IN

Indiana Privacy Law

Indiana Consumer Data Protection Act

Effective: January 1, 2026ActiveReviewed by PrivacyLawMap editorial teamLast verified: January 1, 2026

Overview

The Indiana Consumer Data Protection Act (INCDPA), enacted as Senate Bill 5 during the 2023 legislative session and signed into law on May 1, 2023, is codified at Indiana Code Title 24, Article 15 (IC 24-15). The law became effective on January 1, 2026, making Indiana one of eight states whose comprehensive privacy laws activated that day. Attorney General Todd Rokita, who has been vocal about data privacy as a consumer protection priority, released a Consumer Data Protection Bill of Rights in late 2025 to help Hoosier consumers understand their new rights. AG Rokita's office has emphasized that enforcement will be complaint-driven through the AG's online consumer complaint portal, supplemented by independent AG staff reviews of business practices. Rokita has publicly criticized the law's exemptions for nonprofits, utilities, banks, and HIPAA-covered entities, stating he expects to recommend narrowing these exemptions to the Indiana General Assembly during the 2026 legislative session while enforcing the statute as written in the meantime.

The INCDPA closely follows the Virginia VCDPA framework but includes several Indiana-specific features. Consumers have the right to access, correct, delete, and obtain a portable copy of their personal data, plus opt-out rights for data sales, targeted advertising, and profiling with significant decision-making effects. Two notable deviations from the Virginia model: first, controllers may respond to access requests with either a full copy of the personal data or a "representative summary," reducing compliance costs while maintaining transparency; second, the right to correct is narrower than in most states, applying only to data the consumer previously provided to the controller rather than all personal data in the controller's possession. The law defines "sale" strictly as monetary exchange between a controller and third party — excluding consideration-based data sharing that broader laws like California's CCPA capture. The INCDPA also requires an appeals process for denied consumer rights requests, with a 45-day response window for the controller, after which consumers may contact the Attorney General if their appeal is denied. Sensitive data — including racial or ethnic origin, religious beliefs, health diagnoses, sexual orientation, citizenship or immigration status, genetic or biometric data processed for identification, precise geolocation data (within a 1,750-foot radius), and personal data of known children under 13 — requires opt-in consent before processing.

The INCDPA applies to for-profit entities conducting business in Indiana or targeting Indiana consumers that controlled or processed personal data of at least 100,000 Indiana residents in the prior calendar year, or at least 25,000 residents while deriving over 50% of gross revenue from the sale of personal data. Entity-level exemptions cover HIPAA-covered entities, financial institutions subject to the Gramm-Leach-Bliley Act, nonprofits, higher education institutions, and government entities. Critically, the INCDPA features a permanent 30-day cure period that does not sunset — making it one of the most business-friendly enforcement provisions among all state privacy laws. The AG must provide written notice of alleged violations and allow 30 days to cure before pursuing enforcement. Civil penalties reach up to $7,500 per violation, enforceable exclusively by the Indiana Attorney General through the Consumer Protection Division. There is no private right of action. AG Rokita has indicated that privacy notice compliance will be an early enforcement priority, specifically requiring businesses to place a "clearly marked privacy notice or data-rights link in a prominent spot on their website."

Applicability Thresholds

Conditions are joined by OR meeting ANY one triggers applicability.

100,000+
Indiana consumers' data processed
25,000+ consumers
AND 50%+ revenue from data sales

Consumer Rights

Right to Access
Right to Delete
Right to Correct
Data Portability
Opt-Out of Sale
Opt-Out of Targeted Ads
Opt-Out of Profiling
Limit Sensitive Data Use
Right to Appeal
Private Right of Action

Key Changes in 2025-2026

  • Law became effective January 1, 2026 — all businesses meeting thresholds must be in full compliance
  • AG Todd Rokita released Consumer Data Protection Bill of Rights (late 2025) explaining consumer rights and how to file complaints
  • Permanent 30-day cure period (does not sunset) — one of the most business-friendly enforcement provisions among all 21 state privacy laws
  • AG Rokita criticized exemptions for nonprofits, utilities, banks, and HIPAA entities — expects to recommend narrowing exemptions to legislature in 2026 session
  • AG office prioritizing privacy notice compliance — businesses must display "clearly marked privacy notice or data-rights link" prominently on websites
  • Enforcement driven by consumer complaints via AG online portal plus independent AG staff reviews of business practices
  • Sale of personal data defined narrowly as monetary exchange only — excludes consideration-based sharing captured by CCPA and broader laws
  • No universal opt-out mechanism (GPC) requirement — Indiana aligns with Virginia, Iowa, and Utah in not mandating GPC recognition
  • Right to correct limited to data consumer previously provided — narrower than most state privacy laws
  • Controllers may respond to access requests with "representative summary" instead of full data copy — unique among state privacy laws

Enforcement Details

Enforced By
Indiana Attorney General — Consumer Protection Division
Penalty Per Violation
$7,500
Cure Period
30 days
Private Right of Action
No — AG enforcement only

Sensitive Data Categories

Consent model: opt-in

Racial or ethnic originReligious beliefsMental or physical health diagnosisSexual orientationCitizenship or immigration statusGenetic or biometric data processed for identificationPrecise geolocation data (within 1,750-foot radius)Personal data of a known child under 13

Universal Opt-Out / GPC Requirements

No Universal Opt-Out Requirement

The INCDPA does not require businesses to recognize or honor universal opt-out mechanisms such as Global Privacy Control (GPC). Indiana aligns with Virginia, Iowa, Utah, and Kentucky in not mandating GPC. States that do require GPC recognition include California, Colorado, Connecticut, Texas, Montana, Delaware, New Hampshire, New Jersey, Maryland, Nebraska, Minnesota, and Oregon. Businesses may voluntarily support GPC for Indiana consumers to simplify multistate compliance.

Minor / Child Protections

The INCDPA provides tiered protections for minors. For known children under 13, businesses must obtain opt-in consent before processing any personal data — this data is classified as sensitive data under the law. For consumers aged 13 to 17, businesses must obtain opt-in consent before processing their data for targeted advertising or sale of personal data. The law does not require age verification or age-gating mechanisms, instead applying its protections to "known" children, consistent with the COPPA framework.

Compliance Checklist

  1. 1Determine INCDPA applicability: confirm whether your organization processes personal data of 100,000+ Indiana residents, or 25,000+ residents while deriving 50%+ of gross revenue from data sales. Check entity-level exemptions — HIPAA-covered entities, GLBA financial institutions, nonprofits, higher education, and government entities are fully exempt at the entity level
  2. 2Post a prominent privacy notice or data-rights link on your website — AG Rokita has identified privacy notice compliance as an early enforcement priority. The notice must disclose: categories of personal data processed, purposes of processing, categories of third-party recipients, how consumers can exercise their rights, and categories of data shared with third parties
  3. 3Implement opt-out mechanisms for three categories: sale of personal data (monetary exchange), targeted advertising, and profiling that produces legal or similarly significant effects. Note that Indiana defines "sale" narrowly — only monetary exchanges qualify, not consideration-based data sharing
  4. 4Obtain opt-in consent before processing any of the 8 sensitive data categories: racial/ethnic origin, religious beliefs, health diagnoses, sexual orientation, citizenship/immigration status, genetic or biometric data for identification, precise geolocation (1,750-foot radius), and children's data (under 13). Implement consent mechanisms that are specific, informed, and freely given
  5. 5Build consumer rights request intake and fulfillment processes with a 45-day response window (extendable by 45 additional days with notice to consumer). Include a 10-business-day acknowledgment of receipt. You may provide either a full data copy or a "representative summary" for access requests — Indiana uniquely permits this summary approach
  6. 6Establish an appeals process for denied requests: consumers must be able to appeal within a reasonable time, and the controller must respond within 60 days. Include a mechanism for the consumer to contact the Indiana Attorney General if the appeal is denied — provide the AG complaint portal link in your response
  7. 7Implement age-appropriate protections: for known children under 13, obtain opt-in consent before any data processing. For consumers 13-17, obtain consent before processing for targeted advertising or data sale. Document your age-awareness procedures consistent with the COPPA framework
  8. 8Review and update all data processor agreements to include INCDPA-mandated provisions: clear processing instructions, confidentiality obligations, deletion or return of data upon contract termination, audit cooperation rights, and subcontractor flow-down requirements
  9. 9Apply data minimization principles: collect only personal data that is adequate, relevant, and reasonably necessary for the disclosed purpose. Retain data only for as long as necessary. Conduct and document purpose limitation assessments
  10. 10Prepare for AG enforcement inquiries: maintain records of all consumer requests, responses, and opt-out signals. AG Rokita's office has indicated they will conduct independent reviews in addition to responding to consumer complaints. Establish a 30-day cure-period response protocol — designate a compliance point person who can assess and remediate alleged violations within the statutory cure window
  11. 11Conduct a data protection assessment for processing activities that present heightened risk of harm: targeted advertising, sale of personal data, processing sensitive data, and profiling. Document the assessment and maintain it for AG inspection
  12. 12Map INCDPA requirements against overlapping state laws (Virginia VCDPA, Kentucky KCDPA, Iowa ICDPA) since all follow the VCDPA model — identify Indiana-specific controls including the narrower correction right, representative summary option for access requests, and permanent cure period
Put INCDPA Into Practice on Your SiteSponsored

Termly builds and maintains an Indiana-ready privacy policy, a cookie consent banner, opt-in consent capture for sensitive data, and a workflow for the access, deletion and correction requests INCDPA grants.

Start Free with Termly

Indiana Privacy Law FAQ

Official Resources