Indiana's Privacy Law Looks Like Virginia's — But Don't Assume It's Identical
Indiana's comprehensive privacy law went live on January 1, 2026, joining a wave of eight states whose laws activated that same day. If you've already looked into Virginia's or Colorado's privacy rules, Indiana's will feel familiar. That familiarity is real, but it's not identical, and the differences matter.
Who Has to Comply
The Indiana Consumer Data Protection Act applies to businesses that conduct business in Indiana or target Indiana residents and, during a calendar year, either control or process the personal data of 100,000 or more Indiana consumers, or control or process the data of 25,000 or more consumers while deriving over 50% of gross revenue from selling personal data.
There's no revenue threshold on its own. A business could have modest revenue and still trigger this law purely through consumer volume, or have substantial revenue and stay outside its scope if consumer numbers stay low.
What Rights Indiana Actually Grants
Indiana residents get five rights under this law: access, correction, deletion, obtaining a portable copy of their data, and opting out of targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects. That's a fuller set than some newer state laws, and notably includes the right to correction, which not every state's law provides.
Sensitive data, health information, biometric data, precise geolocation, and similar categories, requires opt-in consent before processing, matching the stricter standard used in California, Virginia, and Colorado rather than a lighter notice-and-opt-out approach.
A Cure Period That Doesn't Expire
Indiana gives businesses a 30-day window to fix a violation before the Attorney General pursues enforcement. What's unusual is that this cure period is permanent. Many states built their cure periods with sunset dates, meaning the grace period disappears after a set number of years. Indiana's doesn't. That's one of the clearer signals that this law was written with an eye toward giving businesses room to correct mistakes rather than penalizing first offenses.
Enforcement Is Complaint-Driven, For Now
Attorney General Todd Rokita's office has stated that enforcement will primarily be complaint-driven through the AG's consumer complaint portal, supplemented by the office's own independent reviews. Ahead of the law's effective date, the AG's office also published a Consumer Bill of Rights, which doubles as a useful compliance reference for businesses trying to understand exactly what's expected of them.
Civil penalties can reach $7,500 per violation. There's no private right of action, meaning individual consumers can't bring their own lawsuits under this law directly.
One Detail Worth Double-Checking If You Operate in Multiple States
If your business also has any obligations tied to Virginia, Colorado, Connecticut, Texas, or California, it's worth having your privacy counsel look at how those overlap with Indiana's requirements rather than assuming full alignment. The frameworks are similar enough to create a false sense of "we're already covered," but small differences, like Indiana's inclusion of correction rights or its specific consumer-count thresholds, can leave gaps if you're relying purely on another state's compliance program.
Check Your Indiana Exposure
All information in this article is sourced from Indiana Code Title 24, Article 15, the Indiana Attorney General's published Consumer Bill of Rights, and independent legal analysis from Hunton Andrews Kurth and Privacy Rights Clearinghouse. Regulens is informational only and this article is not legal advice. Speak to a licensed privacy attorney about your specific compliance situation.
Regulens tracks Indiana as part of its ongoing state-by-state privacy coverage. Your store's readiness is calculated based on your actual inputs and current policy documents.
Free to check, takes three minutes, no credit card needed. Not legal advice. Informational only.
Further Reading
Does Your Store Need to Detect a Browser Signal? A State-by-State Guide
Some states require your store to automatically recognize a consumer's opt-out preference through their browser settings, with no click required on your site at all. Here's exactly which states require it.
Four More States Are About to Get Privacy Laws — Here's Your Advance Notice
Alabama, Oklahoma, Louisiana, and Vermont have all signed comprehensive privacy laws into effect between 2027 and 2028. None are enforceable yet, but each is worth understanding well before its clock starts.