Persons Holding a Customer's Personal Information (disposal of customer records)
IN Customer Data Disposal
Data security
This chapter makes it an infraction to throw away or abandon customers' unencrypted, unredacted personal information (as defined in the breach law, such as SSNs and financial account numbers) in a publicly accessible place without first destroying it. It covers paper and digital records.
- Where
- Indiana
- Citation
- Ind. Code ch. 24-4-14 (IC 24-4-14-1 to 24-4-14-8)
- Status
- In force
- Enforced by
- Prosecuted as an infraction (no agency named in the chapter)
- People can sue
- No
- Penalties
- Class C infraction; a Class A infraction if more than 100 customers' information is involved or the person has a prior judgment (IC 24-4-14-8).
- Applies to
- Individuals, partnerships, corporations, LLCs, and other organizations that hold customers' personal information, including in digital form (IC 24-4-14-5, 24-4-14-6)
- Excludes state and local government offices, waste collectors (except for their own customers' data), and persons that maintain a disposal program under the PATRIOT Act, EO 13224, DPPA, FCRA, GLBA, or HIPAA (IC 24-4-14-1)
Security duties
- Shred, incinerate, mutilate, erase, or otherwise render customers' unencrypted, unredacted personal information unreadable before disposing of it.IC 24-4-14-8
Other duties
- 'Dispose of' means discarding or abandoning information in an area accessible to the public, including putting it in a trash container.IC 24-4-14-3
Sources
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: Effective date of P.L.125-2006, SEC.5 (believed to be July 1, 2006) not confirmed from the enrolled act; left null.
Research reference, not legal advice.