Tennessee Information Protection Act.
Requires both $25M revenue AND consumer threshold. Includes affirmative defense for businesses with privacy programs conforming to NIST frameworks.
/ Diagnostic check ClearConsent scans your storefront for signals related to this law — consent banner state, GPC support, Do Not Sell links, privacy policy disclosures, cookies, and trackers.
What the law requires.
- 01Privacy notice
- 02Right to access, correct, delete personal data
- 03Right to data portability
- 04Right to opt-out of sale, targeted advertising, profiling
- 05Data protection assessments
- 06Consent for sensitive data
- 07NIST framework compliance as affirmative defense
Penalties & cure period.
Up to $7,500 per violation.
60-day cure period
Attorney General
What this means for
your store.
Affirmative defense available if you maintain a NIST-conforming privacy program. Must meet both revenue AND consumer thresholds.