Iowa
ICDPA Compliance Checklist for Businesses (Iowa)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 8 primary sources cited on this page. How we verify our legal content

Complying with the Iowa Consumer Data Protection Act (Iowa Code Chapter 715D) is lighter than complying with almost any other state privacy law. A covered business must confirm it meets the Section 715D.2 thresholds, publish a clear privacy notice, offer a way to opt out of data sales, give a sensitive-data opt-out, sign processor contracts, avoid retaliating against consumers who exercise their rights, and strip any waiver language from its terms. The law took effect January 1, 2025.
As of 2026, the Iowa Attorney General enforces the ICDPA exclusively under Section 715D.8, with a 90-day cure period and penalties up to $7,500 per violation. Iowa requires no data protection assessments and no honoring of universal opt-out signals, so the compliance load is real but smaller than in Colorado, Connecticut, or California.
Jurisdiction scope: This covers Iowa's Consumer Data Protection Act (Iowa Code Chapter 715D). It is general legal information, not legal advice.
Step 1: Determine whether the ICDPA applies to you
The first task is to run the applicability test in Section 715D.2(1). The ICDPA reaches a person conducting business in Iowa, or producing products or services targeted to Iowa residents, that during a calendar year does either of two things.
Under Section 715D.2(1)(a), the business controls or processes personal data of at least 100,000 consumers. Under Section 715D.2(1)(b), it controls or processes personal data of at least 25,000 consumers and derives over 50% of gross revenue from the sale of personal data. A business that hits either prong is covered.
Count carefully. A "consumer" under Section 715D.1 is an Iowa resident acting in an individual or household context, and the definition excludes a person acting in a commercial or employment context. Business-to-business contacts and your own employees do not count toward the thresholds.
Iowa does not add a separate revenue floor to these data thresholds, so a high-volume processor can be covered regardless of total revenue. If your numbers sit near a threshold, document your count and revisit it each calendar year.
Step 2: Check the exemptions
Even if you clear the threshold, you may be exempt. Section 715D.2(2) provides entity-level exemptions for the state and its political subdivisions, financial institutions and their affiliates subject to the Gramm-Leach-Bliley Act, persons who comply with HIPAA and the HITECH Act, nonprofit organizations, and institutions of higher education.
Section 715D.2(3) layers on data-level exemptions. These cover protected health information and health records, information regulated by the federal Fair Credit Reporting Act under paragraph (m), data under the Driver's Privacy Protection Act under paragraph (n), education records under FERPA under paragraph (o), and data under the Farm Credit Act under paragraph (p).
Employment and emergency-contact data are excluded under Section 715D.2(3)(q), and data used in accordance with the federal Children's Online Privacy Protection Act is excluded under paragraph (r). Map your data inventory against these exemptions; an entity that clears the threshold may still find that much of its data is carved out.
Document your analysis. If the Attorney General opens an inquiry, a clear record of why a category is exempt is the first thing you will want to produce.

Step 3: Publish a compliant privacy notice
Section 715D.4(5) requires a reasonably accessible, clear, and meaningful privacy notice. The notice must include five elements, and a checklist makes them easy to track.
The notice must state the categories of personal data the controller processes, the purpose for processing that data, and how consumers may exercise their rights under Section 715D.3, including how to appeal a controller's decision. It must also state the categories of personal data the controller shares with third parties, if any, and the categories of third parties it shares with.
Beyond the five required elements, Section 715D.4(6) adds a conditional disclosure: if a controller sells a consumer's personal data to third parties or engages in targeted advertising, the controller must clearly and conspicuously disclose such activity, as well as the manner in which a consumer may exercise the right to opt out of such activity. Read that wording closely, because the phrase such activity attaches to both triggers. On its face the disclosure duty covers targeted advertising, not only sale.
A drafting tension sits underneath it. Section 715D.3(1) enumerates only four consumer rights, and the opt-out in paragraph (d) is limited to the sale of personal data, so the ICDPA creates no free-standing right to opt out of targeted advertising. The conservative build is to track the statute: disclose both activities and describe the opt-out mechanism you actually offer, rather than narrowing the notice to sale alone.
Keep the notice current. As your processing changes, the notice should change with it, because the privacy notice is the document the Attorney General will read first.
Step 4: Build the sale opt-out and sensitive-data opt-out
Two opt-out mechanisms sit at the center of ICDPA compliance. The first is the opt-out of the sale of personal data under Section 715D.3(1)(d). You must provide a clear method for an Iowan to opt out of having their personal data sold, and disclose that method under Section 715D.4(6).
A "sale" is defined narrowly in Section 715D.1 as the exchange of personal data for monetary consideration to a third party, with several exclusions such as disclosures to processors and affiliates. If you never exchange data for money, you may not be selling under the ICDPA, but you should document that conclusion.
The second mechanism is the sensitive-data opt-out under Section 715D.4(2). Before processing sensitive data for a nonexempt purpose, you must present the consumer with clear notice and an opportunity to opt out. For a known child, you must instead comply with the federal Children's Online Privacy Protection Act.
Importantly, Iowa does not require you to honor a universal opt-out signal such as Global Privacy Control, and it does not require data protection assessments. Both of those obligations exist in several other states but are absent from the ICDPA, which is the single biggest reason Iowa's compliance load is lighter.
Step 5: Put processor contracts in place
If you use vendors to process personal data on your behalf, Section 715D.5(2) requires a written contract that governs the processing. This is a hard requirement, not a best practice.
The contract must set out instructions for processing, the nature and purpose of processing, the type of data, the duration, and the rights and duties of both parties. It must also require the processor to ensure each person processing data is under a duty of confidentiality, to delete or return data at the end of the engagement at the controller's direction, to make available information needed to demonstrate compliance, and to flow these duties down to any subcontractor under a written contract.
Processors have their own duties under Section 715D.5(1), including assisting the controller with consumer-rights requests and with security and breach-notification obligations under Section 715C.2. Review existing vendor agreements and add a data processing addendum where one is missing.

Step 6: Stand up the request, response, and appeal workflow
Operationally, you need a process that meets the timelines in Section 715D.3. Under Section 715D.4(7), you must establish secure and reliable means for consumers to submit requests, and you may not require a consumer to create a new account to do so.
Once you authenticate a request, you must respond within 90 days under Section 715D.3(2)(a), with one optional 45-day extension when reasonably necessary. Responses are free up to twice a year per consumer under Section 715D.3(2)(c). Build authentication, tracking, and a calendar that flags the 90-day deadline.
You also need an appeal process under Section 715D.3(3). It must be conspicuously available, must produce a written decision within 60 days, and, if the appeal is denied, must give the consumer an online mechanism to contact the Attorney General. Document each step, because the appeal record is part of your compliance posture.
Step 7: Check your nondiscrimination posture and your contract terms
Two controller duties in Section 715D.4 are easy to miss because neither is a notice task nor a workflow task. Both apply to every covered controller.
Section 715D.4(3) bars processing personal data in violation of state and federal laws that prohibit unlawful discrimination, and separately bars discriminating against a consumer for exercising any right in the chapter, including by denying goods or services, charging different prices or rates, or providing a different level of quality. The section then carves out three things: a product or service that requires personal data you do not collect or maintain, a different price, rate, level, quality, or selection offered because the consumer exercised an opt-out under Section 715D.3, and a consumer's voluntary participation in a bona fide loyalty, rewards, premium features, discounts, or club card program. Audit any tier or price that changes after a deletion or opt-out request, and be able to name which carve-out it sits in.
Section 715D.4(4) is the shortest duty in the chapter and the easiest to breach in a document you already have. Any provision of a contract or agreement that purports to waive or limit in any way consumer rights under Section 715D.3 is deemed contrary to public policy and is void and unenforceable. Read your terms of service, account agreements, and customer-facing templates for language that waives access, deletion, portability, or the sale opt-out. Such a clause will not hold, and it is a visible problem in the first documents an Attorney General inquiry would request.
Enforcement, the 90-day cure, and penalties
The ICDPA is enforced by the Iowa Attorney General alone. Section 715D.8(1) grants exclusive enforcement authority and the power to issue a civil investigative demand on reasonable cause.
The cure period is generous. Under Section 715D.8(2), the Attorney General must give a controller or processor 90 days' written notice identifying the specific provisions allegedly violated. If the business cures within that window and provides a written statement that the violations are cured and will not recur, no action may be initiated. This 90-day cure is among the longest of any state comprehensive privacy law, and it has no sunset date, so it remains permanently available as of 2026.
| Compliance item | ICDPA requirement | Section |
|---|---|---|
| Privacy notice | Required, five elements | 715D.4(5) |
| Sale opt-out | Required if you sell data | 715D.3(1)(d) |
| Sale or targeted-ad disclosure | Required, must state the opt-out method | 715D.4(6) |
| Sensitive data | Notice plus opt-out | 715D.4(2) |
| Data protection assessment | Not required | None |
| Universal opt-out signal | Not required | None |
| Processor contract | Required | 715D.5(2) |
| Nondiscrimination | Required, loyalty-program carve-out | 715D.4(3) |
| Waiver of consumer rights | Void and unenforceable | 715D.4(4) |
| Cure period | 90 days, no sunset | 715D.8(2) |
| Maximum penalty | $7,500 per violation | 715D.8(3) |
If a business does not cure or breaches its cure statement, Section 715D.8(3) authorizes an injunction and civil penalties of up to $7,500 per violation, paid into the consumer education and litigation fund under Section 714.16C. Because Section 715D.8(4) bars any private right of action, the only enforcement risk under the ICDPA is an Attorney General action, which makes the 90-day cure a meaningful safety valve for businesses acting in good faith.
Related guides
- Iowa Data Privacy Laws (ICDPA hub)
- What Is the ICDPA? Iowa's Data Privacy Law Explained
- ICDPA Consumer Rights: What Iowans Can and Cannot Do
- US State Privacy Laws Comparison
- What Is the CCPA? California's Privacy Law Explained
More Iowa Laws
Frequently Asked Questions
Does the ICDPA apply to my business?
It applies if you conduct business in Iowa or target Iowa residents and, during a calendar year, control or process personal data of at least 100,000 Iowa consumers, or at least 25,000 consumers while deriving over 50% of gross revenue from selling personal data, under Section 715D.2(1). Iowa residents acting in a commercial or employment context do not count as consumers.
What does an ICDPA privacy notice have to include?
Under Section 715D.4(5), the notice must state the categories of personal data you process, the purposes of processing, how consumers can exercise their rights and appeal a decision, the categories of data you share with third parties, and the categories of those third parties. If you sell data or engage in targeted advertising, Section 715D.4(6) requires you to disclose such activity and the manner in which a consumer may opt out of such activity, wording that reaches targeted advertising and not only sale, even though the opt-out right in Section 715D.3(1)(d) is limited to sale.
Does Iowa require data protection assessments?
No. The ICDPA contains no data protection assessment requirement, unlike Colorado, Connecticut, and Texas. This omission is one of the main reasons Iowa's compliance load is lighter than most states. You should still keep reasonable security and documentation under Section 715D.4(1), but you do not have to prepare formal risk assessments.
Do I have to honor Global Privacy Control in Iowa?
No. The ICDPA does not require controllers to recognize universal opt-out signals such as Global Privacy Control. Consumers exercise the sale opt-out through the method you designate under Section 715D.4. This is different from states like Colorado, Connecticut, and California, which require honoring browser-level signals.
What contracts do I need with my vendors?
Section 715D.5(2) requires a written data processing contract with every processor. It must set out processing instructions, nature and purpose, data type, and duration, and require confidentiality, deletion or return of data, compliance demonstrations, and subcontractor flow-down terms. Add a data processing addendum to any vendor agreement that lacks one.
Can I put a waiver of ICDPA rights in my terms of service?
No. Section 715D.4(4) provides that any provision of a contract or agreement purporting to waive or limit in any way consumer rights under Section 715D.3 is deemed contrary to public policy and is void and unenforceable. Section 715D.4(3) separately bars discriminating against a consumer for exercising a chapter right, including by denying goods or services, charging different prices or rates, or providing a different level of quality, with a carve-out for a bona fide loyalty, rewards, premium features, discounts, or club card program.
How long do I have to respond to a consumer request?
Under Section 715D.3(2)(a), you must respond within 90 days of an authenticated request, with one optional 45-day extension when reasonably necessary if you notify the consumer in time. You must also provide an appeal process under Section 715D.3(3) with a written decision within 60 days. Responses are free up to twice a year per consumer.
What is the ICDPA cure period?
Under Section 715D.8(2), the Attorney General must give 90 days' written notice before initiating any action. If you cure the noticed violation within that window and provide a written statement that it is cured and will not recur, no action may be brought. This 90-day cure is among the longest of any state comprehensive privacy law and has no sunset date as of 2026.
What are the penalties for violating the ICDPA?
If a business does not cure within the 90-day window, Section 715D.8(3) authorizes an injunction and civil penalties of up to $7,500 per violation, paid into Iowa's consumer education and litigation fund. Enforcement is exclusively the Attorney General's under Section 715D.8(1), and Section 715D.8(4) bars any private right of action.
Updates
Added the two ICDPA controller duties the checklist had omitted, the Section 715D.4(3) ban on discriminating against consumers who exercise their rights and the Section 715D.4(4) rule voiding contract terms that waive those rights, and corrected the Section 715D.4(6) disclosure duty, which reaches targeted advertising and not only the sale of personal data.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Iowa Code, Chapter 715D: CONSUMER DATA PROTECTIONS
§ 715D.4Data controller duties.In forcecited in 5 of our articles
1. A controller shall adopt and implement reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data. Such data security practices shall be appropriate to the volume and nature of the personal data at issue. 2. A controller shall not process sensitive data collected from a consumer for a nonexempt purpose without the consumer having been presented with clear notice and an opportunity to opt out of such processing, or, in the case of the processing of sensitive data concerning a known child, without processing such data in accordance with the federal Children’s Online Privacy Protection Act, 15 U.S.C. §6501 et seq. 3. A controller shall not process personal data in violation of state and federal laws that prohibit unlawful discrimination against a consumer. A controller shall not discriminate against a consumer for exercising any of the consumer rights contained in this chapter, including denying goods or services, charging different prices or rates for goods or services, or providing a different level of quality of goods and services to the consumer.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at legis.iowa.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2023
Opinions citing this section in our collection:
- Calabretto Building Group v. Tradesmen International, LLC. (Court of Appeals of Iowa 2023)“…s); see also 2023 Iowa Acts ch. 17, § 4 (to be codified at Iowa Code § 715D.4(4)) (voiding terms that “waive or limi…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Iowa Data Privacy Laws: ICDPA Consumer Rights Guide (2026), ICDPA Consumer Rights: What Iowans Can and Cannot Do, What Is the ICDPA? Iowa's Data Privacy Law Explained
§ 715D.2Scope and exemptions.In forcecited in 3 of our articles
1. This chapter applies to a person conducting business in the state or producing products or services that are targeted to consumers who are residents of the state and that during a calendar year does either of the following: a. Controls or processes personal data of at least one hundred thousand consumers. b. Controls or processes personal data of at least twenty-five thousand consumers and derives over fifty percent of gross revenue from the sale of personal data. 2. This chapter shall not apply to the state or any political subdivision of the state; financial institutions, affiliates of financial institutions, or data subject to Tit. V of the federal Gramm-Leach-Bliley Act of 1999, 15 U.S.C. §6801 et seq.; persons who are subject to and comply with regulations promulgated pursuant to Tit. II, subtit. F, of the federal Health Insurance Portability and Accountability Act of 1996, Pub. L. No. 104-191, and Tit. XIII, subtit. D, of the federal Health Information Technology for Economic and Clinical Health Act of 2009, 42 U.S.C. §17921 – 17954; nonprofit organizations; or institutions of higher education. 3. The following information and data is exempt from this chapter: a.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at legis.iowa.gov
§ 715D.3Consumer data rights.In forcecited in 4 of our articles
1. A consumer may invoke the consumer rights authorized pursuant to this section at any time by submitting a request to the controller, through the means specified by the controller pursuant to section 715D.4, subsection 6, specifying the consumer rights the consumer wishes to invoke. A known child’s parent or legal guardian may invoke such consumer rights on behalf of the known child regarding processing personal data belonging to the child. A controller shall comply with an authenticated consumer request to exercise all of the following: a. To confirm whether a controller is processing the consumer’s personal data and to access such personal data. b. To delete personal data provided by the consumer. c. To obtain a copy of the consumer’s personal data, except as to personal data that is defined as “personal information” pursuant to section 715C.1 that is subject to security breach protection, that the consumer previously provided to the controller in a portable and, to the extent technically practicable, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means. d.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at legis.iowa.gov
§ 715D.5Processor duties.In forcecited in 2 of our articles
1. A processor shall assist a controller in duties required under this chapter, taking into account the nature of processing and the information available to the processor by appropriate technical and organizational measures, insofar as is reasonably practicable, as follows: a. To fulfill the controller’s obligation to respond to consumer rights requests pursuant to section 715D.3. b. To meet the controller’s obligations in relation to the security of processing the personal data and in relation to the notification of a security breach of the processor pursuant to section 715C.2. 2. A contract between a controller and a processor shall govern the processor’s data processing procedures with respect to processing performed on behalf of the controller. The contract shall clearly set forth instructions for processing personal data, the nature and purpose of processing, the type of data subject to processing, the duration of processing, and the rights and duties of both parties. The contract shall also include requirements that the processor shall do all of the following: a.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at legis.iowa.gov
§ 715D.8Enforcement — penalties.In forcecited in 3 of our articles
1. The attorney general shall have exclusive authority to enforce the provisions of this chapter. Whenever the attorney general has reasonable cause to believe that any person has engaged in, is engaging in, or is about to engage in any violation of this chapter, the attorney general is empowered to issue a civil investigative demand. The provisions of section 685.6 shall apply to civil investigative demands issued under this chapter. 2. Prior to initiating any action under this chapter, the attorney general shall provide a controller or processor ninety days’ written notice identifying the specific provisions of this chapter the attorney general alleges have been or are being violated. If within the ninety-day period, the controller or processor cures the noticed violation and provides the attorney general an express written statement that the alleged violations have been cured and that no further such violations shall occur, no action shall be initiated against the controller or processor. 3.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at legis.iowa.gov
Explore the law
This article also draws on these acts and chapters (opening at their first section): Iowa Code, Chapter 715D: CONSUMER DATA PROTECTIONS § 715D.1 (Definitions.)
Related law for further reading — not part of this article’s citations.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Iowa Code Chapter 715D: Consumer Data Protections (Full Text)(legis.iowa.gov).gov
- Iowa Code Section 715D.2: Scope and Exemptions(legis.iowa.gov).gov
- Iowa Code Section 715D.4: Data Controller Duties(legis.iowa.gov).gov
- Iowa Code Section 715D.5: Processor Duties(legis.iowa.gov).gov
- Iowa Code Section 715D.3: Consumer Data Rights (Response Window)(legis.iowa.gov).gov
- Iowa Code Section 715D.8: Enforcement and Penalties (90-Day Cure)(legis.iowa.gov).gov
- Iowa Senate File 262 (2023): Consumer Data Protection Act(legis.iowa.gov).gov
- Iowa Attorney General: Consumer Protection(iowaattorneygeneral.gov).gov
- Iowa Code Section 715D.4: Data Controller Duties (official section text)(www.legis.iowa.gov)
- Iowa Code Section 715D.3: Consumer Data Rights (official section text)(www.legis.iowa.gov)