Publication

Indiana Consumer Data Protection Bill of Rights – What Businesses Need to Know About Compliance

May 29, 2026

Indiana’s Consumer Data Protection Act (“INCDPA”), passed in 2023, took effect on January 1, 2026. Businesses that fall within the scope of the law are now required to comply with new obligations designed to give Hoosiers meaningful control over their personal data. To help both organizations and consumers understand these requirements, the Indiana Attorney General has published the Consumer Data Protection Bill of Rights, a practical guide outlining key rights and responsibilities under the law. 

Does the INCDPA Apply to Your Business?

The INCDPA generally applies to businesses that:

  • Control or process the personal data of 100,000 or more Indiana residents, or
  • Control or process the personal data of at least 25,000 Indiana residents and derive more than 50% of gross revenue from the sale of personal data.

If your organization meets one of these thresholds, compliance is mandatory starting January 1, 2026.

Key exclusions: The law does not apply to nonprofit organizations, higher education institutions, state and local government bodies, public utilities, or entities and data regulated by HIPAA, GLBA, FCRA, FERPA, or DPPA. "Consumer" is limited to Indiana residents acting in a personal, family, or household context. Employee and B2B data are excluded.

What Does This Mean for Businesses?

If the INCDPA applies to your business, you should:

  1. Conduct a Data Inventory. Identify and document all aspects of personal data management, including:
    1. What data you collect (types and categories)
    2. How it is collected (sources and methods)
    3. Where it resides (systems, databases, storage locations)
    4. How it flows through your systems (internal processes and transfers)
    5. Whether it is shared, and with whom (third parties, vendors, affiliates)
  2. Understand Consumer Rights Under the INCDPA. Gain an understanding of the rights granted under the INCDPA, as these will shape your compliance obligations. Consumers can:
    1. Confirm if their data is being processed and access their personal data. (Right to Know)
    2. Correct inaccuracies, request deletion, and obtain data in a portable format. (Right to Control)
    3. Opt out of targeted advertising, data sales, and profiling. Clear consent is required for collection of sensitive data and children’s data. (Right to Protect)
    4. Exercise non-discrimination protections and appeal denied requests. (Right to Take Action)
  3. Review & Update Privacy Policies. Clearly explain consumer rights, data collection practices, and usage. This includes reviewing data sharing, ad tracking policies, and third-party relationships.
  4. Implement Consumer Request Mechanisms. Develop efficient, documented processes for consumers exercising their applicable rights. This includes timelines for response, verification processes, and an appeals process.
  5. Strengthen Security Measures. Review safeguards against unauthorized access or breaches.
  6. Review Vendor & Third-Party Contracts. Ensure agreements with processors and third parties include data protection obligations aligned with Indiana’s requirements including data minimization, purpose limitation and breach notification provisions.
  7. Train Employees. Educate staff on privacy obligations and consumer rights.
  8. Integrate Privacy into Governance. Conduct regular audits and risk assessments; consider appointing a dedicated privacy officer or team.

Why This Matters

The INCDPA is now in effect and enforceable by the Indiana Attorney General. Organizations that have not finalized compliance should move quickly to address gaps, particularly in consumer rights response processes, privacy notices, and vendor management.

Acting now will help your organization meet its legal obligations, reduce regulatory risk, and support responsible data management practices.


Frequently Asked Questions About the INCDPA

When did the Indiana Consumer Data Protection Act take effect?

The INCDPA took effect on January 1, 2026. Active enforcement by the Indiana Attorney General begins July 1, 2026.

Does the INCDPA apply to nonprofits or HIPAA-covered entities?

No. The law excludes nonprofit organizations, higher education institutions, state and local government bodies, public utilities, and entities or data regulated by HIPAA, GLBA, FCRA, FERPA, and DPPA.

What is the penalty for violating the INCDPA?

The Indiana Attorney General can impose penalties of up to $7,500 per violation. There is no private right of action.

How long does a business have to respond to a consumer data request?

Controllers must respond within 45 days, with a possible 45-day extension if the consumer is notified during the initial period.

Is there a cure period for INCDPA violations?

Yes. The INCDPA includes a permanent 30-day cure period. The Attorney General must provide written notice before enforcement, and the business has 30 days to resolve the violation.

This publication is intended for general information purposes only and does not and is not intended to constitute legal advice. The reader should consult with legal counsel to determine how laws or decisions discussed herein apply to the reader’s specific circumstances.

Related People

Related Services & Industries

Related Categories

<p>Sign up now to receive periodic updates from Ice Miller&rsquo;s legal professionals.</p>

Sign up now to receive periodic updates from Ice Miller’s legal professionals.

Subscribe

Firm Highlights