EnglishEspañol
Iowa flag

Iowa

What Is the ICDPA? Iowa's Data Privacy Law Explained

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 8 primary sources cited on this page. How we verify our legal content

What Is the ICDPA? Iowa's Data Privacy Law Explained

Frequently Asked Questions

What is the ICDPA?

The ICDPA, or Iowa Consumer Data Protection Act, is Iowa's comprehensive consumer data privacy law, codified at Iowa Code Chapter 715D (Sections 715D.1 through 715D.9). It was enacted as Senate File 262, signed by Governor Kim Reynolds on March 28, 2023, and took effect January 1, 2025. It gives Iowa residents a narrow set of rights over their personal data and is widely regarded as the most business-friendly comprehensive state privacy law in the United States.

When did the Iowa Consumer Data Protection Act take effect?

The ICDPA took effect on January 1, 2025, nearly two years after Governor Kim Reynolds signed Senate File 262 on March 28, 2023. The delayed effective date gave covered businesses time to build privacy notices and consumer-request processes before any obligations began.

Who does the ICDPA apply to?

Under Section 715D.2(1), the ICDPA applies to a business operating in Iowa or targeting Iowa residents that, during a calendar year, controls or processes personal data of at least 100,000 consumers, or controls or processes personal data of at least 25,000 consumers while deriving over 50% of gross revenue from the sale of personal data. Iowa residents acting in a commercial or employment context are not counted as consumers.

Why is Iowa's privacy law called the weakest in the country?

Because it grants the fewest rights and imposes the fewest duties. Iowa gives only four consumer rights under Section 715D.3, with no right to correct data, no targeted-advertising opt-out, and no profiling opt-out. It also requires no data protection assessments and no honoring of universal opt-out signals, and it uses an opt-out rather than opt-in model for sensitive data under Section 715D.4(2).

What entities are exempt from the ICDPA?

Section 715D.2(2) exempts the state and its political subdivisions, GLBA-covered financial institutions, HIPAA and HITECH-compliant entities, nonprofit organizations, and institutions of higher education. Section 715D.2(3) also exempts data governed by HIPAA, the Fair Credit Reporting Act, the Driver's Privacy Protection Act, FERPA, the Farm Credit Act, and COPPA, plus most employment and emergency-contact data.

Does the ICDPA give Iowans a right to correct their data?

No. The ICDPA's consumer rights in Section 715D.3 are limited to confirming and accessing data, deleting data the consumer provided, obtaining a portable copy, and opting out of the sale of personal data. There is no right to correct inaccurate personal data, which distinguishes Iowa from Virginia, Colorado, Connecticut, Texas, and California.

How does the ICDPA handle sensitive data?

The ICDPA uses an opt-out model. Under Section 715D.4(2), a controller may process sensitive data after presenting the consumer with clear notice and an opportunity to opt out. For a known child, the controller must comply with the federal Children's Online Privacy Protection Act. This is lighter than the opt-in consent that most other state privacy laws require.

How is the ICDPA enforced?

The Iowa Attorney General has exclusive enforcement authority under Section 715D.8. Before suing, the Attorney General must give a business 90 days' written notice and a chance to cure, the longest cure period of any state and one with no sunset date. If the business does not cure, penalties run up to $7,500 per violation. There is no private right of action under Section 715D.8(4).

Updates

Added the consumer appeal process under Iowa Code 715D.3(3), which the rights overview previously omitted.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Iowa Code Chapter 715D: Consumer Data Protections (Full Text)(legis.iowa.gov).gov
  2. Iowa Code Section 715D.1: Definitions(legis.iowa.gov).gov
  3. Iowa Code Section 715D.2: Scope and Exemptions(legis.iowa.gov).gov
  4. Iowa Code Section 715D.3: Consumer Data Rights(legis.iowa.gov).gov
  5. Iowa Code Section 715D.4: Data Controller Duties (Sensitive Data Opt-Out)(legis.iowa.gov).gov
  6. Iowa Code Section 715D.8: Enforcement and Penalties(legis.iowa.gov).gov
  7. Iowa Senate File 262 (2023): Consumer Data Protection Act(legis.iowa.gov).gov
  8. Iowa Attorney General: Consumer Protection(iowaattorneygeneral.gov).gov
Share: