The ICDPA compliance checklist below walks Indiana businesses through what the state’s new privacy law requires now that it is live. The Indiana Consumer Data Protection Act (ICDPA) took effect on January 1, 2026, giving Indiana residents new rights over their personal data and empowering the state Attorney General to pursue fines of up to $7,500 per violation.
The timing matters. Indiana ranked second in the nation for cybercrime complaints per capita in 2024, 342 complaints per 100,000 residents, according to an analysis of FBI Internet Crime Complaint Center (IC3) data.
In this article, we’ll cover who the ICDPA applies to, the core obligations it creates, and a step-by-step path to compliance, plus a downloadable checklist your team can work through.
Does the ICDPA Apply to Your Business?
The ICDPA does not apply to every company. It targets larger data processors and leaves many small and mid-sized businesses out of scope entirely.
The law applies to for-profit entities that conduct business in Indiana, or target Indiana residents, and meet at least one threshold in a calendar year:
| Threshold | Criteria |
|---|---|
| Threshold 1 | Control or process the personal data of 100,000 or more Indiana residents. |
| Threshold 2 | Control or process the personal data of 25,000 or more Indiana residents and derive more than 50% of gross revenue from the sale of personal data. |
If you fall below both thresholds, you are not currently in scope. Several categories are also exempt at the entity level, including nonprofits, HIPAA-covered entities, GLBA-covered financial institutions, public utilities, higher-education institutions, and government bodies.
Not sure where you land? Our cornerstone ICDPA guide breaks down the definitions in plain English.
How Do I Comply With the ICDPA in 2026?
Compliance can feel overwhelming, especially when a new law lands on top of everything else your team manages. But it breaks down into a handful of concrete steps.
Here’s a step-by-step path to ICDPA compliance:
- Confirm applicability. Run a data inventory to count how many Indiana residents’ records you hold and how you use them. This tells you whether you are in scope and where your risk sits.
- Map your data. Document what personal data you collect, why you collect it, where it lives, and which third parties you share it with.
- Update your privacy notice. Publish a clear, accessible privacy notice that lists the categories of data you collect, your purposes, consumer rights, opt-out methods, and third-party disclosures.
- Build a consumer-rights process. Indiana residents can access, correct, delete, and port their data. You must respond to verified requests within 45 days (extendable by another 45). Denied requests need a reason and an appeal path, with appeal responses due within 60 days.
- Handle sensitive data and opt-outs. Obtain opt-in consent before processing sensitive data, and give consumers a clear way to opt out of targeted advertising, data sales, and profiling.
- Document DPIAs and processor terms. Conduct Data Protection Impact Assessments for high-risk activities, and put data processing agreements in place with every vendor that touches your data.
A formal compliance audit can confirm each of these is actually working – not just written down.
What Happens If You Don’t Comply?
The ICDPA is enforced solely by the Indiana Attorney General — there is no private right of action, so consumers cannot sue you directly. Instead, they file complaints through the AG’s online portal under the statute first introduced as Senate Bill 5.
Here’s what enforcement looks like:
- A 30-day written notice. The AG must identify the specific violation in writing before pursuing penalties.
- A 30-day cure period. You have 30 days to fix the issue. Indiana’s cure period is permanent; it does not expire after a set number of uses, which makes the law more forgiving than many states’.
- Civil penalties. If a violation goes uncured, the AG may seek up to $7,500 per violation, which can compound quickly across consumers and data categories.
Compliance is also only one layer. Indiana’s separate Data Breach Notification Law (Indiana Code § 24-4.9) requires you to notify affected residents and the Attorney General within 45 days of discovering a breach, regardless of whether the ICDPA applies to you. Indiana’s recent ransomware activity shows why both obligations deserve attention.
Get the Downloadable ICDPA Compliance Checklist
We turned the steps above into a one-page checklist your team can print, share, and work through. It covers applicability thresholds, the four obligation areas, consumer-rights timelines, and enforcement triggers.
Download the ICDPA Compliance Checklist (PDF)
For how the ICDPA fits with SEA 472, breach notification, and federal rules, see our Indiana cybersecurity compliance pillar.
Frequently Asked Questions
Is my business required to comply with the ICDPA?
Your business must comply if it is a for-profit entity that processes the personal data of 100,000 or more Indiana residents in a year, or 25,000 or more residents while earning more than 50% of gross revenue from selling personal data. Nonprofits, HIPAA-covered entities, GLBA-covered financial firms, utilities, and government agencies are exempt. If you fall below both thresholds, you are not currently in scope.
How do I comply with the ICDPA in 2026?
Start by confirming the law applies to you, then map your data, update your privacy notice, and build a process to handle consumer rights requests within 45 days. You also need opt-in consent for sensitive data, opt-outs for targeted advertising and data sales, and Data Protection Impact Assessments for high-risk processing.
What are the penalties for violating the ICDPA?
The Indiana Attorney General can seek civil penalties of up to $7,500 per violation. Before that, the AG must give 30 days’ written notice and a 30-day window to cure the violation. If you fix the issue within that window, the AG cannot continue with that specific action.
Does the ICDPA require a data protection assessment?
Yes. Data Protection Impact Assessments (DPIAs) are required for high-risk activities, including targeted advertising, the sale of personal data, profiling with significant effects, and processing sensitive data. No mandatory format is prescribed, but each assessment should document the purpose, risks, and safeguards for the activity.
Strengthen Your ICDPA Compliance With CyberGlobal Indiana
The ICDPA is live, the Attorney General’s office is active, and Indiana’s threat environment remains one of the most demanding in the country. Meeting the law’s requirements protects both your customers and your bottom line.
But you don’t need to become a privacy lawyer to get there. With the right partner by your side, compliance becomes a clear set of steps rather than a guessing game.
At CyberGlobal Indiana, we’ve built governance, risk, and compliance services for Indiana businesses working to meet the ICDPA and the regulations around it. We’ve supported organizations of every size — including global names like Mercedes-Benz and Emirates.
But behind our advanced technology, there are real people. Professionals who will sit down with your team, translate the law into plain English, and help you decide what to fix first.
Reach out to CyberGlobal Indiana and let us be your ally against today and tomorrow’s cybersecurity challenges.
Secure your business with CyberGlobal Indiana
Turn the ICDPA from a compliance headache into a clear, manageable plan.