Indiana Consumer Data Protection Act (Ind. Code 24-15)
Below is what the official text of Indiana Consumer Data Protection Act (Ind. Code 24-15) states about whom it covers, when it applies to a business and since when. Where the pages we read do not say, the row says "not stated".
The wording shown is taken from the official page named in each row. The duties of a business and the contents of a privacy notice are in the paid checklist.
Typical situations, run through the same conditions as the check
- A for-profit US business with 150,000 people in Indiana and $30 million revenue: Applies, or may apply: conditions to check.
- The same business with 8,000 people in Indiana: Not triggered by these answers.
- A US business with no users in Indiana: Not triggered by these answers.
Judged on 2026-10-06. Our law data was last verified on 2026-10-06; a law that took effect after that date is not in it. These situations leave other answers blank or neutral: use the check for your own.
What the official text states
| Question | What the official text states | Source |
|---|---|---|
| What it covers | Applies to Indiana residents acting in a personal, family, or household capacity (consumers) and to for-profit businesses that meet the applicable threshold and decide how data is processed (controllers), as described by the Attorney General.Official wordingThis law applies to Indiana residents acting in a personal, family, or household capacity (“Consumers”), and for-profit businesses that meet the applicable threshold and make decisions regarding the processing of data (“Controllers”). | www.in.gov read 2026-10-06 |
| When it applies to a business | The Attorney General states the Act generally applies to individuals and companies that do business in Indiana or produce products or services targeted to Indiana residents and that during the applicable calendar year either control or process the personal data of 100,000 or more Indiana residents, or at least 25,000 Indiana residents while deriving more than 50% of gross revenue from the sale of personal data. Conditions to check: Business must do business in Indiana or produce products or services targeted to Indiana residents. Per the Attorney General the Act does not apply to 501(c)(3), 501(c)(6) or 501(c)(12) nonprofits, the state or its agencies, and generally not to financial institutions, HIPAA covered entities, higher education institutions, or public utilities even if thresholds are met; other nonprofits are not stated to be exempt, so we do not test the organisation type. Only residents acting in a personal, family, or household context count as consumers (employees and commercial contacts do not). Source is the Attorney General's plain-language guide, not the statute text. Official wording(i) Control or process the personal data of 100,000 or more Indiana residents; or (ii) Control or process the personal data of at least 25,000 Indiana residents and derive more than 50% of their gross revenue from the sale of personal data. | www.in.gov read 2026-10-06 |
| In force from | 2026-01-01 Per the Attorney General guide: businesses must comply when the Act takes effect on January 1, 2026 . Official wordingA: Businesses are required to comply with the CDPA when it goes into effect on January 1, 2026. | www.in.gov read 2026-10-06 |
| Privacy notice | Included in the paid checklist. See the checklist | — |
| Consent and opt-out | Included in the paid checklist. See the checklist | — |
| Rights of individuals | Included in the paid checklist. See the checklist | — |
| Data protection officer | Not stated on the official pages we read. the Attorney General guide does not mention a data protection or privacy officer; the statute text was not readable | — |
| Breach notification | Not stated on the official pages we read. separate breach-notification statute not read | — |
| What the privacy notice must contain | Included in the paid checklist. See the checklist | — |
What we do not cover
These areas are outside this site, so nothing on this page says anything about them:
- Privacy laws for particular sectors (for example health care, banking and credit, education)
- Rules specific to children's online privacy
- Cookie and electronic-communications rules (including consent for cookies and marketing messages)
- Employee, job applicant and contractor data
- Rules on sending personal data to other countries
- US state data-breach notification laws (a separate set of state laws)
- US state privacy laws that are not yet in force, and state laws on particular topics (for example biometric or health data)
- Privacy laws of countries that are not listed here
- Planned changes to the laws listed here