State Guide
Tennessee Privacy & Data Security Laws
Every statute below can apply to a business handling Tennessee residents' data, depending on your revenue, the number of Tennessee consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Requires $25M+ revenue AND (175,000+ consumers — the highest consumer threshold of any state — OR 25,000+ consumers with 50%+ revenue from selling personal data). Notable for an affirmative defense if you maintain a written privacy program reasonably conforming to the NIST Privacy Framework — no other state offers this. (Note: many secondary sources incorrectly cite this as §47-18-3201 — that section is a repealed, unrelated "Booting Consumer Protection Act" provision; the correct TIPA codification is §47-18-3301 et seq.)
Data Security & Breach Notification · 1
Requires notifying affected residents (and often the state AG/regulator) after a breach of unencrypted personal information such as SSNs, driver's license/state ID numbers, or financial account numbers. Applies regardless of company size whenever you hold covered personal information about a resident of this state.
Genetic Privacy · 1
Regulates direct-to-consumer genetic testing companies and/or genetic data generally — typically requiring express consent before collecting, using, or disclosing genetic data, and consent (or destruction) requirements for biological samples.