Back to Blog
    Compliance

    Indiana, Kentucky & Rhode Island Privacy Laws 2026: Complete Compliance Deep-Dive

    Three new state privacy laws took effect January 1, 2026. This deep-dive covers Indiana's INPA, Kentucky's KCDPA, and Rhode Island's RIDPA — including unique requirements, thresholds, and compliance strategies.

    Indiana, Kentucky & Rhode Island Privacy Laws 2026: Complete Compliance Deep-Dive
    PolicyForge Team
    April 21, 2026
    10 min read
    Indiana privacy law
    Kentucky privacy law
    Rhode Island privacy law
    state privacy
    INPA
    KCDPA
    2026
    Share:

    Three New Privacy Laws You Can't Ignore

    On January 1, 2026, three more US states began enforcing comprehensive consumer privacy laws, bringing the total to 20 states with active privacy legislation. If your business serves customers in Indiana, Kentucky, or Rhode Island, compliance is now mandatory.

    This guide provides a detailed breakdown of each law's unique requirements and practical steps for compliance. PolicyForge's privacy policy generator has been updated to include all three laws.

    Indiana Consumer Data Protection Act (INPA)

    Who It Applies To

    The INPA applies to businesses that:

    • Conduct business in Indiana OR produce products/services targeting Indiana residents
    • Process personal data of at least 100,000 Indiana consumers, OR
    • Process personal data of 25,000+ consumers and derive over 50% of gross revenue from the sale of personal data

    Key Consumer Rights

    • Right to confirm whether data is being processed
    • Right to access personal data
    • Right to delete personal data
    • Right to data portability
    • Right to opt-out of targeted advertising, data sales, and profiling

    Unique INPA Provisions

    • 60-day cure period — Indiana provides businesses 60 days to cure violations before enforcement, the longest of any state law
    • Attorney General enforcement only — No private right of action
    • Sensitive data definition — Includes racial/ethnic origin, religious beliefs, health data, sexual orientation, citizenship status, and genetic/biometric data

    Kentucky Consumer Data Protection Act (KCDPA)

    Who It Applies To

    The KCDPA applies to businesses that:

    • Conduct business in Kentucky OR target products/services to Kentucky residents
    • Process personal data of at least 100,000 consumers, OR
    • Process data of 25,000+ consumers and derive over 50% of gross revenue from data sales

    Key Consumer Rights

    Kentucky's law closely mirrors Virginia's VCDPA, providing rights to access, delete, correct, obtain a copy, and opt-out of data sales and targeted advertising.

    Unique KCDPA Provisions

    • 30-day cure period — Standard cure period for addressing violations
    • Nonprofit exemptions — Certain nonprofit organizations are exempt
    • Data protection assessments — Required for targeted advertising, data sales, profiling, and sensitive data processing

    Rhode Island Data Privacy Act (RIDPA)

    Who It Applies To

    The RIDPA has notably broader applicability:

    • Businesses conducting business in Rhode Island OR targeting RI residents
    • Process personal data of at least 35,000 consumers (lower threshold than most states), OR
    • Process data of 10,000+ consumers and derive revenue from data sales

    Unique RIDPA Provisions

    • Lower thresholds — The 35,000/10,000 consumer thresholds are among the lowest in the country, capturing smaller businesses
    • Strong data minimization — Explicit requirements to limit data collection to what is reasonably necessary
    • Purpose limitation — Data can only be used for disclosed purposes without additional consent
    • No cure period after 2028 — The cure period sunsets, making future enforcement stricter

    Compliance Strategy for All Three Laws

    1. Determine applicability — Check if you meet the threshold for any of these three states based on consumer count or revenue sources.
    2. Update your privacy policy — Include state-specific disclosures. PolicyForge generates policies covering all three laws automatically.
    3. Implement opt-out mechanisms — Provide clear methods for consumers to opt out of data sales and targeted advertising.
    4. Conduct data protection assessments — Required for high-risk processing under all three laws.
    5. Train customer-facing staff — Ensure your team can handle data subject requests within required timeframes.
    6. Review vendor contracts — Update data processing agreements to meet state-specific requirements.

    For businesses already compliant with CCPA/CPRA requirements, achieving compliance with these three laws requires incremental rather than wholesale changes. PolicyForge's compliance tools identify specific gaps in your existing policies.

    Startups operating nationally should use our startup policy generator to create a single comprehensive policy that satisfies all 20 state laws from day one.

    PT

    PolicyForge Team

    Legal compliance expert contributing to PolicyForge insights.

    Legal Compliance

    Related Posts

    Compliance

    CPRA Enforcement Updates 2026: Fines, Audits & What Changed

    California's privacy agency has ramped up enforcement in 2026 with record fines and its first round of formal audits. Learn from recent enforcement actions and ensure your business avoids penalties.

    5/12/20269 min read
    Compliance

    20 US States Now Have Privacy Laws in 2026: Complete Business Compliance Guide

    With 20 US states now enforcing comprehensive privacy laws in 2026, businesses face a complex patchwork of compliance requirements. This guide breaks down every state law, key deadlines, and actionable steps to achieve multi-state compliance.

    3/17/202612 min read
    Compliance

    Complete GDPR Compliance Guide 2025: Everything Your Business Needs to Know

    Comprehensive GDPR compliance guide covering requirements, penalties, and practical steps. Includes checklist, real case studies, and automation tips.

    12/17/20255 min read

    Ready to generate your legal policies?

    Create compliant privacy policies, terms of service, and more with AI assistance.