close
close
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Indiana Privacy Law

IN

Indiana (ICDPA)

Last updated

ICDPA Enacted, in effect

Who this affects: This page tracks Indiana’s ICDPA, which governs controllers and processors.

Who it applies to: Entities that do business in Indiana or target its residents, and meet: 100,000+ consumers, or 25,000+ consumers and more than 50% of gross revenue from selling data.

Content on this page is not legal advice This page aggregates publicly cited regulatory facts for informational purposes only. It is not legal advice, and DataGrail is not responsible for decisions made in reliance on it. Consult qualified counsel for your specific compliance obligations.
Jan 1, 2026
Effective ↗
Attorney General
Enforced by ↗
$7,500
Maximum penalty per violation ↗
None
Private right of action ↗

The law, in plain English

Must · Can’t · Should

ICDPA, distilled to what actually changes your week. Read one column to know your floor, your hard limits, and the further obligations and good practices worth planning for.

Must

  • Respond to authenticated rights requests within 45 days and tell consumers of any extension and its reason in that window. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. IN-24-15-3-1 “a controller shall comply with an authenticated consumer request to exercise a right set forth” Read the statute IN-24-15-3-1 “A controller shall respond to the consumer without undue delay, but in any case not later than forty-five (45) days after receipt of the consumer's request under this section.” Read the statute IN-24-15-3-1 “consumer of any such extension within the initial forty-five (45) day response period, along with the reason for the extension” Read the statute
  • Give a clear, accessible privacy notice and, if you sell data or run targeted ads, disclose it and how to opt out. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. IN-24-15-4-3 “A controller shall provide consumers with a reasonably accessible, clear, and meaningful privacy notice that includes” Read the statute IN-24-15-4-4 “the controller shall clearly and conspicuously disclose such activity, as well as the manner in which a consumer may exercise the right to opt out of such sales or use” Read the statute IN-24-15-3-1 “the sale of personal data; or” Read the statute IN-24-15-3-1 “targeted advertising;” Read the statute
  • Bind each processor by contract setting out instructions, purpose, data type, duration, and both parties' rights and obligations. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. IN-24-15-5-2 “A contract between a controller and a processor shall govern the processor's data processing procedures with respect to processing performed on behalf of the controller. The contract must be binding and clearly set forth instructions for processing personal data, the nature and purpose of processing, the type of data subject to processing, the duration of processing, and the rights and obligations of both parties.” Read the statute

Can't

  • Process sensitive data without consumer consent, or a known child's sensitive data other than in accordance with COPPA. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. IN-24-15-4-1 “A controller shall not process sensitive data concerning a consumer without obtaining the consumer's consent, or, in the case of the processing of sensitive data concerning a known child, without processing such data in accordance with the federal Children's Online Privacy Protection Act (15 U.S.C. 6501 et seq.)” Read the statute
  • Discriminate against consumers for exercising rights, apart from offers tied to an opt-out or a bona fide loyalty program. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. IN-24-15-4-1 “A controller shall not discriminate against a consumer for exercising any of the consumer rights set forth in this article, including by denying goods or services to the consumer, charging different prices or rates for goods and services, or providing a different level or quality of goods or services to the consumer. However, nothing in this subdivision shall be construed to: (A) require a controller to provide a product or service that requires the personal data of a consumer that the controller does not collect or maintain; or (B) prohibit a controller from offering a different price, rate, level, quality, or selection of goods or services to a consumer, including offering goods or services for no fee, if the consumer has exercised the consumer's right to opt out under IC 24-15-3-1(b)(5) or if the offer is related to a consumer's voluntary participation in a bona fide loyalty, rewards, premium features, discount, or club card program” Read the statute
  • Require a new account to exercise rights, or rely on any contract term that waives or limits consumer rights, which is void. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. IN-24-15-4-5 “A controller may not require a consumer to create a new account in order to exercise the consumer's rights under IC 24-15-3” Read the statute IN-24-15-4-2 “Any provision of a contract or agreement of any kind that purports to waive or limit in any way a consumer's rights under IC 24-15-3 is contrary to public policy and is void and unenforceable.” Read the statute

Should

  • When declining a request, explain why and give appeal instructions within 45 days; answer appeals in writing within 60 days. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. IN-24-15-3-1 “the controller shall inform the consumer without undue delay, but in any case not later than forty-five (45) days after receipt of the consumer's request under this section, of the justification for declining to take action, and shall provide instructions for how to appeal the decision” Read the statute IN-24-15-3-1 “Not later than sixty (60) days after receipt of an appeal, a controller shall inform the consumer in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions” Read the statute
  • Check data uses against disclosed purposes; get consent before uses neither reasonably necessary for nor compatible with them. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. IN-24-15-4-1 “a controller shall not process personal data for purposes that are neither reasonably necessary for nor compatible with the disclosed purposes for which the personal data is processed, unless the controller obtains the consumer's consent” Read the statute
  • Require processors to share compliance info on request, cooperate with reasonable assessments, and provide assessment reports. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. IN-24-15-5-2 “Upon the reasonable request of the controller, make available to the controller all information in its possession necessary to demonstrate the processor's compliance with the obligations in this chapter” Read the statute IN-24-15-5-2 “Allow, and cooperate with, reasonable assessments by the controller or the controller's designated assessor” Read the statute IN-24-15-5-2 “The processor shall provide a report of any such assessment to the controller upon request” Read the statute

These are the highlights we judge most important, not everything ICDPA requires. The comprehensive law section below covers the full detail, fact by fact, with the statutory text behind every one.

The comprehensive law

Indiana Consumer Data Protection Act

ICDPA (SB 5) is Indiana’s comprehensive privacy law. Every fact was extracted from the primary statute by the DataGrail regulation engine and is grounded to the cited source. Scan the facts; the exact statutory text sits one click away on each source link.

Status
Enacted, in effect
P.L.94-2023 (SEA 5) § 1 (enacting clause) Archived excerpt — the text we read SECTION 1. IC 24-15 IS ADDED TO THE INDIANA CODE AS A NEW ARTICLE TO READ AS FOLLOWS [EFFECTIVE JANUARY 1, 2026]: ARTICLE 15. CONSUMER DATA PROTECTION Archived from source — captured 2026-08-17 · snapshot da721964 Verify at the source
Effective
January 1, 2026
P.L.94-2023 (SEA 5) § 1 (enacting clause) Archived excerpt — the text we read SECTION 1. IC 24-15 IS ADDED TO THE INDIANA CODE AS A NEW ARTICLE TO READ AS FOLLOWS [EFFECTIVE JANUARY 1, 2026]: ARTICLE 15. CONSUMER DATA PROTECTION Archived from source — captured 2026-08-17 · snapshot da721964 Verify at the source

Corroborated by Privacy-law tracker

Signed
May 1, 2023
“[S.5. Approved May 1, 2023.]” View the source
Enforced by
Attorney General
Archived excerpt — the text we read IC 24-15-10-1 Attorney general's exclusive enforcement authority Sec. 1. The attorney general has exclusive authority to enforce the provisions of this article. As added by P.L.94-2023, SEC.1. Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
Maximum penalty per violation
$7,500
The AG may also recover investigation costs and attorney's fees. “a civil penalty not to exceed seven thousand five hundred dollars ($7,500) for each violation under this article” View the statute
Right to cure
30 days
Archived excerpt — the text we read IC 24-15-10-3 Notice of alleged violation; controller's or processor's right to cure Sec. 3. (a) Before initiating an action under section 2 of this chapter, the attorney general shall provide a controller or processor thirty (30) days written notice identifying the specific provisions of this article that the attorney general alleges have been or are being violated. If within the thirty (30) day period set forth in this section, the controller or processor: (1) cures the alleged violation; and (2) provides the attorney general an express written statement that: (A) the alleged violation has been cured; and (B) actions have been taken to ensure no further such violations will occur; the attorney general shall not initiate an action against the controller or processor. (b) If a controller or processor: (1) continues the alleged violation following the thirty (30) day period set forth in subsection (a); or (2) breaches an express written statement provided to the attorney general unde… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
Private right of action
No private right of action.
Archived excerpt — the text we read IC 24-15-10-4 No private right of action for violation Sec. 4. Nothing in this article shall be construed as providing the basis for a private right of action for violations of this article or any other law. As added by P.L.94-2023, SEC.1. Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source

Corroborated by Privacy-law tracker

Universal opt-out signal
Not required

Corroborated by Privacy-law tracker

Who it applies to

Entities that do business in Indiana or target its residents, and meet: 100,000+ consumers, or 25,000+ consumers and more than 50% of gross revenue from selling data

What the law gives consumers

  • Right to access Archived excerpt — the text we read …itations or conditions set forth in subsections (b) and (c), a controller shall comply with an authenticated consumer request to exercise a right set forth in subsection (b). (b) A consumer has the following rights: (1) To confirm whether or not a controller is processing the consumer's personal data and, subject to the limitations set forth in subdivision (4), to access such personal data. (2) To correct inaccuracies in the consumer's personal data that the consumer previously provided to a controller, taking into account the nature of the personal data and the purposes of the processing of the consumer's… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Right to correct (limited) Only data the consumer previously provided to the controller. Archived excerpt — the text we read … A consumer has the following rights: (1) To confirm whether or not a controller is processing the consumer's personal data and, subject to the limitations set forth in subdivision (4), to access such personal data. (2) To correct inaccuracies in the consumer's personal data that the consumer previously provided to a controller, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data. Upon receiving a request from a consumer under this subdivision, a controller shall correct inaccurate information as requested by the consumer, taking into account the nature of the personal data and the purposes of t… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Right to delete Archived excerpt — the text we read …is subdivision, a controller shall correct inaccurate information as requested by the consumer, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data. (3) To delete personal data provided by or obtained about the consumer. (4) To obtain either: (A) a copy of; or (B) a representative summary of; the consumer's personal data that the consumer previously provided to the controller. Information provided to a consumer under this subdivision mu… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Right to data portability Archived excerpt — the text we read …uested by the consumer, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data. (3) To delete personal data provided by or obtained about the consumer. (4) To obtain either: (A) a copy of; or (B) a representative summary of; the consumer's personal data that the consumer previously provided to the controller. Information provided to a consumer under this subdivision must be in a portable and, to the extent technically practicable, readily usable format that allows the consumer to transmit the data or summary to another controller without hindrance, in any case in which the processing is carried out by automated means. The controller has the discretion to send either a copy or a representative summary of the consumer's personal data under this subdivision, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data. A controller is not required to provide a copy or a representative summary of a consumer's personal data to the same consumer under this subdivision more than one (1) time in a twelve (12) month period. (5) To opt out of the processing of the consumer's personal data for purposes of: (A) targeted advertising; (B) the sale of personal data; or (C) profiling in furtherance of decisions that produce legal or similarly sig… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Right to opt out of sale Archived excerpt — the text we read …onal data to the same consumer under this subdivision more than one (1) time in a twelve (12) month period. (5) To opt out of the processing of the consumer's personal data for purposes of: (A) targeted advertising; (B) the sale of personal data; or (C) profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer. (c) Except as otherwise provided in this article, a controller shall comply with a request by a cons… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Right to opt out of targeted advertising Archived excerpt — the text we read …mmary of a consumer's personal data to the same consumer under this subdivision more than one (1) time in a twelve (12) month period. (5) To opt out of the processing of the consumer's personal data for purposes of: (A) targeted advertising; (B) the sale of personal data; or (C) profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer. (c) Except as otherwise provided in this article, a controller sha… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Right to opt out of profiling for significant decisions Archived excerpt — the text we read …er this subdivision more than one (1) time in a twelve (12) month period. (5) To opt out of the processing of the consumer's personal data for purposes of: (A) targeted advertising; (B) the sale of personal data; or (C) profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer. (c) Except as otherwise provided in this article, a controller shall comply with a request by a consumer to exercise a consumer right set forth in subsection (b) as follows: (1) A controller shall respond to the consum… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Sensitive data: opt-in consent required Archived excerpt — the text we read …xercised the consumer's right to opt out under IC 24-15-3-1(b)(5) or if the offer is related to a consumer's voluntary participation in a bona fide loyalty, rewards, premium features, discount, or club card program. (5) A controller shall not process sensitive data concerning a consumer without obtaining the consumer's consent, or, in the case of the processing of sensitive data concerning a known child, without processing such data in accordance with the federal Children's Online Privacy Protection Act (15 U.S.C. 6501 et seq.). As added by P… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Right to appeal Archived excerpt — the text we read …tion; and (ii) the minimum data necessary to ensure that the consumer's personal data remains deleted from the controller's records; and (B) does not use the data retained under clause (A)(ii) for any other purpose. (d) A controller shall establish a process for a consumer to appeal, within a reasonable period of time after the consumer's receipt of a decision by the controller under subsection (c)(2), the controller's refusal to take action on a request by the consumer under this section. The appeal process shall be conspicuously available and similar to the process for submitting requests to invoke a right under this section. Not later than sixty (60) days after receipt of an appeal, a controller shall … Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Right against discrimination Archived excerpt — the text we read …ust be appropriate to the volume and nature of the personal data at issue. (4) A controller shall not process personal data in violation of state and federal laws that prohibit unlawful discrimination against consumers. A controller shall not discriminate against a consumer for exercising any of the consumer rights set forth in this article, including by denying goods or services to the consumer, charging different prices or rates for goods and services, or providing a different level or quality of goods or services to the consumer. However, nothing in thi… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Not granted: Private right of action Archived excerpt — the text we read IC 24-15-10-4 No private right of action for violation Sec. 4. Nothing in this article shall be construed as providing the basis for a private right of action for violations of this article or any other law. As added by P.L.94-2023, SEC.1. Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source

Who the law governs

  • Controllers Archived excerpt — the text we read IC 24-15-2-9 "Controller" Sec. 9. "Controller" means a person that, alone or jointly with others, determines the purpose and means of processing personal data. As added by P.L.94-2023, SEC.1. Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Processors Archived excerpt — the text we read IC 24-15-2-22 "Processor" Sec. 22. "Processor" means a person that processes personal data on behalf of a controller. As added by P.L.94-2023, SEC.1. Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source

Exemptions

  • State and local government Archived excerpt — the text we read …0) consumers who are Indiana residents and derives more than fifty percent (50%) of gross revenue from the sale of personal data. (b) This article does not apply to any of the following: (1) Either of the following: (A) The state, a state agency, or a body, authority, board, bureau, commission, district, or agency of any political subdivision of the state. (B) A third party under contract with an entity described in clause (A), when acting on behalf of the entity. This clause does not exempt data held or created by third parties outside of the scope of the contract with t… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Third parties under contract with state/local government Only when acting on the government entity's behalf. Data held or created outside the scope of the contract is not exempt. Archived excerpt — the text we read …cle does not apply to any of the following: (1) Either of the following: (A) The state, a state agency, or a body, authority, board, bureau, commission, district, or agency of any political subdivision of the state. (B) A third party under contract with an entity described in clause (A), when acting on behalf of the entity. This clause does not exempt data held or created by third parties outside of the scope of the contract with the entity. (2) Any financial institutions and affiliates, or data subject to Title V of the federal Gramm-Leach-Bliley Act (15 U.S.C. 6801 et seq.). (3) Any covered entity or business associate governed by the privacy, security, a… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • GLBA: financial institutions, their affiliates, and data subject to Title V Entity- and data-level Archived excerpt — the text we read …rty under contract with an entity described in clause (A), when acting on behalf of the entity. This clause does not exempt data held or created by third parties outside of the scope of the contract with the entity. (2) Any financial institutions and affiliates, or data subject to Title V of the federal Gramm-Leach-Bliley Act (15 U.S.C. 6801 et seq.). (3) Any covered entity or business associate governed by the privacy, security, and breach notification rules issued by the United States Department of Health and Human Services (45 CFR Parts 160 and 164) pursuant to HI… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • HIPAA covered entities and business associates Archived excerpt — the text we read …reated by third parties outside of the scope of the contract with the entity. (2) Any financial institutions and affiliates, or data subject to Title V of the federal Gramm-Leach-Bliley Act (15 U.S.C. 6801 et seq.). (3) Any covered entity or business associate governed by the privacy, security, and breach notification rules issued by the United States Department of Health and Human Services (45 CFR Parts 160 and 164) pursuant to HIPAA. (4) Any nonprofit organization. (5) Any institution of higher education. (6) Any public utility (as defined in IC 8-1-2-1(a)) or service company affiliated with a public utility (as defined in IC 8-1-2-1(a)). For purpos… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Nonprofits exempt under IRC 501(c)(3), (6) or (12) Other nonprofits are not exempt as nonprofits. IC 24-15-2-18. Archived excerpt — the text we read …covered entity or business associate governed by the privacy, security, and breach notification rules issued by the United States Department of Health and Human Services (45 CFR Parts 160 and 164) pursuant to HIPAA. (4) Any nonprofit organization. (5) Any institution of higher education. (6) Any public utility (as defined in IC 8-1-2-1(a)) or service company affiliated with a public utility (as defined in IC 8-1-2-1(a)). For purposes of this subdivision, "service… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Institutions of higher education Archived excerpt — the text we read …iate governed by the privacy, security, and breach notification rules issued by the United States Department of Health and Human Services (45 CFR Parts 160 and 164) pursuant to HIPAA. (4) Any nonprofit organization. (5) Any institution of higher education. (6) Any public utility (as defined in IC 8-1-2-1(a)) or service company affiliated with a public utility (as defined in IC 8-1-2-1(a)). For purposes of this subdivision, "service company" means an associate company with… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Public utilities and affiliated service companies Archived excerpt — the text we read …nd breach notification rules issued by the United States Department of Health and Human Services (45 CFR Parts 160 and 164) pursuant to HIPAA. (4) Any nonprofit organization. (5) Any institution of higher education. (6) Any public utility (as defined in IC 8-1-2-1(a)) or service company affiliated with a public utility (as defined in IC 8-1-2-1(a)). For purposes of this subdivision, "service company" means an associate company within a holding company system organized specifically for the purpose of providing goods or services to a public utility (as defined in IC … Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • 501(c)(4) insurance fraud detection organizations under law enforcement MOU Archived excerpt — the text we read … means an associate company within a holding company system organized specifically for the purpose of providing goods or services to a public utility (as defined in IC 8-1-2-1(a)) in the same holding company system. (7) Any organization exempt from taxation under Section 501(c)(4) of the Internal Revenue Code that is: (A) established to detect or prevent insurance related crime or fraud; and (B) subject to a memorandum of understanding with a statewide law enforcement agency. As added by P.L.94-2023, SEC.1. Amended by P.L.236-2025, SEC.5. Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • HIPAA protected health information Archived excerpt — the text we read IC 24-15-1-2 Exempt information and data Sec. 2. The following information and data are exempt from this article: (1) Protected health information under HIPAA and related regulations under 45 CFR Part 160, 45 CFR Part 162, and 45 CFR Part 164. (2) Patient identifying information for purposes of 42 U.S.C. 290dd-2. (3) Any of the following: (A) Identifiable private information for purposes of the federal policy for the protection of human subjects under 45 CFR … Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Patient identifying information under 42 U.S.C. 290dd-2 Archived excerpt — the text we read …ion and data Sec. 2. The following information and data are exempt from this article: (1) Protected health information under HIPAA and related regulations under 45 CFR Part 160, 45 CFR Part 162, and 45 CFR Part 164. (2) Patient identifying information for purposes of 42 U.S.C. 290dd-2. (3) Any of the following: (A) Identifiable private information for purposes of the federal policy for the protection of human subjects under 45 CFR Part 46. (B) Identifiable private information that is otherwise informa… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Human subjects research information under 45 CFR Part 46 Archived excerpt — the text we read …ed health information under HIPAA and related regulations under 45 CFR Part 160, 45 CFR Part 162, and 45 CFR Part 164. (2) Patient identifying information for purposes of 42 U.S.C. 290dd-2. (3) Any of the following: (A) Identifiable private information for purposes of the federal policy for the protection of human subjects under 45 CFR Part 46. (B) Identifiable private information that is otherwise information collected as part of human subjects research under the good clinical practice guidelines issued by the International Council for Harmonisation of Techni… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Good clinical practice human subjects research information Archived excerpt — the text we read …identifying information for purposes of 42 U.S.C. 290dd-2. (3) Any of the following: (A) Identifiable private information for purposes of the federal policy for the protection of human subjects under 45 CFR Part 46. (B) Identifiable private information that is otherwise information collected as part of human subjects research under the good clinical practice guidelines issued by the International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use. (C) The protection of human subjects under 21 CFR Parts 50 and 56. (D) Personal data used or shared in research conducted in accordance with the requirements set forth in this article. (E) Other research conducted in ac… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Human subjects protection under 21 CFR Parts 50 and 56 Archived excerpt — the text we read …information collected as part of human subjects research under the good clinical practice guidelines issued by the International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use. (C) The protection of human subjects under 21 CFR Parts 50 and 56. (D) Personal data used or shared in research conducted in accordance with the requirements set forth in this article. (E) Other research conducted in accordance with applicable law. (4) Information and documents created… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Personal data used or shared in research conducted per this article Archived excerpt — the text we read …good clinical practice guidelines issued by the International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use. (C) The protection of human subjects under 21 CFR Parts 50 and 56. (D) Personal data used or shared in research conducted in accordance with the requirements set forth in this article. (E) Other research conducted in accordance with applicable law. (4) Information and documents created for purposes of the federal Health Care Quality Improvement Act of 1986 (42 U.S.C. 11101 et seq.). (5) Patient safety… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Other research conducted in accordance with applicable law Archived excerpt — the text we read …Pharmaceuticals for Human Use. (C) The protection of human subjects under 21 CFR Parts 50 and 56. (D) Personal data used or shared in research conducted in accordance with the requirements set forth in this article. (E) Other research conducted in accordance with applicable law. (4) Information and documents created for purposes of the federal Health Care Quality Improvement Act of 1986 (42 U.S.C. 11101 et seq.). (5) Patient safety work product for purposes of the federal Patient Safety and Qua… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Health Care Quality Improvement Act information Archived excerpt — the text we read …cts under 21 CFR Parts 50 and 56. (D) Personal data used or shared in research conducted in accordance with the requirements set forth in this article. (E) Other research conducted in accordance with applicable law. (4) Information and documents created for purposes of the federal Health Care Quality Improvement Act of 1986 (42 U.S.C. 11101 et seq.). (5) Patient safety work product for purposes of the federal Patient Safety and Quality Improvement Act (42 U.S.C. 299b-21 et seq.). (6) Information derived from any of the health care related information set forth in th… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Patient Safety and Quality Improvement Act work product Archived excerpt — the text we read … this article. (E) Other research conducted in accordance with applicable law. (4) Information and documents created for purposes of the federal Health Care Quality Improvement Act of 1986 (42 U.S.C. 11101 et seq.). (5) Patient safety work product for purposes of the federal Patient Safety and Quality Improvement Act (42 U.S.C. 299b-21 et seq.). (6) Information derived from any of the health care related information set forth in this section that is de-identified in accordance with the requirements for de-identification under HIPAA. (7) Information: (A) origina… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • HIPAA de-identified health information Archived excerpt — the text we read … the federal Health Care Quality Improvement Act of 1986 (42 U.S.C. 11101 et seq.). (5) Patient safety work product for purposes of the federal Patient Safety and Quality Improvement Act (42 U.S.C. 299b-21 et seq.). (6) Information derived from any of the health care related information set forth in this section that is de-identified in accordance with the requirements for de-identification under HIPAA. (7) Information: (A) originating from; (B) intermingled with so as to be indistinguishable from; or (C) treated in the same manner as; information that is exempt under this section and that is maintained by a covered en… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Information intermingled with exempt HIPAA-related information Archived excerpt — the text we read …de-identified in accordance with the requirements for de-identification under HIPAA. (7) Information: (A) originating from; (B) intermingled with so as to be indistinguishable from; or (C) treated in the same manner as; information that is exempt under this section and that is maintained by a covered entity or business associate, as defined in HIPAA, or a program or qualified service organization under 42 U.S.C. 290dd-2. (8) Information used only for public health activities and purposes, as authorized by HIPAA. (9) The collection, maintenance, disclosure, sale, communication, or use of any personal information bearing on a consumer's c… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • HIPAA public health activities information Archived excerpt — the text we read …manner as; information that is exempt under this section and that is maintained by a covered entity or business associate, as defined in HIPAA, or a program or qualified service organization under 42 U.S.C. 290dd-2. (8) Information used only for public health activities and purposes, as authorized by HIPAA. (9) The collection, maintenance, disclosure, sale, communication, or use of any personal information bearing on a consumer's credit worthiness, credit standing, credit capacity, character, general reputation, personal c… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • FCRA-regulated data Archived excerpt — the text we read …racter, general reputation, personal characteristics, or mode of living by: (A) a consumer reporting agency, furnisher, or user that provides information for use in a consumer report; or (B) a user of a consumer report; but only to the extent that such activity is regulated by and authorized under the federal Fair Credit Reporting Act (15 U.S.C. 1681 et seq.). (10) Personal data collected, processed, sold, or disclosed in compliance with the federal Driver's Privacy Protection Act of 1994 (18 U.S.C. 2721 et seq.). (11) Personal data regulated by the federal Family Educational… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Driver's Privacy Protection Act data Archived excerpt — the text we read …ation for use in a consumer report; or (B) a user of a consumer report; but only to the extent that such activity is regulated by and authorized under the federal Fair Credit Reporting Act (15 U.S.C. 1681 et seq.). (10) Personal data collected, processed, sold, or disclosed in compliance with the federal Driver's Privacy Protection Act of 1994 (18 U.S.C. 2721 et seq.). (11) Personal data regulated by the federal Family Educational Rights and Privacy Act (20 U.S.C. 1232g et seq.). (12) Personal data collected, processed, sold, or disclosed in compliance with the federal Farm Credit Act… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • FERPA-regulated data Archived excerpt — the text we read …deral Fair Credit Reporting Act (15 U.S.C. 1681 et seq.). (10) Personal data collected, processed, sold, or disclosed in compliance with the federal Driver's Privacy Protection Act of 1994 (18 U.S.C. 2721 et seq.). (11) Personal data regulated by the federal Family Educational Rights and Privacy Act (20 U.S.C. 1232g et seq.). (12) Personal data collected, processed, sold, or disclosed in compliance with the federal Farm Credit Act (12 U.S.C. 2001 et seq.). (13) Data processed or maintained: (A) in the course of an individual applying to, emp… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Farm Credit Act data Archived excerpt — the text we read …osed in compliance with the federal Driver's Privacy Protection Act of 1994 (18 U.S.C. 2721 et seq.). (11) Personal data regulated by the federal Family Educational Rights and Privacy Act (20 U.S.C. 1232g et seq.). (12) Personal data collected, processed, sold, or disclosed in compliance with the federal Farm Credit Act (12 U.S.C. 2001 et seq.). (13) Data processed or maintained: (A) in the course of an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party, to the extent that the data is … Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Employment data Archived excerpt — the text we read …ghts and Privacy Act (20 U.S.C. 1232g et seq.). (12) Personal data collected, processed, sold, or disclosed in compliance with the federal Farm Credit Act (12 U.S.C. 2001 et seq.). (13) Data processed or maintained: (A) in the course of an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party, to the extent that the data is collected and used within the context of that role; (B) as emergency contact information for an individual under this article and used for emergency contact purposes; or (C) that is necessary to retain to administer benefits for another individual relating … Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Emergency contact information Archived excerpt — the text we read … an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party, to the extent that the data is collected and used within the context of that role; (B) as emergency contact information for an individual under this article and used for emergency contact purposes; or (C) that is necessary to retain to administer benefits for another individual relating to the individual under clause (A) and used for the purposes of administering those benefits. As added by P.… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Benefits administration data Archived excerpt — the text we read …r third party, to the extent that the data is collected and used within the context of that role; (B) as emergency contact information for an individual under this article and used for emergency contact purposes; or (C) that is necessary to retain to administer benefits for another individual relating to the individual under clause (A) and used for the purposes of administering those benefits. As added by P.L.94-2023, SEC.1. Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Evidentiary privilege (compliance would violate an Indiana evidentiary privilege) Archived excerpt — the text we read IC 24-15-8-3 Evidentiary privilege; exemption from obligations concerning personal data Sec. 3. The obligations imposed on a controller or a processor under this article do not apply if compliance by the controller or processor with this article would violate an evidentiary privilege under Indiana law. This article shall not be construed to prohibit a controller or processor from providing, as part of a privileged communication, personal data concerning a consumer to a person covered by an evidentiary privilege under… Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Purely personal or household activity Archived excerpt — the text we read …imposed on controllers and processors that adversely affects the rights or freedoms of any persons, such as exercising the right of free speech under the First Amendment to the Constitution of the United States; and (2) does not apply to personal data in the context of a purely personal or household activity. As added by P.L.94-2023, SEC.1. Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Trade secrets (no obligation to disclose) Archived excerpt — the text we read IC 24-15-8-6 Controller not required to disclose trade secrets Sec. 6. Nothing in this article shall be construed as requiring a controller to disclose trade secrets. As added by P.L.94-2023, SEC.1. Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Privileged communications to a person covered by an evidentiary privilege Archived excerpt — the text we read …ata Sec. 3. The obligations imposed on a controller or a processor under this article do not apply if compliance by the controller or processor with this article would violate an evidentiary privilege under Indiana law. This article shall not be construed to prohibit a controller or processor from providing, as part of a privileged communication, personal data concerning a consumer to a person covered by an evidentiary privilege under Indiana law. As added by P.L.94-2023, SEC.1. Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source
  • Rights and freedoms of others, including free speech Archived excerpt — the text we read IC 24-15-8-5 Personal rights or freedoms; free speech; personal data in context of purely personal or household activity Sec. 5. This article: (1) shall not be construed as an obligation imposed on controllers and processors that adversely affects the rights or freedoms of any persons, such as exercising the right of free speech under the First Amendment to the Constitution of the United States; and (2) does not apply to personal data in the context of a purely personal or household activity. As added by P.L.94-2023, SEC.1. Archived from source — captured 2026-08-03 · snapshot a8a7f505 Verify at the source

Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source.

Timeline

ICDPA milestones

This state currently has one dated milestone on the books.

Enforcement January 1, 2026

ICDPA took effect

Enforcement began — obligations have been live since this date.

Source: primary citation

Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source. Reference only, not legal advice.

When staying on top of the law isn't enough, DataGrail automates the work.
DSR automation and regulatory tracking — handled by the platform behind this reference.
How DataGrail helps
Back to the Regulations Hub Reference only — not legal advice. Published Sep 29, 2026