Indiana Privacy Law
Indiana’s comprehensive statute and its older consumer-protection law point in opposite directions on the same question, and the gap between them is the most interesting thing about privacy law in the state. Article 24-15 of the Indiana Code, effective January 1, 2026, defines a “sale of personal data’’ narrowly — an exchange for monetary consideration and nothing else. Two years earlier, in litigation the Attorney General brought under the Deceptive Consumer Sales Act, the Court of Appeals held that giving up personal data in exchange for access to a content library is itself a “sale” and therefore a consumer transaction. Indiana also lets a controller answer an access request with a representative summary rather than a copy, and its breach statute carries a $150,000 penalty per deceptive act, an order of magnitude above the $7,500 the comprehensive law allows.
The Indiana Consumer Data Protection Act (INCDPA)
Added by P.L.94-2023 (Senate Bill 5) and effective January 1, 2026, article 24-15 runs to eleven chapters. Section 24-15-1-1(a) sets a two-branch threshold; § 24-15-1-1(b) removes the state and its subdivisions, financial institutions and data subject to Title V of the Gramm-Leach-Bliley Act, HIPAA covered entities and business associates, nonprofits and institutions of higher education. Two drafting choices set Indiana apart from the Virginia model it otherwise follows. Section 24-15-2-27(a) defines the “sale of personal data” as an exchange “for monetary consideration” only, so barter arrangements fall outside the opt-out. And § 24-15-3-1(b)(4) lets a controller satisfy an access request by providing either a copy of the consumer’s data or “a representative summary” of it, at the controller’s discretion, once in any twelve-month period. The article contains no rulemaking authority and no requirement that controllers recognise a universal opt-out preference signal.
| Effective date | January 1, 2026 |
|---|---|
| Citation | Ind. Code art. 24-15 |
| Enforced by | Indiana Attorney General |
| Maximum penalty | Up to $7,500 per violation under Ind. Code § 24-15-10-2(a) |
| Private right of action | No, enforcement by the state only |
| Right to cure | 30 days, with no sunset date (Ind. Code § 24-15-10-3) |
Who Must Comply
The INCDPA reaches a business that conducts business in Indiana or produces products or services targeted to Indiana residents, and during a calendar year controls or processes the personal data of at least 100,000 Indiana consumers, or controls or processes the personal data of at least 25,000 Indiana consumers and derives more than 50% of gross revenue from the sale of personal data.
The access right can be answered with a representative summary rather than a copy, the definition of a sale is limited to monetary consideration, and the article grants no rulemaking authority and requires no universal opt-out signal.
Consumer Rights Under the INCDPA
Residents of Indiana can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.
Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.
Sector-Specific Privacy Laws in Indiana
Age Verification for Adult Oriented Websites (Ind. Code art. 24-4-23)
Added by P.L.98-2024, article 24-4-23 reaches a website where at least one-third of the images and videos published are material harmful to minors as described in § 35-49-2-2. Section 24-4-23-10 bars an operator from knowingly or intentionally publishing such a site without a reasonable age verification method, which § 24-4-23-7 defines as a mobile credential, an independent third-party verification service checking against commercially available databases, or another commercially reasonable method relying on public or private transactional data. The privacy provisions run the other way from the verification duty: § 24-4-23-13(b) bars the operator and any third-party verification service it uses from retaining the identifying information of a person seeking access unless a court order requires retention, and gives an individual whose information is retained a claim for actual damages or up to $5,000, injunctive relief, costs, fees and expert witness fees. Section 24-4-23-11 gives a parent or guardian a parallel claim on the same terms where a minor accessed the site. Section 24-4-23-15 allows the Attorney General to seek an injunction, investigative costs and a civil penalty of up to $250,000, and § 24-4-23-16 supplies civil investigative demand power under § 4-6-3-3. Section 24-4-23-17 requires a minor’s verification information in any such action to be sealed in a confidential envelope in the court file.
Persons Holding a Customer’s Personal Information (Ind. Code ch. 24-4-14)
Chapter 24-4-14 governs disposal rather than collection. Section 24-4-14-8 makes it a Class C infraction to dispose of a customer’s unencrypted, unredacted personal information without shredding, incinerating, mutilating, erasing or otherwise rendering it illegible or unusable, and raises the offense to a Class A infraction where more than 100 customers’ information is involved or where the person has a prior unrelated judgment under the section. Section 24-4-14-3 defines “dispose of” to include placing the information in a container for trash collection, which is what gives the chapter its practical reach. Section 24-4-14-2 defines “customer” broadly enough to include a person who provided information in a transaction with a nonprofit corporation or charitable organization. Section 24-4-14-1 excludes state and local government offices, waste collectors except as to information they hold directly, and persons maintaining a disposal program under the USA PATRIOT Act, Executive Order 13224, the Driver’s Privacy Protection Act, the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act or HIPAA. A parallel duty sits in the breach article: § 24-4.9-3-3.5(c) and (d) require reasonable safeguards and the same disposal practice, enforceable by the Attorney General alone at up to $5,000 per deceptive act.
Deceptive Consumer Sales Act (Ind. Code ch. 24-5-0.5)
The Deceptive Consumer Sales Act is Indiana’s general unfair-practices statute and the vehicle for the state’s largest privacy recoveries. Section 24-5-0.5-2(a)(1) defines a “consumer transaction” as a sale, lease, assignment, award by chance or other disposition of personal property, real property, a service or an intangible, for primarily personal, familial, charitable, agricultural or household purposes. Section 24-5-0.5-1 directs that the chapter be liberally construed. Section 24-5-0.5-4(a) gives a consumer relying on an uncured or incurable deceptive act actual damages or $500, whichever is greater, with treble damages or $1,000 available for a willful act; § 24-5-0.5-4(c) lets the Attorney General seek an injunction and restitution; § 24-5-0.5-4(f) sets a civil penalty of up to $15,000 per violation of such an injunction; and § 24-5-0.5-8 adds a fine of up to $500 for each incurable deceptive act, recoverable only by the Attorney General.
Data Breach Notification in Indiana
Article 24-4.9 of the Indiana Code is triggered by risk rather than by exposure alone. Section 24-4.9-3-1(a) requires a database owner to disclose a breach to an affected Indiana resident where the owner “knows, should know, or should have known” that the unauthorized acquisition has resulted in or could result in identity deception, identity theft or fraud. Section 24-4.9-3-1(c) then attaches Attorney General notice to that disclosure with no threshold of its own: if the resident is notified, the Attorney General is notified. Section 24-4.9-3-1(b) adds notice to every nationwide consumer reporting agency once more than 1,000 consumers are involved. The clock in § 24-4.9-3-3(a) is 45 days from discovery, with delay treated as reasonable only where it is necessary to restore system integrity, to determine the scope of the breach, or where the Attorney General or a law enforcement agency has asked for delay. Section 24-4.9-2-10 counts a Social Security number on its own, and a name with a driver’s license number, state identification card number, credit card number, or financial account or debit card number with its access code; P.L.98-2024 added information collected by an adult oriented website operator under article 24-4-23. Substitute notice becomes available under § 24-4.9-3-4(b) above 500,000 residents or $250,000 in cost. Penalties are unusually high for a breach statute: § 24-4.9-4-2 allows an injunction, the Attorney General’s investigative costs, and a civil penalty of up to $150,000 per deceptive act, with a related series of breaches counted as one act under § 24-4.9-4-1(b).
Residents must be notified without unreasonable delay and not more than 45 days after discovery of the breach. Notify the Attorney General whenever notice is given to any Indiana resident — no headcount threshold. Complaints are taken by the Indiana Attorney General, which enforces the statute.
Recent Enforcement in Indiana
Google location tracking — $20 million Indiana settlement, December 2022. The Attorney General’s office announced on December 29, 2022 that it had settled Indiana’s separate suit against Google over location tracking for $20 million. The office states that it filed an independent action rather than joining the multistate negotiation, and that Indiana consequently received “approximately twice as much money as it would have received” under the settlement later reached by the forty states that did not sue. The release describes the underlying allegation as deception since at least 2014 about how location data was collected and used to build user profiles and target advertising, and notes that the investigations followed 2018 Associated Press reporting. The settlement agreement is published with the release.
State v. TikTok Inc. — personal data held to be the price of a consumer transaction. The Attorney General filed two suits against TikTok, ByteDance and affiliated entities in Allen Superior Court in December 2022 under the Deceptive Consumer Sales Act, one concerning the app’s content rating and one concerning representations about access to user data. The trial court dismissed both for want of specific personal jurisdiction and for failure to state a claim. In consolidated opinions issued September 30, 2024 in Court of Appeals cause numbers 23A-PL-3110 and 23A-PL-3111, the Court of Appeals reversed. On the question that matters most for privacy claims, the court rejected the argument that a consumer transaction requires an exchange for money: the statutory definition “does not include the words ‘exchange for money’”, and the ordinary and legal meanings of “sale” reach “any consideration to effectuate the transfer of property”. Because TikTok “exchanges access to its app’s content library for end-user personal data”, the court held that its business model is a consumer transaction under the Act. The Indiana Supreme Court denied transfer on June 24, 2025, with Justices Slaughter and Goff voting to grant.
Pending Privacy Legislation
Indiana’s recent privacy output has come through the Deceptive Consumer Sales Act and the age-verification article rather than through amendments to article 24-15, which took effect January 1, 2026 in the form enacted by P.L.94-2023 without intervening substantive change. P.L.98-2024 added article 24-4-23 and, in the same act, extended the breach statute’s definition of personal information at § 24-4.9-2-10(3) to information collected by an adult oriented website operator. P.L.171-2022 had earlier fixed the 45-day outer limit in § 24-4.9-3-3(a), which previously ran only to “without unreasonable delay”. No amendment has revisited the monetary-consideration definition of a sale in § 24-15-2-27, the representative-summary option in § 24-15-3-1(b)(4), or the absence of any universal opt-out or rulemaking provision.
Federal Privacy Laws That Apply in Indiana
Federal privacy law applies in Indiana by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The INCDPA sits alongside those rules rather than displacing them: the Indiana Attorney General enforces the state law, while the federal regulators continue to reach the sectors and activities they cover. The state-law counterpart to section 5 is the Deceptive Consumer Sales Act (Ind. Code ch. 24-5-0.5), which the Indiana Attorney General enforces against businesses whose stated data practices differ from their actual ones.
Indiana Privacy Law FAQ
What counts as a “sale” of personal data under Indiana’s comprehensive law?
Can an Indiana controller answer an access request with a summary instead of the data?
Does Indiana require businesses to honour a universal opt-out signal?
When does an Indiana breach have to be reported, and to whom?
Why is Indiana’s breach penalty larger than its comprehensive-law penalty?
Does an Indiana court treat personal data as payment?
What does Indiana law say about retaining age-verification data?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- Ind. Code art. 24-15 — Consumer Data Protection statute
- Ind. Code art. 24-4.9 — Disclosure of Security Breach statute
- Ind. Code art. 24-4 — Regulated Businesses (ch. 14 disposal; ch. 23 age verification) statute
- Ind. Code art. 24-5 — Deceptive Consumer Sales Act statute
- Indiana Attorney General — $20 million Google location-tracking settlement agency
- Indiana Attorney General — TikTok litigation announcement and complaints agency
- State v. TikTok Inc., Ind. Ct. App. Nos. 23A-PL-3110 & 23A-PL-3111 (Sept. 30, 2024) decision
- Indiana Supreme Court order denying transfer, No. 23A-PL-03111 (June 24, 2025) decision
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.