Privacy Law Library

Persons Holding a Customer's Personal Information (disposal of customer records)

IN Customer Data Disposal

Data security

This chapter makes it an infraction to throw away or abandon customers' unencrypted, unredacted personal information (as defined in the breach law, such as SSNs and financial account numbers) in a publicly accessible place without first destroying it. It covers paper and digital records.

Where
Indiana
Citation
Ind. Code ch. 24-4-14 (IC 24-4-14-1 to 24-4-14-8)
Status
In force
Enforced by
Prosecuted as an infraction (no agency named in the chapter)
People can sue
No
Penalties
Class C infraction; a Class A infraction if more than 100 customers' information is involved or the person has a prior judgment (IC 24-4-14-8).
Applies to
  • Individuals, partnerships, corporations, LLCs, and other organizations that hold customers' personal information, including in digital form (IC 24-4-14-5, 24-4-14-6)
  • Excludes state and local government offices, waste collectors (except for their own customers' data), and persons that maintain a disposal program under the PATRIOT Act, EO 13224, DPPA, FCRA, GLBA, or HIPAA (IC 24-4-14-1)

Security duties

  • Shred, incinerate, mutilate, erase, or otherwise render customers' unencrypted, unredacted personal information unreadable before disposing of it.IC 24-4-14-8

Other duties

  • 'Dispose of' means discarding or abandoning information in an area accessible to the public, including putting it in a trash container.IC 24-4-14-3

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Effective date of P.L.125-2006, SEC.5 (believed to be July 1, 2006) not confirmed from the enrolled act; left null.

Research reference, not legal advice.