Per IC 24-15-6 + IC 24-15-7 INCDPA enforcement is exclusively vested in the Indiana Attorney General with no private right of action. (1) Attorney General Exclusive (IC 24-15-7-1): the Attorney General shall have exclusive authority to enforce a violation of this article + no private cause of action permitted (distinguishes INCDPA from California CCPA which has limited private right for breach + similar approach as Virginia + Connecticut + Texas). (2) Right to Cure (IC 24-15-7-2): before initiating any action for a violation the Attorney General shall provide a controller or processor 30 days written notice identifying the specific provisions of this article the Attorney General alleges have been or are being violated + if within the 30 day period the controller or processor cures the noticed violation and provides the Attorney General an express written statement that the alleged violations have been cured + and that no further violations shall occur + the Attorney General shall not initiate an action against the controller or processor. The 30-day cure provision is uniquely persistent in INCDPA (does NOT sunset like Connecticut CTDPA 60-day cure that sunsets 31 December 2024 + Utah 30-day cure permanent + Virginia 30-day cure permanent + Texas 30-day cure permanent + California 30-day cure for CCPA sunset 1 January 2023 + persists for CPRA notice/right to cure narrower). (3) Civil Penalties (IC 24-15-7-3): if the Attorney General brings an action and prevails the Attorney General may seek injunction + civil penalty of up to USD 7500 per violation + reasonable expenses incurred in investigating and preparing the case including attorney fees - per Section 24-15-7-3 penalties go to General Fund of Indiana. (4) Compliance Demonstration: controller may demonstrate compliance through DPA + privacy notice + DPA cure record + audit + record-keeping. (5) Industry Self-Regulation: controllers may join industry self-regulation programs (e.g. NAI Network Advertising Initiative + DAA Digital Advertising Alliance Self-Regulation) to demonstrate compliance though not safe harbour. (6) AG Investigation Cooperation: when AG investigates controller or processor shall cooperate including production of DPA + DPIA + privacy notice + breach records + records of consumer rights requests + processor contracts. (7) Voluntary Compliance: AG may issue informal guidance + best practices + compliance assistance programs. Coordinates with similar US state privacy laws enforcement (Virginia + Colorado + Connecticut + Utah + Texas + Iowa + Tennessee + Montana + Oregon + Delaware + New Jersey + Minnesota + Maryland + Kentucky + Rhode Island + Nebraska) + FTC Section 5 + state UDAP statutes + India DPDP Sec 31 + GDPR Arts 83 + 84. INCDPA Enforcement + 30-Day Cure + AG Only + No PRA + USD 7500 Per Violation applies.
This control maps to 20 controls across 18 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 20 it maps to, and the evidence behind each claim, over MCP and REST.