Law / Indiana

Indiana

age

Indiana's SB 17 (2024) requires age verification on adult oriented websites and has been in effect since 2024; after the U.S. Supreme Court upheld a materially identical Texas law in June 2025, the Seventh Circuit remanded Indiana's case with instructions to rule for the state.

A 2026 law (HEA 1408) separately requires large social media platforms to verify a user's age and Indiana residency and to obtain parental consent before a resident under 16 may hold an account, taking effect January 1, 2027. Indiana has not enacted an app store age verification or design code law.

privacy

The Indiana Consumer Data Protection Act (INCDPA), Ind. Code Art. 24-15 (codified caption "Consumer Data Protection," the popular INCDPA name is not itself codified text), is Indiana's comprehensive consumer-privacy regime, enacted as P.L.94-2023 (Senate Bill 5, 2023 Regular Session) and effective January 1, 2026 across every section of the article.

Genetic or biometric data processed to uniquely identify a specific individual is one of INCDPA's enumerated sensitive-data categories, but the Act's biometric data definition carries a blanket, unconditional exclusion for a photograph, or for a video or audio recording, or any data generated from either, with no clawback for data generated to identify someone, so a faceprint or voiceprint extracted from a recording falls outside biometric data, and therefore outside sensitive data, regardless of purpose.

Florida's FDBR shares this unconditional structure in the same batch, while Maryland's, Minnesota's, and New Jersey's biometric definitions each claw the data back. A separate, older statute, the Disclosure of Security Breach Act (Ind. Code Art. 24-4.9), governs breach notification and is enforced, like INCDPA, exclusively by the Indiana Attorney General, and a violation of either statute is not privately actionable.

INCDPA's 30-day cure right before an Attorney General enforcement action is mandatory, not discretionary, and carries no sunset date anywhere in the article, unlike several peer states' time-limited cure rights.

14 instruments named 7 researched in detail As of 2026-08-27

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Adult content age verification (AV)

SB 17 (2024), age verification for adult oriented websites

cite Ind. Code ch. 24-4-23 stage IN FORCE in force since 2024-07-01 source official Indiana Code text and Indiana General Assembly bill record

Requires an adult oriented website, where at least one third of content is harmful to minors, to use a reasonable age verification method before granting access, and bars retention of a user's identifying information after verification. The Attorney General or a harmed parent may sue for injunctive relief and damages.

Note and primary source

Breach notification

Disclosure of Security Breach Act

cite Ind. Code §§ 24-4.9-3-1, 24-4.9-3-3, 24-4.9-4-1, 24-4.9-4-2 stage IMMINENT commencement not set source official Indiana statute text, Indiana Code Article 4.9, Indiana General Assembly

A data base owner must disclose a breach of the security of a system to an affected Indiana resident if the owner knows, should know, or should have known that the unauthorized acquisition has resulted in or could result in identity deception, identity theft, or fraud affecting that resident, without unreasonable delay and no later than 45 days after discovering the breach.

A data base owner disclosing to more than 1,000 consumers must also notify nationwide consumer reporting agencies, and any disclosure at all triggers a required notice to the Indiana Attorney General.

Failing to make a required disclosure is a deceptive act actionable only by the Attorney General, with a civil penalty of up to $150,000 per deceptive act, and a separate, narrower duty to implement reasonable safeguards and dispose of records properly carries its own $5,000-per-act penalty, also enforced only by the Attorney General. This is a separate, pre-existing statute from INCDPA. The cited sections were added by P.L.125-2006, SEC.6, and have since been amended piecemeal: Ind.

Code sections 24-4.9-3-1 and 24-4.9-4-1 by P.L.137-2009, and section 24-4.9-3-3 by P.L.171-2022; section 24-4.9-4-2 has not been amended since 2006. Indiana's codified history notes carry only a public-law-and-year citation, with no day-precise commencement date, so no effective_date is recorded here.

What it asks of an app

Comprehensive regime

Indiana Consumer Data Protection Act (INCDPA), general applicability and controller duties

cite Ind. Code §§ 24-15-1-1, 24-15-4-1, 24-15-11-1 stage RECENT in force 8 months effective 2026-01-01 source official Indiana statute text, Indiana Code Article 15, Indiana General Assembly

INCDPA governs private-sector processing of Indiana residents' personal data. It applies to a person conducting business in Indiana, or producing a product or service targeted to Indiana residents, that during a calendar year controls or processes the personal data of at least 100,000 Indiana consumers, or of at least 25,000 Indiana consumers while deriving more than 50 percent of gross revenue from selling personal data.

A controller must limit collection to what is adequate, relevant, and reasonably necessary for the purposes disclosed to the consumer, and may not process personal data for an incompatible purpose without the consumer's consent. Article 15 also preempts local law: no city, county, or other local government may regulate a controller's or processor's processing of personal data.

What it asks of an app

Data subject rights

Indiana Consumer Data Protection Act, consumer rights

cite Ind. Code § 24-15-3-1 stage RECENT in force 8 months effective 2026-01-01 source official Indiana statute text, Indiana Code Article 15, Indiana General Assembly

INCDPA gives an Indiana consumer the right to confirm and access their personal data, correct inaccuracies, delete data, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and profiling that produces a legal or similarly significant effect, exercisable against the controller.

A controller must respond without undue delay and no later than 45 days after receipt, with one additional 45-day extension available when reasonably necessary, and must inform the consumer of a decline and the means to appeal it on the same 45-day timeline. This is the ordinary 45-plus-45 response model used across most states in this wave, not the shortened timeline Florida uses.

What it asks of an app

Enforcement supervision

Indiana Consumer Data Protection Act, Attorney General enforcement

cite Ind. Code §§ 24-15-10-1 to 24-15-10-4 stage RECENT in force 8 months effective 2026-01-01 source official Indiana statute text, Indiana Code Article 15, Indiana General Assembly

The Indiana Attorney General has exclusive authority to enforce INCDPA, with a civil penalty of up to $7,500 per violation plus recoverable investigation expenses. Before suing, the Attorney General must give a controller or processor 30 days' written notice identifying the specific provisions violated; if the violation is cured within that period and the controller or processor provides a written attestation of the cure, the Attorney General may not initiate an action.

This cure right is mandatory, not discretionary, and carries no sunset date anywhere in Article 15, unlike Maryland's, New Jersey's, and Minnesota's time-limited or discretionary cure provisions. The chapter creates no private right of action.

What it asks of an app

Sensitive categories

Indiana Consumer Data Protection Act, sensitive data and biometric data definitions

cite Ind. Code §§ 24-15-2-4, 24-15-2-28, 24-15-4-1(5) stage RECENT in force 8 months effective 2026-01-01 source official Indiana statute text, Indiana Code Article 15, Indiana General Assembly

INCDPA classifies racial or ethnic origin, religious belief, a health diagnosis made by a health care provider, sexual orientation, citizenship or immigration status, genetic or biometric data processed to uniquely identify a specific individual, a known child's data, and precise geolocation data as sensitive data requiring the consumer's consent before processing, except that a known child's sensitive data may instead be processed under COPPA's consent framework.

'Biometric data' means data from automatic measurement of an individual's biological characteristics used to identify them, such as a fingerprint, voiceprint, or retina or iris image, but the definition carries a blanket, unconditional exclusion for a physical or digital photograph, a video or audio recording, or any data generated from either, with no clawback for data generated to identify someone.

A faceprint or voiceprint extracted from a recording therefore falls outside both biometric data and sensitive data under Indiana law, regardless of the purpose for which it was extracted; only a biometric identifier captured directly, such as from a live scanner, triggers this consent duty.

What it asks of an app

Social media and minors

HEA 1408 (2026), social media accounts held by minors

cite House Enrolled Act No. 1408 (2026), amending Ind. Code tit. 24, art. 4 stage IMMINENT in force in 125 days effective 2027-01-01 source official Indiana General Assembly bill record, conference committee report

Requires covered social media providers, those using algorithmic content feeds with at least $1 billion in global revenue, to determine whether a user is an Indiana resident under 16 and to obtain verifiable parental consent before creating an account, and to lock safety settings limiting direct messages, search visibility, and targeted advertising for minor accounts.

Note and primary source

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.