{
  "type": "practice-guide",
  "canonical": "https://openagreements.org/practice-guides/privacy/us/indiana",
  "links": [
    {
      "rel": "self",
      "href": "https://openagreements.org/practice-guides/privacy/us/indiana.json",
      "type": "application/json"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/indiana",
      "type": "text/html"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/indiana/markdown",
      "type": "text/markdown"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/indiana/json",
      "type": "application/json"
    }
  ],
  "data": {
    "topic": "privacy",
    "state": "indiana",
    "frontmatter": {
      "title": "Indiana Consumer Privacy Law (INCDPA)",
      "description": "The Indiana Consumer Data Protection Act, effective January 1, 2026, gives Indiana consumers rights over their personal data and imposes notice, contracting, and consent duties on controllers above defined thresholds — it is enforced exclusively by the Attorney General with a permanent 30-day cure period and provides no private right of action, and its entity-level exemptions are unusually broad.",
      "state": "Indiana",
      "lastReviewed": "2026-06-06",
      "license": "CC BY 4.0",
      "authors": [
        "steven-obiajulu"
      ],
      "summary": {
        "keyLaw": "Ind. Code §§ 24-15 et seq. (Indiana Consumer Data Protection Act), effective January 1, 2026",
        "appliesTo": "Persons doing business in Indiana (or targeting residents) that control or process the data of 100,000+ Indiana consumers a year, or 25,000+ while deriving over 50% of gross revenue from selling data — no revenue floor, and entity-level exemptions for nonprofits, HIPAA covered entities, higher education, GLBA institutions, and public utilities",
        "privacyPolicyRequired": "Yes — a reasonably accessible, clear, and meaningful notice with statutorily fixed contents",
        "privateRightOfAction": "No — enforcement is exclusively the Attorney General's",
        "regulator": "Indiana Attorney General (exclusive)",
        "bottomLine": "If you meet the 100,000-consumer (or 25,000 plus majority-data-sale) threshold in Indiana, the INCDPA requires a privacy notice, opt-in consent to process sensitive data, and processor contracts — enforced by the Attorney General with a permanent 30-day cure period and no consumer lawsuits. Its broad entity-level exemptions (nonprofits, HIPAA entities, higher education, utilities) keep many organizations out entirely.",
        "lawCoverage": "comprehensive",
        "policyMandate": "statutoryContents",
        "consumersCanSue": "no",
        "sensitiveDataConsent": "optIn",
        "universalOptOutSignal": "notRequired"
      },
      "about": [
        "Indiana Consumer Data Protection Act INCDPA",
        "Indiana privacy policy requirements",
        "Indiana privacy notice contents",
        "INCDPA applicability thresholds",
        "INCDPA sensitive data consent",
        "INCDPA processor contract requirements",
        "Indiana Attorney General privacy enforcement",
        "INCDPA no private right of action"
      ],
      "translations": [
        {
          "language": "中文",
          "status": "planned"
        },
        {
          "language": "Español",
          "status": "planned"
        },
        {
          "language": "Português",
          "status": "planned"
        },
        {
          "language": "Deutsch",
          "status": "planned"
        }
      ]
    },
    "questions": [
      {
        "slug": "does-incdpa-apply",
        "label": "Does the Indiana Consumer Data Protection Act apply to your business?",
        "heading": "Does the Indiana Consumer Data Protection Act apply to your business?",
        "answerText": "It turns on Indiana consumer volume, not total revenue. The INCDPA applies to persons that do business in Indiana or target its residents and that, in a calendar year, control or process the personal data of at least 100,000 Indiana consumers, or at least 25,000 Indiana consumers while deriving over 50% of gross revenue from selling personal data. On top of the thresholds, whole categories of organizations are carved out at the entity level.",
        "sources": [
          {
            "id": "stat-1-1-apply",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Ind. Code § 24-15-1-1",
            "citation": "Ind. Code § 24-15-1-1(a).",
            "url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
            "proposition": "The INCDPA applies to persons doing business in Indiana or targeting its residents that control or process the data of at least 100,000 Indiana consumers, or 25,000+ while deriving over 50% of gross revenue from selling personal data.",
            "verbatimQuote": "This article applies to a person that conducts business in Indiana or produces products or services that are targeted to residents of Indiana and that during a calendar year: (1) controls or processes personal data of at least one hundred thousand (100,000) consumers who are Indiana residents; or (2) controls or processes personal data of at least twenty-five thousand (25,000) consumers who are Indiana residents and derives more than fifty percent (50%) of gross revenue from the sale of personal data.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/indiana#src-stat-1-1-apply"
          },
          {
            "id": "stat-1-1-exempt",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Ind. Code § 24-15-1-1",
            "citation": "Ind. Code § 24-15-1-1(b).",
            "url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
            "proposition": "The INCDPA exempts whole categories of organizations at the entity level, including nonprofit organizations and institutions of higher education.",
            "verbatimQuote": "(4) Any nonprofit organization. (5) Any institution of higher education.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/indiana#src-stat-1-1-exempt"
          }
        ]
      },
      {
        "slug": "privacy-policy-contents",
        "label": "What must your Indiana privacy policy contain?",
        "heading": "What must your Indiana privacy policy contain?",
        "answerText": "A controller must provide a reasonably accessible, clear, and meaningful privacy notice that lists the categories of personal data processed and the purpose for processing, among the statute's required disclosures.",
        "sources": [
          {
            "id": "stat-4-3-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Ind. Code § 24-15-4-3",
            "citation": "Ind. Code § 24-15-4-3.",
            "url": "https://codes.findlaw.com/in/title-24-trade-regulation/in-code-sect-24-15-4-3/",
            "proposition": "A controller must provide a reasonably accessible, clear, and meaningful privacy notice whose required disclosures include the categories of personal data processed, the purpose for processing, how consumers may exercise and appeal their rights, the categories of personal data the controller shares with third parties, and the categories of those third parties.",
            "verbatimQuote": "A controller shall provide consumers with a reasonably accessible, clear, and meaningful privacy notice that includes: (1) the categories of personal data processed by the controller; (2) the purpose for processing personal data; (3) how consumers may exercise their consumer rights under IC 24-15-3, including how a consumer may appeal a controller's decision with regard to the consumer's request; (4) the categories of personal data that the controller shares with third parties, if any; and (5) the categories of third parties, if any, with whom the controller shares personal data.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/indiana#src-stat-4-3-notice"
          }
        ]
      },
      {
        "slug": "vendor-contracts",
        "label": "What must your contracts with processors say?",
        "heading": "What must your contracts with processors say?",
        "answerText": "A contract between a controller and a processor must govern the processor's data processing on the controller's behalf — so a data processing agreement is a statutory requirement, not a best practice.",
        "sources": [
          {
            "id": "stat-5-2-contract",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Ind. Code § 24-15-5-2",
            "citation": "Ind. Code § 24-15-5-2(a).",
            "url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
            "proposition": "A contract between a controller and a processor must govern the processor's data processing procedures performed on behalf of the controller.",
            "verbatimQuote": "A contract between a controller and a processor shall govern the processor's data processing procedures with respect to processing performed on behalf of the controller.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/indiana#src-stat-5-2-contract"
          },
          {
            "id": "stat-5-2-terms",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Ind. Code § 24-15-5-2",
            "citation": "Ind. Code § 24-15-5-2(a).",
            "url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
            "proposition": "The controller-processor contract must set forth processing instructions, the nature and purpose of processing, the type of data and duration, and the rights and obligations of both parties, and must require the processor to maintain confidentiality, delete or return data, demonstrate compliance, and cooperate with reasonable assessments.",
            "verbatimQuote": "The contract must be binding and clearly set forth instructions for processing personal data, the nature and purpose of processing, the type of data subject to processing, the duration of processing, and the rights and obligations of both parties. The contract must also include requirements that the processor do the following: (1) Ensure that each individual processing personal data is subject to a duty of confidentiality with respect to the data. (2) At the controller's direction, delete or return all personal data to the controller as requested at the end of the provision of services, unless retention of the personal data is required by law. (3) Upon the reasonable request of the controller, make available to the controller all information in its possession necessary to demonstrate the processor's compliance with the obligations in this chapter. (4) Allow, and cooperate with, reasonable assessments by the controller or the controller's designated assessor.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/indiana#src-stat-5-2-terms"
          },
          {
            "id": "stat-5-2-terms-subcontractor",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Ind. Code § 24-15-5-2",
            "citation": "Ind. Code § 24-15-5-2(a).",
            "url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
            "proposition": "The controller-processor contract must also require the processor to bind any subcontractor by written contract to the same data-protection obligations.",
            "verbatimQuote": "(5) Subject to subsection (b), engage any subcontractor pursuant to a written contract that requires the subcontractor to meet the obligations of the processor with respect to the personal data.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/indiana#src-stat-5-2-terms-subcontractor"
          }
        ]
      },
      {
        "slug": "sensitive-data",
        "label": "Do you need consent to process sensitive data?",
        "heading": "Do you need consent to process sensitive data?",
        "answerText": "Yes. A controller may not process a consumer's sensitive data without first obtaining consent, and for a known child it must instead follow the federal Children's Online Privacy Protection Act. Sensitive data includes data revealing race or ethnicity, religious beliefs, a health diagnosis, sexual orientation, or citizenship or immigration status; genetic or biometric data used to identify a person; data from a known child; and precise geolocation.",
        "sources": [
          {
            "id": "stat-4-1-consent",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Ind. Code § 24-15-4-1",
            "citation": "Ind. Code § 24-15-4-1(5).",
            "url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
            "proposition": "A controller may not process a consumer's sensitive data without consent, and must handle a known child's data in accordance with COPPA.",
            "verbatimQuote": "A controller shall not process sensitive data concerning a consumer without obtaining the consumer's consent, or, in the case of the processing of sensitive data concerning a known child, without processing such data in accordance with the federal Children's Online Privacy Protection Act (15 U.S.C. 6501 et seq.).",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/indiana#src-stat-4-1-consent"
          },
          {
            "id": "stat-2-28-sensitive",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Ind. Code § 24-15-2-28",
            "citation": "Ind. Code § 24-15-2-28.",
            "url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
            "proposition": "Sensitive data includes data revealing racial or ethnic origin, religious beliefs, a health diagnosis, sexual orientation, or citizenship or immigration status; genetic or biometric data used to identify a person; data from a known child; and precise geolocation.",
            "verbatimQuote": "means a category of personal data that includes any of the following: (1) Personal data revealing racial or ethnic origin, religious beliefs, a mental or physical health diagnosis made by a health care provider, sexual orientation, or citizenship or immigration status. (2) Genetic or biometric data that is processed for the purpose of uniquely identifying a specific individual. (3) Personal data collected from a known child. (4) Precise geolocation data.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/indiana#src-stat-2-28-sensitive"
          }
        ]
      },
      {
        "slug": "consumer-lawsuit",
        "label": "Can a consumer sue your business under the INCDPA?",
        "heading": "Can a consumer sue your business under the INCDPA?",
        "answerText": "No. The Attorney General has exclusive authority to enforce the INCDPA, and the statute expressly provides no private right of action for consumers. Before suing, the Attorney General must give 30 days' written notice of the specific alleged violations and a chance to cure.",
        "sources": [
          {
            "id": "stat-10-1-enforce",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Ind. Code § 24-15-10-1",
            "citation": "Ind. Code § 24-15-10-1.",
            "url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
            "proposition": "The Attorney General has exclusive authority to enforce the INCDPA.",
            "verbatimQuote": "The attorney general has exclusive authority to enforce the provisions of this article.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/indiana#src-stat-10-1-enforce"
          },
          {
            "id": "stat-10-4-no-pra",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Ind. Code § 24-15-10-4",
            "citation": "Ind. Code § 24-15-10-4.",
            "url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
            "proposition": "The INCDPA provides no private right of action for consumers.",
            "verbatimQuote": "Nothing in this article shall be construed as providing the basis for a private right of action for violations of this article or any other law.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/indiana#src-stat-10-4-no-pra"
          },
          {
            "id": "stat-10-3-cure",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Ind. Code § 24-15-10-3",
            "citation": "Ind. Code § 24-15-10-3(a).",
            "url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
            "proposition": "Before bringing an action, the Attorney General must give the controller or processor 30 days' written notice identifying the specific provisions allegedly violated.",
            "verbatimQuote": "Before initiating an action under section 2 of this chapter, the attorney general shall provide a controller or processor thirty (30) days written notice identifying the specific provisions of this article that the attorney general alleges have been or are being violated.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/indiana#src-stat-10-3-cure"
          }
        ]
      }
    ]
  }
}
