Skip to content
Menu ▾
Patent pending

Regulayer  /  The 146 laws  /  Privacy law

Tennessee · TIPA

Consumer privacy & NIST safe harbor.

Applies to: Controllers under Tennessee's TIPA. Built · effective 1 Jul 2025

What the signed record shows

Security records, 45-day consumer-request signals, and assessment references; NIST-program affirmative defense.

The proof is a signed, tamper-evident record. Anyone can check it, free, without an account, and nothing has to leave the building to make it. Evidence, not a promise.

Citation: Tenn. Code §47-18-3305/3307/3313

In the same family

What to do about it

Seven days free, then $349 a month.

A signed record of which AI you used and what you checked, sealed to the exact file you deliver, made on your own machine and checkable free by anyone you send it to.

Start the free weekOr verify a real record, free →

Part of the Regulayer proof catalogue: 146 laws and standards, one sealed engine. This page is a product description, not legal advice.

What the statute requires, section by section

Tennessee Information Protection Act (TIPA), Tenn. Code Ann. sections 47-18-3301 et seq. (Title 47, Chapter 18, Part 33). Provisions addressed:

§ 47-18-3305
Data controller responsibilities; reasonable administrative, technical and physical data security practices; non-discrimination; data minimization; respond to a consumer request within 45 days.
§ 47-18-3307
Data protection assessments for heightened-risk processing; available to the Attorney General on request.
§ 47-18-3313
Affirmative defense: a controller/processor that maintains a written privacy program reasonably conforming to the NIST Privacy Framework may assert it as a defense (first-in-nation NIST safe harbor). Effective 1 July 2025.

Taken from the Regulayer entry for this instrument, which is built against the primary text.