Indiana Consumer Data Protection Act
Indiana CDPA Sensitive Data + DPA

Indiana Consumer Data Protection Act INCDPA-SensitiveData-Children-Consent-COPPA-DataProtectionAssessment-DPIA: Indiana CDPA Sensitive Data + Consent for Sensitive Categories + Children Under 13 + COPPA Coordination + Data Protection Assessment (DPA) + High-Risk Processing

Per IC 24-15-4 and IC 24-15-5 INCDPA imposes heightened obligations for sensitive data + children + and high-risk processing activities. (1) Sensitive Data Definition: per IC 24-15-1-29 sensitive data includes (a) personal data revealing racial or ethnic origin + religious beliefs + mental or physical health diagnosis + sexual orientation + citizenship or immigration status; (b) genetic or biometric data processed for the purpose of uniquely identifying a specific natural person; (c) personal data collected from a known child (under 13 years per COPPA alignment); (d) precise geolocation data (within radius of 1750 feet). (2) Sensitive Data Consent (IC 24-15-4-7): controller shall not process sensitive data concerning a consumer without obtaining the consumer consent or in the case of the processing of sensitive data concerning a known child processing such data in accordance with the federal Children Online Privacy Protection Act (COPPA 15 U.S.C. 6501 et seq.). Consent must be a clear affirmative action specific + informed + freely given. (3) Children Under 13: data processing of known child requires verifiable parental consent per COPPA + no specific INCDPA child age threshold beyond COPPA (note: some states define teen 13-17 protections; Indiana CDPA does NOT include teen protections unlike Maryland MODPA or California CCPA). (4) Data Protection Assessment (DPA) (IC 24-15-5-1): controller shall conduct and document a data protection assessment of each of the following processing activities involving personal data - (a) the processing of personal data for purposes of targeted advertising; (b) the sale of personal data; (c) the processing of personal data for purposes of profiling where such profiling presents a reasonably foreseeable risk of (i) unfair or deceptive treatment of or unlawful disparate impact on consumers; (ii) financial physical or reputational injury to consumers; (iii) physical or other intrusion upon the solitude or seclusion or the private affairs or concerns of consumers where such intrusion would be offensive to a reasonable person; (iv) other substantial injury to consumers; (d) the processing of sensitive data; (e) any processing activities involving personal data that present a heightened risk of harm to consumers. (5) DPA Content: shall identify and weigh the benefits that may flow directly and indirectly from the processing to the controller + consumer + other stakeholders + and the public against the potential risks to the rights of the consumer associated with such processing as mitigated by safeguards that can be employed by the controller to reduce such risks + including the use of de-identified data + the reasonable expectations of consumers + the context of the processing + and the relationship between the controller and the consumer whose personal data will be processed. (6) DPA Disclosure: Attorney General may request a DPA from a controller during an investigation. Coordinates with COPPA + GDPR DPIA Art 35 + DPDP DPIA + similar state privacy laws + FTC Act Section 5 + UDAP statutes. INCDPA Sensitive Data + DPA applies.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.