EnglishEspañol
Indiana flag

Indiana

INCDPA Compliance Checklist for Indiana Businesses

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 11 primary sources cited on this page. How we verify our legal content

INCDPA Compliance Checklist for Indiana Businesses

Frequently Asked Questions

When do businesses have to comply with the INCDPA?

The INCDPA takes effect January 1, 2026. Governor Eric Holcomb signed it as Senate Bill 5 on May 1, 2023, giving businesses roughly two and a half years to prepare, the longest runway of any state privacy law. Compliance obligations begin on the January 1, 2026 effective date.

How does a business know if the INCDPA applies to it?

Under IC 24-15-1-1, the INCDPA applies to a business operating in Indiana or targeting Indiana residents that, in a calendar year, controls or processes personal data of at least 100,000 Indiana consumers, or at least 25,000 Indiana consumers while deriving more than 50% of gross revenue from the sale of personal data. Employees and business contacts are not counted as consumers.

Does the INCDPA require honoring universal opt-out signals?

No. The INCDPA does not mandate a universal opt-out mechanism. IC 24-15-4-4 requires a controller that sells data or uses it for targeted advertising to clearly and conspicuously disclose that activity and how to opt out, but it does not require recognizing browser signals such as Global Privacy Control, unlike Colorado and Connecticut.

What must an INCDPA privacy notice include?

Under IC 24-15-4-3, the privacy notice must be reasonably accessible, clear, and meaningful, and must disclose the categories of personal data processed, the purpose for processing, how consumers may exercise and appeal their rights, the categories of data shared with third parties, and the categories of those third parties.

Does the INCDPA require consent for sensitive data?

Yes. Under IC 24-15-4-1(5), a controller may not process sensitive data without obtaining the consumer's opt-in consent, and must follow the federal COPPA for a known child. Sensitive data is defined in IC 24-15-2-28 and includes health, biometric, geolocation, immigration status, and other categories.

Are data protection assessments required under the INCDPA?

Yes. IC 24-15-6-1 requires controllers to conduct and document data protection impact assessments for targeted advertising, the sale of personal data, risky profiling, the processing of sensitive data, and any processing that presents a heightened risk of harm. An assessment done for another law with comparable scope can be reused.

What are the penalties for violating the INCDPA?

Under IC 24-15-10-2, the Indiana Attorney General may seek an injunction and a civil penalty up to $7,500 per violation, plus reasonable investigation and litigation expenses. Before suing, the Attorney General must give a 30-day cure period under IC 24-15-10-3, which is permanent. There is no private right of action.

Is the INCDPA cure period permanent?

Yes. The 30-day cure period in IC 24-15-10-3 has no sunset date. If a controller cures an alleged violation within 30 days of the Attorney General's written notice and provides an express written statement of cure and non-recurrence, the Attorney General shall not initiate an action. This cure opportunity remains available indefinitely.

Updates

Corrected the INCDPA compliance checklist: COPPA is now described as a sensitive-data compliance duty rather than a data exemption, the entity-exemption list now includes all seven statutory categories (adding public utilities and 501(c)(4) insurance-fraud-detection nonprofits), and the fee-waiver standard now matches the statute's three grounds (unfounded, excessive, or repetitive).

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Removed a fabricated '1,750-foot radius' qualifier on precise geolocation data; IC 24-15-2-28 treats all precise geolocation data as sensitive with no distance threshold or carve-out.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Indiana Code 24-15-1-1: Applicability and Entity Exemptions(iga.in.gov).gov
  2. Indiana Code 24-15-4-3: Privacy Notice Requirements(iga.in.gov).gov
  3. Indiana Code 24-15-4-1: Controller Responsibilities; Sensitive Data Consent(iga.in.gov).gov
  4. Indiana Code 24-15-4-4: Opt-Out Disclosure for Sale and Targeted Advertising(iga.in.gov).gov
  5. Indiana Code 24-15-3-1: Consumer Requests, Response Deadlines, and Appeals(iga.in.gov).gov
  6. Indiana Code 24-15-6-1: Data Protection Impact Assessments(iga.in.gov).gov
  7. Indiana Code 24-15-10-2: Injunction and Civil Penalty(iga.in.gov).gov
  8. Indiana Code 24-15-10-3: 30-Day Cure Period(iga.in.gov).gov
  9. Indiana Code Article 24-15: Consumer Data Protection (Full Text)(iga.in.gov).gov
  10. Indiana Attorney General: Consumer Protection(in.gov).gov
  11. Indiana Senate Bill 5 (2023): Consumer Data Protection(iga.in.gov).gov
Share: