Announcing Agent Commander - The First Integrated solution from Veeam + Securiti.ai enabling the scaling of safe AI agents

View

Veeamon Tour'26 - Data & AI Trust CONVERGE for the Agentic Era

View

Indiana Consumer Data Protection Act (INCDPA) Assessment

Author

Anas Baig

Product Marketing Manager at Securiti

The Indiana Consumer Data Protection Act (INCDPA) creates privacy obligations for certain organizations that conduct business in Indiana or target Indiana residents. This evaluation tool helps you assess whether INCDPA is likely relevant to your organization and how prepared you may be to meet its core requirements by guiding you through a series of essential questions.

The assessment considers factors such as whether your organization is in scope, whether exemptions apply, whether personal or sensitive data is processed, whether consumer rights workflows are in place, and whether your organization has appropriate governance, transparency, consent, security, assessment, and processor controls.

1. Does your organization conduct business in Indiana or offer products or services specifically targeted to Indiana residents?

INCDPA applies to organizations that conduct business in Indiana or offer products or services specifically targeted to Indiana residents. The law uses an Indiana-resident threshold test tied to consumer counts and sale-of-data revenue.

2. Does your organization meet at least one INCDPA threshold?

INCDPA generally applies if your organization controls or processes personal data of at least 100,000 Indiana consumers in a calendar year, or controls or processes personal data of at least 25,000 Indiana consumers and derives more than 50% of gross revenue from the sale of personal data.

3. Have you assessed whether any INCDPA entity or data exemptions apply to your organization?

INCDPA includes exemptions for certain public bodies, Gramm-Leach-Bliley Act (GLBA)-regulated financial institutions and affiliates, Health Insurance Portability and Accountability Act (HIPAA) covered entities and business associates, nonprofits, institutions of higher education, public utilities and affiliated service companies, and several categories of exempt data such as Health Insurance Portability and Accountability Act (HIPAA), research, Fair Credit Reporting Act (FCRA), Family Educational Rights and Privacy Act (FERPA), Driver's Privacy Protection Act (DPPA), Farm Credit Act, employment, and emergency-contact data.

4. Has your organization mapped its personal data across systems, vendors, and business processes and maintained an up-to-date inventory?

You should conduct regular data mapping to track what personal data is collected, where it is stored, how it flows, who can access it, and what safeguards apply. Maintaining an accurate inventory supports compliance, data governance, and breach response.

5. Does your organization classify personal data and sensitive data consistently, ideally with automation where possible?

INCDPA defines sensitive data to include racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data used to identify a person, personal data collected from a known child, and precise geolocation data. Classification helps operationalize the law’s stricter requirements.

6. Has your organization identified and documented the basis on which your organization processes personal data, including consent where required?

INCDPA is structured around controller duties. Your organization must document its legal basis for processing, specifically ensuring that consent is obtained prior to processing sensitive data and that clear notice and opt-out mechanisms are provided for targeted advertising, sales of personal data, and profiling.

7. Does your organization obtain valid opt-in consent before processing sensitive data, and COPPA-aligned parental consent where known children’s data is involved?

INCDPA requires consent before processing sensitive data, and processing sensitive data concerning a known child must be done in accordance with the Children's Online Privacy Protection Act (COPPA). Consent should be a clear affirmative action on the consumer's behalf that is freely given, specific, informed, and unambiguous agreement to process their personal data.

8. Does your organization provide a clear and reasonably accessible privacy notice that includes all required disclosures?

INCDPA requires a privacy notice that includes categories of personal data processed, purposes, how consumers exercise rights and appeal, categories of personal data shared with third parties, and categories of third parties. It also requires secure and reasonable means for consumers to submit requests.

9. Does your organization provide consumers with the rights and request channels required under INCDPA?

INCDPA gives consumers rights to confirm and access, correct inaccuracies, delete personal data, obtain portable copies, and opt out of targeted advertising, the sale of personal data, and certain profiling. Controllers generally must respond within 45 days, with one possible 45-day extension, and must provide an appeal process with a decision generally within 60 days.

10. Does your organization maintain reasonable administrative, technical, and physical safeguards appropriate to the volume and nature of the personal data?

INCDPA requires controllers to establish, implement, and maintain reasonable administrative, technical, and physical security practices appropriate to the volume and nature of the personal data at issue.

11. Does your organization conduct and document data protection impact assessments for heightened-risk processing?

INCDPA requires data protection impact assessments for targeted advertising, the sale of personal data, certain profiling, sensitive-data processing, and other processing activities presenting a heightened risk of harm. The assessment obligation applies to processing activities created or generated starting December 31, 2025.

12. Does your organization maintain policies and controls for de-identified and pseudonymous data?

Organizations using de-identified data should take reasonable measures to prevent re-identification, publicly commit not to re-identify, contractually bind recipients, and exercise oversight over downstream commitments.

13. Does your organization govern processors through contracts that include all INCDPA-required terms and support obligations?

INCDPA requires processor contracts to address instructions, purpose, type of data, duration, rights and obligations, confidentiality, deletion or return, information-sharing, assessments, and subcontractor controls.

14. Does your organization have a breach response program that complies with Indiana’s separate breach-notification law?

Indiana’s consumer privacy law should be paired operationally with Indiana’s breach-notification law. Indiana generally requires notice without unreasonable delay and not later than 45 days after discovery, subject to specified exceptions, and also requires notice to the Indiana Attorney General when resident notice is required.

 

15. Can your organization produce evidence for notices, rights handling, consent records, DPIAs, security controls, processor contracts, and breach response?

Documentation matters for defensibility and investigation response. Indiana’s law is enforced exclusively by the Attorney General, includes a 30-day cure period, and allows civil penalties of up to $7,500 per violation if issues are not cured.

Turn Your Indiana Privacy Assessment Into an Action Plan

Based on your responses, your organization may need to strengthen key areas of Indiana Consumer Data Protection Act readiness, including consumer rights workflows, consent management, privacy notices, opt-out handling, data protection assessments, security safeguards, and vendor governance.

Securiti helps privacy teams move from assessment to execution by automating data discovery, rights fulfillment, consent and preference management, assessment workflows, vendor oversight, and compliance evidence.

Get a personalized Indiana privacy readiness walkthrough to understand where your program stands, which gaps may require attention, and how to prioritize remediation.

BOOK MY INCDPA READINESS WALKTHROUGH

Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox


Share

More Stories that May Interest You
Videos
View More
Rehan Jalil, Veeam on Agent Commander : theCUBE + NYSE Wired: Cyber Security Leaders
Following Veeam’s acquisition of Securiti, the launch of Agent Commander marks an important step toward helping enterprises adopt AI agents with greater confidence. In...
View More
Mitigating OWASP Top 10 for LLM Applications 2025
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
View More
Top 6 DSPM Use Cases
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
View More
Colorado Privacy Act (CPA)
What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...
View More
Securiti for Copilot in SaaS
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
View More
Top 10 Considerations for Safely Using Unstructured Data with GenAI
A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....
View More
Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
View More
Navigating CPRA: Key Insights for Businesses
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
View More
Navigating the Shift: Transitioning to PCI DSS v4.0
What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...
View More
Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)
AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...

Spotlight Talks

Spotlight 1:02:06
Consent by proxy: When AI agents start deciding for us
Watch Now View
Spotlight 1:00:41
Future-Proofing for the Privacy Professional
Watch Now View
Spotlight 50:52
From Data to Deployment: Safeguarding Enterprise AI with Security and Governance
Watch Now View
Spotlight 11:29
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Watch Now View
Spotlight 11:18
Rewiring Real Estate Finance — How Walker & Dunlop Is Giving Its $135B Portfolio a Data-First Refresh
Watch Now View
Spotlight 13:38
Accelerating Miracles — How Sanofi is Embedding AI to Significantly Reduce Drug Development Timelines
Sanofi Thumbnail
Watch Now View
Spotlight 10:35
There’s Been a Material Shift in the Data Center of Gravity
Watch Now View
Spotlight 14:21
AI Governance Is Much More than Technology Risk Mitigation
AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Spotlight 12:!3
You Can’t Build Pipelines, Warehouses, or AI Platforms Without Business Knowledge
Watch Now View
Spotlight 47:42
Cybersecurity – Where Leaders are Buying, Building, and Partnering
Rehan Jalil
Watch Now View
Latest
What Anthropic’s Zero Trust for AI Agents Means for the Data Layer View More
What Anthropic’s Zero Trust for AI Agents Means for the Data Layer
Enterprises are deploying autonomous AI agents into production faster than they can secure them, and the best practices for securing this complex new landscape are still being...
DSPM in 2026: Why It Matters More Than Ever View More
DSPM in 2026: Why It Matters More Than Ever
In 2026, the convergence of cloud expansion, SaaS proliferation, and agentic AI adoption has fundamentally changed the data security challenge, making Data Security Posture...
Data Risk Management View More
What Is Data Risk Management?
Learn the ins and outs of data risk management, key reasons for data risk and best practices for managing data risks.
View More
An Overview of Bangladesh’s Personal Data Protection Act, 2026
Explore Bangladesh’s Personal Data Protection Act, 2026, including its key provisions, data subject rights, compliance requirements, and business impact.
EU AI Act: What Changes Now vs What Starts in 2026 View More
EU AI Act: What Changes Now vs What Starts in 2026
Understand the EU AI Act rollout—what obligations apply now, what phases in by 2026, and how providers and deployers should prepare for risk tiers,...
AI Governance Fails When Privacy Controls Stay Disconnected View More
AI Governance Fails When Privacy Controls Stay Disconnected
Access the whitepaper and learn how to operationalize core privacy controls across the AI lifecycle to ensure compliance, accountability, and defensible AI use.
You Can’t Protect What You Can’t See View More
You Can’t Protect What You Can’t See
Discover why disconnected security findings create hidden breach paths, why 57% of organizations can't prove data flows, and how to identify toxic risk combinations...
Agentic AI Security: OWASP Top 10 with Enterprise Controls View More
Agentic AI Security: OWASP Top 10 with Enterprise Controls
Map the OWASP Top 10 risks for agentic AI to enterprise-grade controls, identity, data security, guardrails, monitoring, and governance to stop autonomous AI abuse.
View More
Take the Data Risk Out of AI
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
View More
Navigating HITRUST: A Guide to Certification
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...
What's
New