Privacy laws · Tennessee

Tennessee Information Protection Act.

Requires both $25M revenue AND consumer threshold. Includes affirmative defense for businesses with privacy programs conforming to NIST frameworks.

/ Diagnostic check ClearConsent scans your storefront for signals related to this law — consent banner state, GPC support, Do Not Sell links, privacy policy disclosures, cookies, and trackers.

/ Effective
2025-07-01
Effective date
When the law took effect or will take effect.
/ Consumers
25,000
Consumer threshold
The number of Tennessee residents whose data triggers compliance.
/ Revenue
$25,000,000
Revenue threshold
Annual revenue trigger for compliance, if applicable.
01 / Key requirements

What the law requires.

  • 01Privacy notice
  • 02Right to access, correct, delete personal data
  • 03Right to data portability
  • 04Right to opt-out of sale, targeted advertising, profiling
  • 05Data protection assessments
  • 06Consent for sensitive data
  • 07NIST framework compliance as affirmative defense
02 / Enforcement

Penalties & cure period.

Penalties

Up to $7,500 per violation.

Cure period

60-day cure period

Enforcement agency

Attorney General

03 / E-commerce

What this means for
your store.

Affirmative defense available if you maintain a NIST-conforming privacy program. Must meet both revenue AND consumer thresholds.

Scan your store for TIPA privacy gaps →