Iowa Consumer Data Protection Act
ICDPA · Normalized Research Card v2.1
IN FORCELAST VERIFIED · AUG 26 2026At a glance
Who must comply?
Applicability model: Numerical threshold.
Core threshold: 100,000 consumers; or 25,000 consumers and >50% gross revenue from sale
Applicability remains subject to statutory entity, data-level and activity-specific exemptions. Employment/B2B treatment and federal-law carve-outs should be read together with the official statute linked below.
Consumer rights
| Right / protection | Status |
|---|---|
| Access / confirmation | ✓ Included / qualified by statute |
| Deletion | ✓ Included / qualified by statute |
| Portability | ✓ Included / qualified by statute |
| Opt-out of sale | ✓ Included / qualified by statute |
Sensitive data & minors
Sensitive-data standard: Notice + opportunity to opt out; known-child data follows COPPA
Sensitive data concerning a known child is processed in accordance with COPPA.
Business obligations
Reasonable administrative, technical and physical security; privacy notice; request mechanisms; disclosure of sale/targeted advertising; processor duties.
Enforcement
Authority: Iowa Attorney General
Private right of action: No
Penalty / remedy baseline: Up to $7,500 per violation after statutory enforcement process
What makes Iowa different?
Iowa is comparatively business-friendly. It offers a narrower rights package than many peers and uses an opt-out approach for sensitive-data processing rather than a general opt-in consent rule.
Developments to watch
The 2026 Iowa Code retains Chapter 715D as the operative comprehensive privacy framework.
Editorial rule: future-effective, proposed and pending measures are kept separate from current law.
Primary sources & verification
Last verified: August 26, 2026
Research standard: primary official sources prioritized; official guidance used to explain operational requirements.