Tennessee buyer guide
Outsourcing software development from Tennessee
A Tennessee buyer guide to international software and AI outsourcing: TIPA privacy programs, supplier instructions, rights tests, framework change, incidents, and exit.

Tennessee outsourcing at a glance
| Tennessee buyer condition | Decision before international access | Evidence to retain |
|---|---|---|
| Ordinary software work with no TIPA-covered consumer operation | Apply proportionate security, delivery, intellectual-property, acceptance, continuity, and exit controls without claiming TIPA coverage or a defense | Scope record, system and data map, named team, buyer-owned accounts and repositories, tests, releases, support, and exit result |
| Buyer may meet TIPA’s entity, revenue, targeting, and consumer thresholds | Complete a current applicability analysis for the actual legal entity and processing before relying on the statute | Entity and affiliate map, revenue basis, Tennessee-targeting facts, consumer counts, sale-revenue analysis, role, exclusions, source date, reviewer, and decision |
| Provider processes covered personal information on a controller’s behalf | Put the precise processing instructions, assistance, confidentiality, return/deletion, assessment, and subprocessor path into a binding operating packet | Signed terms, instruction IDs, purposes, data, duration, people, systems, subprocessors, rights route, security evidence, assessments, changes, and closure |
| A consumer-rights request reaches a system touched by the supplier | Route and authenticate it, search every approved copy, execute the decision, and return evidence within the buyer’s statutory workflow | Receipt time, authentication result, systems searched, matches, action, exclusions, propagation, export, response, appeal route, owner, and timestamps |
| Targeted advertising, sale, sensitive data, qualifying profiling, or another heightened-risk operation is proposed | Stop the operation until the buyer documents the applicable assessment and approves mitigations | Use and version, data and people, benefits, reasonably foreseeable risks, safeguards, residual decision, reviewer, supplier evidence, and reassessment triggers |
| Buyer or processor relies on a written privacy program | Map actual data operations to program outcomes and keep the program accurate as products, suppliers, and frameworks change | Program and version, framework status, operation-to-outcome mapping, implementation evidence, exceptions, reviews, version-watch decisions, and approved updates |
| Provider maintains Tennessee personal information it does not own and discovers a possible breach | Escalate immediately through the owner route while preserving facts so the owner can evaluate the separate notification law | Discovery time, reporter, owner, systems, data, encryption/key facts, residents, containment, evidence, updates, decisions, notices, and closure |
| Buyer or workflow may fall within a healthcare, financial, nonprofit, higher-education, employment, or other exclusion | Prove the exact entity/data/context exclusion and identify the separate governing lane; do not assume “healthcare-adjacent” equals exempt | Entity and data analysis, agreement, regulated role, records, applicable sources, contract controls, incident path, rights path if any, and qualified approval |
| Tennessee participants span Eastern and Central time | Schedule from actual cities and dates, then protect one decision window plus asynchronous handoff | Named people/cities, IANA zones, date-aware overlap, daylight transitions, authority window, escalation, handoff, and sustainable-hours review |
This table is procurement triage, not a legal determination. TIPA contains defined thresholds, roles, exclusions, limitations, remedies, and conditions. The Tennessee breach statute is a separate analysis. Confirm the current sources and facts with qualified owners before promising coverage, noncoverage, an affirmative defense, or a notice result.
Decide the operating lane before choosing a country
The same Tennessee buyer may have several different lanes. A consumer application could be subject to TIPA, a covered healthcare workflow could sit in an entity or data exclusion, workforce data could be outside the statute’s consumer context, and an internal engineering tool could contain no Tennessee consumer personal information at all. A single global “privacy compliant” field cannot describe that portfolio.
Create one classification record for each material work package:
- Contracting and operating entities: identify the buyer, affiliates, controller, processor, joint decision-makers, data owner, regulated entity, system owner, and decision authority. Do not aggregate unrelated entities merely to reach a preferred answer.
- Consumer and targeting context: identify whose data is processed, why the person is acting, whether the product or service targets Tennessee residents, and which annual period supplies the count and revenue facts.
- Scope facts: record revenue, Tennessee consumer volume, sale-related revenue, covered operation, exemptions or excluded information, and the evidence date. TIPA’s adopted amendment changed the introduced thresholds, so use the final legislative record rather than a recycled summary of the original bill.
- Operation and role: state the purpose and means for each operation. A service provider can be a processor for one operation and exercise controller-like authority for another. The decision follows the facts and actual instruction, not the label in the master agreement.
- Systems and copies: list production, test, analytics, support, ticketing, logs, observability, model, prompt, evaluation, backups, exports, local devices, and subprocessors. A rights or deletion workflow cannot cover copies it does not know exist.
- Separate obligations: identify breach, healthcare, financial, insurance, employment, public-sector, contract, professional, export, destination-country, and intellectual-property lanes without pretending TIPA replaces them.
- Decision and uncertainty: record the source, reviewer, assumptions, unresolved questions, decision, approval, and next review. Keep real data and production access out of scope while a material classification remains unresolved.
TIPA took effect July 1, 2025. The adopted amendment described coverage for a person conducting business in Tennessee or producing products or services targeting Tennessee residents that exceeds $25 million in revenue and also meets either the 175,000-consumer annual processing threshold or the 25,000-consumer plus greater-than-50%-of-gross-revenue-from-sale path. Do not drop the revenue condition, substitute a nationwide count without analysis, or quote the introduced 100,000-consumer threshold as the enacted test.
Coverage is not the only useful design question. A buyer outside TIPA may still choose the same operating controls because they improve product quality, data governance, customer trust, and exit readiness. Label those as buyer requirements or risk controls—not Tennessee statutory mandates.
Build a privacy-program delta register
A written privacy program is not an abstract binder. It should describe how the organization governs actual processing. International delivery creates frequent deltas: a new developer needs access, a model service receives prompts, analytics gains an event, support exports a record, a subprocessor changes region, or a team begins using production data for evaluation. Each change can move operations away from the program even when the policy document remains untouched.
Maintain one buyer-owned register row per material data operation:
| Register field | Required decision | Operating evidence |
|---|---|---|
| Operation ID and owner | What collection, use, disclosure, sale, profiling, storage, support, model, or deletion action exists and who accepts it | Data-flow reference, product owner, privacy owner, system owner, release/version |
| Consumer and scope | Which person context and Tennessee facts apply | Consumer definition, targeting, count/revenue basis, role, exclusion analysis, reviewed source |
| Purpose and necessity | Why the operation exists and whether the fields are adequate, relevant, and reasonably necessary for the disclosed purpose | Product requirement, field list, alternatives, notice, approval, expiry |
| Program outcome | Which written privacy-program outcome governs the operation | Program/version, framework/version or status, profile/outcome, internal requirement, owner |
| Supplier instruction | What the international provider may and may not do | Work-order ID, purpose, data, systems, people, duration, access, prohibited reuse, AI position |
| Consumer-rights behavior | How access, correction, deletion, portability, opt-out, authentication, refusal, and appeal work | Test cases, systems searched, propagation map, response template, appeal route, result |
| Assessment and safeguards | Whether the operation requires an assessment and what reduces risk | Assessment ID, benefits/risks, mitigations, residual decision, security and privacy evidence |
| Supplier chain | Which entities and services receive data or authority | Legal entity, country/region, purpose, fields, terms, retention, training use, subprocessor contract |
| Evidence and exception | How operation-to-program conformance is observed and who can accept a variance | Logs, reports, tests, reviews, exception owner, rationale, expiry, remediation |
| Incident and exit | Who receives an event and how all copies, access, and knowledge transfer end | 24/7 path, evidence preservation, return/deletion steps, retained exceptions, revocation, recovery test |
The register is a control interface between privacy, product, engineering, security, legal, procurement, and the provider. Store sensitive evidence with appropriate restrictions, but keep decision status visible to the people who approve releases and access.
Require a delta record before a new processing path begins. The review can be lightweight for low-risk changes, but it must answer whether purpose, data, people, location, recipient, retention, rights, assessment, program mapping, or evidence changed. If no field changed, record that conclusion. If one did, update the instruction and test before release.
Operate a real framework-version watch
TIPA’s legislative record requires a controller or processor to create, maintain, and comply with a written privacy program that reasonably conforms to the NIST Privacy Framework. It also describes a one-year period to reasonably conform after NIST publishes a subsequent revision. The same record provides an affirmative defense where a controller or processor creates, maintains, and complies with the described program. These are consequential legal concepts; a provider should not market a framework logo as a certification or promise that a buyer qualifies.
As reviewed on August 15, 2026, NIST’s official Version 1.1 project page still labels 1.1 an initial public draft and says the final version is forthcoming. A public draft can be useful planning input, but it is not silently treated here as the published subsequent revision that starts the statutory one-year clock. Monitor the authoritative NIST page and have qualified owners record the status and effect.
Use a version-watch record with:
- authoritative NIST URL, page status, document identifier, version, publication date, and retrieval evidence;
- whether the item is a concept paper, initial public draft, final publication, correction, mapping, or implementation resource;
- current organizational program and profile version;
- delta analysis between current outcomes and the new material;
- legal decision about whether and when a statutory clock starts;
- affected operations, suppliers, policies, tests, contracts, training, and evidence;
- approved implementation plan, owner, milestones, exceptions, and completion evidence;
- next monitoring date and fallback owner.
Do not let the supplier decide this alone. The buyer owns its program and legal position; a processor may also have its own program responsibilities. The contract should require notice of a supplier program or framework change, but buyer acceptance remains explicit.
Reasonable conformance is not the same as copying every framework sentence into a questionnaire. Create a current profile suited to the organization and systems, define observable outcomes, connect them to operations, and collect proportionate evidence. If an outcome does not apply, preserve the rationale. If the program claims an activity that operations do not perform, correct the program or implementation rather than hiding the mismatch.
Turn consumer rights into regression tests
TIPA’s legislative record includes authenticated rights to confirm and access processing, correct inaccuracies, delete personal information, obtain portable data for qualifying automated processing, and opt out of sale, targeted advertising, or profiling in furtherance of decisions producing legal or similarly significant effects. It describes a response without undue delay and within 45 days, one reasonably necessary 45-day extension with timely notice, and a no-cost appeal process with a written response within 60 days. The exact request, authentication, exceptions, frequency, role, and facts still matter.
Treat these as end-to-end product behaviors. A help-desk macro is not enough if data remains in a provider’s search index, feature store, evaluation set, ticket attachment, local file, model context, or subprocessor.
Build a rights test pack with synthetic personas and approved test accounts:
- Submit each supported request through every advertised intake method.
- Verify the request receives a durable timestamp, identity, requested rights, jurisdiction context, and accountable owner.
- Test authentication that is proportionate and does not demand unrelated information or force creation of a new account.
- Search the system-of-record map, including international-provider systems and approved subprocessors.
- Correct a value and prove propagation to product, support, analytics, caches, exports, and future derived processing where applicable.
- Delete approved records and reconcile active systems, deferred backup treatment, legal or security exceptions, provider copies, and response wording.
- Produce a portable export in the actual supported format and test whether it is complete, intelligible, safe, and technically usable.
- Exercise each applicable opt-out and prove that collection, routing, audience, sale, advertising, and significant-decision paths change as intended.
- Test refusal and appeal with a clear reason, conspicuous no-cost route, written decision, and the Attorney General contact mechanism when required.
- Measure queue time, authentication time, system search, supplier action, evidence return, review, response, and appeal. Alert before the statutory outside limit becomes the operating target.
Run the pack before production, after a material schema or service change, and periodically against the live architecture using controlled accounts. Do not insert real consumer information into a test merely to prove deletion. Keep test data clearly marked and prevent it from entering business analytics or model training.
The controller remains accountable for its response. The processor should assist according to the instruction and contract, return evidence in time for buyer review, and refrain from replying independently unless specifically authorized. Define urgent routing for requests that arrive directly at an overseas contributor or subprocessor.
Make the controller-to-processor packet executable
TIPA’s legislative record describes a binding controller-processor contract that states processing instructions, nature and purpose, data types, duration, and party rights and obligations. It also describes confidentiality, return or deletion at the controller’s direction unless law requires retention, information necessary to demonstrate compliance, reasonable assessments or a qualified independent assessment path, and written flow-down to subprocessors.
Convert the legal terms into a versioned packet attached to the work:
- contracting entities and operation-specific controller/processor analysis;
- approved purposes, products, features, systems, fields, people, consumers, and duration;
- prohibited secondary use, sale, targeted advertising, independent profiling, model training, benchmarking, and product improvement unless separately approved;
- identity, role, country, device, repository, environment, and least-privilege access rules;
- confidentiality and training obligations for each authorized person;
- rights-request routing, action, evidence, timing, exception, and appeal assistance;
- assessment inputs, test results, audit or independent-assessment evidence, remediation, and protected access to reports;
- subprocessor request, review, objection, contract flow-down, change notice, incident, and exit;
- security, vulnerability, logging, secure-development, release, incident, continuity, and recovery requirements;
- return, deletion, retained-record exception, backup expiration, access revocation, reconciliation, and buyer validation.
A report from an independent assessor can support a decision, but it does not prove every proposed operation is inside the assessed boundary. Record report type, assessor, system and period, services, locations, subservice organizations, exceptions, complementary buyer controls, bridge coverage, and relevance. Ask for additional targeted evidence where the report does not answer the operation-specific question.
When a supplier requests a change, compare it against the packet. Adding a code assistant, model API, monitoring agent, translation tool, support platform, repository mirror, or new country is a data-operation change even if the statement of work price does not change. Keep the previous instruction until the buyer approves the delta.
Gate assessments before higher-risk processing
TIPA’s legislative record describes data protection assessments for targeted advertising, sale, certain profiling presenting reasonably foreseeable risk, sensitive-data processing, and other processing presenting heightened risk of harm. It describes weighing direct and indirect benefits against risks to consumer rights as mitigated by safeguards. It also allows the Attorney General to request a relevant assessment in an investigation and treats assessments as confidential in the stated circumstances.
Create an assessment trigger screen at intake and change review. It should not be a provider self-certification. Ask whether the operation changes advertising, sale, sensitive data, significant decisions, observation, identity, inference, location, biometrics, children, health signals, financial effects, scale, novelty, recipients, retention, or the ability to exercise rights.
For a triggered assessment, preserve:
- operation, product, model, dataset, system, version, release, and responsible entity;
- affected people and contexts, including people who may not be direct users;
- personal information, sensitive elements, sources, inferred fields, recipients, and retention;
- intended benefits to the controller, consumer, other stakeholders, and public;
- reasonably foreseeable privacy, discrimination, economic, physical, reputational, autonomy, intrusion, and security risks;
- alternatives, data minimization, consent or choice, human review, explanations, monitoring, and rights handling;
- supplier claims, evaluation design, limitations, failure cases, red-team or abuse testing, and production observability;
- safeguards, residual risk, conditions, rejection or approval, named owner, and review date;
- change triggers for new data, model, threshold, vendor, purpose, population, geography, or evidence.
Keep confidential material in an access-controlled evidence store. The product and release systems need only the approved status, conditions, version, owner, and expiry. That separation protects the assessment while preventing a release from bypassing it.
Put AI and automation inside the same operation model
An AI feature is not one processing operation. It can include prompt collection, retrieval, embeddings, inference, safety filtering, human review, logging, evaluation, feedback, fine-tuning, analytics, and support. Each stage can have a different provider, region, retention rule, role, and consumer-rights behavior.
Before an international team connects a model service, require an AI data-path record:
| AI path | Buyer decision | Proof before release |
|---|---|---|
| Prompt and attachment intake | Which fields are necessary and which sensitive or restricted inputs must be blocked or transformed | Schema, UI warning, server validation, redaction test, rejection logs, approved exceptions |
| Retrieval and embeddings | Which sources, permissions, derived vectors, indexes, and deletion relationships exist | Corpus inventory, access inheritance test, index location, lineage, correction/deletion test |
| Model/API provider | Which entity, model/version, region, retention, training setting, abuse monitoring, and subproviders apply | Approved terms, configuration capture, request/response logging policy, change alert, withdrawal test |
| Output and significant action | Whether a person is affected by profiling or a consequential decision and where human authority remains | Use-case assessment, evaluation, thresholds, human review, explanation, contest and override test |
| Feedback and evaluation | Whether real interactions may enter datasets and how rights propagate | Sampling rule, consent or notice analysis, dataset IDs, provenance, access, retention, deletion and correction |
| Support and incident | Who can inspect prompts/outputs and how an event is escalated | Role map, support path, redaction, audit log, 24/7 contacts, preserved evidence, tabletop result |
Do not accept “no training” as a complete data policy. It says nothing about retention, abuse review, logging, subprocessors, region, support access, evaluation, derived records, deletion, or a future terms change. Capture the actual configuration and terms that apply to the buyer account, then monitor them.
If an AI provider changes models automatically, decide which changes are material and create a release gate. Repeat evaluation and assessment review when behavior, data use, location, evidence, or significant-decision risk changes. Preserve rollback or disable authority with the buyer.
Control deidentified, pseudonymous, and derived data honestly
Changing a label does not eliminate privacy risk. TIPA’s legislative record describes measures, a public commitment, contractual recipient obligations, and oversight for deidentified-data treatment. It also addresses pseudonymous data and circumstances in which consumer-rights duties differ. Those conditions require fact-specific review.
Keep a transformation and recipient record:
- original data and accountable owner;
- transformation method, code/version, parameters, operator, environment, and date;
- identifiers removed, generalized, tokenized, hashed, perturbed, aggregated, or retained;
- linkage material, keys, lookup tables, auxiliary information, and who can reach them;
- realistic reidentification or singling-out analysis for the intended recipient and context;
- permitted purpose, prohibition on reidentification, onward transfer, retention, security, and incident terms;
- recipient identity, country/region, systems, subprocessors, evidence, monitoring, and violations;
- correction, deletion, source refresh, model/index rebuild, and exit behavior.
Do not call ordinary pseudonymization, tokenization, or removal of direct names “anonymous” without testing the remaining attributes and recipient context. If the supplier can combine records with buyer or public data, the transformation may not support the promised boundary.
Derived records need special attention. A score, embedding, segment, profile, prediction, summary, or model-training example may retain a relationship to the underlying consumer. The rights test should decide whether and how an approved correction, deletion, or opt-out affects each derivative. Record technical limits and qualified decisions rather than silently excluding derivatives because they are inconvenient.
Separate the breach handoff from TIPA operations
Tennessee’s data-breach notification law is a separate lane. The Attorney General’s current consumer-law page states that businesses, the State, or political subdivisions generally must notify affected Tennessee residents in the described circumstances and identifies a 45-day outside period subject to the law-enforcement condition. Current statutory treatment and the actual personal-information and event facts require qualified review.
For outsourcing, the first control is immediate custodian-to-owner escalation. A provider maintaining Tennessee personal information it does not own should not wait for a polished legal conclusion or the external notice deadline. The buyer needs facts while it still has time to investigate and decide.
The initial incident packet should include:
- discovery time, reporter, supplier, service, environment, affected accounts, and observed behavior;
- whether the supplier owns the information or maintains it for the buyer or another entity;
- possible Tennessee residents, data categories, encryption state, key exposure, acquisition indicators, and current estimate;
- affected systems, logs, devices, exports, backups, model services, subprocessors, and locations;
- containment taken, authority used, actions awaiting buyer approval, and risk of evidence loss;
- preserved artifacts, custody, unavailable evidence, investigation owner, and next update time;
- continuously updated decision, communication, resident-count, remediation, and closure records.
Contract for a 24/7 secure reporting channel, short internal target, acknowledgment, update cadence, cooperation, forensics, notice support, costs, regulator/customer allocation, and evidence retention. Test the path outside the normal overlap window. The buyer—not the overseas engineer—owns legal notification decisions unless authority is expressly assigned and valid.
Handle healthcare and other exclusions as separate lanes
TIPA’s legislative record identifies several excluded entities, data types, and contexts, including specified HIPAA covered entities or business associates and health information, financial institutions or GLBA data, insurers, nonprofits, higher education, and employment-context data, among others. The 2025 amendment adjusted part of the nonprofit definition. These are not interchangeable blanket exclusions.
A health-tech company is not automatically a covered entity. A covered entity does not automatically place every affiliate, product, consumer dataset, marketing workflow, or non-HIPAA operation outside TIPA. A vendor that is a business associate for one service may process separate data in another role. Build an entity-and-data matrix and have qualified owners determine the actual lane.
For healthcare-adjacent work, record:
- covered entity, business associate, subcontractor, consumer application, employer, provider, plan, or other actual role;
- data source, health relationship, HIPAA status, agreement, purpose, system, recipient, and whether information is mixed;
- minimum-necessary or buyer-approved field boundary, access, environment, logging, retention, return, and deletion;
- HIPAA/security/breach route where applicable and separate Tennessee or contract duties;
- consumer-rights behavior for data not inside the relied-on exclusion;
- model, analytics, support, marketing, and research paths that may differ from the core clinical workflow.
Apply the same precision to financial, insurance, nonprofit, higher-education, public-sector, and workforce projects. “Regulated” is not a control specification, and “exempt” does not mean unprotected. Use the governing source and contract for that lane, then preserve proportionate security, purpose, access, incident, continuity, and exit controls.
Schedule Tennessee from the actual buyer city
Tennessee crosses the federal boundary between Eastern and Central time. Nashville and Memphis operate on Central time; Knoxville and Chattanooga operate on Eastern time. Confirm the actual participant cities, maintained IANA identifiers, project dates, and daylight transitions rather than assigning one clock to the state or promising a fixed year-round offset.
Design one dependable decision window for product, security, privacy, release, and incident questions. Put routine work into asynchronous briefs and handoffs so international contributors do not depend on unhealthy schedules. For every critical decision, identify a primary, alternate, response target, and what the supplier may do safely while waiting.
Test the proposed schedule with named people during the paid pilot. Record attendance, handoff latency, blocked decisions, defect response, escalation, and fatigue. A country can look ideal on a time-zone chart and still fail when the proposed team has a commute, another client, rotating shifts, or no buyer-side owner during overlap.
Do not choose a supplier from time zone alone. Evaluate role depth, written reasoning, English or required language, domain knowledge, secure-development practice, privacy operation quality, retention of the named team, intellectual-property chain, continuity, evidence, and exit.
Choose the delivery and commercial model explicitly
Outsourcing.ai can deliver a defined software or AI project directly, coordinate disclosed specialists, or run an independent provider selection. The proposal should identify the contracting entity, delivery model, countries, named roles, supplier relationships, data operations, systems, evidence, acceptance, support, and exit. It should not imply a Tennessee office, a regulator relationship, or client history that has not passed the site’s fail-closed naming-permission gate.
Price the operating model, not just hours. A credible proposal separates discovery and classification, product design, implementation, privacy/security work, environments, automated and manual testing, rights testing, assessment support, release, documentation, transition, support, and contingency. It states currency, taxes, transfer costs, travel, tools, model/API consumption, cloud spend, minimum commitments, rate review, replacement costs, and termination economics.
Fixed price fits a bounded deliverable with testable acceptance and controlled assumptions. Time and materials fits discovery or evolving product work but requires backlog, burn, forecast, and change discipline. A dedicated team fits durable delivery when the buyer can maintain product decisions and continuity. A milestone pilot is usually safer than committing a large production scope before the named team proves the privacy-program control loop.
Compare total operating cost:
delivery fees + buyer management + privacy/security evidence + tools/cloud/model use + transition + expected rework + continuity reserve + exit
A lower hourly rate can be more expensive when the supplier cannot trace data, return rights evidence, preserve a release, or hand the system to a successor. Score uncertainty instead of hiding it behind a blended rate.
Run a Tennessee privacy-program pilot
Use a paid, production-shaped pilot that is small enough to contain but rich enough to test the real boundary. A suitable pilot implements one meaningful workflow with synthetic or approved test data, one international team, buyer-controlled accounts, a program delta register, a rights pack, a change request, an incident tabletop, and an exit exercise.
Before access
- Complete the operation-level coverage, role, data, purpose, system, assessment, and separate-lane classification.
- Approve the privacy-program outcome and framework status without claiming certification or a defense.
- Sign the controller-to-processor packet and named-team/access roster.
- Configure buyer-controlled repository, identity, secrets, environments, logs, issue tracking, artifact storage, and backups.
- Approve model/API, subprocessor, region, retention, support, and training-use settings.
- Define acceptance, evidence, incident, rights, change, escalation, return/deletion, and exit.
During delivery
- Require short written briefs and decisions tied to the operation ID.
- Review repository, identity, cloud, model, ticket, and data-path observations against the register.
- Submit synthetic access, correction, deletion, portability, and opt-out requests; include a refusal-and-appeal tabletop.
- Introduce one proposed supplier or AI service change and verify that work stops pending delta review.
- Run a suspected-breach exercise outside the primary overlap window.
- Build from a clean buyer-controlled environment and preserve source-to-artifact provenance.
Before acceptance
- Resolve every program-register exception or document qualified acceptance and expiry.
- Reconcile data copies, derived records, subprocessors, rights results, assessment conditions, logs, defects, and decisions.
- Have a buyer-side or independent owner deploy or reproduce the accepted build from controlled source.
- Revoke one test contributor and prove access removal across code, cloud, data, models, support, devices, and secrets.
- Export the system, runbooks, configuration, evidence, and open-risk register; restore or transfer without the supplier’s primary administrator.
- Execute return/deletion and reconcile retained exceptions and backup expiry.
Use stop conditions. Pause expansion for undisclosed services or people, unauthorized data, failed rights propagation, unreviewed high-risk processing, unverifiable evidence, unsafe credentials, unexplained framework claims, repeated missed overlap, or an exit that depends on the supplier’s goodwill.
Score evidence, not sales confidence
Use weighted criteria appropriate to the project:
| Criterion | Example weight | Demonstration |
|---|---|---|
| Privacy-program operation fit | 18% | Maps the proposed operation to a versioned program outcome, instruction, evidence, exception, and review |
| Rights and data control | 16% | Completes access, correction, deletion, portability, opt-out, refusal, and appeal exercises across supplier copies |
| Engineering quality | 15% | Produces reviewed, tested, maintainable work from buyer-controlled source with reproducible artifacts |
| Security and incident readiness | 13% | Shows least privilege, protected secrets, logs, vulnerability response, immediate escalation, evidence preservation, and recovery |
| Assessment and AI discipline | 12% | Detects assessment triggers, documents risks and mitigations, controls model data paths, and stops unapproved change |
| Named team and schedule | 9% | Demonstrates role depth, actual Eastern/Central overlap, clear writing, sustainable hours, and alternates |
| Supplier-chain transparency | 7% | Discloses legal entities, people, countries, services, subprocessors, terms, retention, and change routes |
| Continuity and exit | 7% | Revokes access, returns or deletes data, transfers knowledge, rebuilds/restores, and reconciles exceptions |
| Commercial clarity | 3% | States assumptions, total operating costs, change mechanics, dependencies, and termination economics |
Set minimum thresholds for privacy, security, rights, and exit. Do not allow a low price to compensate for a failed mandatory gate. Keep evaluator notes and conflicts. If Outsourcing.ai is a proposed delivery party, disclose that role and keep the same visible criteria.
Tennessee buyer red flags
- The proposal uses the introduced TIPA threshold instead of the adopted threshold or ignores the revenue condition.
- A provider says TIPA applies to every Tennessee business—or that one exclusion eliminates every privacy or security obligation.
- “NIST Privacy Framework 1.1 certified” appears without an authoritative certification scheme or while the cited NIST source still labels 1.1 an initial public draft.
- A framework mapping contains no operation, owner, implementation evidence, exception, or review date.
- The privacy program says one thing while prompts, logs, support exports, analytics, or model evaluation do another.
- Consumer rights stop at the buyer database and do not reach provider systems, derivatives, subprocessors, or approved copies.
- The supplier chooses new purposes, model training, or subprocessors without a controller instruction and delta review.
- A high-risk operation begins before the assessment decision and safeguards are recorded.
- “Deidentified” means only that direct names were removed, with no linkage or recipient-context analysis.
- The incident clause says “as required by law” but provides no 24/7 route, initial fact set, evidence duty, or acknowledgment.
- The schedule describes Tennessee as one time zone or promises overlap without named cities and dates.
- The buyer cannot build, operate, restore, exercise rights, or revoke access without the supplier’s primary administrator.
- The provider wants production data for a free trial before contract, classification, assessment, access, and deletion controls exist.
- A company, client, partner, or regulator name appears without evidence, written naming permission, approved wording, and current publication review.
Frequently asked questions
Does TIPA apply to every Tennessee company that outsources software?
No. The enacted framework has entity, revenue, Tennessee-targeting, consumer-volume or sale-revenue, role, and exclusion conditions. Complete a current fact-specific analysis. A buyer can adopt the guide’s controls voluntarily without claiming TIPA coverage.
What is Tennessee’s enacted TIPA threshold?
The adopted-amendment summary describes a person conducting business in Tennessee or targeting Tennessee residents that exceeds $25 million in revenue and also either controls or processes at least 175,000 consumers in a calendar year, or at least 25,000 consumers while deriving more than 50% of gross revenue from sale of personal information. Confirm the current code and facts with qualified counsel; do not use the introduced 100,000-consumer summary.
Is NIST Privacy Framework 1.1 already the published revision for TIPA’s one-year update clock?
The official NIST project page reviewed August 15, 2026 still labels Version 1.1 an initial public draft and says the final version is forthcoming. This guide therefore treats it as planning input, not automatically as the published subsequent revision. Maintain an authoritative version watch and obtain a qualified decision when NIST publishes a final revision.
Does using the NIST Privacy Framework guarantee Tennessee’s affirmative defense?
No. TIPA’s legislative record ties the defense to creating, maintaining, and complying with the described written privacy program. Eligibility and outcome depend on law and facts. A framework logo, mapping, vendor certificate, or this guide cannot establish the defense.
How quickly should an overseas processor support a Tennessee rights request?
Faster than the controller’s outside response clock. The legislative record describes a controller response without undue delay and within 45 days, with a qualified extension path, plus a 60-day appeal response. The contract should give the supplier a shorter internal target that leaves time for authentication, review, exceptions, communication, and appeal.
Does TIPA exempt all healthcare software?
No. The legislative record identifies specific entity and information exclusions, including certain HIPAA-regulated roles and data. A healthcare-adjacent product, affiliate, marketing system, consumer application, or separate dataset may require a different analysis. Classify the entity, role, data, purpose, and agreement for each operation.
What should an overseas provider do after discovering a possible Tennessee data breach?
Preserve facts and evidence, take only authorized safe containment steps, and immediately escalate through the contracted owner route. The owner and qualified decision-makers evaluate the separate Tennessee notification law and other duties. The supplier should not wait for certainty or a polished root-cause report.
Is Tennessee in Eastern or Central time?
Both. The federal boundary crosses the state. Use each participant’s actual city and maintained IANA time zone for the project dates; then test the schedule and urgent escalation with the named team.
Can Outsourcing.ai deliver the project directly?
Yes. Outsourcing.ai can propose direct delivery, coordinate disclosed specialists, or conduct an independent provider selection. The proposal should state the contracting and delivery model, countries, people, systems, data paths, evidence, acceptance, and exit. No Tennessee office, regulator approval, or unverified client relationship is implied.
May a provider publish the buyer’s or technology partner’s name?
Only with evidence, written naming permission, approved wording, and current publication approval through the site’s fail-closed relationship-claim process. Private tools can be identified for internal diligence without turning them into public client, partner, endorsement, or experience claims.
What is the safest first step?
Run a bounded discovery and pilot. Produce the operation classification, privacy-program delta register, controller instruction, rights test pack, assessment decision, framework-version watch, named-team schedule, incident route, commercial baseline, and exit plan before production access or a long commitment.
Buyers coordinating work north of the state line can use the Kentucky outsourcing buyer guide for its operation-specific role test, separate insurance and Commonwealth lanes, role-drift stop, and Eastern–Central authority record.
Use one operation, one named team, buyer-controlled systems, rights regression tests, a framework-version watch, incident evidence, and a tested exit before scaling international delivery.
Evidence ledger
Sources used on this page
- Public Chapter 408 — Tennessee Information Protection Act — Tennessee Secretary of State. Supports: Official enacted text for TIPA's final scope and thresholds, controller and processor duties, consumer rights and appeal periods, assessments, deidentified data, written privacy programs, enforcement, affirmative defense, exclusions, and July 1, 2025 effective date. Direct source; independently sourced; commercial relationship: none. Verified 8/16/2026 by Outsourcing.ai Editorial Team. Accessed 8/16/2026.
- Public Chapter 201 — TIPA nonprofit-organization amendment — Tennessee Secretary of State. Supports: Official enacted text of the July 1, 2025 amendment to the TIPA nonprofit-organization definition for a public utility organized or regulated under Tennessee law. Direct source; independently sourced; commercial relationship: none. Verified 8/16/2026 by Outsourcing.ai Editorial Team. Accessed 8/16/2026.
- Public Chapter 91 — breach-of-system-security amendment — Tennessee Secretary of State. Supports: Official enacted text for Tennessee's breach-of-system-security definitions, affected-resident disclosure path, 45-day outside notice period, and the additional law-enforcement delay. Direct source; independently sourced; commercial relationship: none. Verified 8/16/2026 by Outsourcing.ai Editorial Team. Accessed 8/16/2026.
- Privacy Framework Version 1.1 project — National Institute of Standards and Technology. Supports: Current official status of Privacy Framework 1.1 as an initial public draft with the final version still forthcoming, supporting a version watch that distinguishes draft activity from a published subsequent revision. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- IANA Time Zone Database — Internet Assigned Numbers Authority. Supports: Maintained time-zone identifiers and transitions for calculating actual overlap between Tennessee buyer locations and proposed international delivery cities. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- 49 CFR § 71.5 — Boundary line between eastern and central zones — Electronic Code of Federal Regulations. Supports: Current federal boundary description supporting location-specific Eastern-versus-Central scheduling inside Tennessee rather than a single statewide clock assumption. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Secure Software Development Framework — National Institute of Standards and Technology. Supports: Maintained secure-development methodology for supplier requirements, protected development environments, provenance, secure releases, vulnerability response, and evidence. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Directory of Intellectual Property Offices — World Intellectual Property Organization. Supports: Official destination-country intellectual-property office links for researching contributor and rights-chain questions without assuming one contract resolves every jurisdiction. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
Next scheduled review: October 15, 2026. Corrections: hello@outsourcing.ai.
