November 14, 2025
Three Privacy Laws Take Effect, With Uncertain Scope
This January, three consumer privacy laws will take effect – in Indiana, Kentucky, and Rhode Island. While most of the requirements laid out in these statutes will appear relatively standard for those familiar with the drill by now, nestled in Rhode Island’s privacy act is an unusual provision that has the potential to cause mischief.
In addition to the usual order of consumer rights and controller obligations required of businesses that collect a certain volume of personal data from Rhode Island residents, the state also requires any commercial website or ISP conducting business in Rhode Island or with customers in Rhode Island to (among other things) affirmatively identify “all third parties to whom the controller has sold or may sell customers’ personally identifiable information.” While a few other states (Oregon and Minnesota) do allow for a resident to request a list of third parties to whom the business has disclosed their data, no other state requires a proactive identification in the privacy policy.
It is unclear the scope of this provision. While elsewhere the statute uses the (defined) phrase “personal data,” this provision is limited to “personally identifiable information.” Unhelpfully, PII is not defined for purposes of the statute. It could be the case that it is sloppy drafting and both terms are intended to have the same meaning – this interpretation is perhaps bolstered by the fact that there are other provisions in the statute that also reference PII. Alternatively, it could be intended as a narrower subset of data. Unfortunately, “sale” of data is not limited to an exchange for money, but also includes an exchange for “other valuable consideration.”
While we hope for legislative clarity to emerge, if your business shares names/emails/phones/addresses or the like with a third party in exchange for receiving other personally identifiable information, please reach out to discuss whether you should consider disclosing this information in your privacy policy.
If you have questions, please reach out to a member of our privacy team.
Stacy Stitham, sstitham@brannlaw.com
David Swetnam-Burland, dsb@brannlaw.com
Nathaniel Bessey, nbessey@brannlaw.com