Skip to content

Cyber Liability by state

Rhode Island data breach notification law and cyber insurance

Direct answer

What is Rhode Island's data breach notification law?

Rhode Island's breach notification law (R.I. Gen. Laws sect. 11-49.3-1 et seq.) requires businesses to notify affected residents in the most expedient time possible and without unreasonable delay, but not later than 45 days after confirming the breach after a breach of personal information.

Reviewed by Cornerstone Staff28 years of financial services state licensing experienceLast verified July 29, 2026

What the statute requires

Rhode Island requires businesses to notify affected residents within 45 days of confirming a breach, with Attorney General notice when more than 500 residents are affected. Cyber liability insurance typically covers the forensics, notification, and legal review this deadline demands.

Consumer notification deadline
In the most expedient time possible and without unreasonable delay, but not later than 45 days after confirming the breach
Regulator notice
Notify the Rhode Island Attorney General when a breach affects more than 500 residents.
Credit bureau notice
Notify consumer reporting agencies when a breach requires notice to more than 500 residents.
Safe harbor
Notification is not required if the compromised data was encrypted and the encryption key was not acquired.
Enforcement
Violations are enforceable by the Attorney General, who may seek civil penalties per record for reckless or knowing violations.

Statutes and sources

  • Rhode Island Identity Theft Protection Act of 2015

    R.I. Gen. Laws sect. 11-49.3-1 et seq.

Regulator: Rhode Island Attorney General . Last verified 2026-07-29 from the official source .

Get Rhode Island coverage handled

Share a few details and an agent will respond within one business day.