IA

Iowa Privacy Law

Iowa Consumer Data Protection Act

Effective: January 1, 2025ActiveReviewed by PrivacyLawMap editorial teamLast verified: January 1, 2025

Overview

The Iowa Consumer Data Protection Act (ICDPA) was signed into law on March 28, 2023, and became effective on January 1, 2025. Iowa's privacy law is widely considered one of the most business-friendly comprehensive state privacy laws, providing fewer substantive rights and more flexibility for businesses than nearly all other state privacy laws.

The ICDPA grants Iowa consumers limited rights, including the right to access, delete, and obtain a portable copy of their personal data, the right to opt out of the sale of personal data and targeted advertising, and an appeal process for denied consumer rights requests. Notably, the ICDPA does not include a right to correction or a right to opt out of profiling, making it one of the narrowest state privacy laws in terms of consumer protections.

The law applies to entities conducting business in Iowa or targeting Iowa consumers that control or process personal data of 100,000 or more consumers, or process personal data of 25,000 or more consumers while deriving over 50% of gross revenue from the sale of personal data. The ICDPA provides a generous 90-day cure period — the longest among state privacy laws — and penalties of up to $7,500 per violation, enforced exclusively by the Iowa Attorney General.

Applicability Thresholds

Conditions are joined by OR meeting ANY one triggers applicability.

100,000+
Iowa consumers' data processed
25,000+ consumers
AND 50%+ revenue from data sales

Consumer Rights

Right to Access
Right to Delete
Right to Correct
Data Portability
Opt-Out of Sale
Opt-Out of Targeted Ads
Opt-Out of Profiling
Limit Sensitive Data Use
Right to Appeal
Private Right of Action

Key Changes in 2025-2026

  • Law became effective January 1, 2025 — first full year of enforcement in 2025-2026
  • Iowa AG developing enforcement priorities and compliance guidance
  • The 90-day cure period remains in effect with no sunset provision
  • Monitoring potential amendments as Iowa evaluates early enforcement experience

Enforcement Details

Enforced By
Iowa Attorney General
Penalty Per Violation
$7,500
Cure Period
90 days
Private Right of Action
No — AG enforcement only

Sensitive Data Categories

Consent model: opt-out

Racial or ethnic originReligious beliefsMental or physical health diagnosisSexual orientationCitizenship or immigration statusBiometric data for identificationPrecise geolocation data

Universal Opt-Out / GPC Requirements

No Universal Opt-Out Requirement

The ICDPA does not require businesses to honor universal opt-out mechanisms such as GPC. Iowa took the most business-friendly approach to consumer privacy legislation.

Minor / Child Protections

The ICDPA requires sensitive personal data concerning a known child to be processed in accordance with COPPA. There are no additional specific protections for teens aged 13-17 beyond what is required under federal law.

Compliance Checklist

  1. 1Determine whether your organization meets the ICDPA applicability thresholds for Iowa consumer data
  2. 2Update privacy notices to include ICDPA-required disclosures about data processing and consumer rights
  3. 3Implement opt-out mechanisms for the sale of personal data and targeted advertising
  4. 4Provide clear notice and an opportunity to opt out before processing adult sensitive personal data categories; handle known children's data under COPPA
  5. 5Establish processes to respond to consumer rights requests within the 90-day response window
  6. 6Review data processing contracts with processors to ensure ICDPA compliance
Put ICDPA Into Practice on Your SiteSponsored

Termly builds and maintains an Iowa-ready privacy policy, a cookie consent banner, and a workflow for the access and deletion requests ICDPA grants.

Start Free with Termly

Iowa Privacy Law FAQ

Official Resources