Privacy Law Library

Indiana Consumer Data Protection Act

INCDPA

Comprehensive privacy

Indiana's comprehensive consumer privacy law, modeled on Virginia's, took effect January 1, 2026. It gives Indiana residents rights to confirm and access, correct, delete, and obtain a copy or representative summary of their personal data, and to opt out of targeted advertising, sale, and significant profiling. Controllers must get opt-in consent for sensitive data, publish a privacy notice, maintain reasonable security, and conduct data protection impact assessments for high-risk processing.

Where
Indiana
Citation
Ind. Code art. 24-15 (IC 24-15-1-1 to 24-15-11-2)
Status
In force
In force since
2026-01-01
Last amended
2026-01-01
Enforced by
Indiana Attorney General (exclusive authority, IC 24-15-10-1)
People can sue
No
Penalties
Injunction and a civil penalty of up to $7,500 per violation plus investigative and attorney's fees (IC 24-15-10-2), but only after 30 days' written notice and an opportunity to cure; the cure period has no sunset (IC 24-15-10-3). No private right of action (IC 24-15-10-4).
Applies to
  • Persons that conduct business in Indiana or produce products or services targeted to Indiana residents and that in a calendar year control or process personal data of at least 100,000 Indiana consumers, or of at least 25,000 Indiana consumers while deriving over 50% of gross revenue from the sale of personal data (IC 24-15-1-1(a))
  • Exempt entities: the state and political subdivisions and their contractors acting for them, GLBA financial institutions and affiliates, HIPAA covered entities and business associates, nonprofits, higher education institutions, public utilities and affiliated service companies, and certain 501(c)(4) insurance-fraud organizations (IC 24-15-1-1(b); the 501(c)(4) exemption added by P.L.236-2025)
  • Exempt data: HIPAA PHI, human-subjects research data, FCRA-regulated activity, DPPA, FERPA and Farm Credit Act data, and employment-context and emergency-contact data (IC 24-15-1-2)

What a privacy notice must say

  • Clearly and conspicuously disclose any sale of personal data or targeted advertising and how to opt out.IC 24-15-4-4 · Only if: If the controller sells personal data or engages in targeted advertising
  • Provide a reasonably accessible, clear, and meaningful privacy notice listing categories of data processed, purposes, how to exercise and appeal rights, categories shared, and categories of third parties.IC 24-15-4-3

Rights it gives people

  • Provide a conspicuous appeal process; answer appeals in writing within 60 days and, if denied, tell the consumer how to complain to the Attorney General.IC 24-15-3-1(d)
  • Consumers may confirm processing and access, correct, delete, obtain a portable copy or representative summary (once per 12 months), and opt out of targeted advertising, sale, and profiling with legal or similarly significant effects; a parent may act for a known child.IC 24-15-3-1(a)-(b)

Practices it requires

  • Do not discriminate against consumers for exercising their rights, though bona fide loyalty programs are allowed.IC 24-15-4-1(4)
  • Respond to authenticated consumer requests within 45 days, extendable once by 45 days with notice; first response each year is free.IC 24-15-3-1(c)(1)-(3)
  • Limit collection to what is adequate, relevant, and reasonably necessary for disclosed purposes; get consent for incompatible secondary uses.IC 24-15-4-1(1)-(2)
  • Do not process sensitive data (e.g., racial or ethnic origin, religion, health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric identifiers, known-child data, precise geolocation) without consent; process known-child data in accordance with COPPA.IC 24-15-4-1(5); IC 24-15-2-28
  • Offer one or more secure, reliable request methods described in the privacy notice; a consumer cannot be required to create a new account.IC 24-15-4-5

Security duties

  • Maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal data.IC 24-15-4-1(3)

Other duties

  • Conduct and document data protection impact assessments for targeted advertising, sale, risky profiling, sensitive data, and other heightened-risk processing, for activities created or generated after December 31, 2025.IC 24-15-6-1 · From 2026-01-01
  • Processors must follow controller instructions and assist with consumer requests, security, breach notification under IC 24-4.9, and impact assessments.IC 24-15-5-1 · Only if: Processors

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Whether the Indiana Attorney General has brought any INCDPA enforcement actions since January 1, 2026 (not checked).

Research reference, not legal advice.