Skip to main content
Indiana Privacy Law Traps That Catch Teams Off GuardPrivacy & Data Governance
5 min readFor Compliance Training Managers

Indiana Privacy Law Traps That Catch Teams Off Guard

The Indiana Consumer Data Protection Act (CDPA) took effect on January 1, 2026, and compliance teams are finding that good intentions alone don't prevent costly mistakes. The Indiana Attorney General's Office is prioritizing enforcement, and businesses that thought they had privacy compliance covered are discovering gaps in their approach.

These mistakes often stem from misunderstanding how the law applies to everyday operations, underestimating the technical work required, and assuming that existing practices will align with the new requirements.

Why These Mistakes Keep Happening

While privacy laws share common principles, each state has its own rules. The Indiana CDPA borrows from other state frameworks, creating a false sense of familiarity. Teams might assume they can simply replicate their California or Virginia approach.

Another issue is that privacy compliance involves legal, IT, marketing, and operations teams. Without a single team owning the full picture, critical requirements can fall through the cracks. Marketing might not know what IT needs to implement, legal might not realize what data HR is collecting, and nobody's sure who's responsible for responding to consumer requests within 45 days.

Mistake 1: Treating Website Contact Forms as Exempt

Why it happens: Teams focus on high-volume data collection like e-commerce transactions. A simple "Contact Us" form collecting a name, email, and message seems trivial by comparison.

The real consequence: That contact form collects personal information from Indiana residents. If your business processes data from 100,000 or more Indiana residents annually, or derives significant revenue from selling or processing personal data, the CDPA applies to all your collection activities. Even a basic contact form triggers obligations around privacy policies, consumer rights disclosures, and data minimization.

The specific fix: Audit every point where you collect personal information, including contact forms, newsletter signups, event registrations, and demo requests. Document what you collect, why you need it, and how long you keep it. Update your privacy policy to reflect these collection points. If you're close to the 100,000-resident threshold, track your Indiana resident count systematically.

Mistake 2: Assuming Your Existing Privacy Policy Covers You

Why it happens: You updated your privacy policy for GDPR or California's privacy law years ago. It looks comprehensive and mentions consumer rights and data security. You figure it's close enough.

The real consequence: The Indiana CDPA requires specific disclosures that generic policies miss. You must explain how Indiana residents can exercise their rights under the CDPA, including opt-out rights for selling, targeted advertising, and profiling. If your policy doesn't match your actual data practices or fails to mention Indiana-specific rights, you're exposed to enforcement action.

The specific fix: Review your current privacy policy against your actual data flows. Do you use customer data for targeted advertising? Does your marketing platform build behavioral profiles? Do you share data with third parties in ways that could qualify as "selling"? Your policy must describe these practices accurately and explain how Indiana residents can opt out.

Mistake 3: Ignoring the Technical Requirements for Opt-Outs

Why it happens: Teams think opt-out rights are just a policy statement. They add language to the privacy policy saying "you can opt out of targeted advertising" and consider the job done.

The real consequence: Operationalizing opt-outs requires technical implementation. When an Indiana resident opts out of targeted advertising, your systems must stop showing them targeted ads. This requires consent management tools, tracking mechanisms, and coordination between your website, marketing platforms, and data partners.

The specific fix: Work with your IT team and website provider to implement consent management tools. These tools need to capture opt-out choices, store them for future visits, and communicate those preferences to your marketing and analytics platforms. Test the implementation to confirm that opt-outs actually stop the targeted behavior.

Mistake 4: Skipping Data Protection Impact Assessments

Why it happens: The Data Protection Impact Assessment (DPIA) requirement sounds like paperwork. Teams assume they can address it later or treat it as a formality.

The real consequence: If you engage in targeted advertising, selling, or profiling, the CDPA requires you to complete a DPIA documenting the risks these activities create for consumers. This isn't optional. If the Attorney General investigates, one of the first things they'll ask for is your DPIA.

The specific fix: Identify which of your activities trigger the DPIA requirement. For each activity, document what data you use, what risks it creates, and what safeguards you've implemented to mitigate those risks. Treat the DPIA as a living document you update when your practices change.

Mistake 5: Building No Process for Consumer Requests

Why it happens: Consumer rights sound theoretical until someone actually exercises them. Teams assume requests will be rare and they can handle them ad hoc.

The real consequence: The CDPA gives you 45 days to respond to consumer requests to know, correct, delete, or obtain copies of their personal information. Without a defined process, requests sit in someone's inbox while the clock runs.

The specific fix: Designate a person or team responsible for handling CDPA requests. Create a documented workflow: how requests come in, how you verify identity, how you search for data across systems, how you apply exemptions, and how you deliver responses. Train your customer service and legal teams so they know how to route requests correctly.

Prevention Checklist

Use this checklist to catch mistakes before they become violations:

  • We've mapped all personal information we collect from Indiana residents, including contact forms and marketing tools.
  • Our privacy policy accurately describes our data practices and explains Indiana-specific consumer rights.
  • We've implemented technical tools to capture and honor opt-out requests for selling, targeted advertising, and profiling.
  • We've completed Data Protection Impact Assessments for activities that require them.
  • We have a documented process for responding to consumer requests within 45 days.
  • We've trained relevant teams (marketing, IT, customer service, legal) on their CDPA responsibilities.
  • We track whether we meet the 100,000 Indiana resident threshold or revenue thresholds that trigger coverage.
  • We've reviewed our vendor contracts to ensure third parties maintain appropriate security safeguards.
  • We can document our exemption if we believe the law doesn't apply to us.

The Indiana Attorney General's Office has signaled active enforcement, but businesses have a 30-day cure period after receiving written notice of a violation. That cure period is valuable, but it's not a substitute for getting compliance right from the start. Use it as a safety net, not a strategy.

Indiana Attorney General's Office

You Might Also Like