Obtainer
Use case

Indiana Consumer Data Protection Act (INCDPA) Compliance: Handle Indiana Data Privacy Law Requests on the 45-Day Deadline

The Indiana Consumer Data Protection Act took effect on January 1, 2026 and gives Indiana residents the right to access, correct, delete, and port their personal data and to opt out of its sale, targeted advertising, and profiling. A request starts a 45-day clock, and Indiana is the one state that lets you answer an access request with a representative summary rather than a raw data dump. Obtainer finds where a person's data lives across your systems, compiles one reviewable manifest, drafts the response, and tracks the deadline so it does not slip.

See how it works
Discovery across your systems Human redaction gate Helps you comply, not legal advice
Request Studio
Requester
Compiled the manifest and drafted the response - illustrative sample request
0
records found
0
systems scanned
Data manifest
Response draft

Assembling the cover letter from the template...

You approve what is disclosed before anything ships

Helps you comply, not legal advice

In short

The Indiana Consumer Data Protection Act (INCDPA), codified at Indiana Code Article 24-15, took effect on January 1, 2026, roughly two and a half years after it was signed. It applies to a for-profit entity that conducts business in Indiana or produces products or services targeted to Indiana residents and, in a calendar year, either controls or processes the personal data of at least 100,000 Indiana consumers, or controls or processes the personal data of at least 25,000 Indiana consumers while deriving more than 50 percent of gross revenue from the sale of personal data.

Indiana consumers can confirm whether you are processing their personal data and access it, correct inaccuracies, delete it, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects. You generally have 45 days from receipt of a request to respond, extendable once by another 45 days when reasonably necessary, provided you notify the consumer inside the first 45 days. If you refuse to act, the consumer can appeal, and IC 24-15-3-1 gives you 60 days from receipt of that appeal to respond in writing with your reasons, plus a route for the consumer to complain to the Attorney General.

Two things make Indiana operationally different from the state laws you may already handle. First, on an access request a controller may provide either a copy of the personal data or a representative summary of it, which no other state statute explicitly permits. Second, the 30-day cure period is mandatory and does not sunset, where most states wrote their cure period with an expiration date. Enforcement rests solely with the Indiana Attorney General, with civil penalties of up to $7,500 per violation, and there is no private right of action.

Obtainer handles the operational side of an Indiana request: it intakes the request, discovers where the person's data lives across your systems, compiles a source-system manifest, drafts a deadline-safe response, and tracks the 45-day clock and any appeal. Nothing is disclosed automatically; a human reviews, redacts, and approves before anything goes out. Obtainer helps you comply. It is not legal advice, so scope calls, exemptions, and any refusal stay with your team. Self-serve from a planned $49/mo.

Last updated August 2026

// THE FIT

Why it fits

Indiana businesses, plus out-of-state SaaS, ecommerce, retail, and B2C firms that target Indiana residents and cross the 100,000 consumer threshold, that want discovery, drafting, appeal handling, and 45-day deadline tracking for a data subject request in one place.

A summary is still an inventory problem

Indiana lets you answer an access request with a representative summary of the personal data rather than a full copy, which sounds like less work and is, on the output side. It changes nothing about the input. To describe accurately what you hold about a named person, you still have to know every system that holds it, and an incomplete summary is a wrong answer rather than a short one. Obtainer produces the source-system manifest the summary is written from.

45 days to respond, then 60 more on appeal

The clock starts when the request arrives, not when someone gets to it, and the appeal is a second deadline most teams have never run. Obtainer starts the countdown at intake, finds the data, drafts the reply, and keeps the appeal on its own 60-day timer so a denial does not turn into a complaint filed with the Attorney General.

The 30-day cure does not expire

Indiana kept a mandatory 30-day cure period with no sunset date, so the Attorney General must give you notice and a chance to fix a violation before seeking the $7,500 per violation penalty. That is genuine breathing room compared with Connecticut or Colorado, where the guaranteed cure window is gone. It rewards teams that can produce a complete request record quickly, which is exactly what a cure letter asks for. Self-serve from a planned $49/mo, with no five-figure floor before your first request.

// THE TABLE

Reference

Where the Indiana Consumer Data Protection Act differs from the state laws you already handle

Indiana is the most controller-friendly comprehensive privacy law in the country on several axes at once. Each row is a place the INCDPA departs from the Virginia-style template most states copied, and what that departure changes in your request workflow.

RequirementIndiana (INCDPA)Typical state lawWhat it changes for you
Applicability threshold100,000 Indiana consumers, or 25,000 plus more than 50 percent of gross revenue from selling personal dataOften 100,000, but the revenue prong is commonly 25 percent, and Connecticut cut its main trigger to 35,000 in July 2026Fewer companies are in scope in Indiana than in Connecticut or Colorado. Check the count per state, not once for the country.
Access response formatA copy of the personal data or a representative summary of itA copy of the personal dataYour response can be shorter, but only if your data discovery is complete enough to summarize honestly.
Response deadline45 days, extendable once by 45 days with notice inside the first period45 days plus a 45-day extension in most states, one month under the GDPRSame clock you already run. The failure mode is intake, not drafting.
AppealRequired, with 60 days to respond in writing and a route to the Attorney General on denialRequired in most states, usually 45 or 60 daysA denial creates a second deadline. Track it separately from the original request.
Universal opt-out signalNot required. Indiana joins Virginia, Iowa, Utah, and Kentucky in not mandating Global Privacy ControlColorado, Connecticut, Texas, Montana, New Jersey, Delaware, Oregon and others require honoring an opt-out preference signalYou still need GPC handling for other states, so build it once and apply it everywhere.
Cure period30 days, mandatory, with no expiration dateOften 30 or 60 days with a sunset, and several have already lapsedYou get a warning before a penalty in Indiana. Producing the request record fast is what turns that warning into a closed file.
Penalty and enforcementUp to $7,500 per violation, Attorney General only, no private right of actionCommonly $7,500 per violation, AG enforcement, no private right of action outside California's breach provisionPer violation usually means per consumer, so a systemic intake failure scales quickly.
// FAQ

Questions

Common questions about this

Who has to comply with the Indiana Consumer Data Protection Act?

A for-profit entity that conducts business in Indiana or produces products or services targeted to Indiana residents and, during a calendar year, either controls or processes the personal data of at least 100,000 Indiana consumers, or controls or processes the personal data of at least 25,000 Indiana consumers and derives more than 50 percent of gross revenue from the sale of personal data. State agencies, financial institutions subject to the Gramm-Leach-Bliley Act, HIPAA covered entities, nonprofits, higher education institutions, and public utilities are exempt at the entity level, and data regulated by the FCRA, FERPA, the Driver's Privacy Protection Act and the Farm Credit Act is exempt at the data level. If you are unsure which statutes reach you, start with which state privacy laws apply to your business.

When did the Indiana Consumer Data Protection Act take effect?

January 1, 2026. Indiana signed the law in May 2023 and gave businesses an unusually long runway of about two and a half years, the longest lead time of any state privacy law passed that year. Indiana took effect the same day as the Kentucky Consumer Data Protection Act and the Rhode Island Data Transparency and Privacy Protection Act, so a company operating nationally picked up three new jurisdictions at once on that date.

What is the penalty for violating the Indiana Consumer Data Protection Act?

Up to $7,500 per violation, sought by the Indiana Attorney General in a civil action, plus injunctive relief and reasonable expenses. There is no private right of action, so consumers cannot sue you directly. Before filing, the Attorney General must give you written notice of the alleged violation and 30 days to cure it, and that cure period is permanent rather than a temporary grace window.

How long do I have to respond to an Indiana data subject request?

Forty-five days from receipt of the request. You can take one additional 45-day extension when reasonably necessary, as long as you tell the consumer inside the first 45 days why you need it. If you decline to act, you have to explain why within that same 45-day window and tell the consumer how to appeal. On appeal, IC 24-15-3-1 gives you 60 days to respond in writing. Obtainer starts both clocks at intake and works the DSAR process against them.

Does Indiana require honoring Global Privacy Control?

No. The INCDPA does not require you to recognize a universal opt-out mechanism such as Global Privacy Control, which puts Indiana alongside Virginia, Iowa, Utah, and Kentucky. That is a narrow exception rather than a general rule: Colorado, Connecticut, Texas, Montana, Oregon, Delaware, New Jersey, Minnesota, Maryland and others do require it. If you operate nationally, build signal handling once and apply it everywhere rather than switching it on by state.

Can I answer an Indiana access request with a summary instead of the data?

Yes, and Indiana is the only state that says so explicitly. On a request to access, a controller may provide either a copy of the personal data or a representative summary of it. That reduces the packaging work on the way out, not the discovery work on the way in, because a summary that omits a system is still an incomplete response. Practically, most teams still assemble the full manifest first and then decide what form the disclosure takes, which is how subject access request software is meant to be used.

Is Indiana a controller-friendly privacy law?

It is currently the most controller-friendly comprehensive privacy law in the country on the axes that matter operationally. Broad entity-level exemptions, a high applicability threshold, a 50 percent revenue prong rather than 25 percent, no universal opt-out mandate, a summary option on access, a permanent 30-day cure period, and no explicit rulemaking authority for the Attorney General. That does not make the request obligations optional. The rights, the 45-day clock, and the appeal all work the way they do everywhere else, so the operational build is the same one you need for Texas and Virginia.

Run a data subject access request end to end

Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.