Indiana's Consumer Data Protection Act: What Lafayette-Area Businesses Need to Know
Indiana's ICDPA took effect January 1, 2026. Who it actually covers, what it requires, and what to do if you are under the threshold but customers still ask.
Indiana’s Consumer Data Protection Act (ICDPA, IC 24-15) took effect on January 1, 2026. It gives Indiana residents a set of privacy rights and puts matching obligations on the businesses that handle their data.
Here is the part most coverage buries: the majority of Lafayette-area small businesses are not covered by it. The thresholds are high. That does not mean you can ignore it — your customers, your insurer, and your contracts increasingly will not care where the statutory line sits — but it does mean you should know which side of the line you are on before you spend money.
Who it actually applies to
The ICDPA applies to a person who conducts business in Indiana, or targets products or services to Indiana residents, and who during a calendar year either:
- controls or processes the personal data of 100,000 or more Indiana consumers, or
- controls or processes the personal data of 25,000 or more Indiana consumers and derives more than 50% of gross revenue from the sale of personal data.
Those are per-year, Indiana-resident counts. A local accounting firm, clinic, or 30-person SaaS company is very unlikely to clear either bar.
“Consumer” also means an Indiana resident acting in an individual or household context. People acting in a commercial or employment context are excluded, so your B2B contact records and your own employee records generally do not count toward the threshold.
Exemptions
Indiana exempts entities as well as data, which is broader than several other state laws. Exempt entities include:
- HIPAA covered entities and business associates
- Financial institutions and data subject to the Gramm-Leach-Bliley Act
- Nonprofit organizations
- Institutions of higher education
- State and local government bodies, and certain public utilities
There are also data-level carve-outs for HIPAA, FCRA, FERPA, and Driver’s Privacy Protection Act data, plus specified employment and job-application data.
If you are a Lafayette medical practice, a credit union, or a nonprofit, read those exemptions carefully — you may be out of scope entirely, or out of scope for the data that matters most.
What it requires if you are covered
Publish a real privacy notice. It has to disclose the categories of personal data you process, your purposes, the categories you share with third parties, the categories of those third parties, and how consumers exercise their rights — including opting out of sale or targeted advertising.
Honor consumer rights on a clock. Consumers can confirm processing and access their data, correct inaccuracies, delete data, obtain a portable copy of data they provided, and opt out of targeted advertising, sale of personal data, and certain profiling. You have 45 days to respond, extendable once by another 45 days with notice.
Run an appeals process. If you refuse a request, the consumer can appeal, and you must respond to the appeal within 60 days — and tell them how to complain to the Attorney General.
Do data protection assessments. Required for targeted advertising, selling personal data, certain profiling, processing sensitive data, and any processing that presents a heightened risk of harm.
Get processor contracts in place. Your vendors need binding contracts covering the nature and purpose of processing, your instructions, and each side’s obligations.
Minimize. Limit collection to what is adequate, relevant, and reasonably necessary for the disclosed purpose.
Two Indiana-specific wrinkles worth knowing
You may answer an access request with a “representative summary.” Under IC 24-15-3-1(b)(4) a controller can provide either a copy of the personal data or a representative summary of it. Most state privacy laws require the copy. This meaningfully lowers the cost of building a request workflow — and it is easy to miss if you are working from a generic multi-state template.
Universal opt-out signals are not mandatory. Indiana does not require controllers to honor browser-level signals such as Global Privacy Control. Colorado, Connecticut, California and others do. If a vendor is selling you a GPC-honoring feature as an Indiana requirement, it isn’t one. It may still be a reasonable thing to do; it is not the law here.
Enforcement
Enforcement sits exclusively with the Indiana Attorney General. There is no private right of action — no consumer can sue you directly under this statute.
Before the AG can act, you get a 30-day written notice identifying the provisions allegedly violated and a 30-day window to cure. Unlike most states, Indiana’s cure period is permanent — it does not sunset. If you cure and provide written notice of the cure, the matter ends there.
If you do not cure, civil penalties run up to $7,500 per violation, and the AG can recover reasonable expenses including attorney’s fees.
If you are under the threshold — and most of you are
Being out of scope statutorily does not put you out of scope commercially. In practice, three things still reach you:
- Customer and partner security reviews. Vendor questionnaires ask about privacy notices, data retention, subprocessors, and deletion. “The statute doesn’t cover us” is not an answer that closes a deal.
- Contract terms. Data protection addenda increasingly flow down obligations regardless of statutory thresholds.
- Other laws that do cover you. HIPAA, GLBA, FERPA, PCI DSS, and Indiana’s breach notification statute apply on their own terms.
The proportionate move for a small organization is not an ICDPA compliance program. It is a short list of things that are cheap now and expensive later:
- Know what personal data you hold, where it lives, and who else touches it
- Publish a privacy notice that is actually true
- Write down a retention period and follow it
- Have a named person who handles a data request or a breach
- Keep a current list of vendors that process personal data on your behalf
That list is defensible to a customer, an insurer, and an auditor, and it is the foundation you would build on if you ever do cross a statutory threshold.
How SC2 can help
Most of this work is scoping, not lawyering. Our Security & Privacy Baseline engagement covers the data inventory, the gap read against ICDPA obligations, and a prioritized roadmap — and tells you plainly whether you are in scope. Where ongoing support makes sense, vCISO Essentials carries the privacy notice, retention policy, and request-handling work alongside the rest of the security program. If the pressure is coming from a customer rather than a regulator, Compliance & Customer Assurance is the right shape.
SC2 is a security and privacy consulting practice, not a law firm. Nothing here is legal advice. For a binding read on whether the ICDPA applies to your organization, talk to Indiana counsel — and we are happy to work alongside them.
Sources and further reading
- IC 24-15 — Consumer Data Protection (Indiana General Assembly) — the statute itself
- IC 24-15-1-1 — Applicability to persons; exceptions
- IC 24-15-1-2 — Exempt information and data
- Indiana privacy law to take effect January 1, 2026 (Hunton)
- Indiana Data Protection Act: what businesses need to know (Akin)
- Indiana Consumer Data Protection Act overview (Privacy Rights Clearinghouse)
- Indiana Attorney General — Consumer Protection Division
Not sure which side of the threshold you are on? Email [email protected] with a short note about your organization — we help Lafayette-area businesses build practical, proportionate privacy programs.