Indiana Consumer Data Protection Act
ICDPA · Normalized Research Card v2.1
IN FORCELAST VERIFIED · AUG 26 2026At a glance
Who must comply?
Applicability model: Numerical threshold.
Core threshold: 100,000 consumers; or 25,000 consumers and >50% gross revenue from sale
Applicability remains subject to statutory entity, data-level and activity-specific exemptions. Employment/B2B treatment and federal-law carve-outs should be read together with the official statute linked below.
Consumer rights
| Right / protection | Status |
|---|---|
| Confirmation / access | ✓ Included / qualified by statute |
| Correction | ✓ Included / qualified by statute |
| Deletion | ✓ Included / qualified by statute |
| Portability | ✓ Included / qualified by statute |
| Opt-out targeted advertising | ✓ Included / qualified by statute |
| Opt-out sale | ✓ Included / qualified by statute |
| Opt-out qualifying profiling | ✓ Included / qualified by statute |
Sensitive data & minors
Sensitive-data standard: Consent required
Known-child sensitive data is handled with COPPA-linked protections.
Business obligations
Privacy notices, request handling, security, processor governance, sensitive-data consent and data protection assessments.
Enforcement
Authority: Indiana Attorney General
Private right of action: No
Penalty / remedy baseline: Attorney General enforcement; consult statute for current remedies
What makes Indiana different?
Indiana largely follows the Virginia-style comprehensive privacy model but became operational only in 2026, making current Attorney General guidance especially important.
Developments to watch
The law is now in force. Any administrative rulemaking should be tracked separately from the statute.
Editorial rule: future-effective, proposed and pending measures are kept separate from current law.
Primary sources & verification
Last verified: August 26, 2026
Research standard: primary official sources prioritized; official guidance used to explain operational requirements.