Indiana Consumer Data Protection Act (ICDPA) Compliance
Pandectes GDPR Compliance helps Shopify stores meet Indiana ICDPA requirements by managing cookie consent, opt-outs of targeted advertising and sale, and consumer privacy requests.
Start Free
The #1 cookie consent app for Shopify, trusted by 185k stores
What is ICDPA?
The Indiana Consumer Data Protection Act (ICDPA) is Indiana’s comprehensive consumer privacy law. It was enacted in 2023 as Senate Enrolled Act 5 and is codified at Indiana Code 24-15. It closely follows the Virginia Consumer Data Protection Act, giving Indiana residents rights over their personal data and setting rules for the businesses that collect it.
Under the ICDPA, Indiana consumers have the right to:
- Confirm whether a business processes their personal data and get a copy or representative summary of the data they provided
- Correct inaccuracies in the personal data they provided
- Delete personal data provided by or obtained about them
- Receive their personal data in a portable, readily usable format
- Opt out of targeted advertising, the sale of their personal data, and profiling that produces legal or similarly significant effects
The law also defines sensitive data, which includes racial or ethnic origin, religious beliefs, health diagnoses, sexual orientation, citizenship or immigration status, genetic or biometric data used to identify a person, precise geolocation, and personal data of a known child.

Who does the ICDPA apply to?
The ICDPA applies to businesses that operate in Indiana or target products or services to Indiana residents and, in a calendar year, either process the personal data of at least 100,000 Indiana consumers, or process the personal data of at least 25,000 Indiana consumers and derive more than 50% of gross revenue from selling personal data.
Government bodies, financial institutions, HIPAA covered entities, nonprofits, institutions of higher education, and public utilities are among those exempt.

What happens if I don’t comply with the ICDPA?
The Indiana Attorney General has exclusive authority to enforce the ICDPA. The main points are:
- Cure period: before bringing an action, the Attorney General must give written notice and 30 days to cure the violation and confirm in writing that it will not happen again. This cure period is permanent and does not expire.
- Civil penalties: up to $7,500 for each violation, along with an injunction to stop the violation.
- Costs: the Attorney General may recover reasonable investigation expenses and attorney’s fees.
- No private right of action: consumers cannot sue a business directly under the ICDPA. They can file a complaint with the Attorney General.
When did the ICDPA go into effect?
The ICDPA took effect on January 1, 2026. Businesses that meet its thresholds must comply now.
Complying with the ICDPA
If your online store meets the ICDPA’s thresholds, the work that matters most for cookies and tracking looks like this:
- Offer an opt-out of targeted advertising and sale. Advertising pixels and tags that track visitors across other websites are typically targeted advertising. If you sell personal data or use it for targeted advertising, you must clearly and conspicuously disclose this and explain how consumers can opt out. A visible opt-out link and a cookie banner with clear choices are the usual way to do this. The ICDPA does not require businesses to honor universal opt-out signals such as Global Privacy Control.
- Get opt-in consent for sensitive data. You must not process sensitive data, such as precise geolocation, without the consumer’s consent. Data from a known child must be handled under the federal Children’s Online Privacy Protection Act.
- Publish a clear privacy notice. It must describe the categories of personal data you process, why you process it, the categories you share with third parties and who those third parties are, and how consumers can exercise their rights and appeal your decisions.
- Handle consumer requests on time. Provide at least one secure and reliable way to submit requests, without requiring a new account. Respond within 45 days, extendable once by another 45 days when reasonably necessary, and answer appeals within 60 days.
- Keep collection to what you need. Limit personal data to what is adequate, relevant, and reasonably necessary for the purposes you disclose, and protect it with reasonable security practices.
To make this easier, consider a Consent Management Platform (CMP) like Pandectes GDPR Compliance. It is built for Shopify stores and provides a cookie banner with opt-out options for US states, a “Do not sell or share my personal information” link, automatic cookie scanning and classification, a cookie declaration, consent logs, and data subject request handling. Region-specific banner settings let you show Indiana visitors the right experience based on their location.
Every business is different, so review your obligations under the ICDPA with legal counsel where appropriate.














