February-August 2026) were identified in this research pass.
Absence provenance: not recorded. Searched: not recorded.
Category narrative86 words
TIPA enforcement is vested exclusively in the Tennessee Attorney General, who must afford covered entities a nonsunsetting 60-day cure period before initiating an action; the statute offers an unusual affirmative defense to enforcement where a controller/processor maintains a privacy program reasonably conforming to the NIST Privacy Framework, ISO 31700, or APEC CBPR/PRP standards. TIPA provides no private right of action. No confirmed TIPA enforcement actions, fines, or settlements were identified as of the dispatch date, and no material developments in the last 180 days were found.
Sources and claims (4)
ConfirmedIAPP — TIPA grants covered entities a nonsunsetting 60-day right to cure alleged violations before the Attorney General may initiate an enforcement action.observed
ConfirmedIAPP — TIPA offers an affirmative defense against enforcement actions to controllers/processors that maintain a privacy program reasonably conforming to recognized standards, including the NIST Privacy Framework, the APEC Cross-Border Privacy Rules, and the APEC Privacy Recognition for Processors System.observed
UncertainDataGuidance — The Tennessee Attorney General published compliance guidance related to TIPA in advance of the statute's effective date.observed
ConfirmedIAPP — TIPA does not create a private right of action for consumers; enforcement is exclusive to the Tennessee Attorney General.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for United States – Tennessee
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 40 claim(s), 18 source(s) in the cumulative register.
GDPR article map
Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).
regulator_and_framework, data_subject_rights, and the enforcement_and_redress core (AG-exclusive enforcement, 60-day cure, NIST affirmative defense, no private right of action) rest on T2/T3 secondary reporting (DataGuidance, IAPP) corroborated across multiple independent outlets, plus one directly-retrieved T1 primary text (Tenn. Code Ann. §47-18-2107 breach statute, and the Insurance Data Security Law Public Chapter 345). controller_processor_duties is partially T1/T3 (breach notice confirmed T1; DPA/security duties T3) with DPO, ROPA, and retention sub-modules unconfirmed (T4-equivalent gaps). lawful_processing_and_special_data and sectoral_watch rely heavily on cross-state pattern inference (T3/Uncertain) rather than TN-specific primary text for GLBA/HIPAA/FERPA/FCRA/employment carve-outs. cross_border_and_adequacy, algorithmic_biometric_and_surveillance_governance, and children_and_vulnerable_groups are the weakest modules, largely populated with explicit absent_field_provenance gap narratives rather than confirmed claims, reflecting both genuine regime gaps (no EU-style transfer regime exists) and research-access limits (no primary TIPA statutory text was directly fetched; only secondary legislative-tracking summaries).
Unresolved questions (7):
The injected seed's disambiguation stated Tennessee has NO comprehensive consumer-privacy statute; research found this to be stale as of the 2026-08-06 dispatch date given TIPA's 1 July 2025 effective date. Operator should confirm whether the seed corpus requires a refresh cycle for US-TN.
Exact codification (Tennessee Code Annotated title/chapter/section numbers) for TIPA's substantive provisions was not independently verified against primary code text; only secondary summaries were available.
Precise numeric applicability thresholds (25,000 vs 175,000 consumers, 50% revenue-from-sale test) were reported with some internal inconsistency across secondary sources and should be verified against the enrolled bill/codified statute.
Whether TIPA contains explicit GLBA/HIPAA/FERPA/FCRA/employment-data exemption clauses (assumed by pattern from peer Virginia-model laws) requires primary-text confirmation.
Whether TIPA includes a distinct profiling opt-out right and/or a children's-data consent provision cross-referencing COPPA was not confirmed from retrieved sources.
No TIPA enforcement actions, settlements, or fines were located as of dispatch date (13 months post-effective-date); unclear whether this reflects true regulatory quiescence or a research-access gap.
The seed-provided regulator URL (naag.org) is the national multistate-AG coordination body, not a Tennessee-specific Attorney General consumer-protection webpage; the correct dedicated TN AG consumer-protection/privacy enforcement URL should be sourced and substituted.