Skip to content
    Back to Regulatory Radar
    ImportantDeadlineJuly 1, 2025

    Tennessee and Minnesota Privacy Laws Take Effect

    The Tennessee Information Protection Act (TIPA) took effect July 1, 2025, and the Minnesota Consumer Data Privacy Act became effective on July 31, 2025, adding two more states to the growing roster of comprehensive privacy jurisdictions. Tennessee's law follows the Virginia model and includes a notable affirmative defense provision for organizations that maintain and comply with a written privacy program conforming to NIST privacy framework standards. Minnesota's law includes broader protections and notably requires data protection assessments for certain processing activities.

    State PrivacySaaSFinTechHealthcare

    Key Analytics

    July 1, 2025
    Event Date
    Time Remaining
    August 1, 2026
    Last Verified
    1
    Frameworks Affected

    Impact Analysis

    Tennessee's affirmative defense provision is the first of its kind and provides a tangible compliance incentive for organizations to adopt recognized privacy frameworks such as the NIST Privacy Framework. This approach may influence other states considering privacy legislation to include similar safe harbor provisions. Minnesota's data protection assessment requirements add to the growing list of states mandating documented risk assessments, making these assessments a de facto national requirement for organizations processing personal data at scale.

    Recommended Actions

    • Evaluate adopting the NIST Privacy Framework as your organization's privacy program foundation, which can serve as the basis for Tennessee's affirmative defense and demonstrate maturity to regulators in other jurisdictions.
    • Complete data protection assessments for processing activities covered under Minnesota's requirements, including targeted advertising, profiling, and sensitive data processing.
    • Update your state privacy law tracking and compliance matrix to incorporate Tennessee and Minnesota's specific requirements, deadlines, and enforcement provisions.

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Analyst estimate
    Moderate50-110 hours
    Key Workstreams
    • NIST Privacy Framework alignment and written program documentation
    • Minnesota data protection assessments for advertising and profiling
    • Compliance matrix update for Tennessee and Minnesota

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowModerate · 50-110 hours
    Start cold under pressureSignificant · 120-260 hours

    Roughly 70 to 150 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events