EnglishEspañol
Indiana flag

Indiana

What Is the INCDPA? Indiana's Data Privacy Law

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 3 primary sources cited on this page. How we verify our legal content

What Is the INCDPA? Indiana's Data Privacy Law

Frequently Asked Questions

What is the INCDPA?

The INCDPA, or Indiana Consumer Data Protection Act, is Indiana's comprehensive consumer data privacy law, codified at Indiana Code Article 24-15 (Chapters 1 through 11). It was enacted as Senate Bill 5, signed by Governor Eric Holcomb on May 1, 2023, and took effect January 1, 2026. It gives Indiana residents a full Virginia-style set of rights over their personal data and is enforced exclusively by the Indiana Attorney General.

When did the Indiana Consumer Data Protection Act take effect?

The INCDPA took effect on January 1, 2026, about two and a half years after Governor Eric Holcomb signed Senate Bill 5 on May 1, 2023. That gap was the longest runway of any state privacy law, and it gave covered businesses more lead time than any comparable statute to build privacy notices and consumer-request processes. That preparation window has closed and the law is now enforceable.

Who does the INCDPA apply to?

Under IC 24-15-1-1, the INCDPA applies to a business operating in Indiana or targeting Indiana residents that, during a calendar year, controls or processes personal data of at least 100,000 Indiana consumers, or controls or processes personal data of at least 25,000 Indiana consumers while deriving more than 50% of gross revenue from the sale of personal data. Indiana residents acting in a commercial or employment context are not counted as consumers.

Is Indiana's privacy law based on Virginia's?

Yes. The INCDPA closely mirrors Virginia's Consumer Data Protection Act (VCDPA). It uses the same coverage thresholds, the same five-part rights list, the same opt-in treatment of sensitive data, and the same attorney-general-only enforcement. A business that built a VCDPA program can largely reuse it for Indiana, because the substantive duties line up almost section for section.

Does the INCDPA require honoring universal opt-out signals?

No. The INCDPA does not mandate a universal opt-out mechanism. IC 24-15-4-4 requires a controller to clearly and conspicuously disclose how a consumer may opt out of the sale of personal data and targeted advertising, but it does not require the controller to recognize browser-level signals such as Global Privacy Control, unlike Colorado, Connecticut, and several other states.

How does the INCDPA handle sensitive data?

The INCDPA uses an opt-in model. Under IC 24-15-4-1(5), a controller may not process sensitive data without obtaining the consumer's consent, and must follow the federal COPPA for a known child. Sensitive data is defined in IC 24-15-2-28 and includes racial or ethnic origin, religious beliefs, health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric identifiers, data of a known child, and precise geolocation.

What entities are exempt from the INCDPA?

IC 24-15-1-1 exempts the state and its agencies and political subdivisions, GLBA-covered financial institutions, HIPAA covered entities and business associates, nonprofit organizations, institutions of higher education, public utilities and their affiliated service companies, and 501(c)(4) organizations established to detect or prevent insurance-related crime or fraud under a memorandum of understanding with a statewide law enforcement agency (the last two added by P.L.236-2025). IC 24-15-1-2 also exempts data governed by HIPAA, the Fair Credit Reporting Act, the Driver's Privacy Protection Act, FERPA, and the Farm Credit Act, plus most employment-related data. COPPA is not a data exemption; under IC 24-15-1-3, complying with COPPA only satisfies the INCDPA's parental-consent obligation for a known child's data.

How is the INCDPA enforced?

The Indiana Attorney General has exclusive enforcement authority under IC 24-15-10-1. Before suing, the Attorney General must give a business 30 days' written notice and a chance to cure under IC 24-15-10-3, a cure right that has no sunset date. If the business does not cure, penalties run up to $7,500 per violation under IC 24-15-10-2. There is no private right of action; IC 24-15-10-4 states that nothing in the article provides the basis for one.

Updates

Updated to reflect that Indiana's Consumer Data Protection Act has been in force since January 1, 2026, corrected the description of the effective-date notation in the Indiana Code and a faulty comparison to Virginia's cure period, and added a pinpoint citation to IC 24-15-10-4 for the absence of a private right of action.

Corrected this page's description of COPPA's role under the INCDPA (it is a parental-consent compliance safe harbor under IC 24-15-1-3, not a data exemption), added two entity exemptions added by a 2025 law amendment (public utilities and certain insurance-fraud-detection nonprofits), fixed the Utah/Connecticut signing order and a citation cross-reference, and repointed several statute citations to working section-specific sources.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Indiana Code Article 24-15: Consumer Data Protection (Full Text)(iga.in.gov).gov
  2. Indiana Code 24-15-1-1: Applicability to Persons; Exceptions(law.justia.com)
  3. Indiana Code 24-15-1-2: Exempt Information and Data(law.justia.com)
  4. Indiana Code 24-15-2-28: Definition of Sensitive Data(law.justia.com)
  5. Indiana Code 24-15-3-1: Personal Data; Consumer Rights(law.justia.com)
  6. Indiana Code 24-15-4-1: Responsibilities of Controller; Sensitive Data Consent(law.justia.com)
  7. Indiana Code 24-15-4-4: Opt-Out Disclosure for Sale and Targeted Advertising(law.justia.com)
  8. Indiana Code 24-15-10: Enforcement and Penalties(law.justia.com)
  9. Indiana Senate Bill 5 (2023): Consumer Data Protection(iga.in.gov).gov
  10. Indiana Attorney General: Consumer Protection(in.gov).gov
  11. Indiana Code 24-15-10-4: No Private Right of Action for Violation(iga.in.gov)
  12. Indiana Code Title 24 (2026 edition): Article 15, Consumer Data Protection, full text(iga.in.gov)
  13. Virginia Code 59.1-584: Enforcement; Civil Penalty; Expenses (VCDPA 30-day cure period)(law.lis.virginia.gov)
Share: