#
TIPA is confirmed in force via multiple corroborating secondary sources, but the primary Tennessee Code codification was not independently fetched (allowlist gap), and the injected seed's factual premise conflicts with research findings, warranting operator verification before treating detailed thresholds as final.
Sub-modules (5)
Regulator And AuthorityAmber
TIPA enforcement is exclusive to the Tennessee Attorney General; there is no private data-protection authority and no rulemaking agency distinct from the AG's office.
Claims (1):
- Enforcement of TIPA is managed exclusively by the Tennessee Attorney General, with no private data-protection regulator or agency established by the statute.
Act And InstrumentsGreen
Primary instruments are TIPA (comprehensive, in force 1 July 2025) and the pre-existing breach-notification statute at Tenn. Code Ann. §47-18-2107; federal FTC Act §5 operates as a general backstop.
Claims (3):
- The Tennessee Information Protection Act (TIPA), enacted 11 May 2023 as Public Chapter 408 (HB 1181, substituted for companion SB 0073), entered into force on 1 July 2025.
- Tennessee's general data-breach notification statute (Tenn. Code Ann. §47-18-2107) defines 'breach of system security' as unauthorized acquisition of unencrypted computerized personal information, or encrypted data together with the encryption key, that materially compromises security, confidentiality, or integrity.
- In the absence of sector-specific coverage, the FTC's general Section 5 unfair-or-deceptive-practices authority operates nationally, including in Tennessee, as a reactive federal privacy-enforcement baseline.
Material ScopeAmber
TIPA covers 'personal data' linked/linkable to identifiable Tennessee consumers, excluding de-identified, aggregate, and publicly available information; coverage is gated by revenue-plus-volume thresholds rather than a flat consumer-count test.
Claims (2):
- TIPA's applicability thresholds require an entity to make more than USD 25 million in annual revenue while controlling or processing personal data of 25,000 or more consumers and deriving over 50% of revenue from the sale of personal data, or otherwise controlling/processing data at higher consumer-volume levels reported in the range of 175,000 consumers.
- TIPA defines 'personal data' as information linked or reasonably linkable to an identified or identifiable individual, expressly excluding de-identified data, aggregate data, and publicly available information.
Territorial ScopeAmber
TIPA applies to entities conducting business in Tennessee or targeting products/services to Tennessee residents that meet the statute's narrow multi-part thresholds, reported as among the narrowest of any US state comprehensive privacy law.
Claims (1):
- Tennessee's coverage thresholds for regulated entities under TIPA are reported as narrower than those of any other US state comprehensive privacy law in effect at the time of passage.
Regulator Registration And FilingRed
No evidence was found of a controller registration, filing, or notification-to-regulator regime under TIPA (unlike EU-style DPA registration models).
Claims (1):
- No general controller registration or pre-filing obligation with the Tennessee Attorney General was identified under TIPA.
no periodic updates on record for this sub-brief
Sources and claims (8)
- ProbableDataGuidance — The Tennessee Information Protection Act (TIPA), enacted 11 May 2023 as Public Chapter 408 (HB 1181, substituted for companion SB 0073), entered into force on 1 July 2025.observed
- ProbableDataGuidance — Enforcement of TIPA is managed exclusively by the Tennessee Attorney General, with no private data-protection regulator or agency established by the statute.observed
- ProbableIAPP — TIPA's applicability thresholds require an entity to make more than USD 25 million in annual revenue while controlling or processing personal data of 25,000 or more consumers and deriving over 50% of revenue from the sale of personal data, or otherwise controlling/processing data at higher consumer-volume levels reported in the range of 175,000 consumers.observed
- ProbableDataGuidance — TIPA defines 'personal data' as information linked or reasonably linkable to an identified or identifiable individual, expressly excluding de-identified data, aggregate data, and publicly available information.observed
- ProbableIAPP — Tennessee's coverage thresholds for regulated entities under TIPA are reported as narrower than those of any other US state comprehensive privacy law in effect at the time of passage.observed
- UncertainDataGuidance — No general controller registration or pre-filing obligation with the Tennessee Attorney General was identified under TIPA.observed
- ProbableState of Tennessee — Tennessee's general data-breach notification statute (Tenn. Code Ann. §47-18-2107) defines 'breach of system security' as unauthorized acquisition of unencrypted computerized personal information, or encrypted data together with the encryption key, that materially compromises security, confidentiality, or integrity.observed
- ProbableFTC — In the absence of sector-specific coverage, the FTC's general Section 5 unfair-or-deceptive-practices authority operates nationally, including in Tennessee, as a reactive federal privacy-enforcement baseline.observed