Skip to main content
Promotional banner for the pentest readiness checklist
Privacy Officers Misread Indiana CDPA ScopePrivacy and Security
6 min readFor Privacy Officers

Privacy Officers Misread Indiana CDPA Scope

Many privacy officers treat new state privacy laws as a simple checklist. You update the privacy policy, add a few opt-out links, and think you're done. But the Indiana Consumer Data Protection Act (CDPA), effective January 1, 2026, reveals a different issue: teams are making operational mistakes that turn straightforward compliance into an enforcement risk.

The Indiana Attorney General's Office has signaled active enforcement. You get a 30-day cure period after receiving a written notice, but that assumes you've caught the violation before the regulator did. Most teams don't, because they're making predictable errors in scoping, documentation, and request handling.

Why These Mistakes Keep Happening

State privacy laws share similar structures, but each has different exemptions, thresholds, and definitions. Privacy officers often copy their California or Virginia approach and assume it translates directly to Indiana. It doesn't. The Indiana CDPA exempts businesses collecting personal information from fewer than 100,000 Indiana residents, uses specific language around "selling" and "profiling," and requires Data Protection Impact Assessments for certain marketing practices. If you're not reading the actual statute, you're guessing at your obligations.

Another reason these mistakes persist is that privacy officers treat compliance as a legal exercise instead of an operational one. You can draft a perfect privacy policy, but if your marketing team doesn't know how to handle an opt-out request or your HR system still processes Indiana applicant data the same way it did in 2025, you're exposed.

Mistake 1: Assuming HIPAA or GLBA Exemptions Cover All Your Data

Why it happens: The CDPA exempts businesses whose collection and use of personal information are already regulated by HIPAA and the Gramm-Leach-Bliley Act (GLBA). Privacy officers at healthcare providers and financial institutions see this and assume they're entirely exempt.

The consequence: Your HIPAA-regulated patient records are exempt. Your marketing database of website visitors who filled out a "Contact Us" form is not. If you're running targeted advertising to Indiana residents or using AI tools to score leads, you're performing CDPA-regulated activities with data that falls outside the federal exemptions.

The fix: Separate your data inventory by regulatory regime. HIPAA covers protected health information. GLBA covers consumer financial records. Everything else, including employee data used for non-employment purposes, marketing data, and customer service records, needs a separate CDPA analysis. Document which datasets fall under which exemption, and don't assume the exemption is organization-wide.

Mistake 2: Treating "Selling" as Only Direct Commercial Transactions

Why it happens: Most privacy officers think "selling" means literally selling a customer list to a data broker for money. The CDPA's definition is broader, including sharing personal information with third parties for valuable consideration, which can mean access to marketing tools, analytics platforms, or performance metrics.

The consequence: Your website uses third-party pixels, retargeting tags, or analytics platforms that share Indiana consumer data in exchange for advertising services. You haven't disclosed this as "selling" in your privacy policy, and you haven't built an opt-out mechanism. When the Indiana Attorney General's Office reviews your practices, you're out of compliance on both disclosure and consumer rights.

The fix: Audit every third-party script, pixel, and integration on your website. Ask your marketing team which platforms receive Indiana consumer data and what you receive in return. If you're getting advertising services, audience insights, or performance analytics in exchange for sharing personal information, treat it as "selling" under the CDPA. Update your privacy policy, add an opt-out mechanism, and complete a Data Protection Impact Assessment.

Mistake 3: Building Consumer Rights Workflows Without HR and Sales Input

Why it happens: Privacy officers design request intake forms and response workflows in isolation, assuming they understand all the systems that touch consumer data. They don't involve the teams that actually collect and use the data.

The consequence: An Indiana consumer submits a deletion request. Your privacy team processes it for the CRM and email marketing platform, but HR still has the consumer's job application in the applicant tracking system, and sales has their information in a lead scoring tool. You confirm deletion, but you've only deleted part of the record. The consumer complains to the Indiana Attorney General, and you can't demonstrate full compliance.

The fix: Map data flows before you build request workflows. Sit down with HR, sales, marketing, and IT. Identify every system that collects Indiana consumer data, who owns it, and how long it's retained. Build your deletion, correction, and access workflows to touch every system, not just the obvious ones. Test the workflow with a real request before you go live, and document each step.

Mistake 4: Skipping Data Protection Impact Assessments for "Low-Risk" Profiling

Why it happens: The CDPA requires Data Protection Impact Assessments for profiling activities. Privacy officers assume this only applies to high-stakes decisions like credit scoring or hiring. They skip the DPIA for marketing lead scoring, customer segmentation, or personalized pricing because it feels low-risk.

The consequence: The CDPA defines profiling as using automated tools to categorize consumers and make decisions that produce legal or similarly significant effects. "Similarly significant" is not defined. If your AI-driven lead scoring tool decides which Indiana consumers get access to premium support or priority service, you're profiling. If you can't produce a DPIA when the Indiana Attorney General asks for it, you're non-compliant.

The fix: Conduct a DPIA for any automated decision-making that segments Indiana consumers and affects their access to services, pricing, or opportunities. Don't interpret "similarly significant" narrowly. Document the processing activity, the data categories involved, the risks to consumers, and the safeguards you've implemented. Store the DPIA where you can produce it quickly if regulators ask.

Mistake 5: Relying on Your California Privacy Policy Without Indiana-Specific Updates

Why it happens: You've already updated your privacy policy for CCPA, VCDPA, or CPA. The Indiana CDPA looks similar, so you add "Indiana" to the list of states and assume you're covered.

The consequence: Your privacy policy describes California's "sale" opt-out but doesn't mention the CDPA's specific rights around targeted advertising and profiling. It explains how California consumers can submit requests but doesn't clarify that Indiana consumers have 45 days for you to respond. An Indiana consumer reads your policy, gets confused about their rights, and files a complaint. You're out of compliance on transparency, which is the entire point of the law.

The fix: Write an Indiana-specific section in your privacy policy or create a separate addendum. Explain the CDPA rights in plain language: the right to know, correct, delete, obtain a portable copy, and opt out of selling, targeted advertising, and profiling. Describe your response timeline (45 days). Link to your consumer rights request form. If your business qualifies for an exemption, explain why in the policy so consumers understand the scope.

Prevention Checklist

Use this checklist before the Indiana Attorney General's Office sends you a notice:

  • Complete a data mapping exercise that includes HR, sales, marketing, and IT systems
  • Identify which datasets fall under HIPAA, GLBA, or other exemptions and which do not
  • Audit third-party scripts and integrations for "selling," "targeted advertising," or "profiling" activities
  • Update your privacy policy with Indiana-specific language, rights, and timelines
  • Build consumer rights workflows that touch every system holding Indiana consumer data
  • Test deletion, correction, and access workflows with a real request
  • Conduct Data Protection Impact Assessments for all automated decision-making that segments consumers
  • Document your exemption analysis if you believe the CDPA does not apply to your business
  • Train marketing, sales, and HR teams on how to recognize and escalate CDPA requests
  • Set up a system to track opt-out requests and apply them to future interactions

You have a 30-day cure period if the Indiana Attorney General sends a notice, but that's not a compliance strategy. Fix these mistakes now, before you're defending your data practices under regulatory scrutiny.

Application Security Isn’t Optional Anymore.

You Might Also Like