Rhode Island · verified through August 25, 2026

Rhode Island: law status and evidence context.

Law status, direct attached-library attribution, and public enforcement context are shown separately. A zero direct total does not mean no enforcement exists.

RI · 6 requirements mapped / control outcomes supported

Law status

Verified comprehensive law

Yes - Rhode Island Data Transparency and Privacy Protection Act

Official name / citation
R.I. Gen. Laws ch. 6-48.1, §§ 6-48.1-1 to 6-48.1-10 (P.L. 2024 ch. 453, enacted June 29, 2024)
Status / effective date
Enacted; provisions effective January 1, 2026 per the codified chapter page
Principal enforcer
Rhode Island Attorney General

Direct attached-library attribution

0 cases · $0

These totals are assigned solely by the attachment’s state heading. Shared multistate totals are not allocated in full to every state.

The attached library does not enumerate participant-level allocations for every multistate matter; shared settlement totals are presented once at the national level and are not duplicated into state totals.

Official law sources

Other generally applicable PII law

Also: Rhode Island Identity Theft Protection Act of 2015, R.I. Gen. Laws §§ 11-49.3-1 to 11-49.3-6 - https://webserver.rilegislature.gov/PublicLaws/law15/law15148.htm

Public enforcement context

Tier 1

Equifax Inc.

Up to $425 million consumer restitution fund; Rhode Island share stated as $1 million · July 22, 2019

Rhode Island participated in the 50-AG Equifax settlement over the 2017 breach affecting about 147 million consumers.

Legal basis: State consumer protection and data-security claims (statutes not named on the page)

Official case source (opens in a new tab)

Mapped control outcomes

1 personal data inventory/data map; 2 sensitive-data discovery; 3 downstream copy tracking; 8 breach blast-radius analysis; 9 retention/minimization; 10 regulator audit evidence

Kestryl can evidence where regulated personal data actually resides across structured stores and unstructured attachments/images, produce audit rows and evidence packs showing when each location was discovered and reviewed, and apply structured-data remediation modes (mask, vault, strip) to reduce exposure. It does not alter source attachments or documents, and its output is technical evidence supporting controls, not proof of legal compliance.