Indiana Consumer Data Protection Act (SB 5) state silhouette

Indiana Consumer Data Protection Act (SB 5)

Effective Date: 2026-01-01

The Indiana Consumer Data Protection Act applies to businesses that control or process personal data of at least 100,000 Indiana residents a year, or 25,000 residents if more than half of gross revenue comes from selling personal data. It took effect January 1, 2026.

What the Indiana Consumer Data Protection Act Requires

The law follows the Virginia template: post a reasonably accessible privacy notice, honor consumer rights to access, correct, delete, and obtain a copy of personal data, get consent before processing sensitive data, and offer opt-outs from targeted advertising, sale, and significant profiling. Data protection assessments are required for higher-risk processing.

Enforcement and Penalties

The Attorney General enforces exclusively, there is no private right of action, and businesses get a permanent 30-day right to cure violations before enforcement. Civil penalties run up to $7,500 per violation. Indiana does not require recognition of universal opt-out browser signals, which keeps the technical lift lighter than in states like Colorado or Texas.

Source: Indiana Attorney General: SB 5, Ind. Code 24-15

Report a violation: If you believe a business is violating this law, you can file a complaint with the Indiana Attorney General Consumer Protection Division.

More Rules & Regulations