Indiana — Comprehensive Law

Indiana Privacy Law

Indiana’s comprehensive statute and its older consumer-protection law point in opposite directions on the same question, and the gap between them is the most interesting thing about privacy law in the state. Article 24-15 of the Indiana Code, effective January 1, 2026, defines a “sale of personal data’’ narrowly — an exchange for monetary consideration and nothing else. Two years earlier, in litigation the Attorney General brought under the Deceptive Consumer Sales Act, the Court of Appeals held that giving up personal data in exchange for access to a content library is itself a “sale” and therefore a consumer transaction. Indiana also lets a controller answer an access request with a representative summary rather than a copy, and its breach statute carries a $150,000 penalty per deceptive act, an order of magnitude above the $7,500 the comprehensive law allows.

The Indiana Consumer Data Protection Act (INCDPA)

Added by P.L.94-2023 (Senate Bill 5) and effective January 1, 2026, article 24-15 runs to eleven chapters. Section 24-15-1-1(a) sets a two-branch threshold; § 24-15-1-1(b) removes the state and its subdivisions, financial institutions and data subject to Title V of the Gramm-Leach-Bliley Act, HIPAA covered entities and business associates, nonprofits and institutions of higher education. Two drafting choices set Indiana apart from the Virginia model it otherwise follows. Section 24-15-2-27(a) defines the “sale of personal data” as an exchange “for monetary consideration” only, so barter arrangements fall outside the opt-out. And § 24-15-3-1(b)(4) lets a controller satisfy an access request by providing either a copy of the consumer’s data or “a representative summary” of it, at the controller’s discretion, once in any twelve-month period. The article contains no rulemaking authority and no requirement that controllers recognise a universal opt-out preference signal.

Effective dateJanuary 1, 2026
CitationInd. Code art. 24-15
Enforced byIndiana Attorney General
Maximum penaltyUp to $7,500 per violation under Ind. Code § 24-15-10-2(a)
Private right of actionNo, enforcement by the state only
Right to cure30 days, with no sunset date (Ind. Code § 24-15-10-3)

Who Must Comply

The INCDPA reaches a business that conducts business in Indiana or produces products or services targeted to Indiana residents, and during a calendar year controls or processes the personal data of at least 100,000 Indiana consumers, or controls or processes the personal data of at least 25,000 Indiana consumers and derives more than 50% of gross revenue from the sale of personal data.

The access right can be answered with a representative summary rather than a copy, the definition of a sale is limited to monetary consideration, and the article grants no rulemaking authority and requires no universal opt-out signal.

Consumer Rights Under the INCDPA

Residents of Indiana can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.

Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.

Sector-Specific Privacy Laws in Indiana

Age Verification for Adult Oriented Websites (Ind. Code art. 24-4-23)

Added by P.L.98-2024, article 24-4-23 reaches a website where at least one-third of the images and videos published are material harmful to minors as described in § 35-49-2-2. Section 24-4-23-10 bars an operator from knowingly or intentionally publishing such a site without a reasonable age verification method, which § 24-4-23-7 defines as a mobile credential, an independent third-party verification service checking against commercially available databases, or another commercially reasonable method relying on public or private transactional data. The privacy provisions run the other way from the verification duty: § 24-4-23-13(b) bars the operator and any third-party verification service it uses from retaining the identifying information of a person seeking access unless a court order requires retention, and gives an individual whose information is retained a claim for actual damages or up to $5,000, injunctive relief, costs, fees and expert witness fees. Section 24-4-23-11 gives a parent or guardian a parallel claim on the same terms where a minor accessed the site. Section 24-4-23-15 allows the Attorney General to seek an injunction, investigative costs and a civil penalty of up to $250,000, and § 24-4-23-16 supplies civil investigative demand power under § 4-6-3-3. Section 24-4-23-17 requires a minor’s verification information in any such action to be sealed in a confidential envelope in the court file.

Persons Holding a Customer’s Personal Information (Ind. Code ch. 24-4-14)

Chapter 24-4-14 governs disposal rather than collection. Section 24-4-14-8 makes it a Class C infraction to dispose of a customer’s unencrypted, unredacted personal information without shredding, incinerating, mutilating, erasing or otherwise rendering it illegible or unusable, and raises the offense to a Class A infraction where more than 100 customers’ information is involved or where the person has a prior unrelated judgment under the section. Section 24-4-14-3 defines “dispose of” to include placing the information in a container for trash collection, which is what gives the chapter its practical reach. Section 24-4-14-2 defines “customer” broadly enough to include a person who provided information in a transaction with a nonprofit corporation or charitable organization. Section 24-4-14-1 excludes state and local government offices, waste collectors except as to information they hold directly, and persons maintaining a disposal program under the USA PATRIOT Act, Executive Order 13224, the Driver’s Privacy Protection Act, the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act or HIPAA. A parallel duty sits in the breach article: § 24-4.9-3-3.5(c) and (d) require reasonable safeguards and the same disposal practice, enforceable by the Attorney General alone at up to $5,000 per deceptive act.

Deceptive Consumer Sales Act (Ind. Code ch. 24-5-0.5)

The Deceptive Consumer Sales Act is Indiana’s general unfair-practices statute and the vehicle for the state’s largest privacy recoveries. Section 24-5-0.5-2(a)(1) defines a “consumer transaction” as a sale, lease, assignment, award by chance or other disposition of personal property, real property, a service or an intangible, for primarily personal, familial, charitable, agricultural or household purposes. Section 24-5-0.5-1 directs that the chapter be liberally construed. Section 24-5-0.5-4(a) gives a consumer relying on an uncured or incurable deceptive act actual damages or $500, whichever is greater, with treble damages or $1,000 available for a willful act; § 24-5-0.5-4(c) lets the Attorney General seek an injunction and restitution; § 24-5-0.5-4(f) sets a civil penalty of up to $15,000 per violation of such an injunction; and § 24-5-0.5-8 adds a fine of up to $500 for each incurable deceptive act, recoverable only by the Attorney General.

Data Breach Notification in Indiana

Article 24-4.9 of the Indiana Code is triggered by risk rather than by exposure alone. Section 24-4.9-3-1(a) requires a database owner to disclose a breach to an affected Indiana resident where the owner “knows, should know, or should have known” that the unauthorized acquisition has resulted in or could result in identity deception, identity theft or fraud. Section 24-4.9-3-1(c) then attaches Attorney General notice to that disclosure with no threshold of its own: if the resident is notified, the Attorney General is notified. Section 24-4.9-3-1(b) adds notice to every nationwide consumer reporting agency once more than 1,000 consumers are involved. The clock in § 24-4.9-3-3(a) is 45 days from discovery, with delay treated as reasonable only where it is necessary to restore system integrity, to determine the scope of the breach, or where the Attorney General or a law enforcement agency has asked for delay. Section 24-4.9-2-10 counts a Social Security number on its own, and a name with a driver’s license number, state identification card number, credit card number, or financial account or debit card number with its access code; P.L.98-2024 added information collected by an adult oriented website operator under article 24-4-23. Substitute notice becomes available under § 24-4.9-3-4(b) above 500,000 residents or $250,000 in cost. Penalties are unusually high for a breach statute: § 24-4.9-4-2 allows an injunction, the Attorney General’s investigative costs, and a civil penalty of up to $150,000 per deceptive act, with a related series of breaches counted as one act under § 24-4.9-4-1(b).

Residents must be notified without unreasonable delay and not more than 45 days after discovery of the breach. Notify the Attorney General whenever notice is given to any Indiana resident — no headcount threshold. Complaints are taken by the Indiana Attorney General, which enforces the statute.

Recent Enforcement in Indiana

Google location tracking — $20 million Indiana settlement, December 2022. The Attorney General’s office announced on December 29, 2022 that it had settled Indiana’s separate suit against Google over location tracking for $20 million. The office states that it filed an independent action rather than joining the multistate negotiation, and that Indiana consequently received “approximately twice as much money as it would have received” under the settlement later reached by the forty states that did not sue. The release describes the underlying allegation as deception since at least 2014 about how location data was collected and used to build user profiles and target advertising, and notes that the investigations followed 2018 Associated Press reporting. The settlement agreement is published with the release.

State v. TikTok Inc. — personal data held to be the price of a consumer transaction. The Attorney General filed two suits against TikTok, ByteDance and affiliated entities in Allen Superior Court in December 2022 under the Deceptive Consumer Sales Act, one concerning the app’s content rating and one concerning representations about access to user data. The trial court dismissed both for want of specific personal jurisdiction and for failure to state a claim. In consolidated opinions issued September 30, 2024 in Court of Appeals cause numbers 23A-PL-3110 and 23A-PL-3111, the Court of Appeals reversed. On the question that matters most for privacy claims, the court rejected the argument that a consumer transaction requires an exchange for money: the statutory definition “does not include the words ‘exchange for money’”, and the ordinary and legal meanings of “sale” reach “any consideration to effectuate the transfer of property”. Because TikTok “exchanges access to its app’s content library for end-user personal data”, the court held that its business model is a consumer transaction under the Act. The Indiana Supreme Court denied transfer on June 24, 2025, with Justices Slaughter and Goff voting to grant.

Pending Privacy Legislation

Indiana’s recent privacy output has come through the Deceptive Consumer Sales Act and the age-verification article rather than through amendments to article 24-15, which took effect January 1, 2026 in the form enacted by P.L.94-2023 without intervening substantive change. P.L.98-2024 added article 24-4-23 and, in the same act, extended the breach statute’s definition of personal information at § 24-4.9-2-10(3) to information collected by an adult oriented website operator. P.L.171-2022 had earlier fixed the 45-day outer limit in § 24-4.9-3-3(a), which previously ran only to “without unreasonable delay”. No amendment has revisited the monetary-consideration definition of a sale in § 24-15-2-27, the representative-summary option in § 24-15-3-1(b)(4), or the absence of any universal opt-out or rulemaking provision.

Federal Privacy Laws That Apply in Indiana

Federal privacy law applies in Indiana by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The INCDPA sits alongside those rules rather than displacing them: the Indiana Attorney General enforces the state law, while the federal regulators continue to reach the sectors and activities they cover. The state-law counterpart to section 5 is the Deceptive Consumer Sales Act (Ind. Code ch. 24-5-0.5), which the Indiana Attorney General enforces against businesses whose stated data practices differ from their actual ones.

Indiana Privacy Law FAQ

What counts as a “sale” of personal data under Indiana’s comprehensive law?
Only an exchange for money. Section 24-15-2-27(a) defines the sale of personal data as the exchange of personal data “for monetary consideration” by a controller to a third party, and subsection (b) excludes disclosures to a processor, disclosures made to provide a product or service the consumer or a child’s parent requested, and several other transfers. Indiana did not adopt the broader “monetary or other valuable consideration” formula used in Connecticut, Oregon and Montana.
Can an Indiana controller answer an access request with a summary instead of the data?
Section 24-15-3-1(b)(4) gives the controller that choice. The consumer may obtain either a copy of, or “a representative summary of”, the personal data the consumer previously provided, and the section states that the controller “has the discretion to send either”, taking into account the nature of the data and the purposes of processing. The same subdivision limits the obligation to once in any twelve-month period.
Does Indiana require businesses to honour a universal opt-out signal?
Article 24-15 contains no such requirement. The opt-out right in § 24-15-3-1(b)(5) is exercised by a request submitted to the controller, and nothing in the article refers to an opt-out preference signal, a browser setting or a global device mechanism of the kind Connecticut, Delaware, Montana, New Hampshire and Oregon each addressed by statute. The article also confers no rulemaking authority on the Attorney General or any other agency.
When does an Indiana breach have to be reported, and to whom?
Section 24-4.9-3-3(a) sets 45 days from discovery as the outer limit, subject to delay that is necessary to restore the integrity of the system, to determine the scope of the breach, or that the Attorney General or a law enforcement agency has requested. Notice to residents is owed under § 24-4.9-3-1(a) where the database owner knows or should know that the acquisition has resulted in or could result in identity deception, identity theft or fraud. Section 24-4.9-3-1(c) requires notice to the Attorney General whenever that resident notice is given, without any headcount threshold, and § 24-4.9-3-1(b) adds the nationwide consumer reporting agencies above 1,000 consumers.
Why is Indiana’s breach penalty larger than its comprehensive-law penalty?
They come from different statutes written eighteen years apart. Section 24-4.9-4-2 allows the Attorney General to recover a civil penalty of not more than $150,000 per deceptive act for a failure to disclose, alongside an injunction and investigative costs, while § 24-15-10-2(a) caps a violation of the comprehensive article at $7,500. Section 24-4.9-4-1(b) limits the multiplier by providing that a failure to notify across a related series of breaches counts as a single deceptive act.
Does an Indiana court treat personal data as payment?
In State v. TikTok Inc., Court of Appeals cause numbers 23A-PL-3110 and 23A-PL-3111 (September 30, 2024), it did for purposes of the Deceptive Consumer Sales Act. The court held that the plain and ordinary meaning of “sale” includes “any consideration to effectuate the transfer of property, not only an exchange for money”, and concluded that exchanging access to a content library for end-user personal data is a consumer transaction under the Act. The Indiana Supreme Court denied transfer on June 24, 2025. The comprehensive article’s own definition of a sale, at § 24-15-2-27(a), remains limited to monetary consideration.
What does Indiana law say about retaining age-verification data?
Section 24-4-23-13(b) prohibits it. A person using or purporting to use a reasonable age verification method to grant or deny access to an adult oriented website, and any third-party verification service it uses, may not retain the identifying information of the person seeking access unless retention is required by a court order. Subsection (c) gives the individual whose information was retained a claim for actual damages or up to $5,000, injunctive relief, court costs, reasonable attorney’s fees and expert witness fees.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.