Iowa Consumer Data Protection Act (ICDPA)
· About Iowa Consumer Data Protection Act (ICDPA)
Key Takeaways
- The Iowa Consumer Data Protection Act (ICDPA) applies to persons conducting business in Iowa or targeting Iowa residents when they control or process at least 100,000 consumers’ data, or 25,000 consumers’ data and derive more than 50% of gross revenue from sale of personal data.[2][10]
- The ICDPA has been in force since 1 January 2025, and the current Iowa Code chapter shows that effective date; no 2025–2026 delay or extension appears in the primary sources reviewed.[2][4]
- Covered controllers must provide consumers rights to access, delete, obtain a copy, and opt out of sale, targeted advertising, and certain profiling, subject to statutory exceptions.[2][6]
- The Iowa Attorney General has exclusive enforcement authority, and the law provides a 90-day cure period before an enforcement action may be filed.[10]
- Maximum civil penalties are up to $7,500 per violation, and the statute does not create a private right of action.[10]
- The statute contains broad exemptions for state and local government bodies, financial institutions, and data subject to HIPAA, FERPA, GLBA, and certain other sectoral laws.[2][6]
What It Is
Scope and enforcement
The ICDPA is Iowa’s comprehensive consumer privacy law governing the collection, processing, sale, and protection of personal data of Iowa consumers by covered controllers and processors.[2][6] It is enforced exclusively by the Iowa Attorney General.[10]
Dates
The law was enacted in 2023 and, as codified in Iowa Code chapter 715D, is effective 1 January 2025.[2][4] The primary sources reviewed do not show any 2025–2026 amendment delaying that effective date.[2][4][13]
Phase-in milestones
The statute’s operative consumer-rights and controller-obligation provisions became effective 1 January 2025.[2][4] The law also includes a pre-enforcement cure period, which means alleged violations may be cured within 90 days after written notice from the Attorney General.[10]
Who Must Comply
Applicability thresholds
The ICDPA applies to a person conducting business in Iowa or a person producing products or services targeted to Iowa residents if, during a calendar year, they either control or process personal data of at least 100,000 consumers, or control or process personal data of at least 25,000 consumers and derive more than 50% of gross revenue from the sale of personal data.[10]
Extraterritorial reach
The law is not limited to Iowa-incorporated or Iowa-headquartered entities; it reaches out-of-state businesses that target Iowa residents and meet the processing or revenue thresholds.[10]
Exemptions
The ICDPA exempts a wide range of entities and data categories, including state and local government bodies, certain nonprofits, institutions of higher education, financial institutions regulated under GLBA, and data already governed by statutes such as HIPAA, FERPA, the Farm Credit Act, and certain clinical research rules.[2][6]
Core Requirements
- Consumer rights handling. Controllers must provide a mechanism for consumers to confirm processing, access personal data, delete personal data, obtain a portable copy, and opt out of sales, targeted advertising, and certain profiling.[2][6]
- Privacy notice. Controllers must publish a reasonably accessible privacy notice that discloses the categories of personal data processed, the purposes of processing, how consumers may exercise rights, categories of data shared with third parties, and categories of third parties.[2][6]
- Data minimization and purpose limitation. Controllers may collect only personal data that is adequate, relevant, and reasonably necessary in relation to the disclosed purposes.[2][6]
- Sensitive data safeguards. Controllers must obtain consumer consent before processing sensitive data, and the statute treats children’s data and certain other sensitive categories with heightened protection.[2][6]
- Processor contracting. Controllers must use contracts with processors that set out instructions, confidentiality obligations, deletion or return provisions, and audit/access terms aligned to the processing relationship.[2][6]
- Security and risk-based governance. Controllers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal data processed.[2][6]
- Appeals process. Controllers must provide a process for consumers to appeal a denial of a rights request and describe how to contact the Attorney General if the appeal is denied.[2][6]
Deadlines and Penalties
| Milestone | Date | What applies | |---|---:|---| | Enactment and codification | 2023 | Iowa enacted chapter 715D as a comprehensive consumer privacy law.[4][10] | | Effective date | 1 January 2025 | Core consumer rights, controller duties, and enforcement framework became operative.[2][4] | | Cure period after notice | 90 days | Controller or processor may cure alleged violations before the Attorney General files suit, if cure is feasible.[10] |
The maximum civil penalty is $7,500 per violation.[10] The statute is enforced by the Iowa Attorney General, and it does not provide a private right of action for consumers.[10] The law also authorizes injunctive and declaratory relief through civil enforcement, so compliance failures can create operational risk beyond monetary penalties.[10]
How to Comply
- Map data and determine scope. Inventory personal data, classify sensitive data, and confirm whether the business meets the 100,000-consumer or 25,000-consumer-plus-revenue threshold.
- Build a rights intake workflow. Create authentication, request tracking, identity verification, deadline management, and appeal handling for access, deletion, copy, and opt-out requests.
- Update notices and vendor contracts. Refresh the privacy notice and amend controller-processor agreements to match ICDPA requirements.
- Implement minimization and retention controls. Use data retention schedules, collection limits, and purpose documentation to ensure processing stays tied to disclosed purposes.
- Strengthen security controls. Align baseline safeguards with ISO 27001 for the security management system, and use NIST CSF 2.0 to structure governance, identify, protect, detect, respond, and recover functions.
- Operationalize AI and profiling oversight. If the business uses profiling, targeted advertising, or automated decision tools, document logic, human review paths, and opt-out handling.
- Use a management-system lens for privacy governance. ISO 42001 is not required by the ICDPA, but it maps well where AI systems process personal data and can support accountability, documentation, and lifecycle controls.
- Test and train. Run periodic tabletop exercises for consumer requests, breach overlap scenarios, and Attorney General inquiry response, then train customer support, marketing, and engineering teams.
Related Regulations
- Virginia Consumer Data Protection Act. The ICDPA resembles Virginia’s law in rights and controller duties, but Iowa’s thresholds and enforcement structure differ in important details.[10]
- Colorado Privacy Act. Colorado is more prescriptive on universal opt-out and certain profiling governance, so multi-state programs should not assume ICDPA compliance alone is enough.[6]
- California Consumer Privacy Act / CPRA. California imposes broader notice and sensitive-data rules, plus a private right of action for certain security breaches, which Iowa does not.[10]
- Federal sectoral laws such as HIPAA and GLBA. These laws can exempt data or entities from ICDPA coverage, so sector classification can change the compliance perimeter.[2][6]
- Iowa data-breach law. ICDPA governance should be coordinated with Iowa’s breach-notification framework because security incidents can trigger both privacy and breach-response obligations.[2][6]
FAQ
Does the ICDPA apply to companies outside Iowa?
Yes, if they conduct business in Iowa or target Iowa residents and meet the statutory processing or revenue thresholds.[10] The law is therefore extraterritorial in practical effect, not limited to Iowa-headquartered organizations.[10]
Does the ICDPA give consumers a right to delete data?
Yes. Consumers can request deletion of personal data, subject to statutory exceptions that preserve certain operational, legal, and security-related uses.[2][6] Controllers need a documented process to evaluate and respond to those requests.
Is there a private right of action under the ICDPA?
No. Enforcement is reserved to the Iowa Attorney General.[10] Consumers can exercise rights and escalate denied appeals, but they cannot sue directly under the ICDPA.[10]
What is the cure period under the ICDPA?
The Attorney General must give written notice and allow 90 days to cure alleged violations before bringing an enforcement action, if cure is feasible.[10] That does not eliminate the violation; it delays suit and creates a remediation window.[10]
Are employee or B2B data covered?
The primary Iowa statutory text excludes some data contexts and sectoral categories, so coverage depends on the type of data and the entity’s status.[2][6] Organizations should not assume workforce or business-contact data are fully outside scope without checking the statutory exemptions and definitions.
Did Iowa delay the ICDPA in 2025 or 2026?
No delay appears in the current codified chapter or the primary sources reviewed; the effective date remains 1 January 2025.[2][4][13] Any claim of a later delayed effective date would need a specific enacted amendment, and none is reflected in the cited official materials.[2][4]
Sources
- Iowa Code chapter 715D, Consumer Data Protections (official codified text)
- Iowa legislative enactment, Senate File 262 (enrolled bill)
- Iowa Code chapter 715D PDF (official text snapshot)
- Washington & Lee / Wilson Sonsini overview of the Iowa law
- Privacy Rights Clearinghouse overview of the Iowa Consumer Data Protection Act
- Mintz state consumer privacy law report
- Exterro summary of Iowa’s consumer privacy law
- Termly overview of the Iowa Consumer Data Protection Act
Put it into practice
- Generate the policy: Iowa CDPA policy generator (generatepolicy.com)
- Buy the policy pack: State Privacy Law Checklist (cyberpolicy.shop)
- Build it yourself: 2026 US Privacy Program Workbook (ciso.diy)