Indiana, Kentucky & Rhode Island Privacy Laws 2026: Complete Compliance Deep-Dive
Three new state privacy laws took effect January 1, 2026. This deep-dive covers Indiana's INPA, Kentucky's KCDPA, and Rhode Island's RIDPA — including unique requirements, thresholds, and compliance strategies.

Three New Privacy Laws You Can't Ignore
On January 1, 2026, three more US states began enforcing comprehensive consumer privacy laws, bringing the total to 20 states with active privacy legislation. If your business serves customers in Indiana, Kentucky, or Rhode Island, compliance is now mandatory.
This guide provides a detailed breakdown of each law's unique requirements and practical steps for compliance. PolicyForge's privacy policy generator has been updated to include all three laws.
Indiana Consumer Data Protection Act (INPA)
Who It Applies To
The INPA applies to businesses that:
- Conduct business in Indiana OR produce products/services targeting Indiana residents
- Process personal data of at least 100,000 Indiana consumers, OR
- Process personal data of 25,000+ consumers and derive over 50% of gross revenue from the sale of personal data
Key Consumer Rights
- Right to confirm whether data is being processed
- Right to access personal data
- Right to delete personal data
- Right to data portability
- Right to opt-out of targeted advertising, data sales, and profiling
Unique INPA Provisions
- 60-day cure period — Indiana provides businesses 60 days to cure violations before enforcement, the longest of any state law
- Attorney General enforcement only — No private right of action
- Sensitive data definition — Includes racial/ethnic origin, religious beliefs, health data, sexual orientation, citizenship status, and genetic/biometric data
Kentucky Consumer Data Protection Act (KCDPA)
Who It Applies To
The KCDPA applies to businesses that:
- Conduct business in Kentucky OR target products/services to Kentucky residents
- Process personal data of at least 100,000 consumers, OR
- Process data of 25,000+ consumers and derive over 50% of gross revenue from data sales
Key Consumer Rights
Kentucky's law closely mirrors Virginia's VCDPA, providing rights to access, delete, correct, obtain a copy, and opt-out of data sales and targeted advertising.
Unique KCDPA Provisions
- 30-day cure period — Standard cure period for addressing violations
- Nonprofit exemptions — Certain nonprofit organizations are exempt
- Data protection assessments — Required for targeted advertising, data sales, profiling, and sensitive data processing
Rhode Island Data Privacy Act (RIDPA)
Who It Applies To
The RIDPA has notably broader applicability:
- Businesses conducting business in Rhode Island OR targeting RI residents
- Process personal data of at least 35,000 consumers (lower threshold than most states), OR
- Process data of 10,000+ consumers and derive revenue from data sales
Unique RIDPA Provisions
- Lower thresholds — The 35,000/10,000 consumer thresholds are among the lowest in the country, capturing smaller businesses
- Strong data minimization — Explicit requirements to limit data collection to what is reasonably necessary
- Purpose limitation — Data can only be used for disclosed purposes without additional consent
- No cure period after 2028 — The cure period sunsets, making future enforcement stricter
Compliance Strategy for All Three Laws
- Determine applicability — Check if you meet the threshold for any of these three states based on consumer count or revenue sources.
- Update your privacy policy — Include state-specific disclosures. PolicyForge generates policies covering all three laws automatically.
- Implement opt-out mechanisms — Provide clear methods for consumers to opt out of data sales and targeted advertising.
- Conduct data protection assessments — Required for high-risk processing under all three laws.
- Train customer-facing staff — Ensure your team can handle data subject requests within required timeframes.
- Review vendor contracts — Update data processing agreements to meet state-specific requirements.
For businesses already compliant with CCPA/CPRA requirements, achieving compliance with these three laws requires incremental rather than wholesale changes. PolicyForge's compliance tools identify specific gaps in your existing policies.
Startups operating nationally should use our startup policy generator to create a single comprehensive policy that satisfies all 20 state laws from day one.
PolicyForge Team
Legal compliance expert contributing to PolicyForge insights.
Recommended for You
Related Posts
CPRA Enforcement Updates 2026: Fines, Audits & What Changed
California's privacy agency has ramped up enforcement in 2026 with record fines and its first round of formal audits. Learn from recent enforcement actions and ensure your business avoids penalties.
20 US States Now Have Privacy Laws in 2026: Complete Business Compliance Guide
With 20 US states now enforcing comprehensive privacy laws in 2026, businesses face a complex patchwork of compliance requirements. This guide breaks down every state law, key deadlines, and actionable steps to achieve multi-state compliance.
Complete GDPR Compliance Guide 2025: Everything Your Business Needs to Know
Comprehensive GDPR compliance guide covering requirements, penalties, and practical steps. Includes checklist, real case studies, and automation tips.
Ready to generate your legal policies?
Create compliant privacy policies, terms of service, and more with AI assistance.