ICDPA · Opt-out model

Indiana Privacy Law (ICDPA): Compliance Guide

The Indiana Consumer Data Protection Act took effect January 1, 2026, making Indiana one of the first states in the 2026 class of privacy laws. It tracks the familiar opt-out framework — access, delete, portability, and opt-out rights for targeted advertising and sale — keeps a majority-revenue-from-sales trigger on the lower threshold, and skips the universal opt-out signal mandate that most recent laws adopted. If you already comply with Virginia or Iowa, Indiana is a short hop.

Effective
January 1, 2026
GPC / universal opt-out
Not required
Required link text
Your Privacy Choices
Handle ICDPA compliance free

Last reviewed July 19, 2026 · Indiana Consumer Data Protection Act (ICDPA)

Applicability

Who must comply with the ICDPA

The Indiana Consumer Data Protection Act applies to businesses that meet the following criteria:

  • Controls or processes the personal data of 100,000 or more Indiana consumers, or
  • Controls or processes the personal data of 25,000 or more Indiana consumers and derives the majority of revenue from the sale of personal data

Consumer rights

What Indiana consumers can demand

  • Right to access personal data
  • Right to delete personal data
  • Right to data portability
  • Right to opt out of targeted advertising and the sale of personal data

Opt-out mechanics

Indiana opt-out & GPC requirements

Like every US state privacy law, the ICDPA uses an opt-out model: you do not need a GDPR-style cookie banner, but you must provide a clear and conspicuous opt-out link. The accepted text for Indiana is Your Privacy Choices.

Global Privacy Control: Not required

Indiana's ICDPA does not require honoring universal opt-out signals such as Global Privacy Control. The opt-out link remains the required mechanism.

Enforcement

ICDPA penalties & enforcement

  • Enforced by the Indiana Attorney General

Cure period: Our reference lists no specific cure period for Indiana; enforcement runs through the Indiana Attorney General.

State quirks

What makes Indiana different

Indiana is deliberately conventional. Its two thresholds — 100,000 consumers, or 25,000 with a majority of revenue from data sales — mirror the business-friendly state model, and it declines both the sensitive-data opt-in and the Global Privacy Control mandate that newer laws increasingly include. The main risk is timing: it only took effect January 1, 2026, so businesses that built compliance programs around the 2023–2025 wave may not have noticed Indiana arrive.

Newest class of laws

Took effect January 1, 2026 — businesses that tracked only the early states should recheck coverage now.

Majority-revenue trigger

The 25,000-consumer prong applies when a majority of revenue comes from selling personal data.

Familiar framework

Closely follows the Virginia/Iowa opt-out model, so existing state-law compliance work carries over.

Automation

How ConsentKit handles Indiana

  • ConsentKit's widget is served from Cloudflare's edge and receives the visitor's US state server-side, so Indiana visitors are identified before any consent UI renders — no client-side geo-lookup delay.
  • Indiana visitors see a persistent Your Privacy Choices link — the exact statutory text — available to new and returning visitors alike.
  • Indiana does not legally require honoring Global Privacy Control. ConsentKit applies automatic GPC honoring in the 12 states that mandate it; in Indiana the opt-out link remains the visitor's control.
  • Every opt-out is recorded server-side with a timestamp and jurisdiction metadata, reviewable and exportable (CSV) from the dashboard — the audit trail regulators ask for.
  • Google Consent Mode v2 stays in sync: analytics and advertising tags update the moment a Indiana visitor makes a choice.

Indiana's law took effect January 1, 2026 — ConsentKit's state map already includes it, so Indiana visitors have been covered from day one with no configuration change.

FAQ

Indiana ICDPA FAQ

When does Indiana's ICDPA take effect?

January 1, 2026. Businesses that waited out the earlier state laws should recheck coverage: the ICDPA applies at 100,000 Indiana consumers, or 25,000 when a majority of revenue comes from selling personal data.

Does Indiana require honoring Global Privacy Control?

No. Indiana joins Virginia, Utah, Iowa, Tennessee, Florida, Kentucky, and Rhode Island as the covered states with no universal opt-out signal mandate. The “Your Privacy Choices” opt-out link is the required mechanism.

What rights do Indiana consumers get?

Indiana consumers can access and delete their personal data, obtain a portable copy of it, and opt out of targeted advertising and the sale of their personal data.

How is the ICDPA enforced?

Enforcement runs through the Indiana Attorney General. Our reference lists no specific per-violation dollar figure or cure period for Indiana.

This guide is for informational purposes and is not legal advice. Work with qualified counsel to confirm your obligations under the ICDPA.

Comply with Indiana's ICDPA — and the other 19 state laws

ConsentKit detects each visitor's state at the Cloudflare edge, renders the exact opt-out link their law requires, honors GPC automatically where mandated, and records every choice for your audit trail.