iQ Cookie  State Law Series

State 8 of 25 · Indiana

Cookie & Privacy Law in Indiana

Published August 2026
Law in effect
Since January 1, 2026

Educational purposes only — not legal advice. This guide is intended to help you understand Indiana’s data privacy law as it relates to cookie consent and website compliance. Laws change, and your specific situation may vary. Always consult a qualified legal professional before making compliance decisions. iQ Cookie is a technology tool, not a law firm.

LAW
INCDPA
SB 5
SIGNED
May 1, 2023
Gov. Eric Holcomb
EFFECTIVE
Jan 1, 2026
Brand new this year
STATE RANK
#7
To enact a law

The short version

Indiana’s Consumer Data Protection Act was signed back in May 2023 but gave businesses an unusually long runway — it did not take effect until January 1, 2026. That means it is one of the newest laws in this series to actually be enforceable, and it follows the business-friendly Virginia/Utah model closely, with a permanent 30-day cure period that never expires.

Indiana does not have a separate cookie law. Cookie compliance flows from the INCDPA itself — its opt-out and sensitive-data rules apply directly to cookies and tracking technology.

Indiana General Assembly — Official Text
Indiana Consumer Data Protection Act, SB 5 — Indiana Code § 24-15

Who does it apply to?

The INCDPA covers businesses that conduct business in Indiana or target Indiana residents, and meet at least one of these thresholds:

THRESHOLD 1

Controls or processes personal data of 100,000 or more Indiana consumers during a calendar year.

THRESHOLD 2

Controls or processes data of 25,000 or more consumers AND derives more than 50% of gross revenue from selling personal data.

Nonprofits are exempt in Indiana, unlike Colorado and Delaware. Consumer counts only include people acting in an individual or household context — commercial and employment contacts do not count toward the threshold. GLBA and HIPAA-regulated data carry their usual exemptions.

Consumer rights

Indiana residents whose data is covered by the INCDPA have these rights:

Access
Confirm whether their data is being processed and receive a copy
Correct
Limited to data the consumer themselves provided
Delete
Request removal of personal data
Portability
Receive data in a usable, portable format
Opt out
Targeted ads, data sales, and profiling
Appeal
Challenge a controller’s decision

Businesses must respond within 45 days, extendable by another 45 if reasonably necessary. There is no private right of action — only the Attorney General’s Consumer Protection Division can enforce.

What makes Indiana different

Permanent 30-day cure period. Unlike Colorado, Delaware, and Connecticut — all of which let their cure periods sunset — Indiana’s does not expire. Businesses always get a chance to fix a violation before the AG can seek penalties.

No GPC requirement. Indiana does not require businesses to recognize or honor Global Privacy Control or any other universal opt-out mechanism, even for covered entities.

Precise geolocation has a specific radius. Indiana defines "precise geolocation" as accurate to within a 1,750-foot radius — a bit tighter than Colorado’s roughly 1,850-foot standard, so check your location-based cookies against Indiana’s own line.

Nonprofits are fully exempt. Where Colorado and Delaware explicitly cover nonprofit organizations, Indiana leaves them out entirely — a notable difference if you run a nonprofit with an Indiana audience.

A long lead time before enforcement. Signed in 2023 but not effective until January 1, 2026, Indiana gave businesses roughly two and a half years of notice — among the longest runways of any state law in this series.

Sensitive data & children

Processing sensitive data requires opt-in consent before any collection begins. Sensitive data includes:

Racial / ethnic origin
Religious beliefs
Health diagnosis
Sexual orientation
Citizenship / immigration status
Genetic data
Biometric data
Precise geolocation (1,750 ft)
Children’s data (under 13)

For known children under 13, opt-in consent is required for any processing of their data — COPPA-compliant parental consent satisfies this. For ages 13–17, businesses need opt-in consent specifically before selling that person’s data or using it for targeted advertising.

What this means for your cookies

Cookie typeRequirementWhat to do
Sensitive data cookies (geolocation, biometric, health)Opt-in requiredGate these behind affirmative consent before they fire.
Targeted advertising cookiesOpt-out requiredProvide a clear opt-out mechanism for sale and targeted ads.
GPC / opt-out signalsNot requiredNo INCDPA obligation, but honoring it keeps you consistent with other states you may also serve.
Any cookies — users 13–17Opt-in requiredNo targeted-ad or sale cookies without consent for known minors.
Analytics & functional cookiesNo specific requirementDisclose in your privacy policy. Confirm they are not building profiles that count as "sale."

Enforcement

$7,500
Max penalty per violation
30 days
Cure period — permanent, no sunset
AG only
No private right of action

The Indiana Attorney General’s Consumer Protection Division has exclusive enforcement authority, working both from consumer complaints and its own independent reviews. Penalties run up to $7,500 per violation. Because the cure period is permanent rather than sunsetting like several of its peer states, businesses that respond promptly to a notice have a genuine, ongoing opportunity to fix problems before facing penalties.

Your action checklist

The law took effect January 1, 2026 — here is what to have in place now:

1

Check your thresholds. Do you process data on 100,000+ Indiana consumers, or 25,000+ while earning over half your revenue from data sales? If yes, you are in scope.

2

Audit your cookies. Identify which cookies touch sensitive data or power targeted advertising — those are the categories with specific compliance obligations.

3

Set up opt-in for sensitive data. Cookies collecting precise geolocation, biometric, or health data must be blocked until the user affirmatively consents.

4

Add a targeted advertising opt-out. A clear "Do Not Sell or Share" link or equivalent mechanism satisfies this requirement.

5

Flag users aged 13–17. Block targeted-ad and data-sale cookies for known minors without opt-in consent.

6

Update your privacy policy. Cover data categories, purposes, consumer rights including appeal, and whether data is sold or used for targeted advertising.

7

Review vendor contracts. Any processor handling Indiana resident data must be covered by a written agreement specifying processing instructions and confidentiality obligations.

Not sure where your site stands with Indiana?

iQ Cookie scans your site, flags gaps, and deploys a lightweight US-built consent banner.

iQ Cookie State Law Series  ·  Guide 8 of 25  ·  Next: Iowa →