Skip to main content
The state of ai impact assessment
Indiana CDPA Compliance: What 30 Days to Cure Actually Looks LikePrivacy & Data Protection
5 min readFor Privacy Officers

Indiana CDPA Compliance: What 30 Days to Cure Actually Looks Like

The Challenge

On January 1, 2026, the Indiana Consumer Data Protection Act (CDPA) took effect, giving enforcement authority to the Indiana Attorney General's Office. For a mid-sized Midwest retailer operating mainly through digital channels, this created an immediate compliance gap. Their existing privacy infrastructure was designed for basic HIPAA carve-outs and general website disclosures, not the detailed consent management and data subject request workflows the CDPA mandates.

The company's privacy policy hadn't been updated in three years. Their marketing team ran retargeting campaigns across multiple platforms, and their customer service database contained personal information on about 150,000 Indiana residents. Critically, they lacked a documented process for handling deletion requests, opt-out preferences, or the Data Protection Impact Assessments (DPIAs) required for profiling activities.

When the Indiana Attorney General's Office announced active enforcement intentions, the compliance team faced a decision: invest in full CDPA alignment immediately or wait for enforcement action and rely on the 30-day cure window the statute provides.

The Environment and Constraints

The CDPA's cure provision gives businesses 30 days to correct violations after receiving written notice from the Attorney General and confirm remedial actions in writing. This isn't a grace period for initial compliance; it's a remedy for documented violations. The statute authorizes fines up to $7,500 per violation for failures not cured within that window.

The company operated under several constraints. Their marketing technology stack included third-party analytics tools, email service providers, and a customer data platform that shared personal information across vendors. Their IT team had limited privacy engineering experience, and they competed in a sector where customer acquisition costs made aggressive digital marketing essential to revenue targets.

They also faced the multi-state compliance problem: 19 other states had enacted similar but not identical privacy laws. Building a CDPA-only solution would create technical debt when California's requirements diverged from Indiana's on Special Categories of Data categories or when Colorado's DPIA thresholds differed from Indiana's profiling triggers.

The compliance lead needed to determine which data practices fell under CDPA scope, what technical controls were mandatory versus advisory, and whether their current vendor contracts shifted liability appropriately.

The Approach Taken

The team started with data mapping, not policy revision. They inventoried every system that collected personal information from Indiana residents, categorized the data types against CDPA definitions, and identified which processing activities constituted "selling," "targeted advertising," or "profiling" under the statute.

This revealed that their retargeting campaigns clearly met the targeted advertising definition. Their use of predictive lead scoring for B2B prospects crossed into profiling territory. And their practice of sharing customer email lists with co-marketing partners likely qualified as selling under the CDPA's broad definition.

For each of these activities, they completed DPIAs documenting the consumer privacy risks and their mitigation controls. These weren't perfunctory checkbox exercises; they used the DPIA process to identify gaps in their vendor security assessments and data retention policies.

On the technical side, they implemented a consent management platform that could handle opt-out signals across their marketing stack. This required coordination with their website provider to add preference centers, their email platform to honor suppression lists, and their analytics vendors to respect opt-out flags. The back-end integration took longer than the front-end UI work.

For data subject requests, they built a workflow that routed deletion, correction, and portability requests to the appropriate system owners with built-in 45-day deadline tracking. They didn't wait for the first request to test the process; they ran tabletop exercises with sample requests to identify handoff failures.

They updated their privacy policy to accurately describe current practices, not aspirational ones. Where their data minimization fell short of CDPA expectations, they acknowledged the gap internally and built a remediation roadmap rather than making false claims in the policy.

Results and Metrics

The company achieved documented CDPA compliance before enforcement actions materialized. Their DPIA process identified three vendor relationships where data security provisions didn't meet CDPA standards for processor agreements, prompting contract renegotiations.

The consent management implementation reduced their retargeting audience by about 18%, but conversion rates on the remaining audience improved because they'd eliminated low-intent traffic. The data subject request workflow processed 23 requests in the first quarter, all within the 45-day statutory window.

More importantly, the infrastructure they built for Indiana CDPA scaled to other state requirements with configuration changes rather than architectural overhauls. When they needed to add Colorado-specific DPIA triggers or modify opt-out mechanisms for California's "Do Not Sell" requirements, the underlying systems supported those variations.

What They Would Do Differently

The compliance lead acknowledged that waiting to see enforcement patterns before investing in full compliance was a calculated risk that didn't pay off. The 30-day cure window sounds generous until you're actually trying to implement consent management infrastructure, retrain customer service teams, and audit vendor contracts under a regulatory deadline.

They also underestimated the complexity of determining CDPA applicability. The statute's exemptions for HIPAA-covered entities and Gramm-Leach-Bliley-regulated activities created edge cases where partial exemptions applied to specific data sets but not others. Documenting why certain processing activities fell outside CDPA scope required more legal analysis than they'd budgeted.

In hindsight, they should have engaged their marketing technology vendors earlier in the process. Several vendors claimed CDPA compliance in their sales materials but couldn't actually support granular opt-out signals or provide sub-processor lists that met the law's data processing agreement requirements.

Takeaways for Your Team

If you're facing CDPA compliance or similar state privacy laws, don't treat the cure provision as a compliance strategy. It's designed for good-faith operational failures, not systematic gaps in your privacy program.

Start with honest data mapping that includes HR systems, sales databases, and marketing platforms. The CDPA's exemptions for employment data and certain regulated sectors create complexity, but you need to document your exemption claims with specifics, not assumptions.

For technical requirements, consent management and data subject request handling aren't optional if you run digital marketing. You can't manually process opt-outs at scale, and you can't meet 45-day response deadlines without workflow automation.

Complete DPIAs for any processing that involves profiling or automated decision-making. These assessments force you to articulate the actual privacy risks in your data practices and document your mitigation controls. Regulators will ask for them, and they're more useful than generic privacy impact assessments.

Finally, build for multi-state compliance from the start. The $7,500 per violation penalty under Indiana law is meaningful, but the real cost is maintaining separate privacy infrastructures for each state jurisdiction. Your consent management platform, data subject request workflow, and vendor management process should accommodate state-specific variations without requiring parallel systems.

The Indiana Attorney General's enforcement posture makes clear that CDPA compliance isn't theoretical. Your 30-day cure window starts when you receive a violation notice, not when the law takes effect.

Promotional banner for the Penetration Report Template Kit

You Might Also Like