Statute is enacted, in force, and unambiguous on regulator identity, scope thresholds and territorial reach; no registration-regime ambiguity exists because none is imposed.
Primary frameworkIndiana Consumer Data Protection Act (IC 24-15), P.L.94-2023, effective January 1, 2026
Traffic-light rationale — GreenStatute is enacted, in force, and unambiguous on regulator identity, scope thresholds and territorial reach; no registration-regime ambiguity exists because none is imposed.
Sub-modules (5)
Regulator And AuthorityGreen
The Attorney General has exclusive statutory enforcement authority over the ICDPA; no other state agency shares jurisdiction.
Claims (1):
The Indiana Attorney General has exclusive statutory authority to enforce the Indiana Consumer Data Protection Act (IC 24-15).
Act And InstrumentsGreen
The ICDPA was enacted via Senate Bill 5 (2023) and codified at IC 24-15, effective January 1, 2026.
Claims (1):
The Indiana Consumer Data Protection Act was enacted as P.L.94-2023 (Senate Bill 5) and codified at Indiana Code Article 24-15, with an effective date of January 1, 2026.
Material ScopeGreen
Applicability turns on dual consumer-count/revenue thresholds (100,000 consumers, or 25,000 consumers plus 50%+ revenue from data sales).
Claims (1):
The Act applies to persons conducting business in Indiana or targeting products/services to Indiana residents that, during a calendar year, control or process personal data of at least 100,000 consumers, or of at least 25,000 consumers while deriving over 50% of gross revenue from the sale of personal data.
Territorial ScopeGreen
Scope is targeting-based (business conducted in, or products/services targeted to, Indiana residents), not establishment-based.
Claims (1):
The Act's territorial scope is targeting-based rather than establishment-based: it reaches any covered entity that conducts business in Indiana or produces products/services targeted to Indiana residents, regardless of the entity's own location.
Regulator Registration And FilingAmber
No general registration or filing regime exists; the only AG-facing procedural step is the pre-suit 30-day cure notice.
Claims (1):
The Act imposes no general controller/processor registration or filing obligation with the Attorney General; the only formal AG-facing procedural step is the pre-suit 30-day cure-notice mechanism, not a registration scheme.
Category narrative69 words
Indiana's data-protection regime is anchored in the Indiana Consumer Data Protection Act (ICDPA), IC 24-15, enacted as P.L.94-2023 (Senate Bill 5) and now in force as of January 1, 2026. Enforcement is vested exclusively in the Indiana Attorney General; there is no dedicated privacy regulator or independent DPA. The Act applies on a threshold-and-targeting basis rather than an establishment basis, and imposes no general controller/processor registration or filing regime.
Sources and claims (5)
ConfirmedIndiana General Assembly — The Indiana Attorney General has exclusive statutory authority to enforce the Indiana Consumer Data Protection Act (IC 24-15).observed
ConfirmedIndiana General Assembly — The Indiana Consumer Data Protection Act was enacted as P.L.94-2023 (Senate Bill 5) and codified at Indiana Code Article 24-15, with an effective date of January 1, 2026.observed
ConfirmedIndiana General Assembly — The Act applies to persons conducting business in Indiana or targeting products/services to Indiana residents that, during a calendar year, control or process personal data of at least 100,000 consumers, or of at least 25,000 consumers while deriving over 50% of gross revenue from the sale of personal data.observed
ConfirmedIAPP — The Act's territorial scope is targeting-based rather than establishment-based: it reaches any covered entity that conducts business in Indiana or produces products/services targeted to Indiana residents, regardless of the entity's own location.observed
ProbableIndiana General Assembly — The Act imposes no general controller/processor registration or filing obligation with the Attorney General; the only formal AG-facing procedural step is the pre-suit 30-day cure-notice mechanism, not a registration scheme.observed
Consent and sensitive-data provisions are clearly codified and in force; the absence of a GDPR-style lawful-bases enumeration is a structural feature of the Virginia-model statute, not a gap.
Primary frameworkIndiana Consumer Data Protection Act (IC 24-15)
Traffic-light rationale — GreenConsent and sensitive-data provisions are clearly codified and in force; the absence of a GDPR-style lawful-bases enumeration is a structural feature of the Virginia-model statute, not a gap.
Sub-modules (4)
Lawful BasesGreen
Processing is grounded in purpose limitation and disclosed-purpose consent rather than an enumerated Art.6-style lawful-bases list.
Claims (1):
Controllers must limit collection of personal data to what is adequate, relevant and reasonably necessary for the disclosed purposes of processing, and must obtain consumer consent to process data for purposes not reasonably necessary to or compatible with those disclosed purposes.
Consent ThresholdsGreen
Consent is defined as a clear affirmative act reflecting freely given, specific, informed, unambiguous agreement.
Claims (1):
Consent under the Act is a clear affirmative act indicating a consumer's freely given, specific, informed and unambiguous agreement, evidenced by a physical or electronic written statement or other affirmative action.
Special CategoriesGreen
Sensitive data is broadly defined (race/ethnicity, religion, health diagnosis, sexual orientation, immigration status, genetic/biometric identifiers, children's data, precise geolocation) and requires opt-in consent.
Claims (2):
Sensitive data under the Act includes racial/ethnic origin, religious beliefs, mental or physical health diagnoses, sexual orientation, citizenship/immigration status, genetic or uniquely-identifying biometric data, personal data collected from a known child, and precise geolocation data within a 1,750-foot radius.
A controller may not process a consumer's sensitive data without obtaining the consumer's opt-in consent, and where the consumer is a known child, must instead process such data in accordance with COPPA.
Pseudonymisation And AnonymisationGreen
De-identified/aggregate data is exempt from scope; pseudonymous/de-identified data disclosures still require reasonable oversight of contractual compliance.
Claims (1):
The Act exempts de-identified and aggregate personal data from scope, and a controller that discloses pseudonymous or de-identified data must exercise reasonable oversight of compliance with any related contractual commitments.
Category narrative36 words
The ICDPA follows the Virginia-model consent/purpose-limitation approach rather than a GDPR Art.6-style enumerated lawful-bases list. Opt-in consent is required for sensitive data (with a COPPA carve-out for known children), and de-identified/aggregate data is exempted from scope.
Sources and claims (5)
ConfirmedIAPP — Controllers must limit collection of personal data to what is adequate, relevant and reasonably necessary for the disclosed purposes of processing, and must obtain consumer consent to process data for purposes not reasonably necessary to or compatible with those disclosed purposes.observed
ConfirmedIAPP — Consent under the Act is a clear affirmative act indicating a consumer's freely given, specific, informed and unambiguous agreement, evidenced by a physical or electronic written statement or other affirmative action.observed
ConfirmedIAPP — Sensitive data under the Act includes racial/ethnic origin, religious beliefs, mental or physical health diagnoses, sexual orientation, citizenship/immigration status, genetic or uniquely-identifying biometric data, personal data collected from a known child, and precise geolocation data within a 1,750-foot radius.observed
ConfirmedIndiana General Assembly — A controller may not process a consumer's sensitive data without obtaining the consumer's opt-in consent, and where the consumer is a known child, must instead process such data in accordance with COPPA.observed
ProbableDataGuidance — The Act exempts de-identified and aggregate personal data from scope, and a controller that discloses pseudonymous or de-identified data must exercise reasonable oversight of compliance with any related contractual commitments.observed
Rights and deadlines are clearly codified and in force; minor deviations from peer-state norms (representative summary, narrower correction right) are documented, not gaps.
Primary frameworkIndiana Consumer Data Protection Act (IC 24-15)
Traffic-light rationale — GreenRights and deadlines are clearly codified and in force; minor deviations from peer-state norms (representative summary, narrower correction right) are documented, not gaps.
Sub-modules (5)
Access RightGreen
Consumers may confirm processing and access data; controllers may satisfy this via a full copy or a 'representative summary'.
Claims (1):
Consumers may confirm whether a controller is processing their personal data and access that data; the Act permits controllers to satisfy access requests by providing either a copy of the data or a 'representative summary' of it.
Rectification And ErasureGreen
Consumers may correct inaccuracies in self-provided data and request deletion of their personal data.
Claims (1):
Consumers may request correction of inaccuracies in personal data they previously provided to a controller, and may request deletion of their personal data held by the controller.
Restriction And ObjectionGreen
Consumers may opt out of targeted advertising, sale of personal data, and certain profiling.
Data PortabilityGreen
The copy or representative summary provided to a consumer must be in a portable, readily usable format enabling transfer to another controller.
Deadlines And Response WindowsGreen
Controllers must respond within 45 days of a rights request, with one permissible 45-day extension where reasonably necessary and disclosed.
Category narrative67 words
Indiana consumers hold access, correction, deletion, portability, opt-out and opt-in (sensitive data) rights modeled closely on the Virginia CDPA. Controllers must respond within 45 days, extendable by a further 45 days with notice. The Act's access right is notable for allowing a 'representative summary' in lieu of raw data, and the correction right is narrower than in some peer states (limited to data the consumer itself provided).
Sources and claims (2)
ConfirmedIAPP — Consumers may confirm whether a controller is processing their personal data and access that data; the Act permits controllers to satisfy access requests by providing either a copy of the data or a 'representative summary' of it.observed
ConfirmedIndiana General Assembly — Consumers may request correction of inaccuracies in personal data they previously provided to a controller, and may request deletion of their personal data held by the controller.observed
Core accountability, security, processor-contract, and breach-notification duties are clear and in force, but DPO, ROPA and retention-limit gaps reduce overall clarity relative to GDPR-style regimes.
Primary frameworkIndiana Consumer Data Protection Act (IC 24-15); Indiana Disclosure of Security Breach Act (IC 24-4.9)
Traffic-light rationale — AmberCore accountability, security, processor-contract, and breach-notification duties are clear and in force, but DPO, ROPA and retention-limit gaps reduce overall clarity relative to GDPR-style regimes.
Sub-modules (7)
Accountability And DpiaGreen
DPIAs are mandatory for targeted advertising, sale, risky profiling, and sensitive-data processing occurring after December 31, 2025; the AG may compel production via civil investigative demand.
Claims (2):
Controllers must conduct and document Data Protection Impact Assessments for processing activities presenting heightened risk, including targeted advertising, sale of personal data, certain profiling, and processing of sensitive data, applicable prospectively to processing occurring after December 31, 2025.
The Attorney General may compel production of a controller's Data Protection Impact Assessment through a civil investigative demand as part of an enforcement investigation.
Dpo RequirementsRed
No DPO-appointment or independence requirement was identified.
Claims (1):
The Act does not impose a mandatory Data Protection Officer appointment or independence requirement on controllers or processors.
Ropa RequirementsRed
No standalone Records-of-Processing-Activities article was identified; documentation duties are tied to DPIA and privacy-notice provisions instead.
Claims (1):
No explicit statutory requirement to maintain formal Records of Processing Activities was identified; documentation obligations are instead tied to DPIA and privacy-notice provisions.
Joint Controller ArrangementsGreen
Controller-processor relationships must be governed by a binding contract specifying instructions, purpose, data types, duration and party obligations.
Claims (1):
Controllers must govern processor relationships through a binding contract specifying processing instructions, purpose, data types, duration, and the rights/obligations of each party, and processors must assist controllers with security, rights-request, breach-notification, and assessment obligations.
Security MeasuresGreen
Controllers must maintain reasonable administrative, technical and physical security practices appropriate to data volume/nature.
Claims (1):
Controllers must establish, implement and maintain reasonable administrative, technical and physical data-security practices appropriate to the volume and nature of the personal data at issue, protecting confidentiality, integrity and accessibility.
Breach NotificationGreen
Indiana's separate Disclosure of Security Breach Act requires notification to affected residents and the AG without unreasonable delay, capped at 45 days, with penalties up to $150,000.
Claims (2):
Under Indiana's Disclosure of Security Breach Act (IC 24-4.9), a business experiencing unauthorized acquisition of computerized personal data must notify affected Indiana residents and the Attorney General without unreasonable delay and in no case more than 45 days after discovery of the breach.
The Attorney General may seek injunctive relief and a civil penalty of up to $150,000 against a business that violates Indiana's breach-notification statute.
Retention And DisposalRed
No standalone retention-limit or disposal-schedule article was identified beyond a general processor duty to assist controllers with 'retention' obligations.
Claims (1):
No general statutory data-retention-limit or mandatory-disposal schedule for personal data was identified under the Act beyond a general processor duty to assist controllers with 'retention' obligations referenced in the processor-obligations provision.
Category narrative55 words
Controllers must run and document DPIAs for higher-risk processing (targeted advertising, sale, risky profiling, sensitive data), maintain reasonable administrative/technical/physical security, bind processors by contract, and handle breach notification under Indiana's separate Disclosure of Security Breach Act (IC 24-4.9). No DPO-appointment duty, no standalone ROPA article, and no explicit retention-limit provision were located in the statute.
Sources and claims (9)
ConfirmedIAPP — Controllers must conduct and document Data Protection Impact Assessments for processing activities presenting heightened risk, including targeted advertising, sale of personal data, certain profiling, and processing of sensitive data, applicable prospectively to processing occurring after December 31, 2025.observed
ConfirmedIAPP — The Attorney General may compel production of a controller's Data Protection Impact Assessment through a civil investigative demand as part of an enforcement investigation.observed
ProbableIndiana General Assembly — The Act does not impose a mandatory Data Protection Officer appointment or independence requirement on controllers or processors.observed
ProbableIndiana General Assembly — No explicit statutory requirement to maintain formal Records of Processing Activities was identified; documentation obligations are instead tied to DPIA and privacy-notice provisions.observed
ConfirmedIAPP — Controllers must govern processor relationships through a binding contract specifying processing instructions, purpose, data types, duration, and the rights/obligations of each party, and processors must assist controllers with security, rights-request, breach-notification, and assessment obligations.observed
ConfirmedDataGuidance — Controllers must establish, implement and maintain reasonable administrative, technical and physical data-security practices appropriate to the volume and nature of the personal data at issue, protecting confidentiality, integrity and accessibility.observed
ConfirmedOffice of the Indiana Attorney General — Under Indiana's Disclosure of Security Breach Act (IC 24-4.9), a business experiencing unauthorized acquisition of computerized personal data must notify affected Indiana residents and the Attorney General without unreasonable delay and in no case more than 45 days after discovery of the breach.observed
ConfirmedOffice of the Indiana Attorney General — The Attorney General may seek injunctive relief and a civil penalty of up to $150,000 against a business that violates Indiana's breach-notification statute.observed
UncertainIAPP — No general statutory data-retention-limit or mandatory-disposal schedule for personal data was identified under the Act beyond a general processor duty to assist controllers with 'retention' obligations referenced in the processor-obligations provision.observed
No comprehensive cross-border transfer regime exists in Indiana law; this is a genuine regulatory gap, not a research gap, confirmed by direct review of the statute text.
Traffic-light rationale — RedNo comprehensive cross-border transfer regime exists in Indiana law; this is a genuine regulatory gap, not a research gap, confirmed by direct review of the statute text.
Sub-modules (6)
Transfer MechanismsRed
No transfer-mechanism regime exists under the Act.
Claims (1):
The Act contains no cross-border data-transfer mechanism, adequacy framework, standard contractual clauses regime, transfer-impact-assessment requirement, or data-localisation mandate; as a US state consumer-privacy statute it does not regulate international personal-data transfers in the manner of the GDPR.
Adequacy ReceivedRed
Not applicable; Indiana law does not operate an adequacy-recognition mechanism.
Adequacy GrantedRed
Not applicable; Indiana law does not grant adequacy to other jurisdictions.
Sccs And BcrsRed
No SCC or BCR framework exists under the Act.
Transfer Impact AssessmentRed
No TIA requirement exists under the Act.
Data LocalisationRed
No data-localisation mandate exists under the Act.
Category narrative51 words
As a US state consumer-privacy statute, the ICDPA contains no international-transfer-mechanism framework, adequacy regime, SCC/BCR provisions, transfer-impact-assessment requirement, or data-localisation mandate. Cross-border data-flow governance for Indiana-touching data is instead a function of whatever framework applies in the destination or origin jurisdiction (e.g., GDPR for EU-bound flows), not of Indiana law itself.
Sources and claims (1)
ProbableIndiana General Assembly — The Act contains no cross-border data-transfer mechanism, adequacy framework, standard contractual clauses regime, transfer-impact-assessment requirement, or data-localisation mandate; as a US state consumer-privacy statute it does not regulate international personal-data transfers in the manner of the GDPR.observed
Financial, health, credit and education sector carve-outs are explicit and clear; telecoms/ePrivacy and insurance-specific overlays are unconfirmed gaps rather than settled findings.
Primary frameworkIndiana Consumer Data Protection Act (IC 24-15), read together with federal GLBA/HIPAA/FCRA/FERPA
Traffic-light rationale — AmberFinancial, health, credit and education sector carve-outs are explicit and clear; telecoms/ePrivacy and insurance-specific overlays are unconfirmed gaps rather than settled findings.
Sub-modules (7)
Financial Sector OverlayGreen
GLBA-covered financial institutions and GLBA-governed data are exempt from the Act.
Claims (1):
The Act exempts data and entities already governed by the federal Gramm-Leach-Bliley Act, so GLBA-covered financial institutions' consumer financial data falls outside the Act's scope and remains subject to GLBA privacy and safeguarding rules instead.
Health Sector OverlayGreen
HIPAA-covered entities/business associates and protected health information are exempt from the Act.
Claims (1):
The Act exempts protected health information and HIPAA-covered entities/business associates governed by 45 CFR Parts 160, 162 and 164, leaving health-sector personal data to the federal HIPAA regime.
Telecoms And EprivacyAmber
No dedicated Indiana ePrivacy/cookie statute distinct from the Act's general targeted-advertising provisions was identified.
Claims (1):
No Indiana-specific ePrivacy-style cookie/electronic-communications consent statute distinct from the Act was identified; cookie and tracker consent is addressed only through the Act's general targeted-advertising opt-out and privacy-notice provisions.
Employment DataGreen
Employment records and covered human-subjects research data are exempt from the Act.
Claims (1):
The Act exempts employment records and human-subjects research data covered by federal law or other recognized standards, leaving Indiana employment-data privacy to sector-specific federal law rather than the Act itself.
Credit And ScoringGreen
FCRA-covered consumer credit-reporting data is exempt from the Act.
Claims (1):
The Act exempts data covered by the federal Fair Credit Reporting Act, so consumer credit-reporting data used for eligibility determinations is governed by FCRA rather than the Act.
EducationGreen
FERPA-covered education records are exempt from the Act.
Claims (1):
The Act exempts personal data regulated by the federal Family Educational Rights and Privacy Act (FERPA), leaving education records to the federal FERPA framework.
InsuranceAmber
No dedicated Indiana insurance-sector privacy overlay distinct from the Act's GLBA exemption was identified.
Claims (1):
No Indiana-specific insurance-sector data-privacy overlay distinct from the Act's general GLBA/HIPAA exemptions was identified; insurance personal data appears to fall under the GLBA exemption where insurers are GLBA-covered financial institutions.
Category narrative47 words
The ICDPA exempts data and entities already covered by GLBA, HIPAA, FCRA, FERPA, the Driver's Privacy Protection Act, and human-subjects research standards, deferring sectoral privacy governance in those areas to the applicable federal regime. No Indiana-specific overlay for telecoms/ePrivacy, education, or insurance beyond these exemptions was identified.
Sources and claims (7)
ConfirmedIndiana General Assembly — The Act exempts data and entities already governed by the federal Gramm-Leach-Bliley Act, so GLBA-covered financial institutions' consumer financial data falls outside the Act's scope and remains subject to GLBA privacy and safeguarding rules instead.observed
ConfirmedIndiana General Assembly — The Act exempts protected health information and HIPAA-covered entities/business associates governed by 45 CFR Parts 160, 162 and 164, leaving health-sector personal data to the federal HIPAA regime.observed
ProbableIAPP — No Indiana-specific ePrivacy-style cookie/electronic-communications consent statute distinct from the Act was identified; cookie and tracker consent is addressed only through the Act's general targeted-advertising opt-out and privacy-notice provisions.observed
ConfirmedIAPP — The Act exempts employment records and human-subjects research data covered by federal law or other recognized standards, leaving Indiana employment-data privacy to sector-specific federal law rather than the Act itself.observed
ConfirmedIAPP — The Act exempts data covered by the federal Fair Credit Reporting Act, so consumer credit-reporting data used for eligibility determinations is governed by FCRA rather than the Act.observed
ConfirmedIndiana General Assembly — The Act exempts personal data regulated by the federal Family Educational Rights and Privacy Act (FERPA), leaving education records to the federal FERPA framework.observed
UncertainIAPP — No Indiana-specific insurance-sector data-privacy overlay distinct from the Act's general GLBA/HIPAA exemptions was identified; insurance personal data appears to fall under the GLBA exemption where insurers are GLBA-covered financial institutions.observed
Core sale/targeted-advertising disclosure and opt-out duties are clear, but the absence of a universal opt-out signal mandate and of dark-pattern/clean-room-specific rules leaves material gaps relative to peer 'hybrid' jurisdictions.
Primary frameworkIndiana Consumer Data Protection Act (IC 24-15)
Traffic-light rationale — AmberCore sale/targeted-advertising disclosure and opt-out duties are clear, but the absence of a universal opt-out signal mandate and of dark-pattern/clean-room-specific rules leaves material gaps relative to peer 'hybrid' jurisdictions.
Sub-modules (6)
Cookies And TrackersAmber
Governed only via the Act's general targeted-advertising/sale disclosure and opt-out duties; no dedicated cookie statute.
Claims (1):
Controllers that sell personal data to third parties or use personal data for targeted advertising must clearly and conspicuously disclose that activity and provide consumers a method to opt out of such sale or targeted advertising.
Dark PatternsAmber
No dedicated dark-patterns statute exists, though the AG has participated in multistate dark-patterns enforcement.
Claims (1):
The Indiana Attorney General has pursued multistate dark-patterns enforcement activity jointly with other state AGs, reflecting active regulatory interest in manipulative consumer-facing design, even though the Act itself contains no dedicated dark-patterns article.
Opt Out SignalsAmber
The Act does not mandate recognition of a universal opt-out mechanism.
Claims (1):
Unlike California, Colorado and Connecticut, the Act does not require controllers to recognize a universal opt-out mechanism such as Global Privacy Control; opt-outs must be exercised through controller-specific request channels.
Clean Rooms And DcrRed
No clean-room-specific regulation was identified; such arrangements fall under general controller-processor/third-party disclosure rules.
Claims (1):
No Indiana-specific data clean-room or data-collaboration-room regulation was identified; such arrangements would be treated as ordinary controller-processor or third-party disclosures under the Act's general definitions.
Cross Context AdvertisingAmber
Targeted-advertising disclosure and opt-out duties function analogously to CPRA's 'sale'/'share' concepts but are narrower in scope.
Claims (1):
Controllers that sell personal data to third parties or use personal data for targeted advertising must clearly and conspicuously disclose that activity and provide consumers a method to opt out of such sale or targeted advertising.
Direct MarketingAmber
Direct-marketing-related processing is covered by the same sale/targeted-advertising disclosure and opt-out framework.
Claims (1):
Controllers that sell personal data to third parties or use personal data for targeted advertising must clearly and conspicuously disclose that activity and provide consumers a method to opt out of such sale or targeted advertising.
Category narrative54 words
Controllers must disclose and provide opt-outs for targeted advertising and sale of personal data, but the Act does not require recognition of universal opt-out signals (e.g., Global Privacy Control), unlike California, Colorado or Connecticut. Dark-patterns and clean-room-specific rules are not separately codified, though the AG has shown multistate enforcement interest in dark patterns generally.
Sources and claims (4)
ConfirmedIAPP — Controllers that sell personal data to third parties or use personal data for targeted advertising must clearly and conspicuously disclose that activity and provide consumers a method to opt out of such sale or targeted advertising.observed
ProbableIAPP — The Indiana Attorney General has pursued multistate dark-patterns enforcement activity jointly with other state AGs, reflecting active regulatory interest in manipulative consumer-facing design, even though the Act itself contains no dedicated dark-patterns article.observed
ConfirmedIAPP — Unlike California, Colorado and Connecticut, the Act does not require controllers to recognize a universal opt-out mechanism such as Global Privacy Control; opt-outs must be exercised through controller-specific request channels.observed
UncertainIndiana General Assembly — No Indiana-specific data clean-room or data-collaboration-room regulation was identified; such arrangements would be treated as ordinary controller-processor or third-party disclosures under the Act's general definitions.observed
Profiling/DPIA and biometric/genetic sensitive-data rules are clear and in force, but the absence of a dedicated ADM-transparency/explanation right leaves a material gap relative to GDPR Art.22 analogues.
Primary frameworkIndiana Consumer Data Protection Act (IC 24-15); Indiana genetic privacy statute HEA 1521 (2025)
Traffic-light rationale — AmberProfiling/DPIA and biometric/genetic sensitive-data rules are clear and in force, but the absence of a dedicated ADM-transparency/explanation right leaves a material gap relative to GDPR Art.22 analogues.
Sub-modules (6)
Profiling RestrictionsGreen
DPIAs are required before profiling that creates a foreseeable risk of unfair/deceptive treatment or substantial injury.
Claims (1):
Controllers must conduct a Data Protection Impact Assessment before processing personal data for profiling that presents a foreseeable risk of unfair or deceptive treatment, unlawful disparate impact, financial/physical/reputational injury, or other substantial injury to consumers.
Automated Decision Making TransparencyRed
No standalone ADM-transparency or explanation right was identified beyond the general profiling DPIA trigger.
Claims (1):
The Act does not create a standalone right to explanation or a dedicated opt-out specifically for automated decision-making distinct from its general profiling-related DPIA and opt-out provisions.
Ai Risk AssessmentsAmber
AI-specific risk-assessment obligations are subsumed within the general profiling DPIA trigger; no separate AI Act-style regime exists.
Claims (1):
Controllers must conduct a Data Protection Impact Assessment before processing personal data for profiling that presents a foreseeable risk of unfair or deceptive treatment, unlawful disparate impact, financial/physical/reputational injury, or other substantial injury to consumers.
Biometric RegimeGreen
Genetic/uniquely-identifying biometric data is sensitive data requiring opt-in consent, with a licensed-riverboat-casino facial-recognition carve-out.
Claims (1):
Sensitive data under the Act includes genetic or biometric data processed to uniquely identify a specific individual, triggering the opt-in consent requirement, though the Act carves out an exemption for licensed riverboat casinos' use of facial recognition technology approved by the Indiana Gaming Commission.
Genetic DataGreen
A dedicated genetic-privacy statute (HEA 1521), effective May 6, 2025, supplements the Act and has been actively enforced by the AG.
Claims (1):
Indiana enacted a dedicated genetic-privacy statute (HEA 1521) on an emergency basis, effective May 6, 2025, imposing consumer-protection obligations on direct-to-consumer genetic-testing companies; the Attorney General has since invoked it to secure data-deletion and no-third-party-transfer commitments from the successor entity in the 23andMe bankruptcy sale.
State Surveillance CarveoutsAmber
An evidentiary-privilege carveout and a government-entity/contractor exemption limit the Act's reach.
Claims (1):
The Act includes an evidentiary-privilege carveout under which controller/processor obligations do not apply where compliance would violate an Indiana evidentiary privilege, and exempts government entities and their contracted agents acting within the scope of a government contract.
Category narrative55 words
The Act triggers DPIA obligations for risky profiling and treats genetic/uniquely-identifying biometric data as sensitive data requiring opt-in consent, subject to a riverboat-casino facial-recognition carve-out. There is no standalone ADM-transparency/explanation right. A separate 2025 genetic-privacy statute (HEA 1521) supplements the Act for direct-to-consumer genetic testing, recently invoked by the AG in the 23andMe bankruptcy matter.
Sources and claims (5)
ConfirmedIAPP — Controllers must conduct a Data Protection Impact Assessment before processing personal data for profiling that presents a foreseeable risk of unfair or deceptive treatment, unlawful disparate impact, financial/physical/reputational injury, or other substantial injury to consumers.observed
UncertainIAPP — The Act does not create a standalone right to explanation or a dedicated opt-out specifically for automated decision-making distinct from its general profiling-related DPIA and opt-out provisions.observed
ConfirmedIAPP — Sensitive data under the Act includes genetic or biometric data processed to uniquely identify a specific individual, triggering the opt-in consent requirement, though the Act carves out an exemption for licensed riverboat casinos' use of facial recognition technology approved by the Indiana Gaming Commission.observed
ConfirmedOffice of the Indiana Attorney General — Indiana enacted a dedicated genetic-privacy statute (HEA 1521) on an emergency basis, effective May 6, 2025, imposing consumer-protection obligations on direct-to-consumer genetic-testing companies; the Attorney General has since invoked it to secure data-deletion and no-third-party-transfer commitments from the successor entity in the 23andMe bankruptcy sale.observed
ConfirmedIndiana General Assembly — The Act includes an evidentiary-privilege carveout under which controller/processor obligations do not apply where compliance would violate an Indiana evidentiary privilege, and exempts government entities and their contracted agents acting within the scope of a government contract.observed
Both the ICDPA's child-related provisions and the standalone social-media parental-consent statute are clearly codified and in force; the only gap is the absence of dependent-adult-specific rules.
Primary frameworkIndiana Consumer Data Protection Act (IC 24-15); Indiana Senate Bill 11 (2025), Verifiable Parental Consent for Social Media (IC 24-4-24)
Traffic-light rationale — GreenBoth the ICDPA's child-related provisions and the standalone social-media parental-consent statute are clearly codified and in force; the only gap is the absence of dependent-adult-specific rules.
Sub-modules (5)
Age VerificationGreen
SB 11 requires social media operators to determine whether a user is a 'minor user' (under 16) before granting account access.
Claims (1):
Indiana Senate Bill 11 (2025) established a verifiable-parental-consent regime under which a social media operator must not allow a 'minor user' — an individual under 16 — to create or access a social media account or profile without obtaining verifiable parental consent, effective July 1, 2025.
Parental ConsentGreen
SB 11 requires verifiable parental consent before a minor under 16 may access social media; the ICDPA separately allows a parent to invoke a known child's rights and requires COPPA-aligned consent for sensitive data.
Claims (2):
Indiana Senate Bill 11 (2025) established a verifiable-parental-consent regime under which a social media operator must not allow a 'minor user' — an individual under 16 — to create or access a social media account or profile without obtaining verifiable parental consent, effective July 1, 2025.
Under the Consumer Data Protection Act, a parent may invoke a known child's consumer rights on the child's behalf, and a controller may not process sensitive data concerning a known child except in accordance with COPPA, effectively requiring parental consent for sensitive-data processing of minors.
Minor Profiling BansAmber
No standalone profiling ban for minors exists; protection is achieved indirectly via sensitive-data opt-in consent and SB 11's account-access restriction.
Claims (1):
No Indiana-specific statutory provision addressing dependent-adult (elderly or mentally incapacitated) data-privacy protections distinct from the Act's general consumer-rights framework was identified.
Education SettingsGreen
Education records are exempted from the ICDPA and remain governed by FERPA.
Claims (1):
The Act exempts personal data regulated by the federal Family Educational Rights and Privacy Act, so education-setting student records remain governed by FERPA rather than the Act.
Dependent AdultsRed
No Indiana-specific dependent-adult data-privacy provision was identified.
Claims (1):
No Indiana-specific statutory provision addressing dependent-adult (elderly or mentally incapacitated) data-privacy protections distinct from the Act's general consumer-rights framework was identified.
Category narrative59 words
Two Indiana statutes jointly govern minors' data: the ICDPA (parental exercise of a known child's rights; COPPA-aligned sensitive-data consent) and Senate Bill 11 (2025), which imposes a verifiable-parental-consent regime for minors under 16 on social media, effective July 1, 2025, with encryption duties and no private right of action. Education records fall to FERPA. No dependent-adult-specific provision was identified.
Sources and claims (5)
ConfirmedIndiana General Assembly — Indiana Senate Bill 11 (2025) established a verifiable-parental-consent regime under which a social media operator must not allow a 'minor user' — an individual under 16 — to create or access a social media account or profile without obtaining verifiable parental consent, effective July 1, 2025.observed
ConfirmedIAPP — Under the Consumer Data Protection Act, a parent may invoke a known child's consumer rights on the child's behalf, and a controller may not process sensitive data concerning a known child except in accordance with COPPA, effectively requiring parental consent for sensitive-data processing of minors.observed
ConfirmedIndiana General Assembly — The Act exempts personal data regulated by the federal Family Educational Rights and Privacy Act, so education-setting student records remain governed by FERPA rather than the Act.observed
UncertainIndiana General Assembly — No Indiana-specific statutory provision addressing dependent-adult (elderly or mentally incapacitated) data-privacy protections distinct from the Act's general consumer-rights framework was identified.observed
ConfirmedIndiana Office of Court Services — The social-media verifiable-parental-consent law requires operators to encrypt information collected and retained about a minor user and removes any private cause of action, leaving enforcement to the Attorney General.observed
Regulator powers, penalty caps, and the absence of a private right of action are clearly codified and in force, but the low penalty cap, absence of collective redress, and lack of confirmed ICDPA-specific enforcement precedent to date temper the overall enforcement-strength assessment.
Traffic-light rationale — AmberRegulator powers, penalty caps, and the absence of a private right of action are clearly codified and in force, but the low penalty cap, absence of collective redress, and lack of confirmed ICDPA-specific enforcement precedent to date temper the overall enforcement-strength assessment.
Sub-modules (6)
Regulator Powers And PenaltiesAmber
AG may issue civil investigative demands, seek injunctions, and pursue penalties up to $7,500 per violation, subject to a mandatory 30-day uncapped cure period.
Claims (1):
The Attorney General may issue civil investigative demands, seek injunctions, and pursue a civil penalty of up to $7,500 per violation under the Act, but must first give a controller or processor 30 days' written notice of the alleged violation and an uncapped opportunity to cure before suing.
Enforcement Activity IndexAmber
Pre-ICDPA privacy-adjacent enforcement (GM/OnStar 2025; Google location data 2022) was brought under the Deceptive Consumer Sales Act, not the ICDPA.
Claims (1):
The Indiana Attorney General has brought data-privacy-related enforcement actions predating the Consumer Data Protection Act's effective date, including a 2025 lawsuit against General Motors/OnStar over undisclosed sale of driver telematics data and a 2022 suit against Google over location-data tracking practices, both litigated under the Indiana Deceptive Consumer Sales Act rather than the ICDPA.
Regulator Funding And CapacityAmber
No published budget/headcount figures for a dedicated ICDPA-enforcement unit were identified; enforcement runs through the general Consumer Protection Division and Data Privacy & Identity Theft Unit.
Claims (1):
No specific budget, headcount or funding figures for a dedicated privacy-enforcement unit within the Indiana Attorney General's office were identified; enforcement is handled through the general Consumer Protection Division and a separate Data Privacy & Identity Theft Unit that also processes breach notifications.
Collective Redress And Class ActionsRed
No consumer class-action mechanism exists under the ICDPA itself.
Claims (1):
Because the Act bars a private right of action, no consumer class-action mechanism is available under the statute itself; any collective redress would need to proceed under a separate cause of action such as the Indiana Deceptive Consumer Sales Act.
Private Right Of ActionRed
The Act expressly bars any private right of action for violations.
Claims (1):
The Act expressly states that nothing in it creates a private right of action for violations, so Indiana consumers cannot sue controllers or processors directly under the Consumer Data Protection Act; enforcement runs solely through the Attorney General.
Recent Developments 180DAmber
The ICDPA took effect January 1, 2026 alongside comparable Kentucky and Rhode Island laws; the AG published a Consumer Data Bill of Rights/FAQ ahead of the effective date, but no ICDPA-specific enforcement action had been publicly reported as of the most recent search.
Claims (1):
As of early 2026, Indiana's Consumer Data Protection Act took effect January 1, 2026 alongside comparable Kentucky and Rhode Island statutes, with the Attorney General's office publishing a Consumer Data Bill of Rights and FAQ guidance ahead of the effective date; no reported enforcement action specifically under the ICDPA had been publicly announced as of the most recent search.
Category narrative87 words
Enforcement of the ICDPA is exclusively vested in the Attorney General, who must give 30 days' cure notice before suing and is capped at a $7,500 civil penalty per violation; the Act bars any private right of action or class-action mechanism under the statute itself. Predating the ICDPA's effective date, the AG has already brought privacy-adjacent enforcement (GM/OnStar, Google location data) under the separate Indiana Deceptive Consumer Sales Act. No enforcement action specifically under the now-effective ICDPA had been publicly identified as of the most recent search.
Sources and claims (6)
ConfirmedIndiana General Assembly — The Attorney General may issue civil investigative demands, seek injunctions, and pursue a civil penalty of up to $7,500 per violation under the Act, but must first give a controller or processor 30 days' written notice of the alleged violation and an uncapped opportunity to cure before suing.observed
ConfirmedIndiana General Assembly — The Act expressly states that nothing in it creates a private right of action for violations, so Indiana consumers cannot sue controllers or processors directly under the Consumer Data Protection Act; enforcement runs solely through the Attorney General.observed
ConfirmedIndiana General Assembly — Because the Act bars a private right of action, no consumer class-action mechanism is available under the statute itself; any collective redress would need to proceed under a separate cause of action such as the Indiana Deceptive Consumer Sales Act.observed
ConfirmedOffice of the Indiana Attorney General — The Indiana Attorney General has brought data-privacy-related enforcement actions predating the Consumer Data Protection Act's effective date, including a 2025 lawsuit against General Motors/OnStar over undisclosed sale of driver telematics data and a 2022 suit against Google over location-data tracking practices, both litigated under the Indiana Deceptive Consumer Sales Act rather than the ICDPA.observed
UncertainOffice of the Indiana Attorney General — No specific budget, headcount or funding figures for a dedicated privacy-enforcement unit within the Indiana Attorney General's office were identified; enforcement is handled through the general Consumer Protection Division and a separate Data Privacy & Identity Theft Unit that also processes breach notifications.observed
ProbableIAPP — As of early 2026, Indiana's Consumer Data Protection Act took effect January 1, 2026 alongside comparable Kentucky and Rhode Island statutes, with the Attorney General's office publishing a Consumer Data Bill of Rights and FAQ guidance ahead of the effective date; no reported enforcement action specifically under the ICDPA had been publicly announced as of the most recent search.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for United States – Indiana
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 49 claim(s), 15 source(s) in the cumulative register.
GDPR article map
Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).
Regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, children_and_vulnerable_groups, and enforcement_and_redress are grounded in T1 primary-source review of the full IC 24-15 statute text (iga.in.gov), Senate Bill 5/11 legislative text, the AG's own Consumer Data Bill of Rights, and IC 24-4.9 breach-notification guidance published directly by the Indiana Attorney General. Cross_border_and_adequacy relies on a T1 negative-finding (direct statute review confirming absence of any transfer/adequacy/SCC/localisation regime). Sectoral_watch, adtech_and_commercial_privacy, and algorithmic_biometric_and_surveillance_governance combine T1 statute citations for exemptions/sensitive-data/profiling triggers with T2 industry analysis (IAPP, DataGuidance) for interpretive detail (e.g., universal opt-out non-recognition, health-data-definition narrowness, dark-patterns enforcement posture) where the bare statute text alone was insufficient to characterize a sub-module. Genetic-data and social-media-minor-consent findings rely on T1 AG press releases and legislative bill text. No T4 sources were used as the basis for any binding claim.
Unresolved questions (5):
Has the Indiana Attorney General issued any formal implementing rules or interpretive regulations under IC 24-15 since its January 1, 2026 effective date?
Has any enforcement action been brought specifically under IC 24-15 (as opposed to the Indiana Deceptive Consumer Sales Act) as of August 2026?
Does Indiana's genetic-privacy statute (HEA 1521) impose obligations distinct from, or overlapping with, IC 24-15's genetic/biometric sensitive-data provisions, and how are the two statutes reconciled in AG guidance?
Is there any Indiana-specific insurance-sector or telecoms/ePrivacy overlay not captured by the Act's GLBA/HIPAA exemptions?
What is the current status of Indiana House Bill 1178 (2026) on minor access to social media, and does it amend or supersede Senate Bill 11 (2025)?