Orange textured background

US state law

TIPA and browser fingerprinting

How the Tennessee Information Protection Act regulates device fingerprinting, why its NIST safe harbor is the most operationally distinctive feature of any US state privacy law, and what treble damages mean for a fingerprinting deployment.

Reviewed

RegionTennessee, USA
RegulatorTennessee Attorney General, Office of Consumer Protection
Effective1 July 2025
Max penaltyUp to $7,500 per violation; treble damages (up to $22,500) for wilful conduct under Tenn. Code Ann. §47-18-3214
Status in-force

The NIST safe harbor: TIPA's defining feature for fingerprinting deployments

Tenn. Code Ann. §47-18-3213 creates a feature that no other US state privacy law provides: an affirmative defense available to any controller or processor that 'creates, maintains, and complies with a written privacy program that reasonably conforms to' the NIST Privacy Framework and one of three recognised cybersecurity frameworks - the NIST Cybersecurity Framework (CSF), ISO/IEC 27701, or the CIS Controls. An affirmative defense is stronger than a mitigating factor. In an AG enforcement action, a controller that raises the §47-18-3213 defense and can substantiate it is not merely asking for reduced penalties - it is asserting that enforcement cannot proceed.

This changes the compliance calculus for fingerprinting in a concrete way. Under every other Virginia-cluster state law, compliance is about ensuring each specific processing activity satisfies the relevant consent, opt-out, or DPA obligation. Under TIPA, there is an additional, parallel path: build and document a comprehensive privacy program that maps to the NIST frameworks, and that program-level conformance becomes an affirmative defense for any enforcement action arising from the fingerprinting deployment.

The practical implication is that two TIPA compliance strategies are available simultaneously. The first is activity-level compliance: honour opt-out requests for targeted advertising, sale, and covered profiling; conduct Data Protection Assessments for those purposes; meet notice and data-subject-rights obligations. The second, available only in Tennessee, is program-level conformance: document the full NIST-aligned privacy program, reference it in your DPA and privacy notice, and preserve that documentation as the evidentiary foundation of the §47-18-3213 defense. Best-practice deployments pursue both - the program-level conformance does not substitute for activity-level compliance, but it provides a backstop if a specific activity is later disputed.

What TIPA says about fingerprinting

Tennessee House Bill 1181 (2023) was enacted and codified at Tenn. Code Ann. §47-18-3201 through §47-18-3215. It took effect on 1 July 2025, making Tennessee among the later Virginia-cluster states to go live. Like every law in that cluster, it does not use the word 'fingerprinting'. Section §47-18-3202 defines 'personal information' as 'data that is linked or reasonably linkable to an identified or identifiable individual'. A browser or device fingerprint hash, composed of canvas output, GPU renderer strings, audio context, installed font enumeration, time zone, and browser-version signals, qualifies as personal information the moment a controller uses it to recognise a returning Tennessee consumer. Linkability, not nominal identity, is the operative test.

TIPA is an opt-out regime, not an opt-in one. Processing fingerprint data for most purposes is permitted by default. Consumer rights - including the right to opt out of targeted advertising, sale of personal data, and certain profiling - are the operative constraints, and they attach only to specific purpose categories, not to fingerprinting as a category.

TIPA's definitions of the key purpose categories follow the Virginia template closely. Targeted advertising means displaying ads selected based on personal information obtained from a consumer's activities across non-affiliated websites or applications. Sale means exchange for monetary consideration - TIPA does not expand sale to include 'other valuable consideration' as Colorado does. Profiling triggers opt-out rights only when it produces legal or similarly significant effects on the consumer.

When TIPA applies to you

Section §47-18-3202 sets a compound applicability test that is closer to Utah's UCPA than to Virginia's VCDPA. A controller falls inside TIPA only if it (a) conducts business in Tennessee or targets products or services to Tennessee residents, AND (b) has annual revenue of $25 million or more, AND (c) meets at least one of two consumer-count conditions: either processes the personal information of 175,000 or more Tennessee consumers in a calendar year, or processes the personal information of 25,000 or more Tennessee consumers AND derives more than 50% of gross revenue from the sale of personal information.

The $25 million revenue gate is the key threshold that distinguishes TIPA from Virginia and Colorado. A startup or early-stage company below that revenue floor is entirely outside TIPA's scope regardless of how many Tennessee consumers it serves or what it does with their fingerprint data. This mirrors Utah's UCPA architecture and reflects Tennessee's stated policy objective of scoping the law to mid-size and larger businesses.

Consumer is defined as a natural person who is a Tennessee resident acting in an individual or household capacity. Employee data, B2B contact data, and data collected from individuals acting in a commercial capacity on behalf of a business are excluded, consistent with the rest of the Virginia cluster. A fingerprint captured on an internal admin tool used only by employees, or on a B2B SaaS product where every visitor is acting on behalf of a business entity, does not trigger TIPA obligations.

Treble damages: TIPA's enforcement arithmetic

Section §47-18-3214 gives the Tennessee Attorney General the power to seek civil penalties of up to $7,500 per violation, but adds a provision found in no other US state privacy law: treble damages for wilful violations. Treble damages means the per-violation cap can reach $22,500 for wilful conduct - three times the base amount.

In practice, the distinction between a negligent and a wilful violation tracks intent. A controller that unknowingly failed to honour an opt-out request because its fingerprint pipeline was misconfigured faces a maximum of $7,500 per violation. A controller that knew it was violating TIPA's opt-out requirement and continued the processing anyway - for example, by deliberately ignoring an opt-out signal after being put on notice of the obligation - faces the $22,500 treble-damage cap. The AG also has recourse to the Tennessee Consumer Protection Act (Tenn. Code Ann. §47-18-101 et seq.), which provides parallel enforcement authority for deceptive trade practices and can be used alongside TIPA to compound exposure in egregious cases.

For a fingerprinting deployment used for targeted advertising across a large Tennessee consumer base, the aggregate exposure from a wilful violation across multiple consumers can be significant. The per-violation framing means the penalty pool scales with the number of affected consumers, not the number of distinct violations at the processing-activity level.

Common fingerprinting purposes under TIPA

PurposePersonal information under TIPA?DPA required?Opt-out right applies?NIST safe harbor relevant?
Anti-fraud at login or paymentYesNo (not heightened-risk processing)NoYes - program-level defense available for any TIPA action
Account-takeover detectionYesNoNoYes
Bot mitigation on a public formYesNoNoYes
Cross-site targeted advertisingYesYesYes (targeted advertising)Yes
Selling fingerprint-derived audience segments for monetary considerationYesYesYes (sale)Yes
Sharing fingerprint hashes with ad-tech partner for non-monetary mutual valueYesNo (not a sale under monetary-consideration-only definition)No (not targeted advertising or sale on these facts)Yes
Profiling for credit, insurance, or employment decisionsYesYesYes (profiling with legal or similarly significant effects)Yes
Product analytics on your own serviceYesNoNoYes
Session-continuity and frequency capping on your own siteYesNo (first-party carve-out)NoYes
Fingerprinting employees on an internal toolNo (employee carve-out)NoNoNo

Data Protection Assessments under TIPA

Section §47-18-3207 requires a controller to conduct and document a Data Protection Assessment (DPA) before engaging in processing that presents a heightened risk of harm to consumers. The categories that trigger a DPA match the Virginia-cluster standard: targeted advertising, sale of personal information, processing of sensitive personal information, and profiling that presents a reasonably foreseeable risk of legal or similarly significant effects on the consumer.

The assessment must weigh the benefits of the processing against the risks to consumers, taking into account the context of the processing, the degree to which the controller can mitigate identified risks, and the consumer-facing transparency measures in place. TIPA does not prescribe the exact contents of the DPA in the level of detail that Colorado's 4 CCR 904-3 Rule 8 does, but the AG can require production of the assessment as part of an enforcement investigation, and the absence of a documented assessment is itself a violation independent of the underlying processing question.

For a fingerprinting deployment, an adequate TIPA DPA names: the signal categories collected by the fingerprint script, the hash construction and retention window, the downstream recipients of the hash, the consumer opt-out mechanism, and the de-identification claim if any. Controllers who have also documented a NIST-aligned privacy program under §47-18-3213 should cross-reference the DPA to the program documentation - the two documents together create the strongest evidentiary posture in any enforcement context.

Cure period and enforcement posture

Section §47-18-3211 gives the Tennessee Attorney General the power to bring civil enforcement actions, with a prior notice requirement. Before initiating an action, the AG must provide the controller with written notice of the alleged violation and 60 days to cure the violation. TIPA currently has no scheduled sunset for the cure period - unlike Colorado, which terminated its 30-day cure window on 1 July 2025, Tennessee has not legislated an expiry date for the 60-day right. This is the longest and most stable cure window of any active Virginia-cluster state.

Enforcement sits within the AG's Office of Consumer Protection, the same unit that administers the Tennessee Consumer Protection Act (TCPA) at Tenn. Code Ann. §47-18-101 through §47-18-131. The AG can pursue TIPA violations independently or in parallel with TCPA claims where the fingerprinting conduct also constitutes a deceptive or unfair trade practice. Because TIPA only took effect on 1 July 2025, no publicly documented fingerprinting enforcement actions have been brought under the statute as of this page's last review. Controllers and practitioners should monitor the AG's Office of Consumer Protection press release archive for the first wave of TIPA enforcement activity.

The TCPA parallel is worth noting for operational risk planning. Tennessee's Consumer Protection Act has been actively enforced for decades and provides the AG with broad authority over deceptive practices. A fingerprinting deployment that makes materially false disclosures about its purpose - for example, claiming fingerprints are used only for anti-fraud when they are also powering targeted advertising - could face a TCPA action independently of any TIPA-specific violation.

TIPA enforcement context: three scenarios to plan for

  • AG-initiated TIPA action for failure to honour opt-out: the most likely first-wave enforcement scenario based on patterns in other Virginia-cluster states. A fingerprinting deployment that continues collecting data for targeted advertising after a consumer has exercised their §47-18-3205 opt-out right, without a documented cure within the 60-day window, is the clearest violation pathway. The treble-damage provision makes wilful continuation of post-opt-out processing particularly costly.
  • AG-initiated TIPA action for missing DPA: the second most common early-enforcement scenario across the cluster. Deploying fingerprinting for targeted advertising without documenting a §47-18-3207 Data Protection Assessment is a standalone violation. The AG can seek penalties for the missing documentation independently of any harm to individual consumers.
  • Parallel Tennessee Consumer Protection Act action: if a fingerprinting deployment's privacy notice misrepresents the purposes for which the fingerprint is used, the AG's Office of Consumer Protection can pursue a TCPA deceptive-practices claim under §47-18-104 in parallel with any TIPA action. Accurate, purpose-specific disclosure language in the privacy notice is the primary mitigation.

Universal Opt-Out Mechanisms: optional, not mandatory

TIPA takes a different position from Colorado and Virginia on Universal Opt-Out Mechanisms such as the Global Privacy Control browser signal. Section §47-18-3205 grants Tennessee consumers the right to opt out of targeted advertising, sale, and covered profiling, but the statute does not require controllers to recognise browser-level UOOM signals. Controllers MAY build GPC recognition into their fingerprinting pipelines, and doing so is operationally prudent where the same deployment also serves Colorado or Virginia consumers - but a Tennessee-only deployment that ignores GPC is not in violation of TIPA on that basis alone.

The distinction matters architecturally. If your Benny deployment serves consumers across multiple states, the GPC check must be in place for Colorado (mandatory since 1 July 2024) and Virginia (mandatory since 1 January 2025). Excluding Tennessee from that check is technically permissible under TIPA but introduces engineering complexity if the fingerprint script cannot distinguish consumer geography before the check. Most multi-state deployments find it simpler to apply the UOOM gate universally and treat Tennessee consumers as GPC-respecting by default.

How Benny the Doorman fits into a TIPA-aware deployment

Benny is a fingerprinting SDK and hosted API, not a consent management or compliance program platform. For a TIPA-aware deployment, Benny's role is to supply the fingerprint signal; the controller's privacy program and CMP own the gating, documentation, and opt-out mechanics.

Three integration steps for a TIPA-aware deployment. First, gate the Benny fingerprint call behind your preference-centre flag for any purpose that triggers an opt-out right - targeted advertising, sale, or covered profiling. TIPA does not mandate GPC recognition, but a universal UOOM gate is the lowest-friction architecture across a multi-state deployment. Second, produce and retain a §47-18-3207 Data Protection Assessment for each regulated fingerprinting purpose before going live. Benny's documentation enumerates the signal categories, hash construction, default retention window, and per-call data flow in the technical detail the DPA must capture. Third, if your organisation has documented a NIST-aligned privacy program under §47-18-3213, reference the Benny deployment explicitly in the data inventory and processing records that underpin the program. Benny's technical documentation is designed to support NIST Privacy Framework Identify-P and Control-P function documentation, which are the two functions most directly implicated by a fingerprinting deployment.

The NIST safe harbor is the most distinctive compliance lever available under Tennessee law, and Benny's documentation approach is specifically built to support NIST-aligned program documentation. Controllers pursuing the §47-18-3213 affirmative defense should ensure their Benny deployment is documented in the program's data inventory, purpose register, and control catalogue.

Frequently asked questions

Is browser fingerprinting illegal under TIPA?

No. Fingerprinting is not banned under the Tennessee Information Protection Act. It is regulated as personal information when the fingerprint can be reasonably linked to a Tennessee consumer. Lawful use requires honouring consumer opt-out requests for targeted advertising, sale, and covered profiling, completing a Data Protection Assessment for those purposes before going live, and maintaining accurate privacy disclosures. TIPA's NIST safe harbor provides an additional affirmative defense for controllers with a conforming written privacy program.

What is the TIPA NIST safe harbor and does it apply to my fingerprinting deployment?

Tenn. Code Ann. §47-18-3213 provides an affirmative defense - not just a mitigating factor - for controllers that create, maintain, and comply with a written privacy program that reasonably conforms to the NIST Privacy Framework plus one of three recognised cybersecurity frameworks: NIST CSF, ISO/IEC 27701, or CIS Controls. If a controller can substantiate that defense, enforcement cannot proceed. It applies to any TIPA enforcement action, including actions arising from a fingerprinting deployment, provided the deployment is documented in the program's data inventory and purpose register. No other US state privacy law offers an equivalent affirmative defense.

How do treble damages work under TIPA and what is the maximum per-violation penalty?

Section §47-18-3214 sets a base civil penalty of up to $7,500 per violation, matching the VCDPA and most other Virginia-cluster states. For wilful violations, the AG may seek treble damages, meaning the per-violation cap reaches $22,500. TIPA is the only US state privacy law that allows treble damages, making it the highest effective per-violation cap in the cluster for deliberate misconduct. Wilful conduct generally means the controller knew about the obligation and chose not to comply, as distinct from an inadvertent misconfiguration.

Does TIPA apply to my organisation?

TIPA applies only if your organisation meets all three conditions: (1) conducting business in Tennessee or targeting products or services to Tennessee residents; (2) annual revenue of $25 million or more; and (3) either processing personal information of 175,000 or more Tennessee consumers in a calendar year, or processing the personal information of 25,000 or more Tennessee consumers while deriving more than 50% of gross revenue from the sale of personal information. A company below the $25 million revenue threshold is outside TIPA's scope entirely, regardless of consumer volume.

Does TIPA require me to honour Global Privacy Control?

No. TIPA grants Tennessee consumers the right to opt out of targeted advertising, sale, and covered profiling, but the statute does not require controllers to recognise Universal Opt-Out Mechanisms such as the GPC browser signal. Recognition is optional in Tennessee, unlike Colorado (mandatory since 1 July 2024) and Virginia (mandatory since 1 January 2025). Multi-state deployments typically apply the UOOM gate universally to simplify engineering and cover the states where it is mandatory.

What is the cure period under TIPA?

Section §47-18-3211 requires the AG to give a controller written notice of an alleged violation and 60 days to cure before initiating a civil enforcement action. Tennessee's 60-day cure window is the longest of any active Virginia-cluster state law and has no scheduled sunset, making it materially more forgiving than Colorado (which eliminated its cure period on 1 July 2025) and Virginia (which has a shorter, constrained window). The cure period applies to all TIPA violations, including fingerprinting-related opt-out and DPA failures.

Does TIPA require a Data Protection Assessment for fingerprinting?

Yes, when the fingerprinting deployment is used for targeted advertising, sale of personal information, processing of sensitive personal information, or profiling that presents a reasonably foreseeable risk of legal or similarly significant effects on the consumer. Section §47-18-3207 requires the assessment to weigh the benefits of the processing against the risks to consumers. There is no DPA obligation for anti-fraud or bot-mitigation fingerprinting where the processing is scoped narrowly and does not carry heightened risk. The absence of a required DPA is itself a standalone TIPA violation.

How does TIPA differ from UCPA (Utah) for fingerprinting?

Both TIPA and UCPA use a revenue-gate plus consumer-count compound applicability test, keeping both laws scoped to mid-size and larger controllers. The key differences: TIPA has a $25 million revenue gate; UCPA uses $25 million too but with different consumer thresholds. TIPA allows treble damages for wilful violations; UCPA does not. TIPA has a NIST safe harbor affirmative defense; UCPA has no equivalent. TIPA's sale definition is monetary consideration only, matching UCPA. TIPA took effect 1 July 2025; UCPA took effect 31 December 2023.

Is sharing fingerprint hashes with an ad-tech partner a 'sale' under TIPA?

Generally no, because TIPA's definition of sale requires monetary consideration. Sharing fingerprint hashes with an ad-tech partner for audience matching, mutual lift, or other non-monetary value is typically not a sale under TIPA, distinguishing Tennessee from Colorado (which extends sale to 'other valuable consideration'). It may, however, constitute targeted advertising if the hashes are used to serve cross-site ads, and the opt-out right for targeted advertising applies regardless of whether money changed hands.

Tooling

Benny the Doorman is built for this compliance posture.

Free, cookieless fingerprinting that defers to your consent management platform, runs on Indian infrastructure, and ships with a DPA addendum sized for the jurisdiction above.

Last reviewed 2026-06-06