Breach notification law in Rhode Island
This page reports what the Rhode Island breach notification statute provides. It is a reference summary, not legal advice, and it does not describe any particular breach. BreachBook is not a law firm and cannot advise on how a statute applies to an individual case.
| Deadline to notify residents | 45 days. |
|---|---|
| Does an exposed Social Security number trigger notice | Yes. A Social Security number is within the statute’s definition of personal information. |
| Cost of a credit freeze | Free to place, lift, and remove. |
| Identity theft monitoring | The statute does not require the entity to provide identity theft monitoring. |
| Attorney general notice | Reported to the attorney general when the breach affects 501 or more residents. |
Statute
R.I. Gen. Laws § 11-49.3-4 — read the statute
Entry last verified August 2, 2026 against the official source above.
How to read this entry
These fields summarize the obligations a statute places on an organization that discloses a breach. They do not establish that any organization met or failed to meet them, and a breach recorded elsewhere on this site is not evidence either way. Where the statute sets no figure, the row says so rather than showing a blank.
Other jurisdictions
Found an error in this entry? See the corrections policy.