EnglishEspañol
Iowa flag

Iowa

ICDPA Compliance Checklist for Businesses (Iowa)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 8 primary sources cited on this page. How we verify our legal content

ICDPA Compliance Checklist for Businesses (Iowa)

Frequently Asked Questions

Does the ICDPA apply to my business?

It applies if you conduct business in Iowa or target Iowa residents and, during a calendar year, control or process personal data of at least 100,000 Iowa consumers, or at least 25,000 consumers while deriving over 50% of gross revenue from selling personal data, under Section 715D.2(1). Iowa residents acting in a commercial or employment context do not count as consumers.

What does an ICDPA privacy notice have to include?

Under Section 715D.4(5), the notice must state the categories of personal data you process, the purposes of processing, how consumers can exercise their rights and appeal a decision, the categories of data you share with third parties, and the categories of those third parties. If you sell data or engage in targeted advertising, Section 715D.4(6) requires you to disclose such activity and the manner in which a consumer may opt out of such activity, wording that reaches targeted advertising and not only sale, even though the opt-out right in Section 715D.3(1)(d) is limited to sale.

Does Iowa require data protection assessments?

No. The ICDPA contains no data protection assessment requirement, unlike Colorado, Connecticut, and Texas. This omission is one of the main reasons Iowa's compliance load is lighter than most states. You should still keep reasonable security and documentation under Section 715D.4(1), but you do not have to prepare formal risk assessments.

Do I have to honor Global Privacy Control in Iowa?

No. The ICDPA does not require controllers to recognize universal opt-out signals such as Global Privacy Control. Consumers exercise the sale opt-out through the method you designate under Section 715D.4. This is different from states like Colorado, Connecticut, and California, which require honoring browser-level signals.

What contracts do I need with my vendors?

Section 715D.5(2) requires a written data processing contract with every processor. It must set out processing instructions, nature and purpose, data type, and duration, and require confidentiality, deletion or return of data, compliance demonstrations, and subcontractor flow-down terms. Add a data processing addendum to any vendor agreement that lacks one.

Can I put a waiver of ICDPA rights in my terms of service?

No. Section 715D.4(4) provides that any provision of a contract or agreement purporting to waive or limit in any way consumer rights under Section 715D.3 is deemed contrary to public policy and is void and unenforceable. Section 715D.4(3) separately bars discriminating against a consumer for exercising a chapter right, including by denying goods or services, charging different prices or rates, or providing a different level of quality, with a carve-out for a bona fide loyalty, rewards, premium features, discounts, or club card program.

How long do I have to respond to a consumer request?

Under Section 715D.3(2)(a), you must respond within 90 days of an authenticated request, with one optional 45-day extension when reasonably necessary if you notify the consumer in time. You must also provide an appeal process under Section 715D.3(3) with a written decision within 60 days. Responses are free up to twice a year per consumer.

What is the ICDPA cure period?

Under Section 715D.8(2), the Attorney General must give 90 days' written notice before initiating any action. If you cure the noticed violation within that window and provide a written statement that it is cured and will not recur, no action may be brought. This 90-day cure is among the longest of any state comprehensive privacy law and has no sunset date as of 2026.

What are the penalties for violating the ICDPA?

If a business does not cure within the 90-day window, Section 715D.8(3) authorizes an injunction and civil penalties of up to $7,500 per violation, paid into Iowa's consumer education and litigation fund. Enforcement is exclusively the Attorney General's under Section 715D.8(1), and Section 715D.8(4) bars any private right of action.

Updates

Added the two ICDPA controller duties the checklist had omitted, the Section 715D.4(3) ban on discriminating against consumers who exercise their rights and the Section 715D.4(4) rule voiding contract terms that waive those rights, and corrected the Section 715D.4(6) disclosure duty, which reaches targeted advertising and not only the sale of personal data.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Iowa Code Chapter 715D: Consumer Data Protections (Full Text)(legis.iowa.gov).gov
  2. Iowa Code Section 715D.2: Scope and Exemptions(legis.iowa.gov).gov
  3. Iowa Code Section 715D.4: Data Controller Duties(legis.iowa.gov).gov
  4. Iowa Code Section 715D.5: Processor Duties(legis.iowa.gov).gov
  5. Iowa Code Section 715D.3: Consumer Data Rights (Response Window)(legis.iowa.gov).gov
  6. Iowa Code Section 715D.8: Enforcement and Penalties (90-Day Cure)(legis.iowa.gov).gov
  7. Iowa Senate File 262 (2023): Consumer Data Protection Act(legis.iowa.gov).gov
  8. Iowa Attorney General: Consumer Protection(iowaattorneygeneral.gov).gov
  9. Iowa Code Section 715D.4: Data Controller Duties (official section text)(www.legis.iowa.gov)
  10. Iowa Code Section 715D.3: Consumer Data Rights (official section text)(www.legis.iowa.gov)
Share: