Get in contact with your local cybersecurity representative

What is the Indiana Consumer Data Protection Act? 

image

Table of Contents

The Indiana Consumer Data Protection Act (ICDPA) is a state privacy law that took effect on January 1, 2026, giving Indiana residents the right to access, correct, delete, and opt out of the sale of their personal data, while requiring covered businesses to honor those rights and protect the data they hold.

The stakes for getting this right are local and specific. A 2025 analysis of FBI Internet Crime Complaint Center data ranked Indiana second in the nation for cybercrime complaints per capita, at 342 complaints per 100,000 residents, behind only Alaska. Against that backdrop, the ICDPA raises the legal floor for how Indiana businesses handle the personal information they collect.

The law is enforced exclusively by the Indiana Attorney General, who can seek civil penalties of up to $7,500 per violation. There is no private right of action, so consumers cannot sue businesses directly, but the regulatory exposure is real.

In this article, we’ll cover what the ICDPA requires, who has to comply, how it compares to Indiana’s other data laws, and the practical steps your organization can take to stay compliant.

What Rights Does the ICDPA Give Indiana Residents?

The ICDPA, enacted as Senate Bill 5 in 2023, gives Indiana consumers a defined set of rights over the personal data that businesses collect about them. A “consumer” under the law is an Indiana resident acting in a personal or household context, not in an employment or business-to-business capacity.

Here are the core rights the law grants:

  • Right to know and access. Consumers can confirm whether a business is processing their data and obtain a copy of the personal data they previously provided.
  • Right to correct. Consumers can request that inaccurate personal data be fixed.
  • Right to delete. Consumers can ask a business to delete personal data it holds about them.
  • Right to data portability. Consumers can receive their data in a portable, usable format where technically feasible.
  • Right to opt out. Consumers can opt out of targeted advertising, the sale of their personal data, and certain types of profiling.

Businesses must establish a clear way for consumers to exercise these rights and respond to verified requests within 45 days, with one 45-day extension allowed for complex cases.

Who Must Comply with the ICDPA?

The most common compliance question is also the most important: Does the law even apply to your business? The ICDPA uses volume-based thresholds rather than a flat revenue cutoff, which means a mid-sized company can fall under it while a larger one with less consumer data may not.

The ICDPA applies to for-profit entities that conduct business in Indiana, or that target products or services to Indiana residents, and that, in a calendar year meet either of the following thresholds:

Threshold 1Control or process the personal data of 100,000 or more Indiana residents.
Threshold 2Control or process the personal data of 25,000 or more Indiana residents and derive more than 50% of gross revenue from the sale of personal data.

Because the second threshold is so low, data brokers and ad-tech firms can be covered even with a relatively small Indiana footprint.

Who Is Exempt?

Not every organization falls under the ICDPA. The law carves out entities and data types that are already regulated elsewhere to avoid stacking overlapping obligations.

The main exemptions include:

  • HIPAA- and GLBA-regulated entities. Healthcare organizations and financial institutions are already governed by federal privacy frameworks.
  • Nonprofit organizations.
  • Colleges and universities.
  • State and local government bodies, utilities, and certain other regulated entities.
  • Employment and B2B data, which sit outside the law’s definition of a consumer.

How Does the ICDPA Compare to Indiana’s Other Data Laws?

The ICDPA does not replace Indiana’s existing data rules — it sits alongside them. Many businesses are subject to more than one of these at once, so it helps to see how they differ in scope and trigger.

LawWho it coversCore obligation
ICDPA (Senate Bill 5)For-profit businesses meeting the 100,000- or 25,000-resident thresholdsHonor consumer privacy rights, publish privacy notices, run data protection assessments
Indiana Data Breach Notification Law (IC § 24-4.9)Any entity holding Indiana residents’ personal dataNotify the Attorney General and affected individuals within 45 days of discovering a breach
Senate Enrolled Act 472 (SEA 472)State agencies, schools, and political subdivisionsMaintain cybersecurity and technology-use policies; some must report incidents to the state within 2 business days

If you want a deeper look at how these obligations fit together, see our overview of cybersecurity compliance in Indiana.

What Are the Penalties for ICDPA Non-Compliance?

For businesses operating in or selling to Indiana, ignoring the ICDPA carries concrete consequences — even without a private right of action.

Here’s what non-compliance can lead to:

  • Civil penalties of up to $7,500 per violation, enforced by the Indiana Attorney General. Because each affected consumer can count as a separate violation, penalties can accumulate quickly across a large dataset.
  • Investigations and injunctions if a business fails to honor consumer rights or protect personal data adequately.
  • Required corrective action, such as updating privacy notices, fixing internal processes, or strengthening security controls.
  • Reputational damage that erodes customer trust and can affect long-term revenue.

One feature sets Indiana apart from stricter state laws: the ICDPA includes a permanent 30-day cure period. The Attorney General must give written notice of an alleged violation, and the business has 30 days to fix it before an enforcement action can proceed. Unlike many states, this cure right does not expire on a set date — but it should be treated as a safety net, not a strategy.

How to Comply with the ICDPA: Best Practices

Meeting the ICDPA is less about a single fix and more about building durable data practices. The same controls that satisfy the law also reduce your breach risk, which is the more expensive problem.

Here are the practical steps that matter most:

  • Publish a clear, accurate privacy notice. State what data you collect, why, whether you share or sell it, and how consumers can exercise their rights.
  • Build a consumer request process. Create a reliable, documented workflow to verify identities and answer access, correction, deletion, and opt-out requests within the 45-day window.
  • Run data protection assessments. Document the risks of higher-risk processing, such as targeted advertising, profiling, and handling sensitive data, which requires opt-in consent.
  • Tighten your security baseline. Multi-factor authentication, access controls, patching, and employee awareness training are the foundation. Routine penetration testing surfaces weaknesses before attackers do.
  • Manage your vendors. Most breaches trace back to a third party, so put data processing agreements in place and confirm partners meet the same standards through structured third-party risk assessments.

For a step-by-step walkthrough you can work against, see our ICDPA compliance checklist for Indiana businesses.

Frequently Asked Questions

When did the Indiana Consumer Data Protection Act take effect?

The Indiana Consumer Data Protection Act took effect on January 1, 2026. It was passed as Senate Bill 5 in 2023, giving businesses more than two years to prepare before the law became enforceable.

Who must comply with the ICDPA?

The ICDPA applies to for-profit businesses that conduct business in Indiana or target Indiana residents and, in a calendar year, either process the personal data of 100,000 or more Indiana residents, or process the data of 25,000 or more residents while earning over 50% of gross revenue from selling personal data.

What rights does the ICDPA give consumers?

Indiana residents have the right to access their personal data, correct inaccuracies, request deletion, obtain a portable copy, and opt out of targeted advertising, the sale of their data, and certain profiling. Businesses must respond to verified requests within 45 days.

What are the penalties for violating the ICDPA?

The Indiana Attorney General can seek civil penalties of up to $7,500 per violation. There is no private right of action, and businesses receive a permanent 30-day period to cure an alleged violation after written notice before enforcement can proceed.

Does the ICDPA apply to businesses outside Indiana?

Yes. The law applies to any qualifying business that targets products or services to Indiana residents, regardless of where the business is located, so an out-of-state or international company can be covered if it meets the data processing thresholds.

Stay Ahead of Indiana’s Privacy Laws with CyberGlobal Indiana

Keeping up with privacy regulations like the Indiana Consumer Data Protection Act can feel overwhelming when you’re already focused on running your business and managing everyday risk. With the right partner by your side, you don’t have to navigate it alone.

At CyberGlobal Indiana, what drives our work is not only delivering high-quality cybersecurity services, but standing beside you as a true ally, every step of the way. As part of a global network that protects enterprises like Mercedes-Benz and Red Bull, we bring that same expertise to growing Indiana businesses.

Our Governance, Risk, and Compliance services in Indiana are built to make compliance clearer and easier. We help you understand what the law expects, turn it into practical steps you can follow, and build a reliable foundation for protecting personal data — from policy creation and risk assessments to ongoing support as a trusted cybersecurity provider in Indiana.

Reach out today, and we’ll stand by your side to help you stay secure, compliant, and confident about the future.

Secure Your Business With CyberGlobal Indiana

Turn ICDPA requirements into a clear, manageable compliance plan with a partner who knows Indiana.

With over a decade of experience, Victoria Neagu translates complex cybersecurity issues into clear, practical guidance for modern businesses.

Additional Reading

93% of data breaches occur in less than one minute, yet it takes companies an average of 207 days to identify a breach.

Protect your business now. Contact us to fortify your defenses and stay ahead.