Skip to main content

Indiana, Kentucky, and Rhode Island Privacy Laws Took Effect in 2026: What Small Businesses Need to Know

8 min readMike ThriftMike Thrift
Indiana, Kentucky, and Rhode Island Privacy Laws Took Effect in 2026: What Small Businesses Need to Know

If your business collects customer emails for a newsletter, runs targeted ads on Instagram, or stores order history in a CRM, you might assume state privacy laws are a coastal-state problem — California, maybe Colorado, definitely not the Midwest or New England. That assumption just got a lot more expensive to hold. As of January 1, 2026, Indiana, Kentucky, and Rhode Island all have comprehensive consumer data privacy laws on the books, bringing the total number of states with this kind of law to twenty. If your business has customers, employees, or website visitors in any of these three states, the rules that used to feel like "big company, big state" compliance now apply to you too.

Here's what actually changed, who has to comply, and what a small business owner should do about it this quarter.

Why Three States at Once?

Indiana, Kentucky, and Rhode Island didn't coordinate a surprise attack on small business paperwork — they're the latest wave in a pattern that's been building since Virginia passed the first "second generation" privacy law in 2021. Each new state law tends to borrow heavily from an earlier one (mostly Virginia's), with small tweaks to thresholds, enforcement, and consumer rights. That's good news for multi-state businesses: once you understand one of these laws, the other two are 80% familiar.

The bad news is the remaining 20%. Small differences in applicability thresholds, cure periods, and opt-out requirements mean you can't just copy a Virginia-compliant privacy policy and call it done in all three states. Each one has its own quirks.

Indiana Consumer Data Protection Act (ICDPA)

Indiana's law is the most business-friendly of the three, and it's worth understanding why.

Who it covers: For-profit businesses that conduct business in Indiana or target goods/services to Indiana residents, and that during a calendar year either:

  • Control or process personal data of at least 100,000 Indiana residents, or
  • Control or process personal data of at least 25,000 Indiana residents and derive more than 50% of gross revenue from selling personal data

That second threshold is the one that quietly catches smaller operations — a data broker or ad-tech company with a modest customer count but a data-sale-heavy revenue model can trip this wire well before it hits six figures of "customers."

What makes it business-friendly:

  • A permanent 30-day cure period — no sunset date, unlike some states where the grace period to fix a violation before enforcement expires after a few years
  • No requirement to recognize universal opt-out mechanisms like the Global Privacy Control signal (more on why this matters below)
  • Exclusive enforcement by the Indiana Attorney General — no private right of action, so individual consumers can't sue you directly over a violation
  • Standard exemptions for HIPAA-covered entities, nonprofits, higher education institutions, and certain financial institutions

If your business already complies with Virginia's or Colorado's privacy law, Indiana compliance is largely a matter of updating your privacy notice to reference the new law and confirming your existing opt-out and data subject request processes cover Indiana residents.

Kentucky Consumer Data Protection Act (KCDPA)

Kentucky's law took an unusual path: the legislature passed amendments (HB 473) before the original law even took effect, so businesses are complying with a pre-patched version from day one.

What HB 473 changed:

  • Healthcare data held by HIPAA-covered entities that already maintain it as protected health information is exempt from KCDPA requirements — closing a gap where health-adjacent businesses might have faced overlapping HIPAA and KCDPA obligations for the same data
  • The requirement to complete a Data Protection Impact Assessment (DPIA) for profiling activities was narrowed to only cases with unlawful disparate impact — meaning the profiling has the potential for disproportionate harm to members of a protected group, not any profiling activity whatsoever

Enforcement and penalties: Kentucky's Attorney General must issue notice and grant a 30-day cure period before pursuing enforcement. Like Indiana, this cure period does not currently have a sunset date, which is a meaningfully lower-risk posture than states where the cure period disappears after a set number of years. If a violation isn't cured, civil penalties can run up to $7,500 per violation — and "per violation" in privacy law usually means per affected consumer record, not per incident, so this can scale quickly with the size of a data set.

Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)

Rhode Island is the outlier of the three, with the lowest applicability threshold and the most consumer-friendly enforcement framing.

Who it covers: Entities that control or process personal data of at least 35,000 consumers, or 10,000 consumers if more than 20% of revenue comes from selling personal data. That 10,000-consumer/20%-revenue combination is a genuinely low bar — a small e-commerce business with a side revenue stream from selling customer lists to marketing partners could hit this threshold with a mailing list smaller than many local Facebook groups.

Key requirements:

  • Explicit opt-in consent required before processing sensitive personal data (health, biometric, precise geolocation, and similar categories), with a mechanism for consumers to both grant and revoke that consent
  • Consumers can opt out of targeted advertising, sale of personal data, and profiling — but Rhode Island does not require honoring universal opt-out signals like the Global Privacy Control, so opt-outs have to be handled on a site-by-site basis rather than through a single browser-level signal
  • Violations are treated as deceptive trade practices, with penalties up to $10,000 per violation

That "deceptive trade practices" framing is worth noting: it ties privacy violations to Rhode Island's existing consumer protection statute, which can carry its own enforcement patterns and precedent beyond what a purpose-built privacy law would create on its own.

The Common Thread: Risk Assessments

Across all three states, one obligation shows up consistently and trips up small businesses more than any single consumer right: the requirement to conduct a data protection assessment (sometimes called a DPIA) before engaging in "high-risk" processing activities. That typically includes:

  • Targeted advertising
  • Selling or sharing personal data with third parties
  • Processing sensitive data categories
  • Profiling that could result in legal or similarly significant effects on a consumer

If your business runs retargeting ads, sells or licenses any customer list, or uses automated tools to score or segment customers, you likely need a documented assessment on file — not something you generate reactively if an AG's office comes calling.

A Practical Compliance Checklist

You don't need outside counsel to get the basics in place. Start here:

  1. Count your exposure. For each state, estimate how many residents' personal data you control or process annually, and whether any meaningful share of revenue comes from selling data. This determines which laws actually apply to you.
  2. Update your privacy notice. Add references to Indiana, Kentucky, and Rhode Island residents' specific rights (access, correction, deletion, opt-out of sale/targeted advertising/profiling) if you're covered.
  3. Build (or confirm) a consumer rights request process. You need a way for consumers to submit — and for you to fulfill — access, deletion, and correction requests within the law's response window.
  4. Document your high-risk processing. If you run targeted ads, sell data, or profile customers, write down what you do, why, and what safeguards are in place. This is your data protection assessment.
  5. Separate sensitive data handling. Health, biometric, and precise location data need explicit opt-in consent in Rhode Island and heightened care generally — don't bundle this consent into a general terms-of-service checkbox.
  6. Watch your vendor contracts. If a payment processor, email platform, or ad network processes personal data on your behalf, your contracts with them should reflect their obligations as a data "processor" under these laws.

Why This Ties Back to Your Books

Compliance work like this often surfaces a less obvious problem: most small businesses don't have a clean answer to "which vendors have access to customer data, and what do we pay them?" That's really a bookkeeping question as much as a legal one. If your chart of accounts doesn't cleanly separate ad-tech spend, data processing fees, and CRM subscriptions from general software costs, you'll struggle to even identify which vendor relationships need a data processing addendum — let alone prove to a regulator that you know where customer data flows.

Plain-text accounting makes this kind of audit far easier than digging through a black-box SaaS dashboard. Because every transaction in Beancount is a human-readable, version-controlled entry, you can grep your ledger for every payment to an ad platform, data broker, or analytics vendor in seconds — turning "which of our vendors touch customer data?" from a multi-day scavenger hunt into a five-minute query.

Keep Your Compliance and Your Books in the Same Place

As more states pass privacy laws that reach smaller and smaller businesses, knowing exactly which vendors process customer data — and what you pay them — stops being optional. Beancount.io gives you plain-text accounting with full transparency and version history, so tracing your data-vendor relationships back through your financial records is as simple as searching a text file. Get started for free and keep your compliance story as clean as your books.

Share this article