EnglishEspañol
Iowa flag

Iowa

Iowa Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 7 primary sources cited on this page. How we verify our legal content

Iowa Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must a business notify me of a data breach in Iowa?

Iowa law requires notification 'in the most expeditious manner possible and without unreasonable delay' after discovering a breach. The state does not set a specific number of days. The timeline must account for law enforcement needs, the time to determine the scope of the breach, and restoring data security. However, businesses must notify the Iowa Attorney General within five business days after notifying affected consumers when a breach affects more than 500 Iowa residents.

Does Iowa's breach notification law cover biometric data?

Yes. Iowa Code 715C.1 defines personal information to include unique biometric data such as fingerprints, retina or iris images, and other unique physical or digital representations of biometric data. If a breach exposes this data alongside your name, the business must comply with the notification requirements.

Can I sue a company for a data breach in Iowa?

Not under Iowa's breach notification law. Chapter 715C does not provide a private right of action, so only the Iowa Attorney General can bring enforcement actions under it. Violations are classified as unlawful practices under Iowa Code 714.16, and the Attorney General can seek damages on behalf of injured consumers. Iowa Code 715C.2(9)(b) adds that the remedies under that section are cumulative to any other rights and remedies available under the law, so the statute does not by itself bar separate claims, such as negligence or breach of contract. Ask an Iowa attorney whether your situation supports one.

What penalties do businesses face for failing to report a data breach in Iowa?

Violations of Iowa's breach notification law are treated as unlawful practices under Iowa Code 714.16. The Attorney General can seek injunctive relief, civil penalties, and damages on behalf of injured consumers. Section 714.16 caps civil penalties at $40,000 per violation, with a course of conduct not counted as separate violations merely because it affected more than one person.

Does Iowa have other laws that protect biometric data?

Yes. In addition to the breach notification law, Iowa enacted the Consumer Data Protection Act (Chapter 715D), effective January 1, 2025. This law classifies biometric data processed for uniquely identifying individuals as sensitive data and requires controllers to give consumers clear notice and an opportunity to opt out before processing it. The ICDPA is enforced exclusively by the Iowa Attorney General.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the definition of a security breach to include personal information transferred from computerized form to paper or another medium, restated the good faith acquisition exception in the statute's own harm and unlawfulness terms, and clarified that while Chapter 715C creates no private right of action, Iowa Code 715C.2(9)(b) makes its remedies cumulative to other rights and remedies available under the law.

Corrected the Attorney General notification threshold (more than 500 Iowa residents, not 500 or more), fixed a misquoted notification-timing standard (statute says "most expeditious manner possible"), and added the law's risk-of-harm and GLBA/HIPAA compliance exemptions from the notification duty.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Corrected a claim that Iowa's breach-notification enforcement statute has no specific dollar cap; Iowa Code 714.16 actually caps civil penalties at $40,000 per violation.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Iowa Code Chapter 715C Personal Information Security Breach Protection(legis.iowa.gov).gov
  2. Iowa Code 715C.1 definitions including biometric data(legis.iowa.gov).gov
  3. Iowa Code 715C.2 breach notification requirements and remedies(legis.iowa.gov).gov
  4. Iowa Attorney General security breach notifications page(iowaattorneygeneral.gov).gov
  5. Iowa Code 714.16 consumer fraud and unfair practices enforcement(legis.iowa.gov).gov
  6. Iowa Consumer Data Protection Act (Chapter 715D)(legis.iowa.gov).gov
  7. Iowa Code 715D.1 definitions including sensitive data and biometric data(legis.iowa.gov).gov
Share: