Skip to content

Cyber Liability by state

Indiana data breach notification law and cyber insurance

Direct answer

What is Indiana's data breach notification law?

Indiana's breach notification law (Ind. Code sect. 24-4.9 et seq.) requires businesses to notify affected residents without unreasonable delay, but not more than 45 days after discovery of the breach after a breach of personal information. Indiana requires businesses to notify affected residents and the Attorney General of breaches of unencrypted personal information without unreasonable delay, and in no case more than 45 days after discovery.

Reviewed by Cornerstone Staff28 years of financial services state licensing experienceLast verified July 29, 2026

What the statute requires

Indiana requires businesses to notify affected residents and the Attorney General of breaches of unencrypted personal information without unreasonable delay, and in no case more than 45 days after discovery. Cyber liability insurance generally funds the forensics, notification, and legal review this statute requires.

Consumer notification deadline
Without unreasonable delay, but not more than 45 days after discovery of the breach
Regulator notice
Notify the Indiana Attorney General without unreasonable delay, but not more than 45 days after discovery of the breach.
Credit bureau notice
Notify consumer reporting agencies when a breach requires notice to more than 1,000 residents.
Safe harbor
Notification is not required if the compromised data was encrypted and the encryption key was not acquired.
Enforcement
Violations are deceptive acts enforceable by the Attorney General, who may seek civil penalties for each deceptive act.

Statutes and sources

  • Indiana Disclosure of Security Breach Law

    Ind. Code sect. 24-4.9 et seq.

Regulator: Indiana Attorney General . Last verified 2026-07-29 from the official source .

Get Indiana coverage handled

Share a few details and an agent will respond within one business day.