Privacy Policy
OVERVIEW
Scope and compliance requirements
The law applies to businesses that conduct business in Indiana or target Indiana residents with products or services and that:
- Control or process personal data of at least 100,000 consumers in a calendar year, or
- Control or process personal data of at least 25,000 consumers while deriving more than 50 percent of gross revenue from the sale of personal data.
The ICDPA does not apply to individuals acting in an employment or business-to-business capacity, or to government entities, nonprofits, and higher education institutions.
Exemptions and federal compliance
The ICDPA incorporates exemptions for data already governed by federal laws such as the Gramm-Leach-Bliley Act (GLBA), Health Insurance Portability and Accountability Act (HIPAA), and other existing privacy or security regulations. Businesses operating under these frameworks should still review their policies to ensure they meet state-level transparency and notice requirements.
CONSUMER RIGHTS AND SENSITIVE DATA PROCESSING
Consumers have the right to:
- Access their personal data.
- Correct inaccuracies.
- Delete personal data.
- Obtain a copy of their data in a portable format.
- Opt out of data processing for targeted advertising, sale of personal data, or profiling.
Controllers must obtain affirmative consent before processing sensitive data, which includes precise geolocation, racial or ethnic origin, biometric and genetic information, children’s data, and certain health information.
OBLIGATIONS AND DATA PROCESSING CONTRACTS
Covered entities must follow sound data governance principles, including:
- Limiting data collection to what is necessary for stated purposes.
- Implementing reasonable administrative, technical, and physical safeguards.
- Providing clear, accessible privacy notices.
- Conducting data protection assessments for high-risk processing activities.
- Maintaining binding contracts between controllers and processors that define responsibilities for data handling and security.
Enforcement and evolution
The Indiana Attorney General has exclusive authority to enforce the ICDPA.
- Civil penalties may reach $7,500 per violation.
- Covered entities receive a 30-day written cure period to correct violations before penalties are imposed.
- There is no private right of action, meaning consumers cannot directly sue under this law.
The ICDPA reflects an evolving model that builds on frameworks from Virginia, Colorado, and the European Union’s General Data Protection Regulation (GDPR).
Preparing for compliance
Businesses should:
- Review how personal data is collected, used, and shared.
- Update privacy policies for clarity and transparency.
- Establish written agreements with vendors that process consumer data.
- Maintain clear records of good-faith compliance to demonstrate readiness if reviewed by the Attorney General.
RESOURCES
FTC and NIST privacy guidance
Educational Resources for Accredited Businesses (Not Legal Advice)
This resource sheet provides links to third-party guidance to help businesses understand general privacy principles and best practices. These sources are widely recognized and used across industries to support privacy and data-protection efforts.
Federal Trade Commission (FTC)
Business Privacy, Data Security & Online Practices
https://www.ftc.gov/business-guidance/privacy-security
The Federal Trade Commission provides education for businesses on:
· Protecting consumer information
· Avoiding unfair or deceptive data practices
· Proper data collection, use, and disclosure
· Reasonable security safeguards
· Transparency in privacy policies and communications
This website offers practical examples and explanations to help businesses understand how privacy expectations are applied in real-world business operations.
National Institute of Standards and Technology (NIST)
NIST Privacy Framework
https://www.nist.gov/privacy-framework
The NIST Privacy Framework is a voluntary framework designed to help organizations:
· Identify privacy risks
· Manage personal data responsibly
· Improve internal privacy practices
· Align operations with leading privacy-risk principles
It provides structure for creating or improving a privacy program, regardless of business size or industry.
