Back to the hub

Does Indiana's Consumer Data Protection Act apply to your business?

Indiana's Consumer Data Protection Act applies to businesses that operate in Indiana or target its residents and, in a calendar year, control or process personal data of at least 100,000 consumers, or at least 25,000 consumers while deriving more than 50 percent of gross revenue from selling personal data. It takes effect January 1, 2026.

Applies to: Businesses that conduct business in Indiana or target Indiana residents and meet either the 100,000-consumer threshold or the 25,000-consumer-plus-data-sales threshold, and that are not otherwise exempt.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

Indiana's privacy law takes effect on January 1, 2026, and it borrows its applicability test almost word for word from Virginia. If you are trying to work out whether it reaches your business, the first thing to know is that Indiana does not look at your total revenue at all. The test is about how many Indiana residents' data you handle.

Who the Indiana Consumer Data Protection Act covers

Under Indiana Code 24-15-1-1, the article applies to a person conducting business in Indiana, or producing products or services targeted to Indiana residents, that during a calendar year either controls or processes the personal data of at least 100,000 Indiana consumers, or controls or processes the personal data of at least 25,000 Indiana consumers and derives more than 50 percent of gross revenue from the sale of personal data. A consumer here means an Indiana resident acting only for a personal, family, or household purpose, so business-to-business contacts and your own employees do not count toward the total.

The 25,000 shortcut, and who hits it first

Most product companies reach coverage through the 100,000 figure. The 25,000 prong targets businesses whose model is selling data. If more than half your gross revenue comes from selling personal data, the bar drops to 25,000 consumers, which a data broker or ad-tech intermediary can pass quickly. If you never sell data in the statutory sense, this second prong will rarely be what pulls you in. The structure mirrors the Virginia VCDPA and the Iowa Consumer Data Protection Act, which use the same two thresholds.

Who is carved out

Indiana Code 24-15-1-1(b) exempts whole categories of organization: state and local government bodies and their contractors, financial institutions and data subject to the Gramm-Leach-Bliley Act, HIPAA-covered entities and business associates, nonprofit organizations, institutions of higher education, and public utilities. These are entity-level exemptions, so a covered nonprofit sits outside the article even when it processes data for large numbers of people. The article also exempts specific data types, including protected health information and Fair Credit Reporting Act data.

What covered businesses owe

Covered controllers publish a privacy notice, honor rights to access, correct, delete, and obtain a copy of personal data, and let consumers opt out of sale, targeted advertising, and profiling that produces legal or similarly significant effects. Consent is required before processing sensitive data. Indiana keeps a permanent 30-day cure period, and the Attorney General has exclusive enforcement, with civil penalties up to 7,500 dollars per violation and no private right of action. The US state privacy laws hub shows how Indiana lines up against the states that share its thresholds.

Next step

Because Indiana counts people rather than dollars, the honest answer to "does it apply?" usually needs a real count of your Indiana users. The free 2-minute Obligation Scan runs the 24-15-1-1 thresholds against your business and flags the notice, opt-out, and consent duties that follow, so you spend your time on the obligations rather than the arithmetic.

Compliance checklist

  • Count the Indiana consumers whose personal data you controlled or processed over the calendar year against the 100,000 and 25,000 figures.
  • If you are near 25,000, work out whether more than 50 percent of your gross revenue comes from selling personal data, since that lowers the trigger.
  • Check the Section 24-15-1-1(b) entity exemptions before assuming you are covered: nonprofits, GLBA institutions, HIPAA entities, higher education, and public utilities are out.
  • If covered, publish a privacy notice and honor consumer rights to access, correct, delete, obtain a copy, and opt out of sale, targeted advertising, and profiling.
  • Get consent before processing sensitive data, and note Indiana keeps a permanent 30-day cure period before the Attorney General can act.

Sources

Last verified: 2026-07-23

Informational, not legal advice.