What are the penalties under the Indiana Consumer Data Protection Act?
Indiana caps the penalty at $7,500 for each violation, and only the attorney general can bring the case. Before suing, IC 24-15-10-3 requires 30 days written notice; a controller that cures inside that window and sends a written statement avoids the action entirely, with no penalty owed.
Applies to: Controllers and processors subject to the Indiana Consumer Data Protection Act, which took effect January 1, 2026, and anyone assessing enforcement exposure across multiple state privacy laws.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanIndiana's penalty number is the same $7,500 per violation you see in Texas, Nebraska and Oregon. The number is not what makes Indiana different. The cure right is, because Indiana's has no expiry date on it while other states are removing theirs.
The penalty: $7,500 for each violation
IC 24-15-10-2(a) lets the attorney general initiate an action in the name of the state, seek an injunction to restrain any violations, and seek a civil penalty not to exceed $7,500 for each violation under the article.
Subsection (b) adds a cost that summaries usually leave out: the attorney general may recover reasonable expenses incurred in investigating and preparing the case, including attorney's fees. A small penalty attached to a long investigation is not a small bill.
The cure right, and the written statement that activates it
IC 24-15-10-3(a) requires the attorney general, before initiating an action, to give the controller or processor 30 days written notice identifying the specific provisions of the article alleged to have been violated.
If, within that 30-day period, the controller or processor cures the alleged violation and provides the attorney general with an express written statement that the alleged violations have been cured and that actions have been taken to ensure no further such violations will occur, the attorney general shall not initiate an action.
Two things are doing work there. The first is "shall not," which is a bar on the action rather than a discretionary factor. The second is that the cure alone is not enough. The statement is a condition, and it has two required elements: the cure, and the forward-looking assurance. A controller that fixes the problem quietly and says nothing has satisfied neither.
Subsection (b) closes the loop. A controller or processor that continues to violate the article after cure, or that breaches its own express written statement, exposes itself to the action the statement was meant to prevent.
Why the absence of a sunset matters
Cure rights are being withdrawn across the country. Colorado's general cure right is now repealed outright. Oregon's expired on January 1, 2026 by a clause written into the original bill. Texas kept a 30-day cure with no expiry, and Indiana did the same.
For a business operating in several states, this means enforcement posture is no longer a single national assumption. The same mistake, discovered on the same day, may produce a warning letter in Indianapolis and a civil investigative demand in Portland.
Enforcement is the attorney general's alone
IC 24-15-10-1 gives the attorney general exclusive authority to enforce the article. IC 24-15-10-4 rules out a private right of action, and does so in unusually broad language: nothing in the article shall be construed as providing the basis for a private right of action for violations of the article or any other law.
That last clause is Indiana trying to prevent its privacy statute from being used as the standard of care in some other kind of claim. Whether it fully achieves that is a question for litigators, but the drafting intent is clear on the face of it.
Next step
Indiana became enforceable on January 1, 2026, so exposure is no longer theoretical. The free 2-minute Obligation Scan checks your business against Indiana and every other US state privacy law and GDPR, and tells you which obligations and which enforcement regimes apply. See the Indiana Consumer Data Protection Act overview for the applicability thresholds, Indiana response deadlines for the request and appeal clocks, and the Texas cure period for the closest comparison. Plans are on the pricing page.
Compliance checklist
- Route any notice from the Indiana attorney general to a named owner on day one, because the 30-day cure clock starts when the notice is received.
- Read the notice for the specific provisions it identifies, since the cure has to address what was alleged rather than the general area of concern.
- Send the express written statement inside the 30 days, confirming both that the violations are cured and that steps have been taken to prevent recurrence. Curing without the statement does not close the matter.
- Do not breach the statement afterwards. A controller that continues to violate or breaches its own written statement loses the protection and can face the full penalty.
- Budget for costs beyond the penalty, because the attorney general may recover reasonable investigation and case preparation expenses, including attorney's fees.
Sources
- IC 24-15-10-1 and IC 24-15-10-2, Attorney general's exclusive enforcement authority; action for violation; civil penalty; recovery of expenses, Indiana General Assembly
- IC 24-15-10-3, Notice of alleged violation; controller's or processor's right to cure, Indiana General Assembly
- IC 24-15, Article 15, Consumer Data Protection, effective January 1, 2026, Indiana General Assembly
Last verified: 2026-09-01
Informational, not legal advice.