Indiana Consumer Data Protection Act
INCDPA
Comprehensive privacy
Indiana's comprehensive consumer privacy law, modeled on Virginia's, took effect January 1, 2026. It gives Indiana residents rights to confirm and access, correct, delete, and obtain a copy or representative summary of their personal data, and to opt out of targeted advertising, sale, and significant profiling. Controllers must get opt-in consent for sensitive data, publish a privacy notice, maintain reasonable security, and conduct data protection impact assessments for high-risk processing.
- Where
- Indiana
- Citation
- Ind. Code art. 24-15 (IC 24-15-1-1 to 24-15-11-2)
- Status
- In force
- In force since
- 2026-01-01
- Last amended
- 2026-01-01
- Enforced by
- Indiana Attorney General (exclusive authority, IC 24-15-10-1)
- People can sue
- No
- Penalties
- Injunction and a civil penalty of up to $7,500 per violation plus investigative and attorney's fees (IC 24-15-10-2), but only after 30 days' written notice and an opportunity to cure; the cure period has no sunset (IC 24-15-10-3). No private right of action (IC 24-15-10-4).
- Applies to
- Persons that conduct business in Indiana or produce products or services targeted to Indiana residents and that in a calendar year control or process personal data of at least 100,000 Indiana consumers, or of at least 25,000 Indiana consumers while deriving over 50% of gross revenue from the sale of personal data (IC 24-15-1-1(a))
- Exempt entities: the state and political subdivisions and their contractors acting for them, GLBA financial institutions and affiliates, HIPAA covered entities and business associates, nonprofits, higher education institutions, public utilities and affiliated service companies, and certain 501(c)(4) insurance-fraud organizations (IC 24-15-1-1(b); the 501(c)(4) exemption added by P.L.236-2025)
- Exempt data: HIPAA PHI, human-subjects research data, FCRA-regulated activity, DPPA, FERPA and Farm Credit Act data, and employment-context and emergency-contact data (IC 24-15-1-2)
What a privacy notice must say
- Clearly and conspicuously disclose any sale of personal data or targeted advertising and how to opt out.IC 24-15-4-4 · Only if: If the controller sells personal data or engages in targeted advertising
- Provide a reasonably accessible, clear, and meaningful privacy notice listing categories of data processed, purposes, how to exercise and appeal rights, categories shared, and categories of third parties.IC 24-15-4-3
Rights it gives people
- Provide a conspicuous appeal process; answer appeals in writing within 60 days and, if denied, tell the consumer how to complain to the Attorney General.IC 24-15-3-1(d)
- Consumers may confirm processing and access, correct, delete, obtain a portable copy or representative summary (once per 12 months), and opt out of targeted advertising, sale, and profiling with legal or similarly significant effects; a parent may act for a known child.IC 24-15-3-1(a)-(b)
Practices it requires
- Do not discriminate against consumers for exercising their rights, though bona fide loyalty programs are allowed.IC 24-15-4-1(4)
- Respond to authenticated consumer requests within 45 days, extendable once by 45 days with notice; first response each year is free.IC 24-15-3-1(c)(1)-(3)
- Limit collection to what is adequate, relevant, and reasonably necessary for disclosed purposes; get consent for incompatible secondary uses.IC 24-15-4-1(1)-(2)
- Do not process sensitive data (e.g., racial or ethnic origin, religion, health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric identifiers, known-child data, precise geolocation) without consent; process known-child data in accordance with COPPA.IC 24-15-4-1(5); IC 24-15-2-28
- Offer one or more secure, reliable request methods described in the privacy notice; a consumer cannot be required to create a new account.IC 24-15-4-5
Security duties
- Maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal data.IC 24-15-4-1(3)
Other duties
- Conduct and document data protection impact assessments for targeted advertising, sale, risky profiling, sensitive data, and other heightened-risk processing, for activities created or generated after December 31, 2025.IC 24-15-6-1 · From 2026-01-01
- Processors must follow controller instructions and assist with consumer requests, security, breach notification under IC 24-4.9, and impact assessments.IC 24-15-5-1 · Only if: Processors
Sources
- Official text
- Indiana Code 2026, Title 24, Article 15 (Indiana General Assembly)
- SEA 5 (2023), P.L.94-2023, bill details and enrolled act, SECTION 1 effective January 1, 2026
- Enrolled SEA 5 (2023) PDF
- HEA 1587 (2025), P.L.236-2025, SECTION 5 amending IC 24-15-1-1 effective January 1, 2026
- Indiana Attorney General, Indiana Consumer Data Protection Consumer Bill of Rights (confirms Jan. 1, 2026 effective date and AG complaint process)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: Whether the Indiana Attorney General has brought any INCDPA enforcement actions since January 1, 2026 (not checked).
Research reference, not legal advice.