Tennessee's Privacy Law Has an Escape Hatch No Other State Offers
Tennessee's privacy law works differently from nearly every other state in two separate ways. First, it requires you to clear two thresholds at once, not just one. Second, it offers something no other comparable state law does: a documented way to build yourself a legal defense before anything ever goes wrong.
A Threshold That Requires Both Conditions
Most comprehensive state privacy laws use an "or" structure: hit this number, or hit that number, either one triggers the law. Tennessee uses "and." The Tennessee Information Protection Act applies only if your business has $25,000,000 or more in annual revenue, and it also processes personal data for 175,000 or more Tennessee consumers, or processes data for 25,000 or more consumers while deriving 50% or more of revenue from data sales.
Practically, this means TIPA is aimed squarely at larger, more established businesses. A smaller Shopify store, even one with meaningful Tennessee consumer traffic, likely falls outside TIPA's scope entirely if revenue stays under $25 million. That's worth knowing precisely, since it's easy to assume any state with 175,000 in its threshold language applies broadly. Here, it only applies once you've also cleared the revenue bar.
Consumer Rights
Businesses that do meet both conditions owe consumers access, correction, deletion, data portability, and the right to opt out of the sale of data, targeted advertising, and profiling.
The NIST Framework Defense
This is the detail that sets Tennessee apart from every other state Regulens tracks. If your business creates, maintains, and complies with a written privacy program that reasonably conforms to the National Institute of Standards and Technology's Privacy Framework, that program can serve as an affirmative legal defense against a TIPA claim.
In plain terms, Tennessee is explicitly rewarding businesses that document a real, structured privacy program in advance, rather than only punishing businesses after a violation occurs. No other state in Regulens' current coverage builds this kind of documented-good-faith defense directly into its privacy statute.
Insurance Companies Are Exempt
Unlike most comprehensive privacy laws, which typically carve out specific data types or activities, Tennessee exempts insurance companies entirely at the entity level. If insurance is any part of your business model, this is worth flagging to whoever handles your compliance review specifically.
The Cure Period Has an Expiration Date
Tennessee gives businesses a 60-day window to fix a violation before facing enforcement, but this cure period itself is scheduled to sunset on July 1, 2027. After that date, businesses lose the automatic right to fix an issue before enforcement proceeds, unless the law is amended before then.
No Universal Opt-Out Requirement
Unlike Colorado, Minnesota, and several other states, Tennessee does not currently require businesses to detect and honor browser-level universal opt-out signals. If you've already built that capability for other states, it satisfies Tennessee too, but it isn't a separate Tennessee-specific obligation on its own.
Enforcement
The Tennessee Attorney General holds exclusive enforcement authority. There is no private right of action.
Check Your Tennessee Exposure
All information in this article is sourced from the Tennessee Information Protection Act (2023 Public Chapter 408, House Bill 1181) and Tennessee Attorney General published guidance. Regulens is informational only and this article is not legal advice. Speak to a licensed privacy attorney about your specific compliance situation.
Regulens tracks Tennessee as part of its ongoing state-by-state privacy coverage. Your store's readiness is calculated based on your actual inputs and current policy documents.
Free to check, takes three minutes, no credit card needed. Not legal advice. Informational only.
Check your store's Tennessee privacy readiness at getregulens.com
Further Reading
Does Your Store Need to Detect a Browser Signal? A State-by-State Guide
Some states require your store to automatically recognize a consumer's opt-out preference through their browser settings, with no click required on your site at all. Here's exactly which states require it.
Four More States Are About to Get Privacy Laws — Here's Your Advance Notice
Alabama, Oklahoma, Louisiana, and Vermont have all signed comprehensive privacy laws into effect between 2027 and 2028. None are enforceable yet, but each is worth understanding well before its clock starts.