EnglishEspañol
Indiana flag

Indiana

Indiana Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 4 primary sources cited on this page. How we verify our legal content

Indiana Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Frequently Asked Questions

Does Indiana have a biometric privacy law?

Indiana does not have a standalone biometric privacy law like Illinois BIPA. Instead, biometric data is regulated under the Indiana Consumer Data Protection Act (IC 24-15), which took effect on January 1, 2026. The ICDPA classifies biometric data as sensitive data, requiring opt-in consent before a covered business can collect or process it. Enforcement is handled exclusively by the Indiana Attorney General.

Can my employer collect my fingerprints in Indiana without consent?

The ICDPA exempts data processed about individuals acting in an employment context. This means Indiana employers using fingerprint time clocks, biometric access controls, or similar systems for employees face fewer restrictions under the ICDPA than they would under Illinois BIPA. However, employers should still follow best practices by disclosing biometric data collection and obtaining consent, as federal laws and common-law privacy torts may still apply.

What penalties exist for violating Indiana biometric data laws?

The Indiana Attorney General can impose civil penalties of up to $7,500 per violation of the ICDPA after providing a mandatory 30-day written notice and cure period. If the business corrects the violation within 30 days, no penalties apply. There is no private right of action, so individual consumers cannot sue for biometric data misuse under state law.

Does Indiana require notification if biometric data is breached?

No. Indiana's breach notification law defines personal information (IC 24-4.9-2-10) as an unencrypted, unredacted Social Security number standing alone; a person's name combined with an unencrypted, unredacted driver's license number, state identification card number, credit card number, or financial account or debit card number plus the code that would permit access to it; or information collected by an adult oriented website operator under IC 24-4-23. Biometric data is not included in this definition. A breach involving only fingerprint templates, voiceprints, or iris scans would not trigger notification requirements under Indiana's breach notification statute, though it could still raise obligations under the ICDPA if the controller failed to implement adequate security measures.

How does Indiana's biometric data law compare to Illinois BIPA?

The two laws differ significantly. Illinois BIPA provides a private right of action allowing individuals to sue with statutory damages of $1,000 to $5,000 per violation, covers employee biometric data, and has generated billions in settlements. Indiana's ICDPA offers no private right of action, relies on Attorney General enforcement with $7,500 penalties per violation, exempts employment-context data, and includes a permanent 30-day cure period. Indiana's approach is substantially more business-friendly than Illinois.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected how this page describes Indiana's consumer access right, which lets a controller provide a representative summary rather than a copy of your data, and the three-part definition of personal information in Indiana's breach notification law; also removed an applicability qualifier that is not in IC 24-15-1-1 and clarified that the ICDPA's consent requirement reaches only businesses that meet the act's thresholds.

Corrected a fabricated pending-legislation claim (the cited bill is an unrelated immigration bill already signed into law), fixed a wrong statute citation for the sensitive-data definition, completed the biometric-data definition to include its two-part legal test and HIPAA exclusion, repointed statute citations to the actual code text, and clarified which breach-notification data elements require an accompanying security code.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Indiana Senate Bill 5 (ICDPA) bill page and enrolled text(iga.in.gov).gov
  2. Indiana Code Title 24, Article 15 Consumer Data Protection full text(iga.in.gov).gov
  3. Indiana AG Consumer Data Protection Bill of Rights(in.gov).gov
  4. Indiana AG security breach notification FAQ and form(in.gov).gov
  5. Akin Gump analysis of Indiana Data Protection Act obligations(akingump.com)
  6. Hunton Andrews Kurth Indiana privacy law overview(hunton.com)
  7. Global Privacy Control specification(globalprivacycontrol.org)
  8. IC 24-15-1-1 - Indiana Consumer Data Protection Act applicability thresholds and entity exemptions(iga.in.gov)
  9. IC 24-15-3-1 - Indiana consumer data rights, copy or representative summary, and controller response limits(iga.in.gov)
  10. IC 24-4.9-2-10 - definition of personal information under Indiana's breach notification law(iga.in.gov)
Share: