The Indiana Attorney General (AG) has published an official Consumer Data Bill of Rights summarizing the consumer rights, complaint process, and basic compliance expectations under Indiana’s Consumer Data Protection Act, which was enacted as SB 5 (Public Law 94-2023) and codified at Indiana Code Article 24-15.
The Attorney General’s Bill of Rights is consumer-facing guidance that summarizes the law’s requirements and explains how consumers may exercise their rights or file a complaint with the Attorney General.
This update applies to businesses that may be subject to Indiana’s Consumer Data Protection Act, which took effect on January 1, 2026.
What Employers Need to Do
- Confirm whether the organization is in scope, because Indiana Code Article 24-15 generally applies only if the business conducts business in Indiana or targets Indiana residents and meets one of the statute’s threshold tests.
- Review consumer-facing privacy notices and request channels, because covered controllers must provide a reasonably accessible privacy notice, explain how consumers may exercise and appeal rights, and provide one or more secure and reliable submission methods.
- Operationalize response, appeal, and authentication workflows, because controllers generally must respond within 45 days, may take one 45-day extension when reasonably necessary, and must provide an appeal path that includes a way for consumers to contact the Attorney General if an appeal is denied.
- Review sensitive-data, targeted-advertising, and data-sale practices, because Indiana requires opt-in consent for sensitive data and opt-out rights for targeted advertising, sale of personal data, and certain profiling.
- Update processor agreements and data protection assessment processes where needed, because the statute requires specific controller-processor contract terms and data protection impact assessments for certain high-risk processing created after December 31, 2025.
Overview
- Indiana’s privacy law was enacted through SB 5, became Public Law 94-2023, added IC 24-15, and took effect on January 1, 2026.
- The AG’s official Consumer Data Bill of Rights organizes the statute into practical consumer-facing themes—Right to Know, Right to Control, Right to Protect, and Right to Take Action—and explains how Hoosiers (people from Indiana or Indiana residents)may exercise rights or file complaints.
- The law applies to organizations that do business in Indiana or target Indiana residents and, during a calendar year, either process personal data of 100,000 or more Indiana consumers or process personal data of 25,000 or more Indiana consumers while deriving more than 50% of gross revenue from the sale of personal data, unless an exemption applies.
- For employers, one important scope point is that a “consumer” means an Indiana resident acting only in a personal, family, or household context, and the law separately exempts certain employment and application data used in that role.
- Covered controllers must be prepared to honor requests to confirm/access, correct, delete, obtain a copy or representative summary, and opt out of targeted advertising, sale of personal data, and certain profiling, all within the statute’s required timelines.
Why This Matters
The AG’s guidance gives covered businesses a clearer picture of how Indiana expects consumer rights to be communicated and operationalized now that the law is in effect.
Even though employee and applicant data are generally outside the consumer-rights framework, employers that also operate consumer-facing websites, apps, portals, or marketing programs may still need to comply with Indiana’s notice, request-handling, consent, and contract requirements.
Key Risks for Employers
- Consumer request operations risk: Employers that also collect Indiana consumer data through websites, apps, or customer-facing platforms may face compliance issues if they are not prepared to authenticate, respond to, and appeal requests within the statute’s deadlines.
- Sensitive-data and AdTech risk: Covered businesses may face exposure if they process sensitive data without consent or fail to provide clear opt-out mechanisms for targeted advertising, sale of personal data, or certain profiling.
- AdTech refers to the tools, software, platforms, and data practices used to deliver, target, measure, and optimize digital advertising.
- Vendor contract risk: Controllers may create avoidable compliance gaps if processor agreements do not include the contract terms and assistance duties required by IC 24-15.
- Enforcement risk: The Indiana Attorney General has exclusive enforcement authority and may seek injunctive relief, civil penalties of up to $7,500 per violation, and recovery of certain enforcement costs, although the law provides a 30-day notice-and-cure period before suit.
Additional Information
Indiana’s law includes several notable exemptions, including exemptions for state entities, financial institutions and data subject to GLBA, HIPAA covered entities and business associates, nonprofits, institutions of higher education, and certain public utilities, as well as data-level carveouts for categories such as HIPAA data, FCRA data, FERPA data, Driver’s Privacy Protection Act data, and specified employment/application-related data.
Indiana also requires controllers to conduct and document data protection impact assessments for high-risk processing, including targeted advertising, sale of personal data, certain profiling, sensitive-data processing, and other processing that presents a heightened risk of harm; those duties apply only to processing activities created after December 31, 2025.
The law provides no private right of action and preempts local rules and ordinances governing the processing of personal data by controllers or processors.
Source Reference
- Indiana SB 5 – Consumer data protection
- April 2023: Indiana Legislature Passes Consumer Data Privacy Bill (VensureHR)
Resources
Need help understanding how changes to employment laws will affect your business?
Learn more about how Vensure's Indiana PEO services can help you navigate complex employment laws and keep your business compliant.
This communication is intended solely for the purpose of conveying information. The present post might incorporate hyperlinks directing readers to websites managed by third-party entities. The inclusion of any links within this communication is meant to serve as points of reference and could encompass opinion articles from various law firms, articles from HR associations, official websites, news releases, and documents of government agencies, and other relevant third-party sources. Vensure has no authority over these external websites and bears no responsibility for their content. Furthermore, Vensure does not endorse the materials present on these websites. The contents of this communication should not be interpreted as legal advice or as a legal standpoint concerning specific facts or scenarios. Nor should it be deemed an exhaustive compilation of facts potentially pertinent to federal, state, or local laws. It is strongly advised that employers solicit legal guidance from an employment attorney when undertaking actions in response to any legal updates provided. This is due to the possibility of future alterations occurring in federal, state, and local laws, regulations, as well as the directives and guidelines issued by governing agencies. These changes may transpire at any given time, potentially rendering certain portions of the content within this update void or inaccurate.