iQ Cookie State Law Series
Cookie & Privacy Law in Indiana
Educational purposes only — not legal advice. This guide is intended to help you understand Indiana’s data privacy law as it relates to cookie consent and website compliance. Laws change, and your specific situation may vary. Always consult a qualified legal professional before making compliance decisions. iQ Cookie is a technology tool, not a law firm.
The short version
Indiana’s Consumer Data Protection Act was signed back in May 2023 but gave businesses an unusually long runway — it did not take effect until January 1, 2026. That means it is one of the newest laws in this series to actually be enforceable, and it follows the business-friendly Virginia/Utah model closely, with a permanent 30-day cure period that never expires.
Indiana does not have a separate cookie law. Cookie compliance flows from the INCDPA itself — its opt-out and sensitive-data rules apply directly to cookies and tracking technology.
Who does it apply to?
The INCDPA covers businesses that conduct business in Indiana or target Indiana residents, and meet at least one of these thresholds:
Controls or processes personal data of 100,000 or more Indiana consumers during a calendar year.
Controls or processes data of 25,000 or more consumers AND derives more than 50% of gross revenue from selling personal data.
Nonprofits are exempt in Indiana, unlike Colorado and Delaware. Consumer counts only include people acting in an individual or household context — commercial and employment contacts do not count toward the threshold. GLBA and HIPAA-regulated data carry their usual exemptions.
Consumer rights
Indiana residents whose data is covered by the INCDPA have these rights:
Businesses must respond within 45 days, extendable by another 45 if reasonably necessary. There is no private right of action — only the Attorney General’s Consumer Protection Division can enforce.
What makes Indiana different
Permanent 30-day cure period. Unlike Colorado, Delaware, and Connecticut — all of which let their cure periods sunset — Indiana’s does not expire. Businesses always get a chance to fix a violation before the AG can seek penalties.
No GPC requirement. Indiana does not require businesses to recognize or honor Global Privacy Control or any other universal opt-out mechanism, even for covered entities.
Precise geolocation has a specific radius. Indiana defines "precise geolocation" as accurate to within a 1,750-foot radius — a bit tighter than Colorado’s roughly 1,850-foot standard, so check your location-based cookies against Indiana’s own line.
Nonprofits are fully exempt. Where Colorado and Delaware explicitly cover nonprofit organizations, Indiana leaves them out entirely — a notable difference if you run a nonprofit with an Indiana audience.
A long lead time before enforcement. Signed in 2023 but not effective until January 1, 2026, Indiana gave businesses roughly two and a half years of notice — among the longest runways of any state law in this series.
Sensitive data & children
Processing sensitive data requires opt-in consent before any collection begins. Sensitive data includes:
For known children under 13, opt-in consent is required for any processing of their data — COPPA-compliant parental consent satisfies this. For ages 13–17, businesses need opt-in consent specifically before selling that person’s data or using it for targeted advertising.
What this means for your cookies
| Cookie type | Requirement | What to do |
|---|---|---|
| Sensitive data cookies (geolocation, biometric, health) | Opt-in required | Gate these behind affirmative consent before they fire. |
| Targeted advertising cookies | Opt-out required | Provide a clear opt-out mechanism for sale and targeted ads. |
| GPC / opt-out signals | Not required | No INCDPA obligation, but honoring it keeps you consistent with other states you may also serve. |
| Any cookies — users 13–17 | Opt-in required | No targeted-ad or sale cookies without consent for known minors. |
| Analytics & functional cookies | No specific requirement | Disclose in your privacy policy. Confirm they are not building profiles that count as "sale." |
Enforcement
The Indiana Attorney General’s Consumer Protection Division has exclusive enforcement authority, working both from consumer complaints and its own independent reviews. Penalties run up to $7,500 per violation. Because the cure period is permanent rather than sunsetting like several of its peer states, businesses that respond promptly to a notice have a genuine, ongoing opportunity to fix problems before facing penalties.
Your action checklist
The law took effect January 1, 2026 — here is what to have in place now:
Check your thresholds. Do you process data on 100,000+ Indiana consumers, or 25,000+ while earning over half your revenue from data sales? If yes, you are in scope.
Audit your cookies. Identify which cookies touch sensitive data or power targeted advertising — those are the categories with specific compliance obligations.
Set up opt-in for sensitive data. Cookies collecting precise geolocation, biometric, or health data must be blocked until the user affirmatively consents.
Add a targeted advertising opt-out. A clear "Do Not Sell or Share" link or equivalent mechanism satisfies this requirement.
Flag users aged 13–17. Block targeted-ad and data-sale cookies for known minors without opt-in consent.
Update your privacy policy. Cover data categories, purposes, consumer rights including appeal, and whether data is sold or used for targeted advertising.
Review vendor contracts. Any processor handling Indiana resident data must be covered by a written agreement specifying processing instructions and confidentiality obligations.
iQ Cookie scans your site, flags gaps, and deploys a lightweight US-built consent banner.
iQ Cookie State Law Series · Guide 8 of 25 · Next: Iowa →