Indiana Consumer Data Protection Act (INCDPA) enacted as Senate Enrolled Act 5 (SEA 5) of 2023 of the Indiana General Assembly + signed by Governor Eric Holcomb on 1 May 2023 + codified at Indiana Code Title 24 Article 15 (IC 24-15). Effective date: 1 January 2026 (delayed effective date allowing controllers and processors time to prepare). Indiana 7th US state to enact comprehensive consumer data privacy law following California (CCPA 2018/CPRA 2020) + Virginia (VCDPA 2021 effective 2023) + Colorado (CPA 2021 effective 2023) + Utah (UCPA 2022 effective 2023) + Connecticut (CTDPA 2022 effective 2023) + Iowa Consumer Data Protection Act (effective 2025) - and modelled closely on Virginia CDPA template with Connecticut/Iowa influences. Applicability per IC 24-15-2-1: applies to persons that conduct business in Indiana or produce products or services that are targeted to residents of Indiana and that during a calendar year (a) control or process personal data of at least 100000 Indiana consumers; or (b) control or process personal data of at least 25000 Indiana consumers AND derive more than 50 percent of gross revenue from the sale of personal data. Exemptions per IC 24-15-1-2: (1) State + political subdivisions; (2) financial institutions or data subject to Title V of the Gramm-Leach-Bliley Act (GLBA); (3) Covered Entity or Business Associate per HIPAA; (4) nonprofits; (5) institution of higher education; (6) data subject to FCRA Fair Credit Reporting Act; (7) data subject to FERPA Family Educational Rights and Privacy Act; (8) Driver Privacy Protection Act; (9) Farm Credit Act; (10) clinical trial data subject to Federal Common Rule; (11) employment data + B2B data exempted (controllers do not need to comply for employment + business contact information). Definitions: Consumer = natural person who is a resident of Indiana acting only in an individual or household context (NOT employees + commercial actors); Controller = natural or legal person that alone or jointly determines purpose and means of processing; Processor = entity that processes personal data on behalf of controller; Personal Data = any information that is linked or reasonably linkable to identifiable or identified natural person (NOT publicly available + NOT deidentified + NOT aggregated); Sensitive Data = data revealing racial or ethnic origin + religious beliefs + mental or physical health diagnosis + sexual orientation + citizenship/immigration status + genetic or biometric data processed to uniquely identify + precise geolocation + personal data from known child (under 13). Public + freely available via iga.in.gov. Coordinates with similar US state privacy laws (Virginia CDPA + Colorado CPA + Connecticut CTDPA + Iowa ICDPA + Texas TDPSA + Tennessee TIPA + Montana MCDPA + Oregon OCPA + New Jersey NJDPA + Delaware DPDPA + Minnesota CDPA + Maryland MODPA + Kentucky KCDPA + Rhode Island RIDPCPA + Nebraska NDPA) + federal sectoral laws (HIPAA + GLBA + FCRA + FERPA + COPPA + DPPA) + GDPR + India DPDP Act + state breach notification laws. INCDPA Scope + SEA 5 of 2023 + IC 24-15 + Applicability applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.