EnglishEspañol
Indiana flag

Indiana

Indiana Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 7 primary sources cited on this page. How we verify our legal content

Indiana Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How long does a business have to notify Indiana residents of a data breach?

Indiana law requires notification without unreasonable delay, but no more than 45 days after the discovery of the breach. This deadline was added by HEA 1351, effective July 1, 2022. The clock starts when the business discovers or is notified of the breach, not when the breach itself occurred. Delays are permitted only to restore system integrity, determine the scope of the breach, or comply with a law enforcement request.

Does Indiana require businesses to notify the Attorney General after a data breach?

Yes. Whenever a business notifies Indiana residents of a data breach, it must also notify the Indiana Attorney General. Businesses submit the Data Breach Notification Form by email to DataBreach@atg.in.gov. A sample of the consumer notification letter should accompany the submission. If more than 1,000 Indiana residents are affected, the business must also notify the nationwide consumer reporting agencies (Equifax, Experian, and TransUnion).

Does encryption protect businesses from Indiana's breach notification requirements?

Yes, Indiana provides an encryption safe harbor. If the compromised personal information was encrypted or redacted, and the encryption key was not accessed or acquired during the breach, notification is not required. However, if the unauthorized person also obtained the encryption key, the full notification obligations apply.

Can individuals sue for a breach notification violation in Indiana?

No. Indiana's breach notification law does not create a private right of action. Only the Indiana Attorney General can enforce the statute. Violations are treated as deceptive acts, with penalties up to $150,000 per deceptive act plus the AG's investigation costs. Individuals may still pursue claims under common law theories like negligence, but not under the breach notification statute itself.

Does Indiana's breach notification law cover biometric data?

No. Indiana's breach notification statute (IC 24-4.9) does not include biometric data in its definition of personal information. This means a breach exposing fingerprints, retina scans, or voiceprints does not trigger notification under this law. The ICDPA (IC 24-15) classifies biometric data as sensitive personal data and requires consent before processing, but it does not extend the breach notification trigger to cover biometric data breaches.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the enforcement section to cite Ind. Code 24-4.9-4-1 and to remove a nonexistent 'knowingly or intentionally' requirement, and narrowed the key takeaway on Attorney General notice to breaches that actually trigger consumer notification.

Corrected the portable-device safe harbor to require full-device encryption (not just a password), fixed the consumer-reporting-agency notification threshold to more than 1,000 residents, re-attributed the federal-compliance-framework exemption to the correct code section, added a 2024 statutory amendment covering adult-website-operator data, fixed a transposed 2022 bill number, and removed an unsupported urgency qualifier from the third-party maintainer's notice duty.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Ind. Code 24-4.9 - Disclosure of Security Breach(iga.in.gov).gov
  2. Indiana AG - Security Breaches Portal(in.gov).gov
  3. Indiana AG - Security Breach FAQs & Notification Form(in.gov).gov
  4. Ind. Code 24-15 - Indiana Consumer Data Protection Act(iga.in.gov).gov
  5. HEA 1351 (2022) - 45-Day Deadline Amendment(iga.in.gov).gov
  6. AG Rokita - Blackbaud $49.5M Settlement(events.in.gov).gov
  7. AG Rokita - Marriott $52M Settlement(events.in.gov).gov
  8. Ind. Code 24-4.9-4-1 - Failure to disclose or notify; deceptive act(iga.in.gov)
  9. Ind. Code 24-4.9-4-2 - Action by attorney general(iga.in.gov)
  10. Ind. Code 24-4.9-3-1 - Disclosure of breach(iga.in.gov)
Share: