Indiana
Indiana Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 4 primary sources cited on this page. How we verify our legal content

Indiana has no standalone biometric privacy law. Instead, the Indiana Consumer Data Protection Act (IC 24-15), effective January 1, 2026, classifies biometric data as sensitive data and requires opt-in consent before a covered business collects fingerprints, voiceprints, or iris scans. The act reaches only businesses that meet the applicability thresholds in IC 24-15-1-1, so most Indiana businesses are not covered at all. Only the Indiana Attorney General may enforce the law; consumers have no private right of action.
Indiana joined the growing number of states regulating biometric data when the Indiana Consumer Data Protection Act (ICDPA) took effect on January 1, 2026. Signed by Governor Eric Holcomb on May 1, 2023, as Senate Bill 5, the law is codified at Indiana Code Title 24, Article 15 and treats biometric data as a category of sensitive information requiring heightened protections.
Unlike Illinois, which gives individuals the right to sue companies that mishandle biometric data under BIPA, Indiana takes an attorney-general-enforcement-only approach. This makes compliance less litigation-heavy for businesses but gives consumers fewer direct remedies.
For a broader look at Indiana's overall data protection framework, see the parent guide to Indiana Data Privacy Laws.
How Indiana Defines Biometric Data
Under IC 24-15-2-4, biometric data means data that must both (1) be generated by automatic measurements of an individual's biological characteristics and (2) be used to identify a specific individual. The statute lists these examples of qualifying measurements:
- Fingerprints
- Voiceprints
- Images of the retina or iris
- Other unique biological patterns or characteristics
The first part of the definition is intentionally broad, covering emerging biometric technologies such as palm vein scans or gait analysis if they rely on automatic measurement of biological traits used to identify a specific individual.
What the Definition Excludes
The ICDPA specifically excludes the following from its biometric data definition:
- Physical or digital photographs, or data generated from a photograph
- Video or audio recordings, or data generated from a video or audio recording
- Information collected, used, or stored for health care treatment, payment, or operations under HIPAA
The statute does not carve out an exception for photographs, video, or audio recordings that are later used for identification purposes. A security camera recording run through facial recognition software to identify someone is still excluded from the biometric data definition under IC 24-15-2-4.
Biometric Data as Sensitive Data Under the ICDPA
The ICDPA groups biometric data with other categories of sensitive data that receive stronger protections than ordinary personal data. Under IC 24-15-2-28, sensitive data includes:
- Data revealing racial or ethnic origin
- Religious beliefs
- Mental or physical health diagnoses made by a health care provider
- Sexual orientation
- Citizenship or immigration status
- Genetic or biometric data processed for the purpose of uniquely identifying a specific individual
- Personal data collected from a known child under age 13
- Precise geolocation data (within a 1,750-foot radius)
The key phrase is "processed for the purpose of uniquely identifying a specific individual." Because the ICDPA's biometric data definition in IC 24-15-2-4 already requires that the data be used to identify a specific individual, any data that meets the biometric data definition at all is sensitive data under the ICDPA. Automatic measurements of biological characteristics collected without an identifying purpose do not qualify as biometric data under Indiana law in the first place.

Consent Requirements for Biometric Data
The ICDPA requires businesses to obtain opt-in consent before processing any sensitive data, including biometric data. This means a covered business cannot collect fingerprints, voiceprints, or iris scans from Indiana consumers unless those consumers affirmatively agree to the collection.
Consent under the ICDPA must be:
- Freely given by the consumer without coercion
- Specific to the processing activity in question
- Informed so the consumer understands what they are agreeing to
- Unambiguous with a clear affirmative act indicating agreement
Pre-checked boxes, bundled consent buried in terms of service, or implied consent through continued use of a service do not meet the ICDPA standard. The consumer must know they are agreeing to biometric data collection and actively choose to allow it.
Who Must Comply
The ICDPA applies to for-profit entities that conduct business in Indiana or produce products or services targeted to Indiana residents and meet one of two thresholds during a calendar year:
- Control or process personal data of at least 100,000 Indiana consumers, or
- Control or process personal data of at least 25,000 Indiana consumers and derive more than 50% of gross revenue from selling personal data
Small and mid-size businesses that fall below these thresholds are not subject to the ICDPA. However, any covered entity that collects biometric data from Indiana residents must comply with the sensitive data consent requirements.
Exemptions
The ICDPA broadly exempts certain entities and data types from its requirements:
- HIPAA-covered entities: Health care providers, health plans, and their business associates are exempt when handling protected health information
- GLBA-regulated entities: Financial institutions already subject to the Gramm-Leach-Bliley Act
- FCRA data: Information governed by the Fair Credit Reporting Act
- FERPA data: Student education records under the Family Educational Rights and Privacy Act
- DPPA data: Driver information under the Driver's Privacy Protection Act
- Employment data: Data processed about individuals acting in a commercial or employment context
The employment data exemption is significant for biometric privacy. Unlike Illinois BIPA, which explicitly covers employer collection of employee biometric data, the ICDPA exempts data collected in an employment context. Indiana employers using fingerprint time clocks or biometric access systems for their employees face fewer restrictions under the ICDPA as a result.
Controller Obligations for Biometric Data
Businesses that qualify as data controllers under the ICDPA must meet several obligations when handling biometric data.
Privacy Notices
Controllers must publish clear, accessible privacy notices that disclose:
- The categories of personal data they process, including whether they collect biometric data
- The purposes for processing each data category
- How consumers can exercise their rights
- Whether data is shared with third parties and which categories of third parties receive it
Data Minimization
Controllers must limit biometric data collection to what is "adequate, relevant, and reasonably necessary" for the disclosed purpose. A business cannot collect fingerprints for identity verification and then use that same data for marketing analytics without additional consent.
Security Requirements
Controllers must implement "reasonable administrative, technical, and physical data security practices" appropriate to the volume and nature of the personal data they process. Biometric data, as sensitive data, warrants stronger security measures than less sensitive categories.
Data Protection Assessments
The ICDPA requires controllers to conduct data protection assessments for processing activities that present a "heightened risk of harm to consumers." Processing sensitive data, including biometric data, triggers this requirement.
The assessment must weigh:
- Benefits that flow from the processing to the controller, the consumer, and the public
- Risks of harm to the consumer, including risks of unfair treatment, unlawful disparate impact, financial injury, physical injury, and intrusion upon privacy
- Any safeguards the controller has in place to mitigate those risks
Assessments are required for processing activities occurring after December 31, 2025.
Processor Contracts
Controllers that share biometric data with processors (third-party service providers) must establish binding contracts that specify the processing purposes, data categories, duration, and consumer rights obligations. Processors must cooperate with controllers on data rights requests and breach notification.
Consumer Rights Over Biometric Data
Indiana consumers have several rights over their personal data, including biometric information, under the ICDPA.
Right to Know and Access
Consumers can confirm whether a controller is processing their personal data and, subject to the limitations in IC 24-15-3-1(b)(4), access that data.
Subdivision (b)(4) is where Indiana departs from several other state privacy laws. A consumer may obtain either a copy of the personal data they previously provided to the controller or a "representative summary" of it, and the statute expressly gives the controller the discretion to choose which one to send. For biometric information that distinction matters: a consumer who asks for their biometric records may be handed a summary rather than the underlying data. Whichever the controller sends must be in a portable and, to the extent technically practicable, readily usable format.
A controller is not required to provide that copy or representative summary to the same consumer more than one time in a 12-month period. A separate provision, IC 24-15-3-1(c)(3), requires responses to be free of charge up to one time annually per consumer. Past that point, or where requests are manifestly unfounded, excessive, or repetitive, the controller may charge a reasonable fee to cover administrative costs or decline to act, rather than simply refusing all further requests.
Right to Correct
Consumers can request correction of inaccurate personal data, taking into account the nature and purpose of the data processing.
Right to Delete
Consumers can request deletion of personal data that a controller holds about them. This applies to biometric data a business has collected, though certain exceptions allow retention (such as completing a transaction or complying with a legal obligation).
Right to Opt Out
Consumers can opt out of the processing of their personal data for targeted advertising, the sale of personal data, or profiling that produces legal or similarly significant effects.
No Universal Opt-Out Requirement
Unlike some newer state privacy laws, the ICDPA does not require businesses to honor universal opt-out mechanisms such as the Global Privacy Control. Businesses may choose to support GPC voluntarily but are not required to do so.
Enforcement and Penalties

The Indiana Attorney General has exclusive enforcement authority over the ICDPA. There is no private right of action. Individual consumers cannot sue businesses for biometric data violations under this law.
30-Day Cure Period
Before taking action, the Attorney General must provide a written notice identifying the specific provisions allegedly violated. The business then has 30 days to cure the violation. This cure period is permanent under the ICDPA and does not expire or sunset, which is unusual among state privacy laws.
If the business fixes the violation within 30 days, the matter ends. If it does not, the Attorney General may pursue enforcement action.
Civil Penalties

Violations that are not cured carry civil penalties of up to $7,500 per violation. The Attorney General may also seek injunctive relief to stop ongoing violations.
Indiana's Breach Notification Law and Biometric Data
Indiana's Disclosure of Security Breach Act (IC 24-4.9) requires businesses to notify affected individuals and the Attorney General after a data breach. IC 24-4.9-2-10 defines "personal information" in three parts:
- A Social Security number that is not encrypted or redacted, standing alone, with no name element required
- An individual's first and last names, or first initial and last name, together with one or more of the following data elements that are not encrypted or redacted: a driver's license number, a state identification card number, a credit card number, or a financial account number or debit card number in combination with a security code, password, or access code that would permit access to the account
- Information collected by an adult oriented website operator, or its designee, under IC 24-4-23
The definition also excludes information lawfully obtained from publicly available information or from federal, state, or local government records lawfully made available to the general public.
Biometric data appears nowhere in this definition. A breach that exposes only fingerprint templates, voiceprints, or iris scans would not trigger notification requirements under IC 24-4.9.
Businesses that notify the Attorney General must email DataBreach@atg.in.gov and include a sample of the notice sent to affected individuals. If more than 1,000 Indiana residents are affected, the business must also notify consumer reporting agencies (Equifax, Experian, and TransUnion).

How Indiana Compares to Other States
Indiana's approach to biometric data sits in the middle of the national spectrum.
Stronger protections exist in:
- Illinois: BIPA provides a private right of action with statutory damages of $1,000 to $5,000 per violation. It covers employee biometric data and has generated billions of dollars in class action settlements.
- Texas: CUBI gives the Attorney General enforcement power with penalties up to $25,000 per violation.
Similar frameworks exist in:
- States with comprehensive privacy laws that classify biometric data as sensitive (Colorado, Connecticut, Virginia, Montana, Oregon, Delaware) follow the same general pattern as Indiana: opt-in consent for sensitive data, AG enforcement, and no private right of action.
Weaker protections exist in:
- States with no comprehensive privacy law and no biometric-specific statute, where biometric data receives no dedicated state-level protection.
The key distinction between Indiana and Illinois is the employment exemption. Illinois BIPA has generated thousands of lawsuits against employers using fingerprint time clocks. Indiana's ICDPA exempts employment-context data, shielding Indiana employers from similar exposure.
Pending Legislation
As of the 2026 Indiana General Assembly session, no bill amending IC 24-15 (the ICDPA) or creating a BIPA-style private right of action for biometric data has been identified as passed or pending. Senate Bill 76 is sometimes cited in connection with this topic, but it does not amend the ICDPA: it addresses attorney general representation of law enforcement officers and postsecondary institutions in certain immigration-related civil suits, and it was signed into law as Public Law 106 on March 5, 2026. Businesses should monitor the Indiana General Assembly website at iga.in.gov for any future bill that could expand biometric data coverage or modify enforcement mechanisms.
The ICDPA is still in its first year of enforcement, and the Attorney General's office is building its enforcement track record. Future rulemaking or guidance documents from the AG could clarify biometric data obligations further.
This article provides general legal information about Indiana biometric privacy laws under the ICDPA. It is not legal advice. Laws and regulations change frequently, and this content may not reflect the most recent developments. Consult a qualified attorney licensed in Indiana for advice about your specific situation.
More Indiana Laws
Frequently Asked Questions
Does Indiana have a biometric privacy law?
Indiana does not have a standalone biometric privacy law like Illinois BIPA. Instead, biometric data is regulated under the Indiana Consumer Data Protection Act (IC 24-15), which took effect on January 1, 2026. The ICDPA classifies biometric data as sensitive data, requiring opt-in consent before a covered business can collect or process it. Enforcement is handled exclusively by the Indiana Attorney General.
Can my employer collect my fingerprints in Indiana without consent?
The ICDPA exempts data processed about individuals acting in an employment context. This means Indiana employers using fingerprint time clocks, biometric access controls, or similar systems for employees face fewer restrictions under the ICDPA than they would under Illinois BIPA. However, employers should still follow best practices by disclosing biometric data collection and obtaining consent, as federal laws and common-law privacy torts may still apply.
What penalties exist for violating Indiana biometric data laws?
The Indiana Attorney General can impose civil penalties of up to $7,500 per violation of the ICDPA after providing a mandatory 30-day written notice and cure period. If the business corrects the violation within 30 days, no penalties apply. There is no private right of action, so individual consumers cannot sue for biometric data misuse under state law.
Does Indiana require notification if biometric data is breached?
No. Indiana's breach notification law defines personal information (IC 24-4.9-2-10) as an unencrypted, unredacted Social Security number standing alone; a person's name combined with an unencrypted, unredacted driver's license number, state identification card number, credit card number, or financial account or debit card number plus the code that would permit access to it; or information collected by an adult oriented website operator under IC 24-4-23. Biometric data is not included in this definition. A breach involving only fingerprint templates, voiceprints, or iris scans would not trigger notification requirements under Indiana's breach notification statute, though it could still raise obligations under the ICDPA if the controller failed to implement adequate security measures.
How does Indiana's biometric data law compare to Illinois BIPA?
The two laws differ significantly. Illinois BIPA provides a private right of action allowing individuals to sue with statutory damages of $1,000 to $5,000 per violation, covers employee biometric data, and has generated billions in settlements. Indiana's ICDPA offers no private right of action, relies on Attorney General enforcement with $7,500 penalties per violation, exempts employment-context data, and includes a permanent 30-day cure period. Indiana's approach is substantially more business-friendly than Illinois.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected how this page describes Indiana's consumer access right, which lets a controller provide a representative summary rather than a copy of your data, and the three-part definition of personal information in Indiana's breach notification law; also removed an applicability qualifier that is not in IC 24-15-1-1 and clarified that the ICDPA's consent requirement reaches only businesses that meet the act's thresholds.
Corrected a fabricated pending-legislation claim (the cited bill is an unrelated immigration bill already signed into law), fixed a wrong statute citation for the sensitive-data definition, completed the biometric-data definition to include its two-part legal test and HIPAA exclusion, repointed statute citations to the actual code text, and clarified which breach-notification data elements require an accompanying security code.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Indiana Code, TITLE 24. TRADE REGULATION
§ 24-15-4-1Responsibilities of controller; discrimination against consumer for exercising consumer rights prohibited; processing of sensitive dataIn forcecited in 4 of our articles
Sec. 1. Except as provided in IC 24-15-7-2, a controller has the following responsibilities: (1) A controller shall limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which such data is processed, as disclosed to the consumer. (2) Except as otherwise provided in this article, a controller shall not process personal data for purposes that are neither reasonably necessary for nor compatible with the disclosed purposes for which the personal data is processed, unless the controller obtains the consumer's consent. (3) A controller shall establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data. The data security practices required under this subdivision must be appropriate to the volume and nature of the personal data at issue. (4) A controller shall not process personal data in violation of state and federal laws that prohibit unlawful discrimination against consumers.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at iga.in.gov
Also relied on in: INCDPA Consumer Rights: Indiana Data Privacy Rights, What Is the INCDPA? Indiana's Data Privacy Law, INCDPA Compliance Checklist for Indiana Businesses
Explore the law
This article also draws on these acts and chapters (opening at their first section): Indiana Code, TITLE 24. TRADE REGULATION § 24-15-1-1 (Applicability to persons; exceptions)
Related law for further reading — not part of this article’s citations.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Indiana Senate Bill 5 (ICDPA) bill page and enrolled text(iga.in.gov).gov
- Indiana Code Title 24, Article 15 Consumer Data Protection full text(iga.in.gov).gov
- Indiana AG Consumer Data Protection Bill of Rights(in.gov).gov
- Indiana AG security breach notification FAQ and form(in.gov).gov
- Akin Gump analysis of Indiana Data Protection Act obligations(akingump.com)
- Hunton Andrews Kurth Indiana privacy law overview(hunton.com)
- Global Privacy Control specification(globalprivacycontrol.org)
- IC 24-15-1-1 - Indiana Consumer Data Protection Act applicability thresholds and entity exemptions(iga.in.gov)
- IC 24-15-3-1 - Indiana consumer data rights, copy or representative summary, and controller response limits(iga.in.gov)
- IC 24-4.9-2-10 - definition of personal information under Indiana's breach notification law(iga.in.gov)