{
  "type": "practice-guide",
  "canonical": "https://openagreements.org/practice-guides/privacy/us/tennessee",
  "links": [
    {
      "rel": "self",
      "href": "https://openagreements.org/practice-guides/privacy/us/tennessee.json",
      "type": "application/json"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/tennessee",
      "type": "text/html"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/tennessee/markdown",
      "type": "text/markdown"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/tennessee/json",
      "type": "application/json"
    }
  ],
  "data": {
    "topic": "privacy",
    "state": "tennessee",
    "frontmatter": {
      "title": "Tennessee Consumer Privacy Law (TIPA)",
      "description": "The Tennessee Information Protection Act gives Tennessee consumers rights over their personal information and imposes notice, contracting, and consent duties on large controllers — it stands out for an unusually high entry bar (over $25 million in revenue plus large consumer-volume tests) and a one-of-a-kind affirmative defense for businesses that maintain a written privacy program conforming to the NIST privacy framework, enforced exclusively by the Attorney General with no private right of action.",
      "state": "Tennessee",
      "lastReviewed": "2026-06-06",
      "license": "CC BY 4.0",
      "authors": [
        "steven-obiajulu"
      ],
      "summary": {
        "keyLaw": "Tenn. Code Ann. §§ 47-18-3301 et seq. (Tennessee Information Protection Act)",
        "appliesTo": "Persons doing business in Tennessee (or targeting residents) that exceed $25 million in revenue AND either process the information of 175,000+ consumers a year, or 25,000+ while deriving over 50% of gross revenue from selling personal information — a high entry bar; nonprofits, government, GLBA, HIPAA, and higher-education entities exempt",
        "privacyPolicyRequired": "Yes — a reasonably accessible, clear, and meaningful notice with statutorily fixed contents",
        "privateRightOfAction": "No — enforcement is exclusively the Attorney General's",
        "regulator": "Tennessee Attorney General and Reporter (exclusive)",
        "bottomLine": "If you exceed the $25 million revenue floor and meet Tennessee's large consumer-volume tests, TIPA requires a privacy notice, opt-in consent to process sensitive data, and processor contracts — enforced by the Attorney General with a 60-day cure period and no consumer lawsuits, and uniquely offering an affirmative defense to businesses that maintain a written privacy program conforming to the NIST privacy framework.",
        "lawCoverage": "comprehensive",
        "policyMandate": "statutoryContents",
        "consumersCanSue": "no",
        "sensitiveDataConsent": "optIn",
        "universalOptOutSignal": "notRequired"
      },
      "about": [
        "Tennessee Information Protection Act TIPA",
        "Tennessee privacy policy requirements",
        "Tennessee privacy notice contents",
        "TIPA applicability thresholds",
        "TIPA sensitive data consent",
        "TIPA processor contract requirements",
        "Tennessee Attorney General privacy enforcement",
        "TIPA NIST affirmative defense",
        "TIPA no private right of action"
      ],
      "translations": [
        {
          "language": "中文",
          "status": "planned"
        },
        {
          "language": "Español",
          "status": "planned"
        },
        {
          "language": "Português",
          "status": "planned"
        },
        {
          "language": "Deutsch",
          "status": "planned"
        }
      ]
    },
    "questions": [
      {
        "slug": "does-tipa-apply",
        "label": "Does the Tennessee Information Protection Act apply to your business?",
        "heading": "Does the Tennessee Information Protection Act apply to your business?",
        "answerText": "Only if you clear a high entry bar. TIPA applies to persons doing business in Tennessee or targeting its residents that exceed $25 million in revenue and either process the information of at least 175,000 consumers in a calendar year, or at least 25,000 consumers while deriving over 50% of gross revenue from selling personal information. Many federally regulated entities and whole categories of organizations are carved out entirely.",
        "sources": [
          {
            "id": "stat-3303-apply",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Tenn. Code Ann. § 47-18-3303",
            "citation": "Tenn. Code Ann. § 47-18-3303.",
            "url": "https://law.justia.com/codes/tennessee/title-47/chapter-18/part-33/section-47-18-3303/",
            "deepLink": "https://law.justia.com/codes/tennessee/title-47/chapter-18/part-33/section-47-18-3303/#:~:text=This%20part%20applies%20to%20persons,hundred%20seventy%2Dfive%20thousand%20(175%2C000)%20consumers.",
            "proposition": "TIPA applies only to persons exceeding $25 million in revenue that also process the personal information of at least 175,000 consumers a year, or 25,000+ while deriving over 50% of gross revenue from selling personal information.",
            "verbatimQuote": "This part applies to persons that conduct business in this state producing products or services that target residents of this state and that: - (1) Exceed twenty-five million dollars ($25,000,000) in revenue; and (2) - (A) Control or process personal information of at least twenty-five thousand (25,000) consumers and derive more than fifty percent (50%) of gross revenue from the sale of personal information; or - (B) During a calendar year, control or process personal information of at least one hundred seventy-five thousand (175,000) consumers.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/tennessee#src-stat-3303-apply"
          },
          {
            "id": "stat-3311-exempt",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Tenn. Code Ann. § 47-18-3311",
            "citation": "Tenn. Code Ann. § 47-18-3311(a).",
            "url": "https://law.justia.com/codes/tennessee/title-47/chapter-18/part-33/section-47-18-3311/",
            "deepLink": "https://law.justia.com/codes/tennessee/title-47/chapter-18/part-33/section-47-18-3311/#:~:text=This%20part%20does%20not%20apply,U.S.C.%20%C2%A7%206801%20et%20seq.)%3B",
            "proposition": "TIPA does not apply to a range of entities and data types, including government bodies, GLBA financial institutions, HIPAA-covered entities, nonprofits, and institutions of higher education.",
            "verbatimQuote": "This part does not apply to: - (1) A body, authority, board, bureau, commission, district, or agency of this state or of a political subdivision of this state; - (2) A financial institution, an affiliate of a financial institution, or data subject to Title V of the federal Gramm-Leach-Bliley Act (15 U.S.C. § 6801 et seq.);",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/tennessee#src-stat-3311-exempt"
          }
        ]
      },
      {
        "slug": "privacy-policy-contents",
        "label": "What must your Tennessee privacy policy contain?",
        "heading": "What must your Tennessee privacy policy contain?",
        "answerText": "A controller must provide a reasonably accessible, clear, and meaningful privacy notice that lists the categories of personal information processed, the purpose for processing, how consumers exercise their rights and appeal a decision, the categories of personal information sold to third parties, and the categories of those third parties.",
        "sources": [
          {
            "id": "stat-3305-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Tenn. Code Ann. § 47-18-3305",
            "citation": "Tenn. Code Ann. § 47-18-3305(c).",
            "url": "https://law.justia.com/codes/tennessee/title-47/chapter-18/part-33/section-47-18-3305/",
            "deepLink": "https://law.justia.com/codes/tennessee/title-47/chapter-18/part-33/section-47-18-3305/#:~:text=A%20controller%20shall%20provide%20a,the%20controller%20sells%20personal%20information.",
            "proposition": "A controller must provide a reasonably accessible, clear, and meaningful privacy notice listing the categories of personal information processed, the purpose for processing, how consumers exercise and appeal their rights, the categories of personal information sold to third parties, and the categories of those third parties.",
            "verbatimQuote": "A controller shall provide a reasonably accessible, clear, and meaningful privacy notice that includes: - (1) The categories of personal information processed by the controller; - (2) The purpose for processing personal information; - (3) How consumers may exercise their consumer rights pursuant to § 47-18-3304, including how a consumer may appeal a controller's decision with regard to the consumer's request; - (4) The categories of personal information that the controller sells to third parties, if any; and - (5) The categories of third parties, if any, to whom the controller sells personal information.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/tennessee#src-stat-3305-notice"
          }
        ]
      },
      {
        "slug": "vendor-contracts",
        "label": "What must your contracts with processors say?",
        "heading": "What must your contracts with processors say?",
        "answerText": "A contract between a controller and a processor must govern the processor's data processing on the controller's behalf — so a data processing agreement is a statutory requirement, not just a best practice.",
        "sources": [
          {
            "id": "stat-3306-contract",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Tenn. Code Ann. § 47-18-3306",
            "citation": "Tenn. Code Ann. § 47-18-3306(b).",
            "url": "https://law.justia.com/codes/tennessee/title-47/chapter-18/part-33/section-47-18-3306/",
            "deepLink": "https://law.justia.com/codes/tennessee/title-47/chapter-18/part-33/section-47-18-3306/#:~:text=A%20contract%20between%20a%20controller,and%20obligations%20of%20both%20parties.",
            "proposition": "A contract between a controller and a processor must govern the processor's data processing performed on behalf of the controller and set forth the required terms.",
            "verbatimQuote": "A contract between a controller and a processor governs the processor's data processing procedures with respect to processing performed on behalf of the controller. The contract is binding and must clearly set forth instructions for processing data, the nature and purpose of processing, the type of data subject to processing, the duration of processing, and the rights and obligations of both parties.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/tennessee#src-stat-3306-contract"
          }
        ]
      },
      {
        "slug": "sensitive-data",
        "label": "Do you need consent to process sensitive data?",
        "heading": "Do you need consent to process sensitive data?",
        "answerText": "Yes. A controller may not process a consumer's sensitive data without obtaining consent, and for a known child it must instead process the data in accordance with the federal Children's Online Privacy Protection Act. Sensitive data includes information revealing race or ethnicity, religious beliefs, a mental or physical health diagnosis, sexual orientation, or citizenship or immigration status; genetic or biometric data used to identify a person; information collected from a known child; and precise geolocation data.",
        "sources": [
          {
            "id": "stat-3305-consent",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Tenn. Code Ann. § 47-18-3305",
            "citation": "Tenn. Code Ann. § 47-18-3305(a)(6).",
            "url": "https://law.justia.com/codes/tennessee/title-47/chapter-18/part-33/section-47-18-3305/",
            "deepLink": "https://law.justia.com/codes/tennessee/title-47/chapter-18/part-33/section-47-18-3305/#:~:text=Not%20process%20sensitive%20data%20concerning,seq.)%20and%20its%20implementing%20regulations.",
            "proposition": "A controller may not process a consumer's sensitive data without consent, and must handle a known child's data in accordance with COPPA.",
            "verbatimQuote": "Not process sensitive data concerning a consumer without obtaining the consumer's consent, or, in the case of the processing of sensitive data concerning a known child, without processing the data in accordance with the federal Children's Online Privacy Protection Act (15 U.S.C. § 6501 et seq.) and its implementing regulations.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/tennessee#src-stat-3305-consent"
          },
          {
            "id": "stat-3302-sensitive",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Tenn. Code Ann. § 47-18-3302",
            "citation": "Tenn. Code Ann. § 47-18-3302(26).",
            "url": "https://law.justia.com/codes/tennessee/title-47/chapter-18/part-33/section-47-18-3302/",
            "deepLink": "https://law.justia.com/codes/tennessee/title-47/chapter-18/part-33/section-47-18-3302/#:~:text=%E2%80%9CSensitive%20data%E2%80%9D%20means%20a%20category,%2D%20(D)%20Precise%20geolocation%20data%3B",
            "proposition": "Sensitive data includes information revealing race or ethnicity, religious beliefs, a health diagnosis, sexual orientation, or citizenship status; genetic or biometric data used to identify a person; information from a known child; and precise geolocation data.",
            "verbatimQuote": "“Sensitive data” means a category of personal information that includes: - (A) Personal information revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, or citizenship or immigration status; - (B) The processing of genetic or biometric data for the purpose of uniquely identifying a natural person; - (C) The personal information collected from a known child; or - (D) Precise geolocation data;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/tennessee#src-stat-3302-sensitive"
          }
        ]
      },
      {
        "slug": "consumer-lawsuit",
        "label": "Can a consumer sue your business under TIPA?",
        "heading": "Can a consumer sue your business under TIPA?",
        "answerText": "No. The Attorney General and Reporter has exclusive authority to enforce TIPA, and the statute says a violation cannot be the basis for a private right of action, including a class action. Before suing, the Attorney General must give 60 days' written notice of the specific alleged violations and a chance to cure. Uniquely, a business has an affirmative defense if it maintains a written privacy program that reasonably conforms to the NIST privacy framework.",
        "sources": [
          {
            "id": "stat-3313-enforce",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Tenn. Code Ann. § 47-18-3313",
            "citation": "Tenn. Code Ann. § 47-18-3313(e).",
            "url": "https://law.justia.com/codes/tennessee/title-47/chapter-18/part-33/section-47-18-3313/",
            "deepLink": "https://law.justia.com/codes/tennessee/title-47/chapter-18/part-33/section-47-18-3313/#:~:text=A%20violation%20of%20this%20part,this%20part%20or%20other%20law.",
            "proposition": "The Attorney General has exclusive authority to enforce TIPA, and a violation cannot be the basis for a private right of action, including a class action.",
            "verbatimQuote": "A violation of this part shall not serve as the basis for, or be subject to, a private right of action, including a class action lawsuit, under this part or other law.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/tennessee#src-stat-3313-enforce"
          },
          {
            "id": "stat-3313-cure",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Tenn. Code Ann. § 47-18-3313",
            "citation": "Tenn. Code Ann. § 47-18-3313(b).",
            "url": "https://law.justia.com/codes/tennessee/title-47/chapter-18/part-33/section-47-18-3313/",
            "deepLink": "https://law.justia.com/codes/tennessee/title-47/chapter-18/part-33/section-47-18-3313/#:~:text=Prior%20to%20initiating%20an%20action,been%20or%20are%20being%20violated.",
            "proposition": "Before bringing an action, the Attorney General must give 60 days' written notice identifying the specific provisions allegedly violated, and may not sue if the violation is cured within that period.",
            "verbatimQuote": "Prior to initiating an action under this part, the attorney general and reporter shall provide a controller or processor sixty-days' written notice identifying the specific provisions of this part the attorney general and reporter alleges have been or are being violated.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/tennessee#src-stat-3313-cure"
          },
          {
            "id": "stat-3314-nist",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Tenn. Code Ann. § 47-18-3314",
            "citation": "Tenn. Code Ann. § 47-18-3314(a).",
            "url": "https://law.justia.com/codes/tennessee/title-47/chapter-18/part-33/section-47-18-3314/",
            "deepLink": "https://law.justia.com/codes/tennessee/title-47/chapter-18/part-33/section-47-18-3314/#:~:text=A%20controller%20or%20processor%20has,designed%20to%20safeguard%20consumer%20privacy%3B",
            "proposition": "A controller or processor has an affirmative defense if it maintains a written privacy program reasonably conforming to the NIST privacy framework and providing consumers the substantive rights TIPA requires.",
            "verbatimQuote": "A controller or processor has an affirmative defense to a cause of action for a violation of this part if the controller or processor creates, maintains, and complies with a written privacy policy that: (1) - (A) Reasonably conforms to the National Institute of Standards and Technology (NIST) privacy framework entitled “A Tool for Improving Privacy through Enterprise Risk Management Version 1.0.” or other documented policies, standards, and procedures designed to safeguard consumer privacy;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/tennessee#src-stat-3314-nist"
          }
        ]
      }
    ]
  }
}
