Back to Blog
Law UpdatesMarch 28, 202612 min readReviewed by the PrivacyLawMap editorial teamLast reviewed June 26, 2026

Iowa ICDPA Compliance 2026: Checklist, Thresholds & 90-Day Cure

Share:
Turn This Guide Into a Working Privacy SetupSponsored

Termly can generate and maintain your privacy policy, consent banner, and data-request workflow as requirements change.

Start Free with Termly

Quick answer

The Iowa Consumer Data Protection Act (ICDPA) took effect January 1, 2025 and remains one of the most business-friendly US state privacy laws: no correction right, no profiling opt-out, no GPC mandate, a 90-day consumer-request clock, and a permanent 90-day enforcement cure period. It applies if you process data of 100,000+ Iowa consumers, or 25,000+ while earning 50%+ of revenue from data sales. Core duties:

  • Honor access, deletion, portability, sale/targeted-ad opt-outs, and an appeal process for denied requests (no correction or profiling opt-out right).
  • Respond to consumer requests within 90 days — the longest window of any state.
  • Give clear notice and an opportunity to opt out before processing adult sensitive data; handle known children’s sensitive data under COPPA.
  • No universal opt-out (GPC) requirement and no data protection assessments are required.

Iowa’s Business-Friendly Approach to Data Privacy

The Iowa Consumer Data Protection Act (ICDPA) took effect on January 1, 2025, after being signed into law on March 28, 2023. As of June 26, 2026, Iowa is the only comprehensive state privacy law we track with both a 90-day consumer-request response window and a permanent 90-day attorney-general cure period.

Iowa is widely recognized as having enacted one of the most business-friendly comprehensive state privacy laws in the United States, offering fewer substantive consumer rights, a longer cure period, and more flexibility for businesses than most other state privacy laws.

If your company operates in Iowa or serves Iowa consumers, the ICDPA may apply to you — but its generous thresholds and enforcement provisions make compliance more straightforward than most state laws. Use our Privacy Law Calculator to check whether your business is covered.

Who Must Comply with the ICDPA?

The ICDPA applies to entities that conduct business in Iowa or produce products or services targeted to Iowa consumers, AND meet either of these thresholds:

  • Control or process personal data of 100,000 or more Iowa consumers during a calendar year, OR
  • Control or process personal data of 25,000 or more Iowa consumers AND derive over 50% of gross revenue from the sale of personal data

These thresholds use OR logic between the two tiers, meaning you only need to meet one of them to be covered. The 50% revenue requirement for the lower tier is the highest among all state privacy laws, significantly limiting which smaller businesses are subject to the law.

Exemptions

The ICDPA exempts several categories of entities and data types:

  • Entity exemptions: Government bodies, financial institutions subject to GLBA, entities covered by HIPAA, nonprofit organizations, and institutions of higher education
  • Data exemptions: Data governed by HIPAA, GLBA, FCRA, FERPA, DPPA, and certain employment and B2B contact data

Consumer Rights Under the ICDPA — A Limited but Appealable Set

Iowa grants consumers a narrower set of substantive privacy rights than most states, but it still requires an appeal process when a controller refuses to act on a request. Iowa residents have these rights:

  • Right to confirm and access — Confirm whether a controller is processing their personal data and access that data
  • Right to delete — Request deletion of personal data provided by the consumer
  • Right to data portability — Obtain a copy of personal data in a portable, readily usable format
  • Right to opt out — Opt out of the sale of personal data and targeted advertising
  • Right to appeal a refusal — If a controller declines to act, it must provide appeal instructions; appeals must be answered within 60 days

Critically, the ICDPA does not include:

  • No right to correction — consumers cannot request correction of inaccurate data
  • No right to opt out of profiling — unlike most other state laws

Controllers must respond to consumer requests within 90 days (the longest response window among state privacy laws), with one 45-day extension if reasonably necessary.

Key Business Obligations

Privacy Notices

Controllers must provide a reasonably accessible, clear privacy notice that includes: categories of personal data processed, purposes of processing, how consumers can exercise their rights, categories of data shared with third parties, and categories of third parties with whom data is shared.

Sensitive Data Notice and Opt-Out

Iowa is unusually lenient on adult sensitive data. Rather than requiring opt-in consent for adults, Iowa Code § 715D.4 requires clear notice and an opportunity to opt out before processing sensitive data for a nonexempt purpose. Sensitive data concerning a known child must be handled in accordance with COPPA.

Sensitive data under the ICDPA includes racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data used for identification, personal data collected from a known child, and precise geolocation data.

Data Processing Agreements

Controllers engaging data processors must establish written contracts governing: the nature and purpose of processing, the type of data subject to processing, the duration of processing, the rights and obligations of both parties, and requirements for confidentiality.

No Universal Opt-Out Requirement

The ICDPA does not require businesses to honor universal opt-out mechanisms such as Global Privacy Control (GPC). This is a significant distinction from states like California, Colorado, Connecticut, Montana, and Delaware. Check your GPC obligations across states with our GPC Compliance Checker.

No Data Protection Assessments

Unlike many state privacy laws, Iowa does not require controllers to conduct data protection impact assessments (DPIAs) for high-risk processing activities. This further reduces compliance burden for Iowa-covered businesses.

ICDPA Website Sale Check and Compliance Checklist

If your GSC, analytics, or ad-tech review is asking how to check if your website sells personal data under the ICDPA, start with Iowa’s narrow sale definition: sale means exchanging personal data for monetary consideration. The practical website audit is still important because targeted advertising and third-party transfers trigger privacy-notice and opt-out disclosures even when they do not meet Iowa’s sale definition.

Website practice ICDPA question Compliance action
Ad pixels, retargeting tags, or cross-site audience toolsAre you selling data for money, or engaging in targeted advertising?Disclose targeted advertising and give a clear opt-out method; do not rely on GPC as the required Iowa mechanism.
Lead forms, list rentals, or data broker transfersIs personal data exchanged for monetary consideration?Treat as a potential sale, map the recipient, and document the opt-out workflow.
Location SDKs, biometric identifiers, health signals, or child-directed featuresIs sensitive data processed for a nonexempt purpose?Provide clear notice and an adult opt-out opportunity; process known children’s data under COPPA.
Denied access, deletion, portability, or opt-out requestsDid the response include appeal instructions?Maintain an appeal channel and answer appeals within 60 days.

This website-focused checklist is the main difference between a generic privacy-policy refresh and an ICDPA compliance pass: it ties the threshold test, privacy notice, opt-out mechanisms, sensitive-data handling, and appeal workflow to the actual tracking and sharing tools on the site.

Enforcement and Penalties

The Iowa Attorney General has exclusive enforcement authority under the ICDPA. There is no private right of action.

  • Penalties: Up to $7,500 per violation
  • Cure period: 90 days — the longest cure period of any state privacy law

The 90-day cure period is permanent (no sunset clause), providing businesses ample time to address any alleged violations before the AG can pursue enforcement action. By comparison, states like California, Colorado, and Delaware have eliminated their cure periods entirely. View enforcement trends on our Enforcement Tracker.

How Iowa Compares to Other State Privacy Laws

Iowa’s ICDPA stands apart from other state laws in multiple ways:

  • Narrow substantive rights: No right to correction and no profiling opt-out; denied requests still require an appeal process
  • Longest cure period: 90 days with no sunset vs. 60 days in Tennessee, 30 days in Nebraska and Indiana
  • No GPC requirement: Businesses do not need to honor universal opt-out signals
  • No DPIAs required: Unlike California, Colorado, Connecticut, Virginia, and most other states
  • Sensitive-data opt-out model: Adult sensitive-data processing uses clear notice plus opt-out, while known children’s data is handled under COPPA
  • Highest data sale revenue threshold: 50% of gross revenue vs. 25% in most other states
  • Longest response window: 90 days to respond to consumer requests vs. 45 days in most states

Use our State Comparison Tool for a detailed side-by-side comparison with other state laws.

6-Step ICDPA Compliance Plan

  1. Assess applicability — Determine if your business processes data of 100,000+ Iowa consumers, or 25,000+ Iowa consumers while deriving 50%+ of revenue from data sales. Use the Privacy Law Calculator for a multi-state assessment.
  2. Update your privacy notice — Ensure it covers all categories of data collected, processing purposes, consumer rights, and third-party sharing categories.
  3. Implement opt-out mechanisms — Provide clear methods for consumers to opt out of targeted advertising and the sale of personal data.
  4. Handle sensitive data correctly — Provide clear notice and an opportunity to opt out before processing adult sensitive data for nonexempt purposes; process known children’s data in accordance with COPPA.
  5. Build consumer rights and appeal processes — Establish intake, verification, fulfillment, and appeal workflows for access, deletion, portability, and opt-out requests. Set up a 90-day response timeline and 60-day appeal timeline.
  6. Review processor contracts — Ensure all data processor agreements include ICDPA-mandated provisions governing processing scope, confidentiality, and data return or deletion.

For a detailed walkthrough, visit our Iowa Compliance Checklist.

Frequently Asked Questions

When did the Iowa Consumer Data Protection Act (ICDPA) take effect?

The ICDPA took effect on January 1, 2025. It was signed into law on March 28, 2023 as Senate File 262 and is codified at Iowa Code Chapter 715D. Iowa gave businesses an unusually long runway — nearly two years between signing and the effective date — consistent with its overall business-friendly posture.

Who has to comply with the ICDPA?

The ICDPA applies to businesses that operate in Iowa or target Iowa consumers and meet one of two thresholds: control or process personal data of 100,000+ Iowa consumers in a calendar year, or 25,000+ Iowa consumers while deriving over 50% of gross revenue from the sale of personal data. The 50% data-sale threshold is the highest of any state, so far fewer small businesses are pulled in than under laws like California’s. Check your status with our Privacy Law Calculator.

What are the penalties for violating the ICDPA?

The Iowa Attorney General can seek civil penalties of up to $7,500 per violation. Before bringing an action, the AG must give written notice and a 90-day cure period — the longest of any state privacy law and, unlike California, Colorado, or Oregon, it has no sunset date. There is no private right of action, so consumers cannot sue directly; only the AG enforces the law.

Does Iowa’s ICDPA require honoring Global Privacy Control (GPC)?

No. The ICDPA does not require businesses to recognize universal opt-out mechanisms such as Global Privacy Control, unlike California, Colorado, Connecticut, Oregon, and a growing list of other states. You must still offer a clear way to opt out of data sales and targeted advertising, but a browser-level GPC signal does not have to be treated as an automatic opt-out. Compare obligations across states with our GPC Compliance Checker.

How do I check if my website sells personal data under the ICDPA?

Inventory every ad pixel, retargeting script, analytics tag, lead-transfer partner, affiliate relationship, and data broker disclosure. Under Iowa Code § 715D.1, a sale means exchanging personal data for monetary consideration, so pure service-provider disclosures, affiliate transfers, consumer-directed disclosures, and merger or asset-transfer disclosures are excluded. Even when a transfer is not a sale, targeted advertising and sensitive-data processing can still require notice, opt-out, or COPPA controls under Iowa Code § 715D.4.

What does an ICDPA compliance checklist include?

A practical ICDPA compliance checklist has six steps: (1) confirm applicability against the 100,000-consumer or 25,000-consumer-plus-50%-data-sales thresholds; (2) publish a clear privacy notice covering data categories, purposes, rights, appeals, and third-party sharing; (3) provide opt-out methods for data sales and targeted advertising; (4) provide notice and opt-out for adult sensitive data, with COPPA handling for known children; (5) build access, deletion, portability, opt-out, and appeal workflows on a 90-day response clock; and (6) put ICDPA-compliant data processing agreements in place with vendors. The 6-step plan above expands each item.

Where can I find the full text of the Iowa ICDPA?

The ICDPA is codified at Iowa Code Chapter 715D, enacted by Senate File 262 (2023). The enrolled bill text and current code are available through the Iowa Legislature at legis.iowa.gov and the current Iowa Code Chapter 715D PDF. Source check: Last verified June 26, 2026 against Iowa Code §§ 715D.1, 715D.2, 715D.3, 715D.4, and 715D.8 (date_retrieved: 2026-06-26).

This article provides general educational information and is not legal advice. Consult qualified legal counsel for guidance specific to your organization. Published: March 28, 2026. Last verified: June 26, 2026.

Put This Guide Into PracticeSponsored

Termly can turn the requirements above into a maintained privacy policy, consent banner, and data-request workflow.

Start Free with Termly