Journal · Field notes
The Indiana privacy law most shops can ignore
Indiana's Consumer Data Protection Act took effect January 1, 2026, but it only covers businesses that handle 100,000 Indiana residents' data a year, a bar almost no single-location shop clears.
Indiana became the twentieth state with a comprehensive privacy law on January 1 this year. The number that decides whether it touches your shop is 100,000.
That's how many Indiana residents' personal data a business has to control or process in one calendar year before the Indiana Consumer Data Protection Act applies at all. A business that sells personal data outright only needs 25,000 residents, provided data sales make up more than half its revenue. Every other business needs six figures.
What is the Indiana Consumer Data Protection Act?
The law lives in the Indiana Code as Article 15. It gives Indiana residents rights over data companies hold on them: the right to see it, correct it, delete it, and opt out of targeted advertising and data sales. Indiana's attorney general, Todd Rokita, enforces it.
Indiana is not an outlier here. Twenty states now have a law like this one, a wave that started with California in 2018. Kentucky and Rhode Island passed their own versions the same year Indiana did, both effective the same date: January 1, 2026.
None of that changes what matters to a shop in Indianapolis: whether you clear the 100,000 mark.
Does it apply to your shop?
Take a gym in Carmel with a membership app. Names, emails, phone numbers, payment details, digital waivers, workout history. That is exactly the kind of personal data the law describes.
I ran the numbers on that gym. Say it signs 40 new Indiana members a month, every one of them someone the gym has never had in its system before. That's 480 new people a year. At that pace, the gym would need 208 years to reach 100,000 people in a single calendar year, which is the only way the count works under the statute: 208 years of adding 40 brand-new Indiana residents a month, every month, without ever counting a repeat customer twice.
Most single-location businesses in Indianapolis, from a bookstore in Zionsville to a brewery in Broad Ripple, never come close, even counting every customer who ever walked in, every email subscriber, and every person who filled out a waiver.
The law also carves out entire categories of business: nonprofits, banks, insurers, hospitals and clinics already covered by HIPAA, colleges, and government agencies. If you run one of those, the exemption applies regardless of size.
What happens if your shop crosses the threshold?
Say a business does cross it, or violates a right the law grants Indiana residents anyway. Enforcement runs through one office. The attorney general can seek a civil penalty of up to $7,500 per violation, plus the cost of investigating the case.
Indiana wrote in a cure period that never expires. Before the state can sue, it has to send 30 days of written notice naming the exact violation. Fix the problem inside that window and confirm it in writing, and the case stops there. A lot of state privacy laws let that cure right disappear after a year or two, once lawmakers decide businesses have had enough time to comply. Indiana's stays open, section 24-15-10-3, no sunset date attached.
Do this anyway
None of this means a privacy policy written in 2019 is fine forever. Two things are worth ten minutes each, threshold or no threshold.
Read your own privacy policy, if your site has one, and check it describes what you do with a customer's email address. Most don't match reality anymore.
Then look at your point-of-sale system. If Square, Toast, or Clover has quietly turned years of transactions into a mailing list, decide on purpose whether to use it. We wrote about exactly that a few weeks ago.
Being exempt from Indiana's privacy law doesn't mean you have nothing to explain when a customer asks what you do with their email.
Twenty states have a law like Indiana's now, and more join the list most years. The shop that's exempt today might not be exempt in five years. Better to know where the privacy policy lives before then.
Sources
| # | Source | What it backed up |
|---|---|---|
| 1 | Indiana Code, Article 15: Consumer Data Protection | The 100,000/25,000-resident thresholds, the January 1, 2026 effective date, the $7,500-per-violation penalty, and the unexpiring 30-day cure period (IC 24-15-10-3). |
| 2 | Hunton Andrews Kurth, "Indiana Privacy Law To Take Effect January 1, 2026" | Confirmation of the applicability thresholds and the HIPAA, GLBA, and entity-level exemptions. |
| 3 | Ketch, "Data privacy laws: what to expect for 2026" | Indiana as the twentieth state with a comprehensive privacy law, alongside Kentucky and Rhode Island. |
| 4 | Indiana Attorney General, Consumer Data Protection Bill of Rights | Confirmation that the attorney general's office is the sole enforcement authority under the act. |
| 5 | Luminest, "There are 2,000 email addresses in your Square account" | Background on how point-of-sale systems accumulate customer data without an owner noticing. |