Iowa
Iowa Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 6 primary sources cited on this page. How we verify our legal content

Iowa has no standalone biometric privacy law. Instead, the Iowa Consumer Data Protection Act (Iowa Code Ch. 715D), effective January 1, 2025, classifies biometric data as sensitive data, requiring businesses to give consumers notice and an opt-out opportunity before processing it. The Attorney General enforces the law; no private right of action exists.
Iowa provides two layers of protection for biometric data. The Iowa Consumer Data Protection Act (ICDPA) treats biometric identifiers as sensitive data subject to disclosure and opt-out requirements. Separately, the state's breach notification law requires companies to alert consumers when biometric records are exposed in a data breach.
Neither law is as strong as dedicated biometric privacy statutes in states like Illinois or Texas. Iowa's approach relies on opt-out rather than opt-in consent, and enforcement rests solely with the Attorney General.
For the full picture of Iowa's privacy framework, see the parent guide to Iowa Data Privacy Laws.
How Iowa Defines Biometric Data
Under Iowa Code 715D.1, biometric data means data generated by automatic measurements of an individual's biological characteristics that is used to identify a specific individual. The statute lists these examples:
- Fingerprints
- Voiceprints
- Eye retinas and irises
- Other unique biological patterns or characteristics
The definition explicitly excludes physical or digital photographs, video or audio recordings (and data generated from them), and information collected, used, or stored for health care treatment, payment, or operations under HIPAA.
Biometric data falls under the broader category of "sensitive data" in the ICDPA when it is processed for the purpose of uniquely identifying a natural person. Other categories of sensitive data include racial or ethnic origin, religious beliefs, health diagnoses, sexual orientation, citizenship or immigration status, genetic data, data from known children, and precise geolocation data.
The ICDPA's Biometric Data Requirements

Opt-Out, Not Opt-In
This is the most important distinction between Iowa and stronger biometric privacy states. Under Iowa Code 715D.4, a data controller that processes sensitive data (including biometric data) must provide the consumer with clear notice and an opportunity to opt out of that processing.
Iowa does not require affirmative opt-in consent. A business can begin processing your fingerprint or facial geometry data as long as it tells you about it and gives you a way to say no. In contrast, states like Colorado, Connecticut, and Virginia require consumers to opt in before sensitive data processing begins.
For data collected from a known child, the ICDPA requires compliance with the federal Children's Online Privacy Protection Act (COPPA) rather than using the standard opt-out framework.
Who the ICDPA Applies To
The ICDPA applies to businesses that conduct business in Iowa or produce products or services targeted to Iowa consumers and that during a calendar year either:
- Control or process the personal data of at least 100,000 Iowa consumers, or
- Control or process personal data of at least 25,000 consumers and derive more than 50% of gross revenue from selling personal data
Iowa Code 715D.2 exempts several categories of entities, including state and local government bodies, financial institutions subject to the Gramm-Leach-Bliley Act, entities covered by HIPAA, nonprofits, and institutions of higher education.
Consumer Rights Over Biometric Data
Under Iowa Code 715D.3, Iowa consumers have the right to:
- Confirm and access whether a controller is processing their personal data, including biometric data
- Delete personal data the consumer provided to the controller
- Obtain a copy of personal data the consumer previously provided, in a portable format, except personal data that qualifies as "personal information" under Iowa Code 715C.1 and is subject to security breach protection
- Opt out of the sale of personal data
That exception is the single most relevant qualification on the rights menu for anyone asking about biometric data. Iowa Code 715C.1(11)(a)(5) counts unique biometric data as "personal information," so where a controller holds a consumer's name together with unencrypted biometric data, that data is carved out of the right to obtain a copy. The confirm, access, and delete rights are unaffected.
The right to opt out of targeted advertising comes from a different section. Iowa Code 715D.4(6) provides that a controller that sells a consumer's personal data to third parties or engages in targeted advertising must clearly and conspicuously disclose that activity, as well as the manner in which a consumer may exercise the right to opt out of it. Section 715D.3 itself lists only the confirm and access, delete, copy, and sale opt-out rights.
Notably, Iowa does not grant consumers the right to correct inaccurate personal data, which most other state privacy laws include. Iowa Code 715D.3(3) requires controllers to give consumers a way to appeal a refusal to act on a data rights request: the controller must respond to the appeal in writing within 60 days, and if the appeal is denied, must provide an online mechanism for the consumer to file a complaint with the Attorney General.
Data Controller Duties
Iowa Code 715D.4 sets out the complete list of controller duties. The ones that bear on biometric data are:
- Adopt reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the data
- Give the consumer clear notice and an opportunity to opt out before processing sensitive data, including biometric data, for a nonexempt purpose
- Refrain from discriminating against a consumer for exercising a right under the chapter
- Publish a reasonably accessible, clear, and meaningful privacy notice describing the categories of personal data processed, the purpose for processing, how consumers exercise and appeal their rights, and the categories of personal data shared with third parties along with the categories of those third parties
- Clearly and conspicuously disclose any sale of personal data or targeted advertising, along with how to opt out
- Establish secure and reliable means for consumers to submit rights requests, without requiring the consumer to create a new account
What is absent from that list is as telling as what is on it. Iowa enacted no general data minimization duty and no purpose limitation duty requiring consent before processing data for a purpose incompatible with the one disclosed. Both are standard in Virginia's law and the statutes modeled on it, and Iowa left them out. The phrase "adequate, relevant, and limited to what is necessary" appears in the chapter exactly once, at Iowa Code 715D.7(6), where it constrains only data processed under that section's exemptions. That gap is a substantial part of why Iowa's law sits at the weaker end of the comprehensive state privacy statutes.
Iowa's Breach Notification Law and Biometric Data
Iowa's second layer of biometric protection comes from Iowa Code Chapter 715C, the Personal Information Security Breach Protection Act.
This law defines personal information to include "unique biometric data" alongside Social Security numbers, driver's license numbers, and financial account numbers. The definition is narrower than it first looks. Under Iowa Code 715C.1(11)(a), biometric data counts only when it is held in combination with the individual's first name or first initial and last name, and only when the data is not encrypted, redacted, or otherwise rendered unreadable. An exposure of biometric templates on their own, or of properly encrypted ones, does not trigger the notification duty.
Notification Requirements
Any person who owns or licenses computerized data containing an Iowa consumer's personal information must notify affected consumers following discovery of a breach. Key requirements include:
- Timing: Notification must occur as expediently as possible and without unreasonable delay
- Attorney General notification: Breaches affecting more than 500 Iowa residents require written notice to the Iowa Attorney General within five business days after notifying affected individuals
- Content: Iowa Code 715C.2(5) requires the notice to include, at a minimum, a description of the breach, the approximate date of the breach, the type of personal information obtained, contact information for consumer reporting agencies, and advice to report suspected incidents of identity theft to local law enforcement or the Attorney General
- Method: Notice can be provided in writing, electronically (with consent), or through substitute notice if the cost exceeds $250,000 or affected individuals exceed 350,000
This means a business that falls below the ICDPA's processing thresholds can still owe breach notice when biometric data meeting the 715C.1 definition is compromised. Two limits cut the other way. Under Iowa Code 715C.2(6), notice is not required at all if, after an appropriate investigation or consultation with the relevant law enforcement agencies, the business determines that no reasonable likelihood of financial harm to affected consumers has resulted or will result; that determination must be documented in writing and the documentation kept for five years. Under 715C.2(7), the section does not apply to entities that are subject to and comply with Gramm-Leach-Bliley or HIPAA breach regulations, or with another state or federal law providing greater protection and at least as thorough disclosure requirements.

Employer Use of Biometric Data
Iowa Code 715D.1(7) defines consumer to exclude any natural person acting in a commercial or employment context. Because of that exclusion, an employer's collection of employee biometric data, such as fingerprints for time clocks or facial recognition for facility access, falls outside the ICDPA's scope entirely. The opt-out notice requirements do not apply to employee biometric data, regardless of how many consumers the employer processes data for overall.
This is a structural exclusion built into the ICDPA's definition of consumer, not a conditional exemption tied to compliance with other employment laws.
Iowa does not currently have a standalone law that requires employers to obtain written consent before collecting biometric data, establish retention schedules, or provide a private right of action for employees whose biometric data is mishandled.
Enforcement and Penalties

The Iowa Attorney General has exclusive enforcement authority under the ICDPA. Under Iowa Code 715D.8:
- The AG may seek an injunction and civil penalties of up to $7,500 per violation
- Before bringing an action, the AG must provide the business with a 90-day cure period to address the alleged violation
- If the business cures the violation within 90 days and provides the AG with an express written statement that the violation has been cured and that no further violations will occur, no action may be brought
There is no private right of action under the ICDPA. Individual consumers cannot sue businesses directly for violations related to biometric data handling. This is a significant limitation compared to Illinois's Biometric Information Privacy Act (BIPA), which allows individuals to recover $1,000 to $5,000 per violation.
For breach notification violations under Chapter 715C, the Attorney General may also bring enforcement actions.
Pending Legislation: SSB 3085

The Iowa Legislature is considering Senate Study Bill 3085, which would create a dedicated biometric data statute with stronger protections than the ICDPA currently provides.
What SSB 3085 Would Require
If enacted, the bill would require private entities to:
- Develop written retention policies available to the public, limiting storage to three years after the final interaction with the individual or until the original collection purpose has been satisfied
- Obtain informed written consent before collecting biometric data, including disclosing the specific purpose and length of time the data will be retained
- Never sell, lease, trade, or otherwise profit from an individual's biometric data
- Store and transmit biometric data using reasonable security measures equivalent to or more protective than the methods used for passwords and account access credentials
Penalties Under SSB 3085
The Department of Inspections, Appeals, and Licensing would oversee enforcement with escalating penalties:
- First violation: $1,000
- Second violation: $5,000
- Third or subsequent violation: $10,000
- A 30-day cure period would be allowed for initial violations
Employer Exemption
The bill exempts employers that use employee biometric data solely within the scope of employment. This would allow continued use of fingerprint time clocks and biometric access systems at work without triggering the consent and retention requirements.
SSB 3085 was introduced in the 91st General Assembly, which runs through January 2027. It has not yet advanced past the study bill stage.
How Iowa Compares to Other States
Iowa occupies a middle tier for biometric privacy protection. Here is how the state stacks up:
- Illinois has the strongest protections in the country through BIPA, with informed written consent requirements and a private right of action allowing $1,000 to $5,000 per violation
- Texas and Washington have biometric-specific statutes with attorney general enforcement but no private right of action
- Colorado, Connecticut, and Virginia require opt-in consent for processing biometric data under their comprehensive privacy laws
- Iowa requires only notice and opt-out for biometric data under the ICDPA, making it one of the weaker comprehensive privacy laws on this issue
- States without protections like Georgia have no biometric data provisions in either a comprehensive privacy law or a breach notification statute
This article provides general legal information about Iowa biometric privacy laws. It is not legal advice. Laws and regulations change frequently, and this content may not reflect the most recent developments. Consult a qualified attorney licensed in Iowa for advice about your specific situation.
More Iowa Laws
Frequently Asked Questions
Does Iowa have a biometric privacy law?
Iowa does not have a standalone biometric privacy law like Illinois BIPA. However, biometric data is classified as sensitive data under the Iowa Consumer Data Protection Act (ICDPA, Iowa Code Ch. 715D), which took effect January 1, 2025. The ICDPA requires businesses to give consumers notice and an opportunity to opt out before processing biometric data. Iowa's breach notification law (Ch. 715C) also covers biometric data.
Can my employer collect my fingerprints without consent in Iowa?
Under current Iowa law, there is no requirement for employers to obtain written consent before collecting fingerprints or other biometric data. Iowa Code 715D.1(7) excludes people acting in an employment context from the ICDPA's definition of consumer, so the ICDPA's notice-and-opt-out requirement never applies to an employer's collection of employee biometric data, regardless of how many consumers the employer processes data for overall. Pending legislation SSB 3085 would require written consent but includes an exemption for employers using biometric data within the scope of employment.
What is the difference between opt-in and opt-out for biometric data?
Opt-in consent means a business cannot process your biometric data until you affirmatively agree. Opt-out means the business can process your biometric data as long as it notifies you and gives you the opportunity to refuse. Iowa uses the weaker opt-out standard. States like Illinois, Colorado, Connecticut, and Virginia require opt-in consent, which gives consumers stronger control over their biometric information.
Can I sue a company in Iowa for misusing my biometric data?
No. The ICDPA does not include a private right of action. Only the Iowa Attorney General can enforce the law, with penalties up to $7,500 per violation. Businesses also receive a 90-day cure period before any enforcement action. If your biometric data is misused, you can file a complaint with the Iowa Attorney General's Consumer Protection Division but cannot bring a personal lawsuit under state law.
What happens if my biometric data is breached in Iowa?
Iowa Code Chapter 715C requires notice as expediently as possible, but only where the exposed biometric data was held with your first name or first initial and last name and was not encrypted or redacted. Notice is also excused if the business documents a determination that there is no reasonable likelihood of financial harm, and entities that comply with Gramm-Leach-Bliley or HIPAA breach rules fall outside the section. Where notice is required and the breach affects more than 500 Iowa residents, the entity must also notify the Iowa Attorney General within five business days. The notice must state the approximate date of the breach, the type of information obtained, contact information for consumer reporting agencies, and advice to report suspected identity theft.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the consumer-rights and controller-duty sections against the Iowa Code: the targeted-advertising opt-out is attributed to section 715D.4(6) rather than 715D.3, biometric data is now correctly shown as excluded from the right to obtain a copy of your data, two duties Iowa never enacted were removed, and the breach-notification section now states the five required notice elements along with the encryption, name-combination and no-financial-harm limits on when notice is owed.
Corrected three errors: Iowa consumers can appeal a controller's refusal to act on a data-rights request (Iowa Code 715D.3(3)), the Attorney General breach-notice threshold applies to breaches affecting more than 500 Iowa residents rather than exactly 500 (Iowa Code 715C.2(8)), and employee biometric data is excluded from the ICDPA because Iowa Code 715D.1(7) excludes employment-context individuals from the definition of consumer, not because of an employment-law exemption in 715D.6.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Iowa Code, Chapter 715D: CONSUMER DATA PROTECTIONS
§ 715D.4Data controller duties.In forcecited in 5 of our articles
1. A controller shall adopt and implement reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data. Such data security practices shall be appropriate to the volume and nature of the personal data at issue. 2. A controller shall not process sensitive data collected from a consumer for a nonexempt purpose without the consumer having been presented with clear notice and an opportunity to opt out of such processing, or, in the case of the processing of sensitive data concerning a known child, without processing such data in accordance with the federal Children’s Online Privacy Protection Act, 15 U.S.C. §6501 et seq. 3. A controller shall not process personal data in violation of state and federal laws that prohibit unlawful discrimination against a consumer. A controller shall not discriminate against a consumer for exercising any of the consumer rights contained in this chapter, including denying goods or services, charging different prices or rates for goods or services, or providing a different level of quality of goods and services to the consumer.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at legis.iowa.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2023
Opinions citing this section in our collection:
- Calabretto Building Group v. Tradesmen International, LLC. (Court of Appeals of Iowa 2023)“…s); see also 2023 Iowa Acts ch. 17, § 4 (to be codified at Iowa Code § 715D.4(4)) (voiding terms that “waive or limi…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Iowa Data Privacy Laws: ICDPA Consumer Rights Guide (2026), ICDPA Compliance Checklist for Businesses (Iowa), ICDPA Consumer Rights: What Iowans Can and Cannot Do
Explore the law
This article also draws on these acts and chapters (opening at their first section): Iowa Code, Chapter 715D: CONSUMER DATA PROTECTIONS § 715D.1 (Definitions.)
Related law for further reading — not part of this article’s citations.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Iowa Code Chapter 715D - Consumer Data Protections(legis.iowa.gov).gov
- Iowa Code Chapter 715C - Personal Information Security Breach Protection(legis.iowa.gov).gov
- Senate File 262 - Enrolled (ICDPA)(legis.iowa.gov).gov
- Gov. Reynolds Signs SF 262 into Law(governor.iowa.gov).gov
- Iowa Attorney General - Security Breach Notifications(iowaattorneygeneral.gov).gov
- Senate Study Bill 3085 - Biometric Data Requirements(legis.iowa.gov).gov
- Iowa Code 715D.3 - Consumer data rights (copy right excepts 715C.1 personal information)(legis.iowa.gov)
- Iowa Code 715D.4 - Data controller duties (subsection 6: sale and targeted advertising disclosure)(legis.iowa.gov)
- Iowa Code 715C.1 - Definitions (unique biometric data as personal information)(legis.iowa.gov)
- Iowa Code 715C.2 - Security breach notification requirements, contents and exceptions(legis.iowa.gov)
- Iowa Code 715D.7 - Limitations (exemption-scoped adequate, relevant and limited standard)(legis.iowa.gov)