Indiana
What Is the INCDPA? Indiana's Data Privacy Law
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 3 primary sources cited on this page. How we verify our legal content

The Indiana Consumer Data Protection Act (INCDPA) is Indiana's comprehensive consumer data privacy law, codified at Indiana Code Article 24-15 (Chapters 1 through 11). The legislature passed it as Senate Bill 5, Governor Eric Holcomb signed it on May 1, 2023, and it took effect January 1, 2026. The statute is now in force, so the duties described below are current obligations rather than future ones. It gives Indiana residents a full Virginia-style set of rights over their personal data while tracking the controller and processor framework that most state laws now share.
As of 2026, the Indiana Attorney General holds exclusive authority to enforce the INCDPA under IC 24-15-10-1, with civil penalties up to $7,500 per violation. Before any action, a controller gets a 30-day window to cure the alleged violation under IC 24-15-10-3, and that cure right has no sunset date. There is no private right of action: IC 24-15-10-4 provides that nothing in the article creates one.
Jurisdiction scope: This covers Indiana's Consumer Data Protection Act (Indiana Code Article 24-15). It is general legal information, not legal advice.
What the INCDPA is: statute, enactment, and effective date
The Indiana Consumer Data Protection Act is Indiana's first comprehensive consumer data privacy law. It is codified at Indiana Code Article 24-15, which runs from Chapter 1 (Applicability) through Chapter 11 (Preemption; Other Laws), with the definitions in Chapter 2, consumer rights in Chapter 3, controller duties in Chapter 4, and enforcement in Chapter 10.
The legislature passed it as Senate Bill 5 during the 2023 session, and Governor Eric Holcomb signed it on May 1, 2023. The delayed start was carried in the published code itself: in the 2025 edition of the Indiana Code, every section of Article 24-15 appeared under the notation "Effective 1-1-2026." The 2026 edition no longer carries that notation, because the article is now in force.
That timing is the law's single most distinctive feature. Indiana gave covered businesses roughly two and a half years between signing and effect, the longest runway of any state privacy law in the country. Where Virginia, Colorado, and Connecticut all moved from signing to effect in well under two years, Indiana deliberately pushed its start date to January 1, 2026. That date has passed, and the article has been enforceable since.
When it enacted SB 5, Indiana became the seventh state to pass a broad consumer privacy law, following California, Virginia, Colorado, Utah, Connecticut, and Iowa. The INCDPA sits in the Virginia lineage rather than the California one, using the same controller and processor vocabulary and the same opt-out-rights structure.
The Virginia clone: why Indiana modeled the VCDPA
Commentators consistently describe the INCDPA as a close copy of Virginia's Consumer Data Protection Act (VCDPA). The two statutes share the same coverage thresholds, the same five-part rights list, the same opt-in treatment of sensitive data, and the same enforcement-by-attorney-general design.
That lineage matters for compliance. A business that already built a VCDPA program can largely reuse it for Indiana, because the substantive duties line up almost section for section. The privacy notice elements, the appeal process, and the data protection assessment triggers are all recognizably Virginia in origin.
Indiana did make its own choices on a few numbers, but the cure period is not one of them: Indiana's 30-day right to cure in IC 24-15-10-3 is the same length as Virginia's in Va. Code 59.1-584(B), and neither provision carries a sunset date. The effective date, January 1, 2026, is also far later than Virginia's January 1, 2023 start.
The practical takeaway is that the INCDPA is a mainstream, middle-of-the-road state privacy law. It is neither the strictest (California, Colorado) nor the most business-friendly (Iowa, Utah), and the Virginia template is the best mental model for understanding it.

Who the INCDPA covers: the IC 24-15-1-1 thresholds
The applicability test in IC 24-15-1-1 controls who must comply. The article applies to a person that conducts business in Indiana, or produces products or services targeted to Indiana residents, that during a calendar year meets either of two thresholds.
First, the business "controls or processes personal data of at least one hundred thousand (100,000) consumers who are Indiana residents." Second, the business "controls or processes personal data of at least twenty-five thousand (25,000) consumers who are Indiana residents and derives more than fifty percent (50%) of gross revenue from the sale of personal data."
A "consumer" is defined in Chapter 2 as a natural person who is an Indiana resident acting only in an individual or household context. The definition excludes a person acting in a commercial or employment context, so business-to-business contacts and employees do not count toward the thresholds.
Indiana does not pair its data thresholds with a separate revenue floor. A business clears the test by hitting the 100,000-consumer mark, or the 25,000-consumer-plus-data-sales mark, regardless of total revenue. Small businesses below those data volumes fall outside the INCDPA entirely.
Exemptions under IC 24-15-1-1 and IC 24-15-1-2
Even among businesses that clear the threshold, Chapter 1 removes whole categories of organizations and data from the law's reach. These exemptions are both entity-based and data-based, tracking the pattern set by Virginia and the other state laws.
On the entity side, IC 24-15-1-1 provides that the article does not apply to the state, a state agency, or a political subdivision; a financial institution or data subject to Title V of the federal Gramm-Leach-Bliley Act; a covered entity or business associate governed by HIPAA and its regulations at 45 CFR Parts 160 and 164; a nonprofit organization; an institution of higher education; a public utility (as defined in IC 8-1-2-1(a)) or its affiliated service company; or a 501(c)(4) organization established to detect or prevent insurance-related crime or fraud that operates under a memorandum of understanding with a statewide law enforcement agency. The last two categories were added by P.L.236-2025. These are all full entity exemptions, so charities, universities, utilities, and qualifying insurance-fraud units generally fall outside the law even when they hold large volumes of Indiana-resident data.
On the data side, IC 24-15-1-2 excludes protected health information under HIPAA, patient identifying information, human-subjects research data, and information regulated by federal laws such as the Fair Credit Reporting Act, the Driver's Privacy Protection Act, the Family Educational Rights and Privacy Act, and the Farm Credit Act. Employment-related data is also carved out. COPPA is not one of these data exemptions. Under the separate IC 24-15-1-3, a controller or processor that complies with COPPA satisfies only the INCDPA's obligation to obtain parental consent for a known child's data; the data-minimization, security, non-discrimination, and access-and-deletion duties in IC 24-15-3-1 and IC 24-15-4-1 still apply to that data.
The practical upshot is that banks, credit unions, hospitals, schools, and state agencies generally operate outside the INCDPA as to the data those federal laws already govern. Indiana's exemption list is broad and closely matches Virginia's.
The opt-in sensitive-data rule and the no-UOOM choice
Indiana takes the stricter, opt-in approach to sensitive data. Under IC 24-15-4-1(5), a controller "shall not process sensitive data concerning a consumer without obtaining the consumer's consent," and for a known child must instead process the data in accordance with the federal Children's Online Privacy Protection Act.
That is opt-in consent, the same approach Virginia, Colorado, Connecticut, and most other states use, and the opposite of the notice-and-opt-out model in Utah and Iowa. Sensitive data is defined in IC 24-15-2-28 to include personal data revealing racial or ethnic origin, religious beliefs, a mental or physical health diagnosis, sexual orientation, or citizenship or immigration status, plus genetic or biometric data used to uniquely identify a person, personal data collected from a known child, and precise geolocation data, which IC 24-15-2-20 defines as locating an individual within a 1,750-foot radius.
On opt-out signals, Indiana made the business-friendly choice. IC 24-15-4-4 requires a controller that sells personal data or uses it for targeted advertising to "clearly and conspicuously disclose" that activity and how a consumer may opt out, but the statute does not require the controller to recognize a universal opt-out mechanism. There is no obligation to honor Global Privacy Control or similar browser-level signals, a duty that Colorado, Connecticut, and several other states do impose.

Enforcement, the 30-day cure, and no private right of action
The INCDPA is enforced through the Attorney General alone. IC 24-15-10-1 provides that "the attorney general has exclusive authority to enforce the provisions of this article," backed by the investigative authority in Chapter 9.
Under IC 24-15-10-2, the Attorney General may initiate an action in the name of the state, seek an injunction to restrain violations, and recover a civil penalty "not to exceed seven thousand five hundred dollars ($7,500) for each violation." The Attorney General may also recover reasonable investigation and litigation expenses.
Before filing, IC 24-15-10-3 requires the Attorney General to give the controller or processor 30 days' written notice identifying the specific provisions allegedly violated. If the business cures the violation within that window and provides an express written statement that the violation has been cured and that steps have been taken to prevent recurrence, the Attorney General "shall not initiate an action." Unlike several states whose cure rights expire, Indiana's 30-day cure has no sunset and is a permanent feature of the law. IC 24-15-10-4 closes the loop: nothing in the article "shall be construed as providing the basis for a private right of action for violations of this article or any other law." Individual Indiana residents therefore cannot sue a business directly under the INCDPA.
INCDPA vs. CCPA: the key differences
Companies operating nationally often compare Indiana's law to California's CCPA. Our state data privacy law comparison page covers the full multistate picture, but a few distinctions between the INCDPA and California's CCPA matter most.
| Feature | Indiana INCDPA (Art. 24-15) | California CCPA |
|---|---|---|
| Statutory model | Virginia VCDPA clone | California sui generis |
| Sensitive data | Opt-in consent (24-15-4-1(5)) | Right to limit use |
| Universal opt-out signal | Not required (24-15-4-4) | Required (GPC) |
| Response window | 45 days (24-15-3-1(c)) | 45 days |
| Cure period | 30 days, permanent (24-15-10-3) | None as of 2023 |
| Private right of action | None (24-15-10-4) | Limited, for data breaches |
Model and rights. The INCDPA follows the Virginia template, granting access, correction, deletion, portability, and three opt-outs under IC 24-15-3-1. California's CCPA uses a different structure built around a right to limit the use of sensitive personal information and a right to opt out of sharing for cross-context behavioral advertising.
Opt-out signals. California requires businesses to honor opt-out preference signals such as Global Privacy Control. Indiana does not; IC 24-15-4-4 only requires disclosure of how to opt out, leaving universal-signal recognition voluntary.
Remedies. California retains a limited private right of action for certain data breaches, with statutory damages. The INCDPA has no private right of action at all under IC 24-15-10-4; under IC 24-15-10-1, only the Indiana Attorney General may enforce.
Related guides
- Indiana Data Privacy Laws (INCDPA hub)
- INCDPA Consumer Rights: What Indiana Residents Can Do
- INCDPA Compliance Checklist for Businesses
- US State Privacy Laws Comparison
- What Is the CCPA? California's Privacy Law Explained
More Indiana Laws
Frequently Asked Questions
What is the INCDPA?
The INCDPA, or Indiana Consumer Data Protection Act, is Indiana's comprehensive consumer data privacy law, codified at Indiana Code Article 24-15 (Chapters 1 through 11). It was enacted as Senate Bill 5, signed by Governor Eric Holcomb on May 1, 2023, and took effect January 1, 2026. It gives Indiana residents a full Virginia-style set of rights over their personal data and is enforced exclusively by the Indiana Attorney General.
When did the Indiana Consumer Data Protection Act take effect?
The INCDPA took effect on January 1, 2026, about two and a half years after Governor Eric Holcomb signed Senate Bill 5 on May 1, 2023. That gap was the longest runway of any state privacy law, and it gave covered businesses more lead time than any comparable statute to build privacy notices and consumer-request processes. That preparation window has closed and the law is now enforceable.
Who does the INCDPA apply to?
Under IC 24-15-1-1, the INCDPA applies to a business operating in Indiana or targeting Indiana residents that, during a calendar year, controls or processes personal data of at least 100,000 Indiana consumers, or controls or processes personal data of at least 25,000 Indiana consumers while deriving more than 50% of gross revenue from the sale of personal data. Indiana residents acting in a commercial or employment context are not counted as consumers.
Is Indiana's privacy law based on Virginia's?
Yes. The INCDPA closely mirrors Virginia's Consumer Data Protection Act (VCDPA). It uses the same coverage thresholds, the same five-part rights list, the same opt-in treatment of sensitive data, and the same attorney-general-only enforcement. A business that built a VCDPA program can largely reuse it for Indiana, because the substantive duties line up almost section for section.
Does the INCDPA require honoring universal opt-out signals?
No. The INCDPA does not mandate a universal opt-out mechanism. IC 24-15-4-4 requires a controller to clearly and conspicuously disclose how a consumer may opt out of the sale of personal data and targeted advertising, but it does not require the controller to recognize browser-level signals such as Global Privacy Control, unlike Colorado, Connecticut, and several other states.
How does the INCDPA handle sensitive data?
The INCDPA uses an opt-in model. Under IC 24-15-4-1(5), a controller may not process sensitive data without obtaining the consumer's consent, and must follow the federal COPPA for a known child. Sensitive data is defined in IC 24-15-2-28 and includes racial or ethnic origin, religious beliefs, health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric identifiers, data of a known child, and precise geolocation.
What entities are exempt from the INCDPA?
IC 24-15-1-1 exempts the state and its agencies and political subdivisions, GLBA-covered financial institutions, HIPAA covered entities and business associates, nonprofit organizations, institutions of higher education, public utilities and their affiliated service companies, and 501(c)(4) organizations established to detect or prevent insurance-related crime or fraud under a memorandum of understanding with a statewide law enforcement agency (the last two added by P.L.236-2025). IC 24-15-1-2 also exempts data governed by HIPAA, the Fair Credit Reporting Act, the Driver's Privacy Protection Act, FERPA, and the Farm Credit Act, plus most employment-related data. COPPA is not a data exemption; under IC 24-15-1-3, complying with COPPA only satisfies the INCDPA's parental-consent obligation for a known child's data.
How is the INCDPA enforced?
The Indiana Attorney General has exclusive enforcement authority under IC 24-15-10-1. Before suing, the Attorney General must give a business 30 days' written notice and a chance to cure under IC 24-15-10-3, a cure right that has no sunset date. If the business does not cure, penalties run up to $7,500 per violation under IC 24-15-10-2. There is no private right of action; IC 24-15-10-4 states that nothing in the article provides the basis for one.
Updates
Updated to reflect that Indiana's Consumer Data Protection Act has been in force since January 1, 2026, corrected the description of the effective-date notation in the Indiana Code and a faulty comparison to Virginia's cure period, and added a pinpoint citation to IC 24-15-10-4 for the absence of a private right of action.
Corrected this page's description of COPPA's role under the INCDPA (it is a parental-consent compliance safe harbor under IC 24-15-1-3, not a data exemption), added two entity exemptions added by a 2025 law amendment (public utilities and certain insurance-fraud-detection nonprofits), fixed the Utah/Connecticut signing order and a citation cross-reference, and repointed several statute citations to working section-specific sources.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Indiana Code, TITLE 24. TRADE REGULATION
§ 24-15-3-1Personal data; consumer rights; consumer's request to controller; compliance by controller; consumer's right to appealIn forcecited in 6 of our articles
Sec. 1. (a) A consumer may invoke one (1) or more rights set forth in subsection (b) by submitting to a controller a request specifying the rights the consumer wishes to invoke. A known child's parent or legal guardian may invoke on behalf of the child one (1) or more rights set forth in subsection (b) with respect to the processing of personal data belonging to the known child by submitting to a controller a request specifying the rights the consumer wishes to invoke on behalf of the child. Except as provided in IC 24-15-7-1(c) and IC 24-15-7-2, and subject to any limitations or conditions set forth in subsections (b) and (c), a controller shall comply with an authenticated consumer request to exercise a right set forth in subsection (b). (b) A consumer has the following rights: (1) To confirm whether or not a controller is processing the consumer's personal data and, subject to the limitations set forth in subdivision (4), to access such personal data.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at iga.in.gov
Also relied on in: INCDPA Compliance Checklist for Indiana Businesses, How to Request Your Personal Data: US Privacy Rights by State, Indiana Data Privacy Laws: ICDPA Consumer Rights Guide (2026)
§ 24-15-1-1Applicability to persons; exceptionsIn forcecited in 4 of our articles
Sec. 1. (a) This article applies to a person that conducts business in Indiana or produces products or services that are targeted to residents of Indiana and that during a calendar year: (1) controls or processes personal data of at least one hundred thousand (100,000) consumers who are Indiana residents; or (2) controls or processes personal data of at least twenty-five thousand (25,000) consumers who are Indiana residents and derives more than fifty percent (50%) of gross revenue from the sale of personal data. (b) This article does not apply to any of the following: (1) Either of the following: (A) The state, a state agency, or a body, authority, board, bureau, commission, district, or agency of any political subdivision of the state. (B) A third party under contract with an entity described in clause (A), when acting on behalf of the entity. This clause does not exempt data held or created by third parties outside of the scope of the contract with the entity. (2) Any financial institutions and affiliates, or data subject to Title V of the federal Gramm-Leach-Bliley Act (15 U.S.C. 6801 et seq.).
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at iga.in.gov
Also relied on in: Indiana Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 24-15-4-1Responsibilities of controller; discrimination against consumer for exercising consumer rights prohibited; processing of sensitive dataIn forcecited in 4 of our articles
Sec. 1. Except as provided in IC 24-15-7-2, a controller has the following responsibilities: (1) A controller shall limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which such data is processed, as disclosed to the consumer. (2) Except as otherwise provided in this article, a controller shall not process personal data for purposes that are neither reasonably necessary for nor compatible with the disclosed purposes for which the personal data is processed, unless the controller obtains the consumer's consent. (3) A controller shall establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data. The data security practices required under this subdivision must be appropriate to the volume and nature of the personal data at issue. (4) A controller shall not process personal data in violation of state and federal laws that prohibit unlawful discrimination against consumers.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at iga.in.gov
Also relied on in: INCDPA Consumer Rights: Indiana Data Privacy Rights
§ 24-15-4-4Sale of personal data to third parties; use of personal data for targeted advertising; disclosure; consumer's right to opt outIn forcecited in 2 of our articles
Sec. 4. If a controller sells a consumer's personal data to third parties or uses a consumer's personal data for targeted advertising, the controller shall clearly and conspicuously disclose such activity, as well as the manner in which a consumer may exercise the right to opt out of such sales or use.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at iga.in.gov
§ 24-15-1-2Exempt information and dataIn force
Sec. 2. The following information and data are exempt from this article: (1) Protected health information under HIPAA and related regulations under 45 CFR Part 160, 45 CFR Part 162, and 45 CFR Part 164. (2) Patient identifying information for purposes of 42 U.S.C. 290dd-2. (3) Any of the following: (A) Identifiable private information for purposes of the federal policy for the protection of human subjects under 45 CFR Part 46. (B) Identifiable private information that is otherwise information collected as part of human subjects research under the good clinical practice guidelines issued by the International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use. (C) The protection of human subjects under 21 CFR Parts 50 and 56. (D) Personal data used or shared in research conducted in accordance with the requirements set forth in this article. (E) Other research conducted in accordance with applicable law. (4) Information and documents created for purposes of the federal Health Care Quality Improvement Act of 1986 (42 U.S.C. 11101 et seq.).
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at iga.in.gov
§ 24-15-2-28"Sensitive data"In forcecited in 2 of our articles
Sec. 28. "Sensitive data" means a category of personal data that includes any of the following: (1) Personal data revealing racial or ethnic origin, religious beliefs, a mental or physical health diagnosis made by a health care provider, sexual orientation, or citizenship or immigration status. (2) Genetic or biometric data that is processed for the purpose of uniquely identifying a specific individual. (3) Personal data collected from a known child. (4) Precise geolocation data.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at iga.in.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Indiana Code Article 24-15: Consumer Data Protection (Full Text)(iga.in.gov).gov
- Indiana Code 24-15-1-1: Applicability to Persons; Exceptions(law.justia.com)
- Indiana Code 24-15-1-2: Exempt Information and Data(law.justia.com)
- Indiana Code 24-15-2-28: Definition of Sensitive Data(law.justia.com)
- Indiana Code 24-15-3-1: Personal Data; Consumer Rights(law.justia.com)
- Indiana Code 24-15-4-1: Responsibilities of Controller; Sensitive Data Consent(law.justia.com)
- Indiana Code 24-15-4-4: Opt-Out Disclosure for Sale and Targeted Advertising(law.justia.com)
- Indiana Code 24-15-10: Enforcement and Penalties(law.justia.com)
- Indiana Senate Bill 5 (2023): Consumer Data Protection(iga.in.gov).gov
- Indiana Attorney General: Consumer Protection(in.gov).gov
- Indiana Code 24-15-10-4: No Private Right of Action for Violation(iga.in.gov)
- Indiana Code Title 24 (2026 edition): Article 15, Consumer Data Protection, full text(iga.in.gov)
- Virginia Code 59.1-584: Enforcement; Civil Penalty; Expenses (VCDPA 30-day cure period)(law.lis.virginia.gov)