Tennessee Information Protection Act (Tenn. Code Ann. 47-18-3201 et seq., as enacted by Public Chapter 408 of 2023, HB 1181)
Below is what the official text of Tennessee Information Protection Act (Tenn. Code Ann. 47-18-3201 et seq., as enacted by Public Chapter 408 of 2023, HB 1181) states about whom it covers, when it applies to a business and since when. Where the pages we read do not say, the row says "not stated".
The wording shown is taken from the official page named in each row. The duties of a business and the contents of a privacy notice are in the paid checklist.
Typical situations, run through the same conditions as the check
- A for-profit US business with 150,000 people in Tennessee and $30 million revenue: Not triggered by these answers.
- The same business with 8,000 people in Tennessee: Not triggered by these answers.
- A US business with no users in Tennessee: Not triggered by these answers.
Judged on 2026-10-06. Our law data was last verified on 2026-10-06; a law that took effect after that date is not in it. These situations leave other answers blank or neutral: use the check for your own.
What the official text states
| Question | What the official text states | Source |
|---|---|---|
| What it covers | The Act adds a new part to Tenn. Code Ann. Title 47, Chapter 18 that binds persons conducting business in Tennessee producing products or services that target Tennessee residents and that exceed $25,000,000 in revenue and meet a personal-information volume threshold.Official wording47-18-3202. Scope. This part applies to persons that conduct business in this state producing products or services that target residents of this state and that: (1) Exceed twenty-five million dollars ($25,000,000) in revenue; and | publications.tnsosfiles.com read 2026-10-06 |
| When it applies to a business | Applies to persons that conduct business in Tennessee producing products or services that target Tennessee residents, that exceed $25,000,000 in revenue, and that either control or process personal information of at least 25,000 consumers while deriving more than 50% of gross revenue from the sale of personal information, or, during a calendar year, control or process personal information of at least 175,000 consumers. Conditions to check: Business must conduct business in Tennessee and produce products or services that target Tennessee residents (the meaning of targeting is not covered by our questions). The text says 'revenue' without stating annual or global; the $25,000,000 test is applied here to annual revenue. Exempt entities (47-18-3210): state and local government bodies, financial institutions and their affiliates or GLBA-subject data, insurers licensed under title 56, HIPAA covered entities and business associates, nonprofit organizations (defined to include Tennessee nonprofit corporations and organizations exempt under 26 U.S.C. 501-530), institutions of higher education, and several data types (PHI, health records, research data, employee data, etc.). Counts are of consumers, which may differ from 'people in one place' where the business serves several places. Official wordingin revenue; and (2) (A) Control or process personal information of at least twenty-five thousand (25,000) consumers and derive more than fifty percent (50%) of gross revenue from the sale of personal information; or (B) During a calendar year, control or process personal information of at least one hundred seventy-five thousand (175,000) consumers. | publications.tnsosfiles.com read 2026-10-06 |
| In force from | 2025-07-01 Section 6 of Public Chapter 408: the act takes effect July 1, 2025. No later amendment was read. Official wordingSECTION 6. This act takes effect July 1, 2025 | publications.tnsosfiles.com read 2026-10-06 |
| Privacy notice | Included in the paid checklist. See the checklist | — |
| Consent and opt-out | Included in the paid checklist. See the checklist | — |
| Rights of individuals | Included in the paid checklist. See the checklist | — |
| Data protection officer | Not stated on the official pages we read. the text we read (Public Chapter 408) contains no provision requiring a data protection or privacy officer | — |
| Breach notification | Not stated on the official pages we read. separate breach-notification statute not read | — |
| What the privacy notice must contain | Included in the paid checklist. See the checklist | — |
What we do not cover
These areas are outside this site, so nothing on this page says anything about them:
- Privacy laws for particular sectors (for example health care, banking and credit, education)
- Rules specific to children's online privacy
- Cookie and electronic-communications rules (including consent for cookies and marketing messages)
- Employee, job applicant and contractor data
- Rules on sending personal data to other countries
- US state data-breach notification laws (a separate set of state laws)
- US state privacy laws that are not yet in force, and state laws on particular topics (for example biometric or health data)
- Privacy laws of countries that are not listed here
- Planned changes to the laws listed here