EnglishEspañol
Iowa flag

Iowa

Iowa Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 6 primary sources cited on this page. How we verify our legal content

Iowa Biometric Privacy Laws: Collection, Consent & Penalties (2026)

Frequently Asked Questions

Does Iowa have a biometric privacy law?

Iowa does not have a standalone biometric privacy law like Illinois BIPA. However, biometric data is classified as sensitive data under the Iowa Consumer Data Protection Act (ICDPA, Iowa Code Ch. 715D), which took effect January 1, 2025. The ICDPA requires businesses to give consumers notice and an opportunity to opt out before processing biometric data. Iowa's breach notification law (Ch. 715C) also covers biometric data.

Can my employer collect my fingerprints without consent in Iowa?

Under current Iowa law, there is no requirement for employers to obtain written consent before collecting fingerprints or other biometric data. Iowa Code 715D.1(7) excludes people acting in an employment context from the ICDPA's definition of consumer, so the ICDPA's notice-and-opt-out requirement never applies to an employer's collection of employee biometric data, regardless of how many consumers the employer processes data for overall. Pending legislation SSB 3085 would require written consent but includes an exemption for employers using biometric data within the scope of employment.

What is the difference between opt-in and opt-out for biometric data?

Opt-in consent means a business cannot process your biometric data until you affirmatively agree. Opt-out means the business can process your biometric data as long as it notifies you and gives you the opportunity to refuse. Iowa uses the weaker opt-out standard. States like Illinois, Colorado, Connecticut, and Virginia require opt-in consent, which gives consumers stronger control over their biometric information.

Can I sue a company in Iowa for misusing my biometric data?

No. The ICDPA does not include a private right of action. Only the Iowa Attorney General can enforce the law, with penalties up to $7,500 per violation. Businesses also receive a 90-day cure period before any enforcement action. If your biometric data is misused, you can file a complaint with the Iowa Attorney General's Consumer Protection Division but cannot bring a personal lawsuit under state law.

What happens if my biometric data is breached in Iowa?

Iowa Code Chapter 715C requires notice as expediently as possible, but only where the exposed biometric data was held with your first name or first initial and last name and was not encrypted or redacted. Notice is also excused if the business documents a determination that there is no reasonable likelihood of financial harm, and entities that comply with Gramm-Leach-Bliley or HIPAA breach rules fall outside the section. Where notice is required and the breach affects more than 500 Iowa residents, the entity must also notify the Iowa Attorney General within five business days. The notice must state the approximate date of the breach, the type of information obtained, contact information for consumer reporting agencies, and advice to report suspected identity theft.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the consumer-rights and controller-duty sections against the Iowa Code: the targeted-advertising opt-out is attributed to section 715D.4(6) rather than 715D.3, biometric data is now correctly shown as excluded from the right to obtain a copy of your data, two duties Iowa never enacted were removed, and the breach-notification section now states the five required notice elements along with the encryption, name-combination and no-financial-harm limits on when notice is owed.

Corrected three errors: Iowa consumers can appeal a controller's refusal to act on a data-rights request (Iowa Code 715D.3(3)), the Attorney General breach-notice threshold applies to breaches affecting more than 500 Iowa residents rather than exactly 500 (Iowa Code 715C.2(8)), and employee biometric data is excluded from the ICDPA because Iowa Code 715D.1(7) excludes employment-context individuals from the definition of consumer, not because of an employment-law exemption in 715D.6.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Iowa Code Chapter 715D - Consumer Data Protections(legis.iowa.gov).gov
  2. Iowa Code Chapter 715C - Personal Information Security Breach Protection(legis.iowa.gov).gov
  3. Senate File 262 - Enrolled (ICDPA)(legis.iowa.gov).gov
  4. Gov. Reynolds Signs SF 262 into Law(governor.iowa.gov).gov
  5. Iowa Attorney General - Security Breach Notifications(iowaattorneygeneral.gov).gov
  6. Senate Study Bill 3085 - Biometric Data Requirements(legis.iowa.gov).gov
  7. Iowa Code 715D.3 - Consumer data rights (copy right excepts 715C.1 personal information)(legis.iowa.gov)
  8. Iowa Code 715D.4 - Data controller duties (subsection 6: sale and targeted advertising disclosure)(legis.iowa.gov)
  9. Iowa Code 715C.1 - Definitions (unique biometric data as personal information)(legis.iowa.gov)
  10. Iowa Code 715C.2 - Security breach notification requirements, contents and exceptions(legis.iowa.gov)
  11. Iowa Code 715D.7 - Limitations (exemption-scoped adequate, relevant and limited standard)(legis.iowa.gov)
Share: