Law / United States / Indiana

Indiana

United States law applies in Indiana Indiana is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Indiana, described on this page below, applies here too.

15 of 16 named instruments researched to a stage, across five of the six areas of law we track: 12 in force and 3 enacted but not yet in force. As of 14 September 2026.

When they take effect12 of 15 carry a date, 3 do not. Earlier is before 2015.
Before 2015: 1 instrument (1 in force) earlier 2015: 0 instruments 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 3 instruments (3 in force) 2025: 0 instruments ’25 2026: 7 instruments (7 in force) 2027: 1 instrument (1 enacted but not yet in force) ’27 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 4
  2. Privacy law 5
  3. Scraping law 3
  4. Cybersecurity law 1
  5. Age gating law 2
  6. News aggregation law none researched

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law4 instruments, 4 in force

Research summary (225 words)

Indiana has no general statute requiring disclosure or labeling of AI-generated content outside the election context, and no chatbot-disclosure statute has been enacted; a 2025 health-care AI bill covering similar ground to the enacted downcoding law did not pass.

Indiana instead reaches AI through targeted amendments to existing criminal and civil statutes: House Enrolled Act 1133 of 2024 (Public Law 81-2024) added a disclaimer duty for campaign communications containing fabricated or AI-generated media of a candidate, and House Enrolled Act 1047 of 2024 (Public Law 79-2024) extended the criminal offense of distributing an intimate image, and the parallel civil action for disclosing nonconsensual pornography, to images created or altered by artificial intelligence.

Separately, Indiana's child-exploitation and child-pornography statute already reaches an obscene, computer-generated image of a fictional child, without requiring that the depicted child actually exist.

House Enrolled Act 1271 of 2026 (Public Law 88-2026) bars a health insurer from using an automated tool, including artificial intelligence, as the sole basis for downcoding a medical-necessity claim without human review, and requires disclosure when artificial intelligence is used to make an adverse prior-authorization determination or to downcode a claim.

Indiana Code Article 4-13.1 creates an AI task force and requires state agencies to inventory their own AI systems; that duty runs to state government's own use of AI and is not catalogued here as an instrument.

AI prohibited practices

Child Exploitation and Possession of Child Pornography, obscene simulated or computer-generated images

Ind. Code § 35-42-4-4current Indiana Code text, Indiana General Assembly

In force. Binds public and private bodies.

What this law does

Indiana's child-exploitation statute defines "image" to include a computer-generated image, and separately reaches simulated sexual conduct involving a representation that appears to be a child under eighteen, where the representation is obscene, without requiring that the child depicted actually exist.

Producing, disseminating, or possessing with intent to disseminate such an image is child exploitation, a Level 5 felony (a Level 4 felony on aggravating circumstances such as the depicted conduct including force or a victim under twelve), and knowingly possessing or accessing such an image is possession of child pornography, a Level 6 felony (a Level 5 felony on the same aggravating circumstances).

This reaches an AI-generated depiction of a fictional child in an obscene sexual context on the same terms as any other computer-generated image; the statute's own code history shows its most recent amendment in 2022, predating the current wave of AI-specific legislation, and the calendar date on which the simulated-image and computer-generated-image language quoted here first took effect is not confirmed.

What it requires

Distribution of an Intimate Image and Civil Action for Nonconsensual Pornography, extended to AI-generated images (House Enrolled Act 1047, 2024)

Ind. Code §§ 35-45-4-8, 34-21.5-2-1, 34-21.5-3official enrolled act text, Indiana General Assembly, and the current Indiana Code sections it amended

In force since 1 July 2024. Binds public and private bodies.

What this law does

House Enrolled Act 1047 amended the definition of "intimate image" that runs through both Indiana's criminal distribution-of-an-intimate-image statute and its civil nonconsensual-pornography-disclosure statute to include a photograph, digital image, or video of a person that was created or modified by a computer software program, artificial intelligence, application, or other digital editing tool, so that an AI-generated or AI-altered depiction of a real, identifiable person in an intimate context is treated the same as an authentic one.

Distributing such an image without the depicted person's consent, when the distributor knows or reasonably should know the person does not consent, is a Class A misdemeanor, elevated to a Level 6 felony on a prior unrelated conviction.

A depicted individual who is identifiable and suffered harm may separately bring a civil action for disclosing nonconsensual pornography, recovering the greater of actual and emotional-distress damages or statutory damages up to $10,000 per defendant, plus any of the defendant's monetary gain, punitive damages, attorney's fees, and injunctive relief. Both amendments took effect July 1, 2024 under the act's own effective-date clause.

What it requires

AI risk obligations

Downcoding of Health Benefits Claims, automated and AI decision-making (House Enrolled Act 1271, 2026)

Ind. Code § 27-1-52official enrolled act text, Indiana General Assembly

In force 84 days, effective 1 July 2026. Binds private bodies.

What this law does

A new Indiana Code chapter on downcoding of health benefits claims bars a health insurer, HMO, or dental preferred-provider plan from using an automated process, system, or tool, including artificial intelligence, as the sole basis to downcode a claim based on medical necessity, without a covered individual's medical record first being reviewed by an insurer employee or contractor; it likewise bars a provider from submitting a claim through such an automated tool without human review.

The insurer must disclose, in an easily accessible and readable manner, whenever artificial intelligence is used to make an adverse determination on a prior authorization request or to downcode a claim. The chapter does not apply to the Medicaid program or a Medicaid managed care organization. Enacted as House Enrolled Act 1271, it took effect July 1, 2026 under the act's own effective-date clause.

What it requires

AI transparency

Use of Digitally Altered Media in Elections (House Enrolled Act 1133, 2024)

Ind. Code § 3-9-8official enrolled act text, Indiana General Assembly

In force since 12 March 2024. Binds public and private bodies.

What this law does

If a campaign communication includes fabricated media, meaning audio, video, or an image that has been altered or artificially generated to convey a materially inaccurate depiction of a candidate that a reasonable person would not recognize as altered, the person who paid for the communication must include a disclaimer stating that elements of the media have been digitally altered or artificially generated.

The disclaimer requirements vary by medium: a printed or video disclaimer must be displayed continuously, and an audio disclaimer must be read at the start, the end, and every two minutes for a communication longer than two minutes.

A candidate depicted in noncompliant fabricated media may bring a civil action against the person who paid for or sponsored the communication, and against a disseminator who knowingly, intentionally, or recklessly removed the disclaimer, for actual damages, injunctive relief, and attorney's fees, on a clear-and-convincing-evidence standard.

The enrolled act declared an emergency and took effect upon passage; the Indiana General Assembly's own bill-actions record shows the Governor signed it March 12, 2024.

What it requires

Privacy law5 instruments, 4 in force, 1 enacted but not yet in force

Research summary (216 words)

The Indiana Consumer Data Protection Act (INCDPA), Ind. Code Art. 24-15 (codified caption "Consumer Data Protection," the popular INCDPA name is not itself codified text), is Indiana's comprehensive consumer-privacy regime, enacted as P.L.94-2023 (Senate Bill 5, 2023 Regular Session) and effective January 1, 2026 across every section of the article.

Genetic or biometric data processed to uniquely identify a specific individual is one of INCDPA's enumerated sensitive-data categories, but the Act's biometric data definition carries a blanket, unconditional exclusion for a photograph, or for a video or audio recording, or any data generated from either, with no clawback for data generated to identify someone, so a faceprint or voiceprint extracted from a recording falls outside biometric data, and therefore outside sensitive data, regardless of purpose.

Florida's FDBR shares this unconditional structure in the same batch, while Maryland's, Minnesota's, and New Jersey's biometric definitions each claw the data back. A separate, older statute, the Disclosure of Security Breach Act (Ind. Code Art. 24-4.9), governs breach notification and is enforced, like INCDPA, exclusively by the Indiana Attorney General, and a violation of either statute is not privately actionable.

INCDPA's 30-day cure right before an Attorney General enforcement action is mandatory, not discretionary, and carries no sunset date anywhere in the article, unlike several peer states' time-limited cure rights.

Breach notification

Disclosure of Security Breach Act

Ind. Code §§ 24-4.9-3-1, 24-4.9-3-3, 24-4.9-4-1, 24-4.9-4-2official Indiana statute text, Indiana Code Article 4.9, Indiana General Assembly

Commencement not set. Binds private bodies.

What this law does

A data base owner must disclose a breach of the security of a system to an affected Indiana resident if the owner knows, should know, or should have known that the unauthorized acquisition has resulted in or could result in identity deception, identity theft, or fraud affecting that resident, without unreasonable delay and no later than 45 days after discovering the breach.

A data base owner disclosing to more than 1,000 consumers must also notify nationwide consumer reporting agencies, and any disclosure at all triggers a required notice to the Indiana Attorney General.

Failing to make a required disclosure is a deceptive act actionable only by the Attorney General, with a civil penalty of up to $150,000 per deceptive act, and a separate, narrower duty to implement reasonable safeguards and dispose of records properly carries its own $5,000-per-act penalty, also enforced only by the Attorney General. This is a separate, pre-existing statute from INCDPA. The cited sections were added by P.L.125-2006, Securities and Exchange Commission (SEC).6, and have since been amended piecemeal: Ind.

Code sections 24-4.9-3-1 and 24-4.9-4-1 by P.L.137-2009, and section 24-4.9-3-3 by P.L.171-2022; section 24-4.9-4-2 has not been amended since 2006. Indiana's codified history notes carry only a public-law-and-year citation, with no day-precise commencement date, so no effective date is recorded here.

What it requires

Comprehensive regime

Indiana Consumer Data Protection Act (INCDPA), general applicability and controller duties

Ind. Code §§ 24-15-1-1, 24-15-4-1, 24-15-11-1official Indiana statute text, Indiana Code Article 15, Indiana General Assembly

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

INCDPA governs private-sector processing of Indiana residents' personal data. It applies to a person conducting business in Indiana, or producing a product or service targeted to Indiana residents, that during a calendar year controls or processes the personal data of at least 100,000 Indiana consumers, or of at least 25,000 Indiana consumers while deriving more than 50 percent of gross revenue from selling personal data.

A controller must limit collection to what is adequate, relevant, and reasonably necessary for the purposes disclosed to the consumer, and may not process personal data for an incompatible purpose without the consumer's consent. Article 15 also preempts local law: no city, county, or other local government may regulate a controller's or processor's processing of personal data.

What it requires

Data subject rights

Indiana Consumer Data Protection Act, consumer rights

Ind. Code § 24-15-3-1official Indiana statute text, Indiana Code Article 15, Indiana General Assembly

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

INCDPA gives an Indiana consumer the right to confirm and access their personal data, correct inaccuracies, delete data, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and profiling that produces a legal or similarly significant effect, exercisable against the controller.

A controller must respond without undue delay and no later than 45 days after receipt, with one additional 45-day extension available when reasonably necessary, and must inform the consumer of a decline and the means to appeal it on the same 45-day timeline. This is the ordinary 45-plus-45 response model used across most states, not the shortened timeline Florida uses.

What it requires

Enforcement supervision

Indiana Consumer Data Protection Act, Attorney General enforcement

Ind. Code §§ 24-15-10-1 to 24-15-10-4official Indiana statute text, Indiana Code Article 15, Indiana General Assembly

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

The Indiana Attorney General has exclusive authority to enforce INCDPA, with a civil penalty of up to $7,500 per violation plus recoverable investigation expenses. Before suing, the Attorney General must give a controller or processor 30 days' written notice identifying the specific provisions violated; if the violation is cured within that period and the controller or processor provides a written attestation of the cure, the Attorney General may not initiate an action.

This cure right is mandatory, not discretionary, and carries no sunset date anywhere in Article 15, unlike Maryland's, New Jersey's, and Minnesota's time-limited or discretionary cure provisions. The chapter creates no private right of action.

What it requires

Sensitive categories

Indiana Consumer Data Protection Act, sensitive data and biometric data definitions

Ind. Code §§ 24-15-2-4, 24-15-2-28, 24-15-4-1(5)official Indiana statute text, Indiana Code Article 15, Indiana General Assembly

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

INCDPA classifies racial or ethnic origin, religious belief, a health diagnosis made by a health care provider, sexual orientation, citizenship or immigration status, genetic or biometric data processed to uniquely identify a specific individual, a known child's data, and precise geolocation data as sensitive data requiring the consumer's consent before processing, except that a known child's sensitive data may instead be processed under COPPA's consent framework.

'Biometric data' means data from automatic measurement of an individual's biological characteristics used to identify them, such as a fingerprint, voiceprint, or retina or iris image, but the definition carries a blanket, unconditional exclusion for a physical or digital photograph, a video or audio recording, or any data generated from either, with no clawback for data generated to identify someone.

A faceprint or voiceprint extracted from a recording therefore falls outside both biometric data and sensitive data under Indiana law, regardless of the purpose for which it was extracted; only a biometric identifier captured directly, such as from a live scanner, triggers this consent duty.

What it requires

Scraping law3 instruments, 3 in force

Research summary (146 words)

Indiana is the one jurisdiction with a genuinely scraping-specific statute: House Enrolled Act 1360 (2026), effective July 1, 2026, which amends Indiana's Access to Public Records Act to add the state's first statutory definition of data scraping and to let government agencies build CAPTCHA-gated portals, deprioritize, delay, and surcharge automated public-records requests.

That is a real divergence from federal law, which has no analog regulating government responses to automated records requests. Indiana also has a computer-trespass statute phrased around lack of the owner's consent rather than lack of authorization, and a comprehensive privacy act (INCDPA) with the same publicly-available-information exclusion structure several peer states use. No database right or state text-and-data-mining exception exists; copyright is exclusively federal.

ToS enforceability and general unfair competition (the Indiana Deceptive Consumer Sales Act) rest on general law not independently confirmed against primary text, so neither earns its own instrument here.

Computer misuse

Indiana Computer Trespass, lack of owner's consent

Ind. Code § 35-43-2-3official text, Indiana General Assembly (iga.in.gov)

In force since 1 July 1986. Binds public and private bodies.

What this law does

Section 35-43-2-3(b) provides that a person who knowingly or intentionally accesses a computer system, computer network, or any part of either without the consent of the owner or the owner's licensee commits computer trespass, a Class A misdemeanor. This is phrased as lack of the owner's consent, a single-prong test with no separate exceeds authority prong, closer in structure to several peer states' single-prong wording though those use authorization rather than consent as the operative noun.

The same chapter separately punishes, at section 35-43-1-8, knowing and intentional unauthorized disruption or denial of computer system services. No Indiana appellate decision squarely construes section 35-43-2-3 against a scraper of an open public page.

What it requires

Crawl signals

House Enrolled Act 1360 (2026), data scraping definition and public-records anti-bot portal authorization

House Enrolled Act 1360 (2026), amending Ind. Code §§ 5-14-3, 5-14-4official enrolled act text, Indiana General Assembly (iga.in.gov)

In force 84 days, effective 1 July 2026. Binds government bodies.

What this law does

House Enrolled Act 1360 adds new IC 5-14-3-2(d), defining data scraping to mean use of an automated system to extract data from websites and other Internet accessible sources, Indiana's first statutory definition of the term. New IC 5-14-3-3.3 authorizes, but does not require, a public agency to build a records-request portal using a CAPTCHA or an equivalent mechanism for ensuring that a requestor is a human, and to verify a requestor's address and Indiana residency.

New IC 5-14-3-8.1 lets an agency give priority to Indiana residents and to civic, journalistic, academic, or personal-use requests, while delaying or surcharging requests identified as originating from out-of-state entities or automated systems. New IC 5-14-3-11 requires an agency to report suspected automated, phishing, or data-scraping requests to the state Public Access Counselor through a standardized mechanism.

The enrolled act's own text confirms it passed the General Assembly with a July 1, 2026 effective date on every section and no indication of a veto, contrary to reports that the bill died.

What it requires

Personal data

Indiana Consumer Data Protection Act (INCDPA), publicly available information exemption

Ind. Code Art. 24-15 (Senate Enrolled Act 5, 2023)official text, Indiana General Assembly (iga.in.gov)

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

IC 24-15-2-19(b) defines personal data to exclude de-identified data, aggregate data, or publicly available information.

IC 24-15-2-26 defines publicly available information as information that is lawfully made available through federal, state, or local government records, or that a business has a reasonable basis to believe is lawfully made available to the general public through widely distributed media, by the consumer to whom the information pertains, or by a person to whom the consumer has disclosed it, the same three-way structure several peer states use.

As in those states, the exemption excludes scraped government-record and public-media personal data from the statute's scope by definition rather than by carve-out. IC 24-15-1-1(a)(1) applies the Act to a person conducting business in Indiana or targeting Indiana residents that, during a calendar year, controls or processes personal data of at least 100,000 consumers. Enforcement is Attorney-General-only; there is no private right of action.

What it requires

Cybersecurity law1 instrument, 1 enacted but not yet in force

Research summary (733 words)

Indiana's private-sector security-topic presence is a single standalone duty sitting inside its breach-notification statute: Ind.

Code sec. 24-4.9-3-3.5, added to the Disclosure of Security Breach Act by P.L.137-2009 and amended by P.L.76-2017, requires a 'data base owner' (a person that owns or licenses computerized data including personal information of an Indiana resident) to implement and maintain reasonable procedures to protect and safeguard that personal information from unlawful use or disclosure, and to dispose of records containing it only by shredding, incinerating, mutilating, erasing, or otherwise rendering it illegible.

A data base owner already following its own compliance plan under a named federal privacy or security regime (the USA PATRIOT Act, Executive Order 13224, the Driver's Privacy Protection Act, the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, or Health Insurance Portability and Accountability Act (HIPAA)) is exempt from this duty, except that a current or former health care provider that claimed the HIPAA-based exemption remains bound for personal information, including health records, if its own compliance plan does not require, or is not implemented to provide, that protection once the provider stops being a HIPAA covered entity.

Indiana's codified history notes for this section carry only a public-law-and-year citation with no day-precise commencement date, so no effective date is recorded here, the same source-quality gap this jurisdiction's privacy-topic row records for the surrounding breach-notification sections. The duty sits structurally the same way New York's SHIELD Act splits across two topics: the Disclosure of Security Breach Act's title and its notification sections (Ind.

Code secs. 24-4.9-3-1 through 24-4.9-3-4, 24-4.9-4-1, 24-4.9-4-2) are already this jurisdiction's privacy-topic row, a breach-notification duty about personal data, while section 3-3.5's safeguards and disposal duty is a standalone security-programme provision inside that same article, so it is filed here instead. The Indiana Consumer Data Protection Act's own security clause, Ind.

Code sec. 24-15-4-1(3), requiring a controller to establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal data at issue, is likewise not repeated here: it is one subsection of INCDPA's own controller-duties chapter, the same shape as the General Data Protection Regulation's Article 32 and the Texas Data Privacy and Security Act's section 541.101(a)(2), and it is already researched as part of this jurisdiction's privacy-topic INCDPA row.

No enacted Indiana statute was located that sets security requirements a connected device or software product must meet before or after it reaches the market, comparable to California's, Oregon's, or Connecticut's connected-device statutes or the Cyber Resilience Act; a targeted search for an Indiana connected-device or IoT security law returned no citable statutory text on the Indiana General Assembly's or Justia's own Indiana Code pages, only unsourced secondary summaries that are not relied on for this finding, so it is treated as a researched absence rather than a gap in coverage.

Indiana has no general private-sector duty to report an exploited vulnerability or a security incident to an authority or to users: the state's only cyber-incident-reporting statute, enacted in 2021 and administered through the Indiana Office of Technology's IN-ISAC, binds only a political subdivision of Indiana state government to a 48-hour reporting duty, outside this profile's private-sector scope, and 2025's Senate Enrolled Act 472, effective July 1, 2025, likewise requires only a public entity's own technology-resources and cybersecurity policies, so neither is recorded as an instrument here.

Indiana's Insurance Data Security Law, Ind.

Code sec. 27-2-27 (P.L.130-2020, applicable after June 30, 2021), requires a 'licensee,' any person licensed, authorized to operate, or registered, or required to be, under Indiana's insurance title, to develop, implement, and maintain a comprehensive written information security program and to notify the insurance commissioner of a cybersecurity event, with an exemption for a licensee under 50 employees, under $5,000,000 in gross annual revenue, or under $10,000,000 in year-end total assets, no private right of action, and an affirmative tort defense for a compliant licensee; because it binds only an insurance-title licensee, a bound-party class no activity in the LexLint vocabulary expresses, it is recorded here rather than flagged on a guess or filed as an instrument.

Section 3.5 is enforced solely by the Indiana Attorney General as a deceptive act, with a civil penalty of up to $5,000 per deceptive act (a related series of acts or omissions counts as one), and it creates no private right of action, distinct from the $150,000-per-act penalty that governs a failure of the article's own breach-notification duty.

Security baseline statutes

Disclosure of Security Breach Act, data base owner's duty to maintain reasonable security procedures and dispose of records

Ind. Code sec. 24-4.9-3-3.5Official statute text, Indiana Code Article 4.9, Disclosure of Security Breach Act

Commencement not set. Binds private bodies.

What this law does

A data base owner, a person that owns or licenses computerized data including personal information of an Indiana resident, must implement and maintain reasonable procedures, including taking any appropriate corrective action, to protect and safeguard that personal information from unlawful use or disclosure.

A data base owner must also not dispose of or abandon records or documents containing unencrypted and unredacted personal information of Indiana residents without shredding, incinerating, mutilating, erasing, or otherwise rendering it illegible or unusable. A data base owner that maintains its own data security procedures under a listed federal privacy or security regime, and complies with that regime's own reasonable-procedures requirement, is exempt.

A current or former health care provider that claimed the Health Insurance Portability and Accountability Act (HIPAA)-based exemption remains bound for personal information, including health records, if its own compliance plan does not require, or is not implemented to provide, that protection once the provider stops being a HIPAA covered entity.

A knowing or intentional failure to comply is a deceptive act, actionable only by the Indiana Attorney General, and a related series of acts or omissions in violation of this section constitutes one deceptive act.

What it requires

Age gating law2 instruments, 1 in force, 1 enacted but not yet in force

Research summary (96 words)

Indiana's SB 17 (2024) requires age verification on adult oriented websites and has been in effect since 2024; after the U.S. Supreme Court upheld a materially identical Texas law in June 2025, the Seventh Circuit remanded Indiana's case with instructions to rule for the state.

A 2026 law (HEA 1408) separately requires large social media platforms to verify a user's age and Indiana residency and to obtain parental consent before a resident under 16 may hold an account, taking effect January 1, 2027. Indiana has not enacted an app store age verification or design code law.

Adult content age verification (AV)

SB 17 (2024), age verification for adult oriented websites

Ind. Code ch. 24-4-23official Indiana Code text and Indiana General Assembly bill record

In force since 1 July 2024. Binds private bodies.

What this law does

Requires an adult oriented website, where at least one third of content is harmful to minors, to use a reasonable age verification method before granting access, and bars retention of a user's identifying information after verification. The Attorney General or a harmed parent may sue for injunctive relief and damages.

Note and primary source

Social media and minors

HEA 1408 (2026), social media accounts held by minors

House Enrolled Act No. 1408 (2026), amending Ind. Code tit. 24, art. 4official Indiana General Assembly bill record, conference committee report

In force in 100 days, effective 1 January 2027. Binds private bodies.

What this law does

Requires covered social media providers, those using algorithmic content feeds with at least $1 billion in global revenue, to determine whether a user is an Indiana resident under 16 and to obtain verifiable parental consent before creating an account, and to lock safety settings limiting direct messages, search visibility, and targeted advertising for minor accounts.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.