{
 "jurisdiction_id": "US-IN",
 "jurisdiction": "United States – Indiana",
 "url": "https://dataprotection.gi/jurisdictions/united-states-indiana/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-06",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 49,
  "sub_modules": 57,
  "source_register": 15
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-indiana/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Statute is enacted, in force, and unambiguous on regulator identity, scope thresholds and territorial reach; no registration-regime ambiguity exists because none is imposed.",
   "claims": [
    {
     "statement": "The Indiana Attorney General has exclusive statutory authority to enforce the Indiana Consumer Data Protection Act (IC 24-15).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Indiana General Assembly",
     "source_url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Indiana Consumer Data Protection Act was enacted as P.L.94-2023 (Senate Bill 5) and codified at Indiana Code Article 24-15, with an effective date of January 1, 2026.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Indiana General Assembly",
     "source_url": "https://iga.in.gov/legislative/2023/bills/senate/5",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Act applies to persons conducting business in Indiana or targeting products/services to Indiana residents that, during a calendar year, control or process personal data of at least 100,000 consumers, or of at least 25,000 consumers while deriving over 50% of gross revenue from the sale of personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Indiana General Assembly",
     "source_url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Act's territorial scope is targeting-based rather than establishment-based: it reaches any covered entity that conducts business in Indiana or produces products/services targeted to Indiana residents, regardless of the entity's own location.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/indiana-governor-signs-a-comprehensive-privacy-act-into-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Act imposes no general controller/processor registration or filing obligation with the Attorney General; the only formal AG-facing procedural step is the pre-suit 30-day cure-notice mechanism, not a registration scheme.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "Indiana General Assembly",
     "source_url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-indiana/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Consent and sensitive-data provisions are clearly codified and in force; the absence of a GDPR-style lawful-bases enumeration is a structural feature of the Virginia-model statute, not a gap.",
   "claims": [
    {
     "statement": "Controllers must limit collection of personal data to what is adequate, relevant and reasonably necessary for the disclosed purposes of processing, and must obtain consumer consent to process data for purposes not reasonably necessary to or compatible with those disclosed purposes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/indiana-governor-signs-a-comprehensive-privacy-act-into-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Consent under the Act is a clear affirmative act indicating a consumer's freely given, specific, informed and unambiguous agreement, evidenced by a physical or electronic written statement or other affirmative action.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/indiana-governor-signs-a-comprehensive-privacy-act-into-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Sensitive data under the Act includes racial/ethnic origin, religious beliefs, mental or physical health diagnoses, sexual orientation, citizenship/immigration status, genetic or uniquely-identifying biometric data, personal data collected from a known child, and precise geolocation data within a 1,750-foot radius.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/indiana-governor-signs-a-comprehensive-privacy-act-into-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "A controller may not process a consumer's sensitive data without obtaining the consumer's opt-in consent, and where the consumer is a known child, must instead process such data in accordance with COPPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Indiana General Assembly",
     "source_url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Act exempts de-identified and aggregate personal data from scope, and a controller that discloses pseudonymous or de-identified data must exercise reasonable oversight of compliance with any related contractual commitments.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://legacy.dataguidance.com/opinion/indiana-consumer-data-protection-act-comprehensive",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-indiana/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Rights and deadlines are clearly codified and in force; minor deviations from peer-state norms (representative summary, narrower correction right) are documented, not gaps.",
   "claims": [
    {
     "statement": "Consumers may confirm whether a controller is processing their personal data and access that data; the Act permits controllers to satisfy access requests by providing either a copy of the data or a 'representative summary' of it.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/indiana-governor-signs-a-comprehensive-privacy-act-into-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Consumers may request correction of inaccuracies in personal data they previously provided to a controller, and may request deletion of their personal data held by the controller.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Indiana General Assembly",
     "source_url": "https://iga.in.gov/legislative/2023/bills/senate/5",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-indiana/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Core accountability, security, processor-contract, and breach-notification duties are clear and in force, but DPO, ROPA and retention-limit gaps reduce overall clarity relative to GDPR-style regimes.",
   "claims": [
    {
     "statement": "Controllers must conduct and document Data Protection Impact Assessments for processing activities presenting heightened risk, including targeted advertising, sale of personal data, certain profiling, and processing of sensitive data, applicable prospectively to processing occurring after December 31, 2025.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/indiana-governor-signs-a-comprehensive-privacy-act-into-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Attorney General may compel production of a controller's Data Protection Impact Assessment through a civil investigative demand as part of an enforcement investigation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/indiana-governor-signs-a-comprehensive-privacy-act-into-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Act does not impose a mandatory Data Protection Officer appointment or independence requirement on controllers or processors.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "Indiana General Assembly",
     "source_url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No explicit statutory requirement to maintain formal Records of Processing Activities was identified; documentation obligations are instead tied to DPIA and privacy-notice provisions.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "Indiana General Assembly",
     "source_url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Controllers must govern processor relationships through a binding contract specifying processing instructions, purpose, data types, duration, and the rights/obligations of each party, and processors must assist controllers with security, rights-request, breach-notification, and assessment obligations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/indiana-governor-signs-a-comprehensive-privacy-act-into-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Controllers must establish, implement and maintain reasonable administrative, technical and physical data-security practices appropriate to the volume and nature of the personal data at issue, protecting confidentiality, integrity and accessibility.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://legacy.dataguidance.com/opinion/indiana-consumer-data-protection-act-comprehensive",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Under Indiana's Disclosure of Security Breach Act (IC 24-4.9), a business experiencing unauthorized acquisition of computerized personal data must notify affected Indiana residents and the Attorney General without unreasonable delay and in no case more than 45 days after discovery of the breach.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Indiana Attorney General",
     "source_url": "https://www.in.gov/attorneygeneral/3037.htm",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Attorney General may seek injunctive relief and a civil penalty of up to $150,000 against a business that violates Indiana's breach-notification statute.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Indiana Attorney General",
     "source_url": "https://www.in.gov/attorneygeneral/3037.htm",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No general statutory data-retention-limit or mandatory-disposal schedule for personal data was identified under the Act beyond a general processor duty to assist controllers with 'retention' obligations referenced in the processor-obligations provision.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/indiana-governor-signs-a-comprehensive-privacy-act-into-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "red",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-indiana/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "No comprehensive cross-border transfer regime exists in Indiana law; this is a genuine regulatory gap, not a research gap, confirmed by direct review of the statute text.",
   "claims": [
    {
     "statement": "The Act contains no cross-border data-transfer mechanism, adequacy framework, standard contractual clauses regime, transfer-impact-assessment requirement, or data-localisation mandate; as a US state consumer-privacy statute it does not regulate international personal-data transfers in the manner of the GDPR.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "Indiana General Assembly",
     "source_url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-indiana/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Financial, health, credit and education sector carve-outs are explicit and clear; telecoms/ePrivacy and insurance-specific overlays are unconfirmed gaps rather than settled findings.",
   "claims": [
    {
     "statement": "The Act exempts data and entities already governed by the federal Gramm-Leach-Bliley Act, so GLBA-covered financial institutions' consumer financial data falls outside the Act's scope and remains subject to GLBA privacy and safeguarding rules instead.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Indiana General Assembly",
     "source_url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Act exempts protected health information and HIPAA-covered entities/business associates governed by 45 CFR Parts 160, 162 and 164, leaving health-sector personal data to the federal HIPAA regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Indiana General Assembly",
     "source_url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No Indiana-specific ePrivacy-style cookie/electronic-communications consent statute distinct from the Act was identified; cookie and tracker consent is addressed only through the Act's general targeted-advertising opt-out and privacy-notice provisions.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/indiana-governor-signs-a-comprehensive-privacy-act-into-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Act exempts employment records and human-subjects research data covered by federal law or other recognized standards, leaving Indiana employment-data privacy to sector-specific federal law rather than the Act itself.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/indiana-governor-signs-a-comprehensive-privacy-act-into-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Act exempts data covered by the federal Fair Credit Reporting Act, so consumer credit-reporting data used for eligibility determinations is governed by FCRA rather than the Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/indiana-governor-signs-a-comprehensive-privacy-act-into-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Act exempts personal data regulated by the federal Family Educational Rights and Privacy Act (FERPA), leaving education records to the federal FERPA framework.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Indiana General Assembly",
     "source_url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No Indiana-specific insurance-sector data-privacy overlay distinct from the Act's general GLBA/HIPAA exemptions was identified; insurance personal data appears to fall under the GLBA exemption where insurers are GLBA-covered financial institutions.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/indiana-governor-signs-a-comprehensive-privacy-act-into-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-indiana/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Core sale/targeted-advertising disclosure and opt-out duties are clear, but the absence of a universal opt-out signal mandate and of dark-pattern/clean-room-specific rules leaves material gaps relative to peer 'hybrid' jurisdictions.",
   "claims": [
    {
     "statement": "Controllers that sell personal data to third parties or use personal data for targeted advertising must clearly and conspicuously disclose that activity and provide consumers a method to opt out of such sale or targeted advertising.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/indiana-governor-signs-a-comprehensive-privacy-act-into-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Indiana Attorney General has pursued multistate dark-patterns enforcement activity jointly with other state AGs, reflecting active regulatory interest in manipulative consumer-facing design, even though the Act itself contains no dedicated dark-patterns article.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/indiana-attorney-general-rokita-on-federal-indiana-privacy-regulations-cybersecurity-and-more",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Unlike California, Colorado and Connecticut, the Act does not require controllers to recognize a universal opt-out mechanism such as Global Privacy Control; opt-outs must be exercised through controller-specific request channels.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/indiana-governor-signs-a-comprehensive-privacy-act-into-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No Indiana-specific data clean-room or data-collaboration-room regulation was identified; such arrangements would be treated as ordinary controller-processor or third-party disclosures under the Act's general definitions.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "Indiana General Assembly",
     "source_url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-indiana/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Profiling/DPIA and biometric/genetic sensitive-data rules are clear and in force, but the absence of a dedicated ADM-transparency/explanation right leaves a material gap relative to GDPR Art.22 analogues.",
   "claims": [
    {
     "statement": "Controllers must conduct a Data Protection Impact Assessment before processing personal data for profiling that presents a foreseeable risk of unfair or deceptive treatment, unlawful disparate impact, financial/physical/reputational injury, or other substantial injury to consumers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/indiana-governor-signs-a-comprehensive-privacy-act-into-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Act does not create a standalone right to explanation or a dedicated opt-out specifically for automated decision-making distinct from its general profiling-related DPIA and opt-out provisions.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/indiana-governor-signs-a-comprehensive-privacy-act-into-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Sensitive data under the Act includes genetic or biometric data processed to uniquely identify a specific individual, triggering the opt-in consent requirement, though the Act carves out an exemption for licensed riverboat casinos' use of facial recognition technology approved by the Indiana Gaming Commission.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/indiana-governor-signs-a-comprehensive-privacy-act-into-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Indiana enacted a dedicated genetic-privacy statute (HEA 1521) on an emergency basis, effective May 6, 2025, imposing consumer-protection obligations on direct-to-consumer genetic-testing companies; the Attorney General has since invoked it to secure data-deletion and no-third-party-transfer commitments from the successor entity in the 23andMe bankruptcy sale.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Indiana Attorney General",
     "source_url": "https://events.in.gov/event/attorney-general-todd-rokita-secures-protections-for-hoosiers-dna-amid-23andme-bankruptcy",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Act includes an evidentiary-privilege carveout under which controller/processor obligations do not apply where compliance would violate an Indiana evidentiary privilege, and exempts government entities and their contracted agents acting within the scope of a government contract.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Indiana General Assembly",
     "source_url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "green",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-indiana/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Both the ICDPA's child-related provisions and the standalone social-media parental-consent statute are clearly codified and in force; the only gap is the absence of dependent-adult-specific rules.",
   "claims": [
    {
     "statement": "Indiana Senate Bill 11 (2025) established a verifiable-parental-consent regime under which a social media operator must not allow a 'minor user' — an individual under 16 — to create or access a social media account or profile without obtaining verifiable parental consent, effective July 1, 2025.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Indiana General Assembly",
     "source_url": "https://iga.in.gov/pdf-documents/124/2025/senate/bills/SB0011/SB0011.02.COMS.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Under the Consumer Data Protection Act, a parent may invoke a known child's consumer rights on the child's behalf, and a controller may not process sensitive data concerning a known child except in accordance with COPPA, effectively requiring parental consent for sensitive-data processing of minors.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/indiana-governor-signs-a-comprehensive-privacy-act-into-law",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Act exempts personal data regulated by the federal Family Educational Rights and Privacy Act, so education-setting student records remain governed by FERPA rather than the Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Indiana General Assembly",
     "source_url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No Indiana-specific statutory provision addressing dependent-adult (elderly or mentally incapacitated) data-privacy protections distinct from the Act's general consumer-rights framework was identified.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "Indiana General Assembly",
     "source_url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The social-media verifiable-parental-consent law requires operators to encrypt information collected and retained about a minor user and removes any private cause of action, leaving enforcement to the Attorney General.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Indiana Office of Court Services",
     "source_url": "https://legislativeupdate.courts.in.gov/2025/01/17/minor-access-and-use-of-social-media/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-indiana/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Regulator powers, penalty caps, and the absence of a private right of action are clearly codified and in force, but the low penalty cap, absence of collective redress, and lack of confirmed ICDPA-specific enforcement precedent to date temper the overall enforcement-strength assessment.",
   "claims": [
    {
     "statement": "The Attorney General may issue civil investigative demands, seek injunctions, and pursue a civil penalty of up to $7,500 per violation under the Act, but must first give a controller or processor 30 days' written notice of the alleged violation and an uncapped opportunity to cure before suing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Indiana General Assembly",
     "source_url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Act expressly states that nothing in it creates a private right of action for violations, so Indiana consumers cannot sue controllers or processors directly under the Consumer Data Protection Act; enforcement runs solely through the Attorney General.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Indiana General Assembly",
     "source_url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Because the Act bars a private right of action, no consumer class-action mechanism is available under the statute itself; any collective redress would need to proceed under a separate cause of action such as the Indiana Deceptive Consumer Sales Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Indiana General Assembly",
     "source_url": "https://iga.in.gov/ic/2024/Title_24/Article_15.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Indiana Attorney General has brought data-privacy-related enforcement actions predating the Consumer Data Protection Act's effective date, including a 2025 lawsuit against General Motors/OnStar over undisclosed sale of driver telematics data and a 2022 suit against Google over location-data tracking practices, both litigated under the Indiana Deceptive Consumer Sales Act rather than the ICDPA.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Indiana Attorney General",
     "source_url": "https://events.in.gov/event/general-motors-sold-hoosier-drivers-on-using-onstar-then-sold-their-data-to-raise-rates-now-attorney-general-todd-rokita-is-driving-right-through-this-deceptive-collection-plan",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No specific budget, headcount or funding figures for a dedicated privacy-enforcement unit within the Indiana Attorney General's office were identified; enforcement is handled through the general Consumer Protection Division and a separate Data Privacy & Identity Theft Unit that also processes breach notifications.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "Office of the Indiana Attorney General",
     "source_url": "https://www.in.gov/attorneygeneral/3037.htm",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "As of early 2026, Indiana's Consumer Data Protection Act took effect January 1, 2026 alongside comparable Kentucky and Rhode Island statutes, with the Attorney General's office publishing a Consumer Data Bill of Rights and FAQ guidance ahead of the effective date; no reported enforcement action specifically under the ICDPA had been publicly announced as of the most recent search.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/new-year-new-rules-us-state-privacy-requirements-coming-online-as-2026-begins",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  }
 ]
}