Law status
Verified comprehensive law
Yes - Rhode Island Data Transparency and Privacy Protection Act
- Official name / citation
- R.I. Gen. Laws ch. 6-48.1, §§ 6-48.1-1 to 6-48.1-10 (P.L. 2024 ch. 453, enacted June 29, 2024)
- Status / effective date
- Enacted; provisions effective January 1, 2026 per the codified chapter page
- Principal enforcer
- Rhode Island Attorney General
Official-source case register
1 verified case
Company, date, amount, legal basis, why the action was brought and the exact official URL are available in the dedicated register. Shared multistate amounts are not summed as unique state penalties.
Official law sources
- Official state source (opens in a new tab)
- Official state source (opens in a new tab)
- Official state source (opens in a new tab)
Other generally applicable PII law
Also: Rhode Island Identity Theft Protection Act of 2015, R.I. Gen. Laws §§ 11-49.3-1 to 11-49.3-6 - https://webserver.rilegislature.gov/PublicLaws/law15/law15148.htm
Mapped control outcomes
1 personal data inventory/data map; 2 sensitive-data discovery; 3 downstream copy tracking; 8 breach blast-radius analysis; 9 retention/minimization; 10 regulator audit evidence
Kestryl can evidence where regulated personal data actually resides across structured stores and unstructured attachments/images, produce audit rows and evidence packs showing when each location was discovered and reviewed, and apply structured-data remediation modes (mask, vault, strip) to reduce exposure. It does not alter source attachments or documents, and its output is technical evidence supporting controls, not proof of legal compliance.
Educational information, not legal advice. This reference snapshot is dated September 16, 2026; confirm current law, applicability, exceptions, official status, and reporting decisions with qualified counsel and the relevant authority.