Indiana Consumer Data Protection Act
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Indiana CDPA Consumer Rights
Indiana CDPA grants Indiana consumers six core rights subject to verifiable consumer request procedures per IC 24-15-3 and IC 24-15-4. (1) Right to Confirm + Access (IC 24-15-3-1): consumer may confirm whether or not a controller is processing the consumer personal data and access such personal data. (2) Right to Correct (IC 24-15-3-2): consumer may correct inaccuracies in the consumer personal data taking into account the nature of the personal data and the purposes of processing. (3) Right to Delete (IC 24-15-3-3): consumer may delete personal data provided by or obtained about the consumer. (4) Right to Portability (IC 24-15-3-4): consumer may obtain a copy of consumer personal data that the consumer previously provided to the controller in a portable and to the extent technically feasible readily usable format that allows the consumer to transmit the data to another controller withou
- Consumer rights portal + 6 rights operationalised + intake + verification + records
- 45-day response SLA + 45-day extension tracking + 60-day appeal response + records
- Authorised agent procedure + GPC recognition + identity verification + records
- Free of charge policy + 12-month tracking + subsequent fee + records
- Profiling opt-out + legal/similarly significant effects + decision impact assessment + records
- Consumer rights portal absent (no intake mechanism)
- 45-day SLA missed (no tracking or breach)
- Authorised agent not recognised (only direct consumer requests)
- Free of charge violated (every request charged)
- Profiling opt-out absent (no automated decision impact assessment)
Indiana CDPA Controller Obligations
Per IC 24-15-4 controllers operating subject to INCDPA must comply with five core obligations. (1) Privacy Notice (IC 24-15-4-1): controller shall provide consumers with a reasonably accessible + clear + and meaningful privacy notice that includes (a) the categories of personal data processed by the controller; (b) the purpose for processing personal data; (c) how consumers may exercise their consumer rights including how a consumer may appeal a controller decision with regard to a consumer request; (d) the categories of personal data that the controller shares with third parties if any; (e) the categories of third parties if any with which the controller shares personal data; (f) an active email address or other online mechanism that the consumer may use to contact the controller. If a controller sells personal data to third parties or processes personal data for targeted advertising th
- Privacy notice + 6 required elements + targeted ad disclosure + records + version control
- Purpose limitation + per processing activity + adequate/relevant/reasonably necessary + records
- Data minimisation procedure + new purpose assessment + consumer consent + records
- Reasonable security TOMs + Admin + Technical + Physical + volume-appropriate + records
- Non-discrimination policy + no penalty for rights exercise + records + audit
- Privacy notice missing elements (e.g. no appeal procedure)
- Purpose limitation not enforced (overbroad data collection)
- Data minimisation absent (legacy purposes never re-assessed)
- Reasonable security pro forma (no TOMs assessment)
- Discrimination claimed by consumers for exercising rights
Indiana CDPA Coord + Multi-Jurisdictional
Coordination positions INCDPA within the broader US and international privacy regulatory landscape. (1) US State Privacy Law Patchwork: 20+ comprehensive US state privacy laws as of 2026 (California CCPA/CPRA + Virginia VCDPA + Colorado CPA + Utah UCPA + Connecticut CTDPA + Iowa ICDPA + Indiana INCDPA + Tennessee TIPA + Montana MCDPA + Texas TDPSA + Oregon OCPA + Delaware DPDPA + New Jersey NJDPA + New Hampshire NHCDPA + Kentucky KCDPA + Maryland MODPA + Minnesota MNCDPA + Rhode Island RIDPCPA + Nebraska NDPA + Maine MCDPA) - common multistate compliance program addresses all - Privacy Notice template + Consumer Rights portal + DPA process + Sensitive Data inventory + Indianapolis + multi-state response timeline (45 days INCDPA-compatible) + opt-out mechanisms + GPC honour + multi-state enforcement coordination. (2) Federal Sectoral Carve-Outs: HIPAA (health) + GLBA (financial) + FCRA (c
- Multistate compliance program + 20+ state privacy laws + Privacy Notice + GPC honour + records
- Federal sectoral carve-out mapping + per data type + records + audit
- FTC Section 5 + UDAP + settlements monitoring + alignment + records
- International privacy compliance + GDPR + DPDP + LGPD + adequacy + SCCs + records
- NIST Privacy + ISO 27701 + NAI/DAA + GPC + IAB TCF + records
- Indiana-only compliance (other states ignored + multistate gaps)
- Federal sectoral overlaps unmanaged (HIPAA-covered entity unaware of INCDPA carve-out)
- FTC enforcement risk unmonitored (Section 5 + UDAP + settlements)
- International compliance fragmented (GDPR + DPDP + LGPD treated as separate)
- Standards alignment absent (no NIST Privacy + ISO 27701 + industry self-regulation)
Indiana CDPA Enforcement + Penalties
Per IC 24-15-6 + IC 24-15-7 INCDPA enforcement is exclusively vested in the Indiana Attorney General with no private right of action. (1) Attorney General Exclusive (IC 24-15-7-1): the Attorney General shall have exclusive authority to enforce a violation of this article + no private cause of action permitted (distinguishes INCDPA from California CCPA which has limited private right for breach + similar approach as Virginia + Connecticut + Texas). (2) Right to Cure (IC 24-15-7-2): before initiating any action for a violation the Attorney General shall provide a controller or processor 30 days written notice identifying the specific provisions of this article the Attorney General alleges have been or are being violated + if within the 30 day period the controller or processor cures the noticed violation and provides the Attorney General an express written statement that the alleged violat
- AG investigation cooperation procedure + production capability + records + retention
- 30-day cure procedure + express written statement + remediation + records
- Industry self-regulation membership (NAI/DAA) + records + compliance demonstration
- Civil penalty risk assessment + per violation USD 7500 + portfolio + Board awareness
- Voluntary compliance + AG informal guidance + best practices integration + records
- AG cooperation untested (would not respond timely)
- 30-day cure capability absent (would forfeit cure opportunity)
- Industry self-regulation not pursued (compliance posture isolated)
- Civil penalty not Board-level (multiple-violation exposure unmanaged)
- Voluntary compliance not used (no AG informal guidance leveraged)
Indiana CDPA Processor Contracts
Per IC 24-15-4-8 + IC 24-15-4-9 + IC 24-15-1-25 INCDPA imposes contractual requirements on the relationship between controller and processor. (1) Processor Obligations: a processor shall adhere to the instructions of a controller and shall assist the controller in meeting the controller obligations under this article + by following the directions of the controller. (2) Contract Required: a contract between a controller and a processor shall govern the processor data processing procedures with respect to processing performed on behalf of the controller. The contract shall be binding and clearly set forth: (a) instructions for processing data; (b) the nature and purpose of processing; (c) the type of data subject to processing; (d) the duration of processing; (e) the rights and obligations of both parties. (3) Confidentiality: contract shall require that the processor shall ensure that eac
- DPA in place with each processor + 5 required provisions + records + version control
- Confidentiality + personnel binding + records + audit
- Subprocessor list + approval procedure + objection rights + written contract cascade + records
- Audit rights + information provision + audit reports + at-cost + records
- End of contract + deletion or return + records + statutory retention exceptions
- No DPA with processors (or out of date)
- Confidentiality not cascaded to subprocessors
- Subprocessor approval bypassed (cloud vendors substitute without notice)
- Audit rights not exercised (clauses paper-only)
- End-of-contract deletion not enforced (data retained indefinitely)
Indiana CDPA Scope + Applicability
Indiana Consumer Data Protection Act (INCDPA) enacted as Senate Enrolled Act 5 (SEA 5) of 2023 of the Indiana General Assembly + signed by Governor Eric Holcomb on 1 May 2023 + codified at Indiana Code Title 24 Article 15 (IC 24-15). Effective date: 1 January 2026 (delayed effective date allowing controllers and processors time to prepare). Indiana 7th US state to enact comprehensive consumer data privacy law following California (CCPA 2018/CPRA 2020) + Virginia (VCDPA 2021 effective 2023) + Colorado (CPA 2021 effective 2023) + Utah (UCPA 2022 effective 2023) + Connecticut (CTDPA 2022 effective 2023) + Iowa Consumer Data Protection Act (effective 2025) - and modelled closely on Virginia CDPA template with Connecticut/Iowa influences. Applicability per IC 24-15-2-1: applies to persons that conduct business in Indiana or produce products or services that are targeted to residents of Indian
- Applicability assessment + Indiana consumer count + revenue from sale + per calendar year + records
- Exemption mapping + GLBA/HIPAA/FCRA/FERPA/COPPA + employee + B2B carve-outs + records
- Roles mapping + Controller/Processor/Consumer/Personal Data per IC 24-15 + records
- Sensitive data inventory + per defined categories + processing locations + records
- 1 January 2026 readiness + program + governance + records
- Applicability not assessed (operating without count tracking)
- Exemptions claimed without validation (e.g. HIPAA covers some but not all data)
- Roles unclear (controller vs processor not mapped at vendor level)
- Sensitive data not inventoried per INCDPA categories
- 1 January 2026 effective date missed (no readiness program)
Indiana CDPA Security + Breach + Records
Per IC 24-15-4-5 and IC 24-15-4-10 plus the separate Indiana Personal Information Disclosure Statute IC 24-4.9 (Indiana data breach notification law) controllers and processors must implement security + breach response + and records discipline. (1) Reasonable Security (IC 24-15-4-5): establish + implement + and maintain reasonable administrative + technical + and physical data security practices to protect the confidentiality + integrity + and accessibility of personal data + appropriate to the volume and nature of the personal data at issue (FTC reasonable security baseline + NIST CSF + ISO 27001). (2) Indiana Breach Notification (IC 24-4.9): separately requires controllers (database owners) holding personal information of Indiana residents (including SSN + driver license + financial account + credit card with security code + Indian ID + ITIN + biometric) to notify (a) affected Indiana
- Reasonable security TOMs + Admin/Technical/Physical + volume-appropriate + NIST/ISO alignment + records
- Indiana breach notification procedure + IC 24-4.9 + residents + AG + CRA + records
- Records of consumer rights + DPA + contracts + breach + audit + retention + records
- Encryption + key management + SDLC + EDR + pseudonymisation + records
- De-identification + attestation + public commitment + re-ID prohibition + contracts + records
- Reasonable security pro forma (no TOMs or NIST CSF alignment)
- IC 24-4.9 breach procedure not coordinated with INCDPA
- Records absent for consumer rights/DPA/contracts (audit failure risk)
- Encryption partial (e.g. at rest only, not in transit)
- De-identification claimed without attestation + public commitment
Indiana CDPA Sensitive Data + DPA
Per IC 24-15-4 and IC 24-15-5 INCDPA imposes heightened obligations for sensitive data + children + and high-risk processing activities. (1) Sensitive Data Definition: per IC 24-15-1-29 sensitive data includes (a) personal data revealing racial or ethnic origin + religious beliefs + mental or physical health diagnosis + sexual orientation + citizenship or immigration status; (b) genetic or biometric data processed for the purpose of uniquely identifying a specific natural person; (c) personal data collected from a known child (under 13 years per COPPA alignment); (d) precise geolocation data (within radius of 1750 feet). (2) Sensitive Data Consent (IC 24-15-4-7): controller shall not process sensitive data concerning a consumer without obtaining the consumer consent or in the case of the processing of sensitive data concerning a known child processing such data in accordance with the fed
- Sensitive data inventory + per category + processing activities + records
- Sensitive data consent capture + records + opt-in + audit
- Children under 13 + COPPA verifiable parental consent + records
- DPA register + per processing activity + 5 triggers + documentation + records
- DPA content + benefits/risks/safeguards + AG disclosure ready + records
- Sensitive data inventory absent (categories not mapped)
- Sensitive data processed without consent (e.g. health/biometric)
- Children under 13 processed without COPPA compliance
- DPA absent for high-risk activities (e.g. targeted advertising)
- DPA not ready for AG disclosure (informal documentation)
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Indiana Consumer Data Protection Act framework page.