Indiana Consumer Data Protection Act (INCDPA) Compliance: Handle Indiana Data Privacy Law Requests on the 45-Day Deadline
The Indiana Consumer Data Protection Act took effect on January 1, 2026 and gives Indiana residents the right to access, correct, delete, and port their personal data and to opt out of its sale, targeted advertising, and profiling. A request starts a 45-day clock, and Indiana is the one state that lets you answer an access request with a representative summary rather than a raw data dump. Obtainer finds where a person's data lives across your systems, compiles one reviewable manifest, drafts the response, and tracks the deadline so it does not slip.
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
In short
The Indiana Consumer Data Protection Act (INCDPA), codified at Indiana Code Article 24-15, took effect on January 1, 2026, roughly two and a half years after it was signed. It applies to a for-profit entity that conducts business in Indiana or produces products or services targeted to Indiana residents and, in a calendar year, either controls or processes the personal data of at least 100,000 Indiana consumers, or controls or processes the personal data of at least 25,000 Indiana consumers while deriving more than 50 percent of gross revenue from the sale of personal data.
Indiana consumers can confirm whether you are processing their personal data and access it, correct inaccuracies, delete it, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects. You generally have 45 days from receipt of a request to respond, extendable once by another 45 days when reasonably necessary, provided you notify the consumer inside the first 45 days. If you refuse to act, the consumer can appeal, and IC 24-15-3-1 gives you 60 days from receipt of that appeal to respond in writing with your reasons, plus a route for the consumer to complain to the Attorney General.
Two things make Indiana operationally different from the state laws you may already handle. First, on an access request a controller may provide either a copy of the personal data or a representative summary of it, which no other state statute explicitly permits. Second, the 30-day cure period is mandatory and does not sunset, where most states wrote their cure period with an expiration date. Enforcement rests solely with the Indiana Attorney General, with civil penalties of up to $7,500 per violation, and there is no private right of action.
Obtainer handles the operational side of an Indiana request: it intakes the request, discovers where the person's data lives across your systems, compiles a source-system manifest, drafts a deadline-safe response, and tracks the 45-day clock and any appeal. Nothing is disclosed automatically; a human reviews, redacts, and approves before anything goes out. Obtainer helps you comply. It is not legal advice, so scope calls, exemptions, and any refusal stay with your team. Self-serve from a planned $49/mo.
Last updated August 2026
Why it fits
Indiana businesses, plus out-of-state SaaS, ecommerce, retail, and B2C firms that target Indiana residents and cross the 100,000 consumer threshold, that want discovery, drafting, appeal handling, and 45-day deadline tracking for a data subject request in one place.
A summary is still an inventory problem
Indiana lets you answer an access request with a representative summary of the personal data rather than a full copy, which sounds like less work and is, on the output side. It changes nothing about the input. To describe accurately what you hold about a named person, you still have to know every system that holds it, and an incomplete summary is a wrong answer rather than a short one. Obtainer produces the source-system manifest the summary is written from.
45 days to respond, then 60 more on appeal
The clock starts when the request arrives, not when someone gets to it, and the appeal is a second deadline most teams have never run. Obtainer starts the countdown at intake, finds the data, drafts the reply, and keeps the appeal on its own 60-day timer so a denial does not turn into a complaint filed with the Attorney General.
The 30-day cure does not expire
Indiana kept a mandatory 30-day cure period with no sunset date, so the Attorney General must give you notice and a chance to fix a violation before seeking the $7,500 per violation penalty. That is genuine breathing room compared with Connecticut or Colorado, where the guaranteed cure window is gone. It rewards teams that can produce a complete request record quickly, which is exactly what a cure letter asks for. Self-serve from a planned $49/mo, with no five-figure floor before your first request.
Reference
Where the Indiana Consumer Data Protection Act differs from the state laws you already handle
Indiana is the most controller-friendly comprehensive privacy law in the country on several axes at once. Each row is a place the INCDPA departs from the Virginia-style template most states copied, and what that departure changes in your request workflow.
| Requirement | Indiana (INCDPA) | Typical state law | What it changes for you |
|---|---|---|---|
| Applicability threshold | 100,000 Indiana consumers, or 25,000 plus more than 50 percent of gross revenue from selling personal data | Often 100,000, but the revenue prong is commonly 25 percent, and Connecticut cut its main trigger to 35,000 in July 2026 | Fewer companies are in scope in Indiana than in Connecticut or Colorado. Check the count per state, not once for the country. |
| Access response format | A copy of the personal data or a representative summary of it | A copy of the personal data | Your response can be shorter, but only if your data discovery is complete enough to summarize honestly. |
| Response deadline | 45 days, extendable once by 45 days with notice inside the first period | 45 days plus a 45-day extension in most states, one month under the GDPR | Same clock you already run. The failure mode is intake, not drafting. |
| Appeal | Required, with 60 days to respond in writing and a route to the Attorney General on denial | Required in most states, usually 45 or 60 days | A denial creates a second deadline. Track it separately from the original request. |
| Universal opt-out signal | Not required. Indiana joins Virginia, Iowa, Utah, and Kentucky in not mandating Global Privacy Control | Colorado, Connecticut, Texas, Montana, New Jersey, Delaware, Oregon and others require honoring an opt-out preference signal | You still need GPC handling for other states, so build it once and apply it everywhere. |
| Cure period | 30 days, mandatory, with no expiration date | Often 30 or 60 days with a sunset, and several have already lapsed | You get a warning before a penalty in Indiana. Producing the request record fast is what turns that warning into a closed file. |
| Penalty and enforcement | Up to $7,500 per violation, Attorney General only, no private right of action | Commonly $7,500 per violation, AG enforcement, no private right of action outside California's breach provision | Per violation usually means per consumer, so a systemic intake failure scales quickly. |
More use cases
Related features
Questions
Common questions about this
Who has to comply with the Indiana Consumer Data Protection Act?
A for-profit entity that conducts business in Indiana or produces products or services targeted to Indiana residents and, during a calendar year, either controls or processes the personal data of at least 100,000 Indiana consumers, or controls or processes the personal data of at least 25,000 Indiana consumers and derives more than 50 percent of gross revenue from the sale of personal data. State agencies, financial institutions subject to the Gramm-Leach-Bliley Act, HIPAA covered entities, nonprofits, higher education institutions, and public utilities are exempt at the entity level, and data regulated by the FCRA, FERPA, the Driver's Privacy Protection Act and the Farm Credit Act is exempt at the data level. If you are unsure which statutes reach you, start with which state privacy laws apply to your business.
When did the Indiana Consumer Data Protection Act take effect?
January 1, 2026. Indiana signed the law in May 2023 and gave businesses an unusually long runway of about two and a half years, the longest lead time of any state privacy law passed that year. Indiana took effect the same day as the Kentucky Consumer Data Protection Act and the Rhode Island Data Transparency and Privacy Protection Act, so a company operating nationally picked up three new jurisdictions at once on that date.
What is the penalty for violating the Indiana Consumer Data Protection Act?
Up to $7,500 per violation, sought by the Indiana Attorney General in a civil action, plus injunctive relief and reasonable expenses. There is no private right of action, so consumers cannot sue you directly. Before filing, the Attorney General must give you written notice of the alleged violation and 30 days to cure it, and that cure period is permanent rather than a temporary grace window.
How long do I have to respond to an Indiana data subject request?
Forty-five days from receipt of the request. You can take one additional 45-day extension when reasonably necessary, as long as you tell the consumer inside the first 45 days why you need it. If you decline to act, you have to explain why within that same 45-day window and tell the consumer how to appeal. On appeal, IC 24-15-3-1 gives you 60 days to respond in writing. Obtainer starts both clocks at intake and works the DSAR process against them.
Does Indiana require honoring Global Privacy Control?
No. The INCDPA does not require you to recognize a universal opt-out mechanism such as Global Privacy Control, which puts Indiana alongside Virginia, Iowa, Utah, and Kentucky. That is a narrow exception rather than a general rule: Colorado, Connecticut, Texas, Montana, Oregon, Delaware, New Jersey, Minnesota, Maryland and others do require it. If you operate nationally, build signal handling once and apply it everywhere rather than switching it on by state.
Can I answer an Indiana access request with a summary instead of the data?
Yes, and Indiana is the only state that says so explicitly. On a request to access, a controller may provide either a copy of the personal data or a representative summary of it. That reduces the packaging work on the way out, not the discovery work on the way in, because a summary that omits a system is still an incomplete response. Practically, most teams still assemble the full manifest first and then decide what form the disclosure takes, which is how subject access request software is meant to be used.
Is Indiana a controller-friendly privacy law?
It is currently the most controller-friendly comprehensive privacy law in the country on the axes that matter operationally. Broad entity-level exemptions, a high applicability threshold, a 50 percent revenue prong rather than 25 percent, no universal opt-out mandate, a summary option on access, a permanent 30-day cure period, and no explicit rulemaking authority for the Attorney General. That does not make the request obligations optional. The rights, the 45-day clock, and the appeal all work the way they do everywhere else, so the operational build is the same one you need for Texas and Virginia.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.