Skip to content
Coverage

Data rights

Indiana Consumer Data Protection Act

Sub-nationalUS-INDerived or secondary source

Indiana, United States

Rule id
data.us-in
Version
1.0.0
In force from
January 1, 2026
Last read against its sources
August 5, 2026
Countries bound
United States

In plain language

What this regime says.

Indiana Consumer Data Protection Act gives Indiana residents access, deletion, portability and opt-out rights, with a 45-day response deadline and no private right of action.

Who is covered

Residents of Indiana acting in an individual or household context. Employee and business-to-business data is excluded in every state except California.

What you get

Your data, its deletion, or an opt-out from sale and targeted advertising. No money — enforcement belongs to the Attorney General.

Where claims go wrong

  • Skipping the internal appeal and going straight to the Attorney General.
  • Writing a letter when setting Global Privacy Control would have done the job in thirty seconds.
  • Assuming employment data is covered. Outside California it is not.
The official claim route

Authority

Every citation,
with its pinpoint.

A claim that cites “EU law” gets filed. A claim that cites Article 7(1)(c) gets answered. These are the exact coordinates this entry rests on.
  1. Ind. Code art. 24-15 (Consumer Data Protection)Indiana Code, Title 24, Article 15URL verified 2026-08-05IC 24-15-3, IC 24-15-4

Sources

Where a figure is indexed, converted or published by a regulator rather than fixed in the instrument, the provenance is recorded separately. Anything marked as a modelled estimate is exactly that — a model, not a statutory number.

What it imposes

Clocks, defences and the ladder.

A rule module builds these while it evaluates, because a limitation period depends on which forum is open to you. What follows is the structure this regime produces — deliberately with no dates and no figures, because those belong to your facts rather than to the law.

The clocks it starts

  • Indiana Consumer Data Protection Act: deadline for the controller to respondINCDPA: the controller must respond without undue delay and in any event within 45 days of receipt.Ind. Code art. 24-15 (Consumer Data Protection) — IC 24-15-3, IC 24-15-4Response due
  • Indiana Consumer Data Protection Act: extended deadline if the controller notified an extensionA single extension of 45 days is available where reasonably necessary, but the controller must notify you of the extension and the reason for it within the original 45-day period.Ind. Code art. 24-15 (Consumer Data Protection) — IC 24-15-3, IC 24-15-4Response due

What it entitles you to, beyond money

  • Compliance with your access requestConfirmation of whether the controller processes your personal data, and access to it. Most of these statutes give access to the data itself rather than merely to categories, but the level of detail varies — ask explicitly for the data, the categories of third parties it was disclosed to, and the purposes.right to access

What the other side will say

Each of these is a refusal this regime lets a counterparty attempt, paired with the answer to it. Reading them before you write is worth more than any amount of polish on the letter itself.

"We are not a covered business"

high likelihood

We do not meet the applicability thresholds in your state's law, so we are not required to respond to your request.

What answers it

Make them say which threshold they fall under, in writing. The thresholds differ sharply between states — Texas and Nebraska use a small-business test rather than a revenue figure, Montana and Delaware have low consumer-count thresholds, and a company that sells personal data is usually covered at a much lower volume. A business that will not identify the threshold it relies on is worth reporting to the Attorney General for exactly that reason.

They ignore the appeal too

high likelihood

(silence)

What answers it

Good. Almost every one of these statutes requires the controller, when it denies an appeal, to give you a written explanation AND a mechanism to contact the Attorney General. Silence on an appeal is therefore two violations, not one, and it converts a complaint about a request into a complaint about the statutory appeal machinery — which is the sort of thing enforcement divisions actually act on.

Endless identity verification

high likelihood

We cannot action your request until you verify your identity. Please send a copy of your passport, a utility bill, and a selfie holding your ID.

What answers it

A controller may use reasonable measures to verify identity, but it may only ask for information it actually needs and already holds a basis to check. Demanding a passport scan from someone whose account you identify by email address is disproportionate and is itself a data-minimisation problem. Offer to verify through the same channel you already use to log in, state that you consider the demand excessive, and note that the response clock is running.

"We hold no personal data about you"

high likelihood

A search of our systems returned no personal data relating to you.

What answers it

Ask for that in writing, signed, together with a description of the systems searched and the search terms used. A nil return is a substantive answer that the controller must stand behind, and it is frequently wrong: it usually means one production database was searched and backups, CRM, marketing, support tickets, call recordings, and third-party processors were not. Name the systems you believe hold your data, including any you have interacted with.

"We are only a service provider / processor"

medium likelihood

We process this data on behalf of our business customers. Direct your request to them.

What answers it

A processor still has to assist the controller and, in most of these statutes, to help the consumer reach the controller. Ask for the identity and contact details of the controller. If they will not tell you who they process for, they are asserting a status whose only condition they refuse to evidence.

Blanket confidentiality or trade-secret refusal

medium likelihood

The information you have requested is commercially confidential / contains our trade secrets / is proprietary.

What answers it

Confidentiality and intellectual-property carve-outs are narrow and must be applied item by item, not as a blanket. The correct response is redaction of the protected element and disclosure of the rest, with a schedule explaining what was withheld and why. Ask for that schedule.

Refusal because the data mentions someone else

medium likelihood

We cannot disclose these records because they contain the personal data of other individuals.

What answers it

The presence of third-party data is a reason to redact, not to refuse. The controller must consider whether it can disclose with the third party removed, whether the third party has consented, and whether it is reasonable to disclose without consent. A blanket refusal on this ground is not a lawful answer.

"Your request is manifestly excessive"

medium likelihood

Your request is manifestly unfounded or excessive, so we are refusing it / charging a fee.

What answers it

The burden of showing that a request is manifestly unfounded or excessive is on the controller, and it is a high bar — the regulator guidance treats it as exceptional, not as a routine response to a broad request. Ask the controller to state, in writing, the specific grounds and the evidence for them. If you have made only one request, say so. A single, first, ordinary request is not excessive.

Where to take it next

  1. Written request to Sample ControllerSend it to the named data-protection contact or privacy team, in writing, and keep proof of the date. If the organisation has a designated Data Protection Officer, address it to them by title. Use the word "request" and name the right you are exercising.Claim directtypically 45 days
  2. Internal appeal / complaint to the controllerINCDPA requires the controller to establish an appeal process for a refused request, to respond to your appeal in writing with the reasons, and — this is the part people miss — to give you a way to contact the Indiana Attorney General if the appeal is denied. Use the appeal. Skipping it is the most common reason a state complaint goes nowhere.Internal appealtypically 45 days
  3. Complain to the Indiana Attorney Generalthe Indiana Attorney General takes complaints from individuals about a specific organisation's handling of a specific request. It is free. Attach your original request, proof of the date you sent it, and anything the organisation sent back.Regulatortypically 120 daysofficial page

Documents

What this regime can produce.

Every one of these is a document you send yourself, in your own name. Duesday never writes to anybody on your behalf and is never anyone’s agent.

The same claim type elsewhere

Other rights in the same countries

Does this one reach your facts?

The engine runs every regime that could apply at once and reconciles them, rather than making you guess which page to read.

Not a law firm. Not legal advice. You send it yourself. This page describes a law; it is not advice about your situation and no outcome is promised.