Indiana
INCDPA Compliance Checklist for Indiana Businesses
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 11 primary sources cited on this page. How we verify our legal content

A business complies with the Indiana Consumer Data Protection Act (INCDPA) by confirming it meets the IC 24-15-1-1 thresholds, publishing a privacy notice that covers the elements in IC 24-15-4-3, obtaining opt-in consent before processing sensitive data, building a consumer-request and appeal workflow, conducting data protection assessments for high-risk processing, and signing data processing agreements with every processor. The law takes effect January 1, 2026, the longest runway any state has given.
As of 2026, enforcement is the Indiana Attorney General's alone under IC 24-15-10. A controller gets a 30-day cure period under IC 24-15-10-3 that has no sunset, but an uncured violation can draw a civil penalty up to $7,500 each under IC 24-15-10-2. There is no private right of action.
Jurisdiction scope: This covers Indiana's Consumer Data Protection Act (Indiana Code Article 24-15). It is general legal information, not legal advice.
Step 1: Confirm whether the INCDPA applies
The first task is the applicability test in IC 24-15-1-1. The law reaches a person that conducts business in Indiana, or produces products or services targeted to Indiana residents, that during a calendar year controls or processes personal data of at least 100,000 Indiana consumers, OR at least 25,000 Indiana consumers while deriving more than 50% of gross revenue from the sale of personal data.
Count carefully. A "consumer" is an Indiana resident acting in an individual or household context, so employees, job applicants, and business-to-business contacts do not count. Many mid-sized businesses fall below the 100,000-consumer threshold and outside the law entirely.
Then check the entity exemptions in IC 24-15-1-1. The article does not apply to the state and its agencies and political subdivisions, GLBA-covered financial institutions, HIPAA covered entities and business associates, nonprofit organizations, institutions of higher education, public utilities (as defined in IC 8-1-2-1(a)) and their affiliated service companies, or 501(c)(4) organizations established to detect or prevent insurance-related crime or fraud that operate under a memorandum of understanding with a statewide law enforcement agency. If a full entity exemption applies, the analysis can end there.
Finally, review the data exemptions in IC 24-15-1-2 for data already regulated by HIPAA, the Fair Credit Reporting Act, the Driver's Privacy Protection Act, FERPA, and the Farm Credit Act. COPPA is not one of these data exemptions; it is a separate compliance duty under IC 24-15-4-1(5), which requires processing a known child's sensitive data in accordance with COPPA rather than relying on ordinary consent. A covered business may still need a program for its non-exempt data even if much of its data is carved out.
Step 2: Write a compliant privacy notice
Covered controllers must publish a privacy notice. IC 24-15-4-3 requires a reasonably accessible, clear, and meaningful notice that includes five elements, and a notice that omits any of them is non-compliant.
The notice must disclose: the categories of personal data the controller processes; the purpose for processing; how consumers may exercise their rights under Chapter 3, including how to appeal a controller's decision; the categories of personal data the controller shares with third parties, if any; and the categories of third parties with whom it shares personal data.
Because the INCDPA mirrors Virginia, a business that already maintains a VCDPA-compliant notice can usually adapt it for Indiana with minimal changes. The required elements are nearly identical.
Separately, IC 24-15-4-4 imposes an opt-out disclosure. If the controller sells personal data or uses it for targeted advertising, it must clearly and conspicuously disclose that activity and the manner in which a consumer may opt out. This disclosure is distinct from the general privacy notice and should be unmistakable.
Step 3: Handle sensitive data with opt-in consent
Indiana takes the stricter, opt-in route to sensitive data. Under IC 24-15-4-1(5), a controller "shall not process sensitive data concerning a consumer without obtaining the consumer's consent." There is no notice-and-opt-out alternative as there is in Iowa or Utah.
Sensitive data is defined in IC 24-15-2-28. It includes personal data revealing racial or ethnic origin, religious beliefs, a mental or physical health diagnosis, sexual orientation, or citizenship or immigration status, plus genetic or biometric data used to uniquely identify a person, data collected from a known child, and precise geolocation data.
For a known child, IC 24-15-4-1(5) requires the controller to process the data in accordance with the federal Children's Online Privacy Protection Act rather than relying on ordinary consent. Build a consent flow that captures, records, and can later prove opt-in for each sensitive-data use.
Map your data first. Many businesses discover they collect sensitive data, such as precise location or health-related fields, without a consent mechanism. Identifying those flows before January 1, 2026 is the practical core of this step.

Step 4: Build the consumer-request and appeal workflow
A covered controller must be able to receive and fulfill the five rights in IC 24-15-3-1: confirm and access, correct, delete, portability, and the three opt-outs. Stand up secure intake channels and an identity-verification process before the effective date.
Meet the deadlines. Under IC 24-15-3-1(c)(1), respond within 45 days, with one optional 45-day extension that you must announce within the first 45 days. Under IC 24-15-3-1(c)(3), provide information free up to once a year per consumer, charging a fee (or declining to act) only for requests that are manifestly unfounded, excessive, or repetitive, and only when you can prove that basis.
Build the appeal process. IC 24-15-3-1(d) requires a conspicuous appeal mechanism, similar to the request mechanism, with a written decision within 60 days. If you deny an appeal, you must give the consumer a way to contact the Indiana Attorney General to submit a complaint.
Remember the third-party-data accommodation. Under IC 24-15-3-1(c)(5), if you obtained data from a source other than the consumer, you comply with a deletion request by retaining only a record of the request and the minimum data needed to keep the consumer's data suppressed, and using it for no other purpose.
Step 5: Run data protection impact assessments
Indiana requires data protection impact assessments for higher-risk processing. IC 24-15-6-1 lists the activities that trigger an assessment, and the requirement applies to processing activities created or generated after December 31, 2025.
A controller must conduct and document an assessment for: processing for targeted advertising; the sale of personal data; profiling that presents a reasonably foreseeable risk of unfair or deceptive treatment, financial or physical or reputational injury, intrusion on solitude, or other substantial injury; the processing of sensitive data; and any processing that presents a heightened risk of harm to consumers.
Each assessment must weigh the benefits of the processing against the risks to the consumer, as mitigated by safeguards, and must factor in de-identification, consumer expectations, and the context of the controller-consumer relationship. A single assessment may cover a comparable set of similar processing operations.
An assessment done for another law or regulation can satisfy the INCDPA if it has a reasonably comparable scope and effect, so a GDPR or VCDPA assessment can often be reused. Keep these assessments because the Attorney General can require disclosure during an investigation.

Step 6: Put processor contracts in place
The INCDPA distinguishes controllers from processors and requires a contract between them, following the Virginia template in Chapter 5. A processor that handles personal data on a controller's behalf must do so under a binding agreement.
That contract must set out processing instructions, the nature and purpose of processing, the type of data, the duration, and the rights and obligations of both parties. It should also bind the processor to confidentiality, to assisting the controller in responding to consumer requests, to deleting or returning data at the end of the engagement, and to flowing the same terms down to any subcontractors.
Inventory every vendor that touches Indiana-resident personal data: cloud hosts, analytics providers, marketing platforms, and support tools. Each needs a data processing agreement that satisfies Chapter 5 before the engagement continues past the effective date.
Misclassifying a processor as a mere vendor is a common gap. If a service provider determines the purposes and means of processing, it may itself be a controller with independent duties, which changes the contract and the compliance posture.
Step 7: Plan for enforcement and the 30-day cure
The INCDPA is enforced by the Indiana Attorney General alone. IC 24-15-10-1 grants exclusive enforcement authority, and Chapter 9 gives the Attorney General investigative tools, including the ability to compel information.
The penalty exposure is set by IC 24-15-10-2: an injunction plus a civil penalty up to $7,500 for each violation, and the Attorney General may recover reasonable investigation and litigation expenses. There is no private right of action, so the risk is regulatory rather than class-action driven.
Indiana provides a permanent cure period. Under IC 24-15-10-3, before initiating an action the Attorney General must give 30 days' written notice identifying the specific provisions allegedly violated. If the controller cures within 30 days and provides an express written statement that the violation is cured and that steps were taken to prevent recurrence, the Attorney General "shall not initiate an action." Unlike several states whose cure rights expire, Indiana's has no sunset, so the cure opportunity remains available indefinitely.
INCDPA compliance at a glance
| Requirement | Indiana INCDPA citation | Key point |
|---|---|---|
| Applicability | IC 24-15-1-1 | 100,000 consumers, or 25,000 plus 50% sale revenue |
| Privacy notice | IC 24-15-4-3 | Five required disclosure elements |
| Sensitive data | IC 24-15-4-1(5) | Opt-in consent; COPPA for children |
| Opt-out disclosure | IC 24-15-4-4 | Disclose sale and targeted-ad opt-outs; no UOOM mandate |
| Consumer requests | IC 24-15-3-1(c) | 45-day response, one 45-day extension |
| Appeals | IC 24-15-3-1(d) | 60-day decision; route to Attorney General |
| Assessments | IC 24-15-6-1 | Required for high-risk processing |
| Enforcement | IC 24-15-10 | AG only; 30-day cure; up to $7,500 per violation |
Related guides
- Indiana Data Privacy Laws (INCDPA hub)
- What Is the INCDPA? Indiana's Data Privacy Law Explained
- INCDPA Consumer Rights: What Indiana Residents Can Do
- US State Privacy Laws Comparison
- What Is the CCPA? California's Privacy Law Explained
More Indiana Laws
Frequently Asked Questions
When do businesses have to comply with the INCDPA?
The INCDPA takes effect January 1, 2026. Governor Eric Holcomb signed it as Senate Bill 5 on May 1, 2023, giving businesses roughly two and a half years to prepare, the longest runway of any state privacy law. Compliance obligations begin on the January 1, 2026 effective date.
How does a business know if the INCDPA applies to it?
Under IC 24-15-1-1, the INCDPA applies to a business operating in Indiana or targeting Indiana residents that, in a calendar year, controls or processes personal data of at least 100,000 Indiana consumers, or at least 25,000 Indiana consumers while deriving more than 50% of gross revenue from the sale of personal data. Employees and business contacts are not counted as consumers.
Does the INCDPA require honoring universal opt-out signals?
No. The INCDPA does not mandate a universal opt-out mechanism. IC 24-15-4-4 requires a controller that sells data or uses it for targeted advertising to clearly and conspicuously disclose that activity and how to opt out, but it does not require recognizing browser signals such as Global Privacy Control, unlike Colorado and Connecticut.
What must an INCDPA privacy notice include?
Under IC 24-15-4-3, the privacy notice must be reasonably accessible, clear, and meaningful, and must disclose the categories of personal data processed, the purpose for processing, how consumers may exercise and appeal their rights, the categories of data shared with third parties, and the categories of those third parties.
Does the INCDPA require consent for sensitive data?
Yes. Under IC 24-15-4-1(5), a controller may not process sensitive data without obtaining the consumer's opt-in consent, and must follow the federal COPPA for a known child. Sensitive data is defined in IC 24-15-2-28 and includes health, biometric, geolocation, immigration status, and other categories.
Are data protection assessments required under the INCDPA?
Yes. IC 24-15-6-1 requires controllers to conduct and document data protection impact assessments for targeted advertising, the sale of personal data, risky profiling, the processing of sensitive data, and any processing that presents a heightened risk of harm. An assessment done for another law with comparable scope can be reused.
What are the penalties for violating the INCDPA?
Under IC 24-15-10-2, the Indiana Attorney General may seek an injunction and a civil penalty up to $7,500 per violation, plus reasonable investigation and litigation expenses. Before suing, the Attorney General must give a 30-day cure period under IC 24-15-10-3, which is permanent. There is no private right of action.
Is the INCDPA cure period permanent?
Yes. The 30-day cure period in IC 24-15-10-3 has no sunset date. If a controller cures an alleged violation within 30 days of the Attorney General's written notice and provides an express written statement of cure and non-recurrence, the Attorney General shall not initiate an action. This cure opportunity remains available indefinitely.
Updates
Corrected the INCDPA compliance checklist: COPPA is now described as a sensitive-data compliance duty rather than a data exemption, the entity-exemption list now includes all seven statutory categories (adding public utilities and 501(c)(4) insurance-fraud-detection nonprofits), and the fee-waiver standard now matches the statute's three grounds (unfounded, excessive, or repetitive).
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Removed a fabricated '1,750-foot radius' qualifier on precise geolocation data; IC 24-15-2-28 treats all precise geolocation data as sensitive with no distance threshold or carve-out.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Indiana Code, TITLE 24. TRADE REGULATION
§ 24-15-4-1Responsibilities of controller; discrimination against consumer for exercising consumer rights prohibited; processing of sensitive dataIn forcecited in 4 of our articles
Sec. 1. Except as provided in IC 24-15-7-2, a controller has the following responsibilities: (1) A controller shall limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which such data is processed, as disclosed to the consumer. (2) Except as otherwise provided in this article, a controller shall not process personal data for purposes that are neither reasonably necessary for nor compatible with the disclosed purposes for which the personal data is processed, unless the controller obtains the consumer's consent. (3) A controller shall establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data. The data security practices required under this subdivision must be appropriate to the volume and nature of the personal data at issue. (4) A controller shall not process personal data in violation of state and federal laws that prohibit unlawful discrimination against consumers.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at iga.in.gov
Also relied on in: INCDPA Consumer Rights: Indiana Data Privacy Rights, What Is the INCDPA? Indiana's Data Privacy Law, Indiana Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 24-15-1-1Applicability to persons; exceptionsIn forcecited in 4 of our articles
Sec. 1. (a) This article applies to a person that conducts business in Indiana or produces products or services that are targeted to residents of Indiana and that during a calendar year: (1) controls or processes personal data of at least one hundred thousand (100,000) consumers who are Indiana residents; or (2) controls or processes personal data of at least twenty-five thousand (25,000) consumers who are Indiana residents and derives more than fifty percent (50%) of gross revenue from the sale of personal data. (b) This article does not apply to any of the following: (1) Either of the following: (A) The state, a state agency, or a body, authority, board, bureau, commission, district, or agency of any political subdivision of the state. (B) A third party under contract with an entity described in clause (A), when acting on behalf of the entity. This clause does not exempt data held or created by third parties outside of the scope of the contract with the entity. (2) Any financial institutions and affiliates, or data subject to Title V of the federal Gramm-Leach-Bliley Act (15 U.S.C. 6801 et seq.).
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at iga.in.gov
Also relied on in: Indiana Data Privacy Laws: ICDPA Consumer Rights Guide (2026)
§ 24-15-4-3Privacy notice to consumers; required elementsIn force
Sec. 3. A controller shall provide consumers with a reasonably accessible, clear, and meaningful privacy notice that includes: (1) the categories of personal data processed by the controller; (2) the purpose for processing personal data; (3) how consumers may exercise their consumer rights under IC 24-15-3, including how a consumer may appeal a controller's decision with regard to the consumer's request; (4) the categories of personal data that the controller shares with third parties, if any; and (5) the categories of third parties, if any, with whom the controller shares personal data.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at iga.in.gov
§ 24-15-4-4Sale of personal data to third parties; use of personal data for targeted advertising; disclosure; consumer's right to opt outIn forcecited in 2 of our articles
Sec. 4. If a controller sells a consumer's personal data to third parties or uses a consumer's personal data for targeted advertising, the controller shall clearly and conspicuously disclose such activity, as well as the manner in which a consumer may exercise the right to opt out of such sales or use.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at iga.in.gov
§ 24-15-3-1Personal data; consumer rights; consumer's request to controller; compliance by controller; consumer's right to appealIn forcecited in 6 of our articles
Sec. 1. (a) A consumer may invoke one (1) or more rights set forth in subsection (b) by submitting to a controller a request specifying the rights the consumer wishes to invoke. A known child's parent or legal guardian may invoke on behalf of the child one (1) or more rights set forth in subsection (b) with respect to the processing of personal data belonging to the known child by submitting to a controller a request specifying the rights the consumer wishes to invoke on behalf of the child. Except as provided in IC 24-15-7-1(c) and IC 24-15-7-2, and subject to any limitations or conditions set forth in subsections (b) and (c), a controller shall comply with an authenticated consumer request to exercise a right set forth in subsection (b). (b) A consumer has the following rights: (1) To confirm whether or not a controller is processing the consumer's personal data and, subject to the limitations set forth in subdivision (4), to access such personal data.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at iga.in.gov
Also relied on in: How to Request Your Personal Data: US Privacy Rights by State
§ 24-15-6-1Applicability of data protection impact assessment requirements; controller's duty to conduct assessment; activities subject to assessment; weighing of benefits and risks; assessments conducted for compliance with other lawsIn force
Sec. 1. (a) The data protection impact assessment requirements set forth in this chapter apply to processing activities created or generated after December 31, 2025, and are not retroactive to any processing activities created or generated before January 1, 2026. (b) A controller shall conduct and document a data protection impact assessment of each of the following processing activities involving personal data: (1) The processing of personal data for purposes of targeted advertising. (2) The sale of personal data. (3) The processing of personal data for purposes of profiling, if such profiling presents a reasonably foreseeable risk of: (A) unfair or deceptive treatment of, or unlawful disparate impact on, consumers; (B) financial, physical, or reputational injury to consumers; (C) a physical or other intrusion upon the solitude or seclusion, or the private affairs or concerns, of consumers, if such intrusion would be offensive to a reasonable person; or (D) other substantial injury to consumers. (4) The processing of sensitive data. (5) Any processing activities involving personal data that present a heightened risk of harm to consumers.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at iga.in.gov
§ 24-15-10-3Notice of alleged violation; controller's or processor's right to cureIn forcecited in 2 of our articles
Sec. 3. (a) Before initiating an action under section 2 of this chapter, the attorney general shall provide a controller or processor thirty (30) days written notice identifying the specific provisions of this article that the attorney general alleges have been or are being violated. If within the thirty (30) day period set forth in this section, the controller or processor: (1) cures the alleged violation; and (2) provides the attorney general an express written statement that: (A) the alleged violation has been cured; and (B) actions have been taken to ensure no further such violations will occur; the attorney general shall not initiate an action against the controller or processor. (b) If a controller or processor: (1) continues the alleged violation following the thirty (30) day period set forth in subsection (a); or (2) breaches an express written statement provided to the attorney general under subsection (a)(2); the attorney general may initiate an action under section 2 of this chapter.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at iga.in.gov
§ 24-15-10-2Action by attorney general for violation; injunction; civil penalty; recovery of expensesIn forcecited in 2 of our articles
Sec. 2. (a) The attorney general may initiate an action in the name of the state and may seek an injunction to restrain any violations of this article and a civil penalty not to exceed seven thousand five hundred dollars ($7,500) for each violation under this article. (b) The attorney general may recover reasonable expenses incurred in investigating and preparing the case, including attorney's fees, in any action initiated under this chapter.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at iga.in.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Indiana Code 24-15-1-1: Applicability and Entity Exemptions(iga.in.gov).gov
- Indiana Code 24-15-4-3: Privacy Notice Requirements(iga.in.gov).gov
- Indiana Code 24-15-4-1: Controller Responsibilities; Sensitive Data Consent(iga.in.gov).gov
- Indiana Code 24-15-4-4: Opt-Out Disclosure for Sale and Targeted Advertising(iga.in.gov).gov
- Indiana Code 24-15-3-1: Consumer Requests, Response Deadlines, and Appeals(iga.in.gov).gov
- Indiana Code 24-15-6-1: Data Protection Impact Assessments(iga.in.gov).gov
- Indiana Code 24-15-10-2: Injunction and Civil Penalty(iga.in.gov).gov
- Indiana Code 24-15-10-3: 30-Day Cure Period(iga.in.gov).gov
- Indiana Code Article 24-15: Consumer Data Protection (Full Text)(iga.in.gov).gov
- Indiana Attorney General: Consumer Protection(in.gov).gov
- Indiana Senate Bill 5 (2023): Consumer Data Protection(iga.in.gov).gov