close
close
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Iowa Privacy Law

IA

Iowa (ICDPA)

Last updated

ICDPA Enacted, in effect

Who this affects: This page tracks Iowa’s ICDPA, which governs controllers and processors.

Who it applies to: Persons that do business in Iowa or target its residents, and meet: 100,000+ consumers, or 25,000+ consumers and more than 50% of gross revenue from selling data.

Content on this page is not legal advice This page aggregates publicly cited regulatory facts for informational purposes only. It is not legal advice, and DataGrail is not responsible for decisions made in reliance on it. Consult qualified counsel for your specific compliance obligations.
Jan 1, 2025
Effective ↗
Attorney General
Enforced by ↗
$7,500
Maximum penalty per violation ↗
None
Private right of action ↗

The law, in plain English

Must · Can’t · Should

ICDPA, distilled to what actually changes your week. Read one column to know your floor, your hard limits, and the further obligations and good practices worth planning for.

Must

  • Honor consumer requests to access, delete, copy, and opt out of sale of personal data, responding within ninety days. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. IA-715D.3 “To confirm whether a controller is processing the consumer’s personal data and to access such personal data.” Read the statute IA-715D.3 “To delete personal data provided by the consumer.” Read the statute IA-715D.3 “To obtain a copy of the consumer’s personal data, except as to personal data that is defined as “personal information” pursuant to section 715C.1 that is subject to security breach” Read the statute IA-715D.3 “To opt out of the sale of personal data.” Read the statute IA-715D.3 “A controller shall respond to the consumer without undue delay, but in all cases within ninety days of receipt of a request submitted pursuant to the methods described in this section.” Read the statute
  • Explain any refusal, offer an appeal process, and answer appeals in writing within sixty days with your reasons. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. IA-715D.3 “the controller shall inform the consumer without undue delay of the justification for declining to take action, except in the case of a suspected fraudulent request, in which case the controller may state that the controller was unable to authenticate the request. The controller shall also provide instructions for appealing the decision pursuant to subsection 3.” Read the statute IA-715D.3 “A controller shall establish a process for a consumer to appeal the controller’s refusal to take action on a request within a reasonable period of time after the consumer’s receipt of the decision pursuant to this section.” Read the statute IA-715D.3 “Within sixty days of receipt of an appeal, a controller shall inform the consumer in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decision.” Read the statute
  • Bind processors by contract setting instructions, nature and purpose, data type, duration, and both parties' rights and duties. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. IA-715D.5 “A contract between a controller and a processor shall govern the processor’s data processing procedures with respect to processing performed on behalf of the controller. The contract shall clearly set forth instructions for processing personal data, the nature and purpose of processing, the type of data subject to processing, the duration of processing, and the rights and duties of both parties.” Read the statute

Can't

  • Process sensitive data for a nonexempt purpose without clear notice and opt-out, or a known child's sensitive data outside COPPA. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. IA-715D.4 “A controller shall not process sensitive data collected from a consumer for a nonexempt purpose without the consumer having been presented with clear notice and an opportunity to opt out of such processing, or, in the case of the processing of sensitive data concerning a known child, without processing such data in accordance with the federal Children’s Online Privacy Protection Act” Read the statute
  • Discriminate against a consumer for exercising any right under this law, including by denying goods or services. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. IA-715D.4 “A controller shall not discriminate against a consumer for exercising any of the consumer rights contained in this chapter, including denying goods or services, charging different prices or rates for goods or services” Read the statute
  • Require a consumer to create a new account to exercise privacy rights, though you may require use of an existing account. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. IA-715D.4 “A controller shall not require a consumer to create a new account in order to exercise consumer rights pursuant to section 715D.3, but may require a consumer to use an existing account.” Read the statute

Should

  • Track each request's ninety-day deadline; if extending once by forty-five days, tell the consumer why before it expires. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. IA-715D.3 “A controller shall respond to the consumer without undue delay, but in all cases within ninety days of receipt of a request submitted pursuant to the methods described in this section.” Read the statute IA-715D.3 “The response period may be extended once by forty-five additional days when reasonably necessary upon considering the complexity and number of the consumer’s requests by informing the consumer of any such extension within the initial ninety-day response period, together with the reason for the extension” Read the statute
  • Log requests per consumer, because responses must be provided free of charge up to twice annually per consumer. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. IA-715D.3 “Information provided in response to a consumer request shall be provided by a controller free of charge, up to twice annually per consumer.” Read the statute
  • Publish a clear, accessible privacy notice that describes secure and reliable means for consumers to submit rights requests. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. IA-715D.4 “A controller shall provide consumers with a reasonably accessible, clear, and meaningful privacy notice that includes the following:” Read the statute IA-715D.4 “A controller shall establish, and shall describe in a privacy notice, secure and reliable means for consumers to submit a request to exercise their consumer rights under this chapter.” Read the statute

These are the highlights we judge most important, not everything ICDPA requires. The comprehensive law section below covers the full detail, fact by fact, with the statutory text behind every one.

The comprehensive law

Iowa Consumer Data Protection Act

ICDPA (SF 262) is Iowa’s comprehensive privacy law. Every fact was extracted from the primary statute by the DataGrail regulation engine and is grounded to the cited source. Scan the facts; the exact statutory text sits one click away on each source link.

Status
Enacted, in effect
Archived excerpt — the text we read Sec. 10. EFFECTIVE DATE. This Act takes effect January 1, 2025. ______________________________ AMY SINCLAIR President of the Senate ______________________________ PAT GRASSLEY Speaker of the House I hereby certify that this bill originated in the Senate and is known as Senate File… Archived from source — captured 2026-08-14 · snapshot 88345958 Verify at the source
Effective
January 1, 2025
Archived excerpt — the text we read Sec. 10. EFFECTIVE DATE. This Act takes effect January 1, 2025. ______________________________ AMY SINCLAIR President of the Senate ______________________________ PAT GRASSLEY Speaker of the House I hereby certify that this bill originated in the Senate and is known as Senate File… Archived from source — captured 2026-08-14 · snapshot 88345958 Verify at the source
Signed
March 28, 2023
“March 28, 2023 Signed by Governor. S.J. 719.” View the source

Corroborated by Legislative record

Enforced by
Attorney General
Archived excerpt — the text we read 715D.8 Enforcement — penalties. 1. The attorney general shall have exclusive authority to enforce the provisions of this chapter. Whenever the attorney general has reasonable cause to believe that any person has engaged in, is engaging in, or is about to engage in any violation of this chapter, the attorney general is empowered to issue a civil in… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
Maximum penalty per violation
$7,500
“the attorney general may initiate an action in the name of the state and may seek an injunction to restrain any violations of this chapter and civil penalties of up to seven thousand five hundred dollars for each violation under this chapter” View the statute
Right to cure
90 days
Archived excerpt — the text we read …ney general is empowered to issue a civil investigative demand. The provisions of section 685.6 shall apply to civil investigative demands issued under this chapter. 2. Prior to initiating any action under this chapter, the attorney general shall provide a controller or processor ninety days’ written notice identifying the specific provisions of this chapter the attorney general alleges have been or are being violated. If within the ninety-day period, the controller or processor cures the noticed violation and provides the attorney general an express written statement that the alleged violations have been cured and that no further su… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
Private right of action
No private right of action.
Archived excerpt — the text we read …ollected under this section including civil penalties, costs, attorney fees, or amounts which are specifically directed shall be paid into the consumer education and litigation fund established under section 714.16C. 4. Nothing in this chapter shall be construed as providing the basis for, or be subject to, a private right of action for violations of this chapter or under any other law. 2023 Acts, ch 17, §8, 10 Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source

Corroborated by Privacy-law tracker

Universal opt-out signal
Not required

Corroborated by Privacy-law tracker

Who it applies to

Persons that do business in Iowa or target its residents, and meet: 100,000+ consumers, or 25,000+ consumers and more than 50% of gross revenue from selling data

What the law gives consumers

  • Right to access Archived excerpt — the text we read …y invoke such consumer rights on behalf of the known child regarding processing personal data belonging to the child. A controller shall comply with an authenticated consumer request to exercise all of the following: a. To confirm whether a controller is processing the consumer’s personal data and to access such personal data. b. To delete personal data provided by the consumer. c. To obtain a copy of the consumer’s personal data, except as to personal data that is defined as “personal information” pursuant to section 715C.1 that is subject t… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Right to delete Archived excerpt — the text we read …hild. A controller shall comply with an authenticated consumer request to exercise all of the following: a. To confirm whether a controller is processing the consumer’s personal data and to access such personal data. b. To delete personal data provided by the consumer. c. To obtain a copy of the consumer’s personal data, except as to personal data that is defined as “personal information” pursuant to section 715C.1 that is subject to security breach … Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Right to data portability (limited) Excludes 'personal information' under 715C.1 that is subject to security breach protection; covers only data the consumer previously provided, where processing is automated. Archived excerpt — the text we read … consumer request to exercise all of the following: a. To confirm whether a controller is processing the consumer’s personal data and to access such personal data. b. To delete personal data provided by the consumer. c. To obtain a copy of the consumer’s personal data, except as to personal data that is defined as “personal information” pursuant to section 715C.1 that is subject to security breach protection, that the consumer previously provided to the controller in a portable and, to the extent technically pr… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Right to opt out of sale Archived excerpt — the text we read …ortable and, to the extent technically practicable, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means. d. To opt out of the sale of personal data. 2. Except as otherwise provided in this chapter, a controller shall comply with a request by a consumer to exercise the consumer rights authorized pursuant to this section as follows: a. A controller shall respond to th… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Sensitive data: notice and opt-out Archived excerpt — the text we read …hysical data security practices to protect the confidentiality, integrity, and accessibility of personal data. Such data security practices shall be appropriate to the volume and nature of the personal data at issue. 2. A controller shall not process sensitive data collected from a consumer for a nonexempt purpose without the consumer having been presented with clear notice and an opportunity to opt out of such processing, or, in the case of the processing of sensitive data concerning a known child, without processing such data in accordance with the federal Children’s Online Privacy Protection Act, 15 U.S.C. §6501 et seq. 3. A controlle… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Right to appeal Archived excerpt — the text we read …equired to comply with a request to initiate an action under this section and may request that the consumer provide additional information reasonably necessary to authenticate the consumer and the consumer’s request. 3. A controller shall establish a process for a consumer to appeal the controller’s refusal to take action on a request within a reasonable period of time after the consumer’s receipt of the decision pursuant to this section. The appeal process shall be conspicuously available and similar to the process for submitting requests to initiate action pursuant to this section. Within sixty days of receipt of an appeal, a controller shall inform th… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Right against discrimination Archived excerpt — the text we read … federal Children’s Online Privacy Protection Act, 15 U.S.C. §6501 et seq. 3. A controller shall not process personal data in violation of state and federal laws that prohibit unlawful discrimination against a consumer. A controller shall not discriminate against a consumer for exercising any of the consumer rights contained in this chapter, including denying goods or services, charging different prices or rates for goods or services, or providing a diff… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Not granted: Private right of action Archived excerpt — the text we read …ollected under this section including civil penalties, costs, attorney fees, or amounts which are specifically directed shall be paid into the consumer education and litigation fund established under section 714.16C. 4. Nothing in this chapter shall be construed as providing the basis for, or be subject to, a private right of action for violations of this chapter or under any other law. 2023 Acts, ch 17, §8, 10 Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source

Who the law governs

  • Controllers Archived excerpt — the text we read …s affirmative action. 7. “Consumer” means a natural person who is a resident of the state acting only in an individual or household context and excluding a natural person acting in a commercial or employment context. 8. “Controller” means a person that, alone or jointly with others, determines the purpose and means of processing personal data. 9. “Covered entity” means the same as “covered entity” defined by HIPAA. 10. “De-identified data” means data that cannot reasonably be linked to an identified or identifiable natural person. 11. “Fund” means the consume… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Processors Archived excerpt — the text we read …et of operations performed, whether by manual or automated means, on personal data or on sets of personal data, such as the collection, use, storage, disclosure, analysis, deletion, or modification of personal data. 21. “Processor” means a person that processes personal data on behalf of a controller. 22. “Protected health information” means the same as protected health information established by HIPAA. 23. “Pseudonymous data” means personal data that cannot be attributed to a specific natural person without the use … Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source

Exemptions

  • State and political subdivisions Archived excerpt — the text we read …sonal data of at least one hundred thousand consumers. b. Controls or processes personal data of at least twenty-five thousand consumers and derives over fifty percent of gross revenue from the sale of personal data. 2. This chapter shall not apply to the state or any political subdivision of the state; financial institutions, affiliates of financial institutions, or data subject to Tit. V of the federal Gramm-Leach-Bliley Act of 1999, 15 U.S.C. §6801 et seq.; persons who are subject to and comply with regulations pro… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • GLBA: financial institutions, their affiliates, and data subject to Title V Entity- and data-level Archived excerpt — the text we read …nal data of at least twenty-five thousand consumers and derives over fifty percent of gross revenue from the sale of personal data. 2. This chapter shall not apply to the state or any political subdivision of the state; financial institutions, affiliates of financial institutions, or data subject to Tit. V of the federal Gramm-Leach-Bliley Act of 1999, 15 U.S.C. §6801 et seq.; persons who are subject to and comply with regulations promulgated pursuant to Tit. II, subtit. F, of the federal Health Insurance Portability and Accountability Act of 1996, Pub. L. No. 104-191, and Tit. XIII, subtit.… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Persons subject to and complying with HIPAA and HITECH regulations Entity-level Archived excerpt — the text we read …ply to the state or any political subdivision of the state; financial institutions, affiliates of financial institutions, or data subject to Tit. V of the federal Gramm-Leach-Bliley Act of 1999, 15 U.S.C. §6801 et seq.; persons who are subject to and comply with regulations promulgated pursuant to Tit. II, subtit. F, of the federal Health Insurance Portability and Accountability Act of 1996, Pub. L. No. 104-191, and Tit. XIII, subtit. D, of the federal Health Information Technology for Economic and Clinical Health Act of 2009, 42 U.S.C. §17921 – 17954; nonprofit organizations; or institutions of higher education. 3. The following information and data is exempt from this chapter: a. Protected health information under HIPAA. b. Health records.… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Nonprofit organizations Archived excerpt — the text we read …h Insurance Portability and Accountability Act of 1996, Pub. L. No. 104-191, and Tit. XIII, subtit. D, of the federal Health Information Technology for Economic and Clinical Health Act of 2009, 42 U.S.C. §17921 – 17954; nonprofit organizations; or institutions of higher education. 3. The following information and data is exempt from this chapter: a. Protected health information under HIPAA. b. Health records. c. Patient identifying information for purposes of 42 U.S.C. §290dd-2. d. Identifiable … Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Institutions of higher education Archived excerpt — the text we read …nd Accountability Act of 1996, Pub. L. No. 104-191, and Tit. XIII, subtit. D, of the federal Health Information Technology for Economic and Clinical Health Act of 2009, 42 U.S.C. §17921 – 17954; nonprofit organizations; or institutions of higher education. 3. The following information and data is exempt from this chapter: a. Protected health information under HIPAA. b. Health records. c. Patient identifying information for purposes of 42 U.S.C. §290dd-2. d. Identifiable … Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Protected health information under HIPAA Archived excerpt — the text we read …tion Technology for Economic and Clinical Health Act of 2009, 42 U.S.C. §17921 – 17954; nonprofit organizations; or institutions of higher education. 3. The following information and data is exempt from this chapter: a. Protected health information under HIPAA. b. Health records. c. Patient identifying information for purposes of 42 U.S.C. §290dd-2. d. Identifiable private information for purposes of the federal policy for the protection of human subjects under 45 C.F.R. pt. 4… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Health records Archived excerpt — the text we read …lth Act of 2009, 42 U.S.C. §17921 – 17954; nonprofit organizations; or institutions of higher education. 3. The following information and data is exempt from this chapter: a. Protected health information under HIPAA. b. Health records. c. Patient identifying information for purposes of 42 U.S.C. §290dd-2. d. Identifiable private information for purposes of the federal policy for the protection of human subjects under 45 C.F.R. pt. 46. … Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Patient identifying information Archived excerpt — the text we read … U.S.C. §17921 – 17954; nonprofit organizations; or institutions of higher education. 3. The following information and data is exempt from this chapter: a. Protected health information under HIPAA. b. Health records. c. Patient identifying information for purposes of 42 U.S.C. §290dd-2. d. Identifiable private information for purposes of the federal policy for the protection of human subjects under 45 C.F.R. pt. 46. … Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Human subjects research information Archived excerpt — the text we read …her education. 3. The following information and data is exempt from this chapter: a. Protected health information under HIPAA. b. Health records. c. Patient identifying information for purposes of 42 U.S.C. §290dd-2. d. Identifiable private information for purposes of the federal policy for the protection of human subjects under 45 C.F.R. pt. 46. e. Identifiable private information that is otherwise information collected as part of human subjects research purs… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Good clinical practice research information Archived excerpt — the text we read …vate information for purposes of the federal policy for the protection of human subjects under 45 C.F.R. pt. 46. e. Identifiable private information that is otherwise information collected as part of human subjects research pursuant to the good clinical practice guidelines issued by the international council for harmonization of technical requirements for pharmaceuticals for human use. f. The protection of human subjects under 21 C.F.R. pts. 6, 50, and 56. g. Personal data used or shared in research conducted in accordance with the requirements set forth in this chapter, or other research conducted in… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Protection of human subjects under FDA rules Archived excerpt — the text we read …mation collected as part of human subjects research pursuant to the good clinical practice guidelines issued by the international council for harmonization of technical requirements for pharmaceuticals for human use. f. The protection of human subjects under 21 C.F.R. pts. 6, 50, and 56. g. Personal data used or shared in research conducted in accordance with the requirements set forth in this chapter, or other research conducted in accordance with applicable law. h. Information and documents created fo… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Personal data used or shared in research conducted under this chapter or other applicable law Archived excerpt — the text we read … clinical practice guidelines issued by the international council for harmonization of technical requirements for pharmaceuticals for human use. f. The protection of human subjects under 21 C.F.R. pts. 6, 50, and 56. g. Personal data used or shared in research conducted in accordance with the requirements set forth in this chapter, or other research conducted in accordance with applicable law. h. Information and documents created for purposes of the federal Health Care Quality Improvement Act of 1986, 42 U.S.C. §11101 et seq. i. Patient safety work product for purposes of the federal Patient Safety and Qualit… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Health Care Quality Improvement Act information Archived excerpt — the text we read … under 21 C.F.R. pts. 6, 50, and 56. g. Personal data used or shared in research conducted in accordance with the requirements set forth in this chapter, or other research conducted in accordance with applicable law. h. Information and documents created for purposes of the federal Health Care Quality Improvement Act of 1986, 42 U.S.C. §11101 et seq. i. Patient safety work product for purposes of the federal Patient Safety and Quality Improvement Act, 42 U.S.C. §299b-21 et seq. j. Information derived from any of the health care-related information listed in this sub… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Patient Safety and Quality Improvement Act work product Archived excerpt — the text we read …h in this chapter, or other research conducted in accordance with applicable law. h. Information and documents created for purposes of the federal Health Care Quality Improvement Act of 1986, 42 U.S.C. §11101 et seq. i. Patient safety work product for purposes of the federal Patient Safety and Quality Improvement Act, 42 U.S.C. §299b-21 et seq. j. Information derived from any of the health care-related information listed in this subsection that is de-identified in accordance with the requirements for de-identification pursuant to HIPAA. k. Information originat… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • De-identified health information Archived excerpt — the text we read …s of the federal Health Care Quality Improvement Act of 1986, 42 U.S.C. §11101 et seq. i. Patient safety work product for purposes of the federal Patient Safety and Quality Improvement Act, 42 U.S.C. §299b-21 et seq. j. Information derived from any of the health care-related information listed in this subsection that is de-identified in accordance with the requirements for de-identification pursuant to HIPAA. k. Information originating from, and intermingled to be indistinguishable with, or information treated in the same manner as information exempt under this subsection that is maintained by a covered entity or business as… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Information intermingled with HIPAA-exempt data Archived excerpt — the text we read ….C. §299b-21 et seq. j. Information derived from any of the health care-related information listed in this subsection that is de-identified in accordance with the requirements for de-identification pursuant to HIPAA. k. Information originating from, and intermingled to be indistinguishable with, or information treated in the same manner as information exempt under this subsection that is maintained by a covered entity or business associate as defined by HIPAA or a program or a qualified service organization as defined by 42 U.S.C. §290dd-2. l. Information used only for public health activities and purposes as authorized by HIPAA. m. The collection, maintenance, disclosure, sale, communication, or use of any personal information bearing on a consumer’s cred… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Public health activities information Archived excerpt — the text we read …e manner as information exempt under this subsection that is maintained by a covered entity or business associate as defined by HIPAA or a program or a qualified service organization as defined by 42 U.S.C. §290dd-2. l. Information used only for public health activities and purposes as authorized by HIPAA. m. The collection, maintenance, disclosure, sale, communication, or use of any personal information bearing on a consumer’s credit worthiness, credit standing, credit capacity, character, general reputation, personal ch… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • FCRA-regulated data Archived excerpt — the text we read …apacity, character, general reputation, personal characteristics, or mode of living by a consumer reporting agency or furnisher that provides information for use in a consumer report, and by a user of a consumer report, but only to the extent that such activity is regulated by and authorized under the federal Fair Credit Reporting Act, 15 U.S.C. §1681 et seq. n. Personal data collected, processed, sold, or disclosed in compliance with the federal Driver’s Privacy Protection Act of 1994, 18 U.S.C. §2721 et seq. o. Personal data regulated by the federal Family Educational Righ… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Driver's Privacy Protection Act data Archived excerpt — the text we read …ormation for use in a consumer report, and by a user of a consumer report, but only to the extent that such activity is regulated by and authorized under the federal Fair Credit Reporting Act, 15 U.S.C. §1681 et seq. n. Personal data collected, processed, sold, or disclosed in compliance with the federal Driver’s Privacy Protection Act of 1994, 18 U.S.C. §2721 et seq. o. Personal data regulated by the federal Family Educational Rights and Privacy Act, 20 U.S.C. §1232 et seq. p. Personal data collected, processed, sold, or disclosed in compliance with the federal Farm Credit Act, 12 U… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • FERPA-regulated data Archived excerpt — the text we read …the federal Fair Credit Reporting Act, 15 U.S.C. §1681 et seq. n. Personal data collected, processed, sold, or disclosed in compliance with the federal Driver’s Privacy Protection Act of 1994, 18 U.S.C. §2721 et seq. o. Personal data regulated by the federal Family Educational Rights and Privacy Act, 20 U.S.C. §1232 et seq. p. Personal data collected, processed, sold, or disclosed in compliance with the federal Farm Credit Act, 12 U.S.C. §2001 et seq. q. Data processed or maintained as follows: (1) In the course of an individual applying t… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Farm Credit Act data Archived excerpt — the text we read …r disclosed in compliance with the federal Driver’s Privacy Protection Act of 1994, 18 U.S.C. §2721 et seq. o. Personal data regulated by the federal Family Educational Rights and Privacy Act, 20 U.S.C. §1232 et seq. p. Personal data collected, processed, sold, or disclosed in compliance with the federal Farm Credit Act, 12 U.S.C. §2001 et seq. q. Data processed or maintained as follows: (1) In the course of an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party, to the extent that the… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Employment data Archived excerpt — the text we read … and Privacy Act, 20 U.S.C. §1232 et seq. p. Personal data collected, processed, sold, or disclosed in compliance with the federal Farm Credit Act, 12 U.S.C. §2001 et seq. q. Data processed or maintained as follows: (1) In the course of an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party, to the extent that the data is collected and used within the context of that role. (2) As the emergency contact information of an individual under this chapter used for emergency contact purposes. (3) That is necessary to retain to administer benefits for another individual relating to the individual … Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Emergency contact information Archived excerpt — the text we read … an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party, to the extent that the data is collected and used within the context of that role. (2) As the emergency contact information of an individual under this chapter used for emergency contact purposes. (3) That is necessary to retain to administer benefits for another individual relating to the individual under subparagraph (1) and used for the purposes of administering those benefits. r. Personal data used in accorda… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Benefits administration data Archived excerpt — the text we read …r, or third party, to the extent that the data is collected and used within the context of that role. (2) As the emergency contact information of an individual under this chapter used for emergency contact purposes. (3) That is necessary to retain to administer benefits for another individual relating to the individual under subparagraph (1) and used for the purposes of administering those benefits. r. Personal data used in accordance with the federal Children’s Online Privacy Protection Act, 15 U.S.C. §6501 – 6506, and its rules, regulations, and exceptions thereto. 2023 Acts, ch 17, §2, 10 Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • COPPA-regulated data Archived excerpt — the text we read …r emergency contact purposes. (3) That is necessary to retain to administer benefits for another individual relating to the individual under subparagraph (1) and used for the purposes of administering those benefits. r. Personal data used in accordance with the federal Children’s Online Privacy Protection Act, 15 U.S.C. §6501 – 6506, and its rules, regulations, and exceptions thereto. 2023 Acts, ch 17, §2, 10 Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Privileged communications to a person covered by an evidentiary privilege Archived excerpt — the text we read …e obligations imposed on controllers or processors under this chapter shall not apply where compliance by the controller or processor with this chapter would violate an evidentiary privilege under the laws of the state. Nothing in this chapter shall be construed to prevent a controller or processor from providing personal data concerning a consumer to a person covered by an evidentiary privilege under the laws of the state as part of a privileged communication. 4. A controller or processor that discloses personal data to a third-party controller or processor, in compliance with the requirements of this chapter, is not in violation of this chapter if the third-party controller … Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Evidentiary privilege (compliance would violate an Iowa evidentiary privilege) Archived excerpt — the text we read …rance of the provision of a product or service specifically requested by a consumer or parent or guardian of a child or the performance of a contract to which the consumer or parent or guardian of a child is a party. 3. The obligations imposed on controllers or processors under this chapter shall not apply where compliance by the controller or processor with this chapter would violate an evidentiary privilege under the laws of the state. Nothing in this chapter shall be construed to prevent a controller or processor from providing personal data concerning a consumer to a person covered by an evidentiary privilege under the laws of the state as part of … Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Purely personal or household activity Archived excerpt — the text we read … controller or a processor that adversely affects the privacy or other rights or freedoms of any persons, such as exercising the right of free speech pursuant to the first amendment to the United States Constitution, or applies to personal data by a person in the course of a purely personal or household activity. 6. Personal data processed by a controller pursuant to this section shall not be processed for any purpose other than those expressly listed in this section unless otherwise allowed by this chapter. Personal data proce… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Trade secrets (no obligation to disclose) Archived excerpt — the text we read …omplies with the requirements in subsection 6. 8. Processing personal data for the purposes expressly identified in subsection 1 shall not in and of itself make an entity a controller with respect to such processing. 9. This chapter shall not require a controller, processor, third party, or consumer to disclose trade secrets. 2023 Acts, ch 17, §7, 10 Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source
  • Rights and freedoms of others, including free speech Archived excerpt — the text we read …om a controller or processor in compliance with the requirements of this chapter is likewise not in violation of this chapter for the offenses of the controller or processor from which it receives such personal data. 5. Nothing in this chapter shall be construed as an obligation imposed on a controller or a processor that adversely affects the privacy or other rights or freedoms of any persons, such as exercising the right of free speech pursuant to the first amendment to the United States Constitution, or applies to personal data by a person in the course of a purely personal or household activity. 6. Personal data processed by a controller pursuant to this section shall not be processed for any purpose other than th… Archived from source — captured 2026-07-16 · snapshot 6df3505b Verify at the source

Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source.

Timeline

ICDPA milestones

This state currently has one dated milestone on the books.

Enforcement January 1, 2025

ICDPA took effect

Enforcement began — obligations have been live since this date.

Source: primary citation

Enforcement so far

The fines are already landing

Real regulatory actions and settlements under the Iowa privacy laws we track. Every entry is a DataGrail summary linking to the primary source.

$18M Total penalties
1 Actions on record
View all

DataGrail’s wording, not statutory text. The figures are computed from the linked sources.

Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source. Reference only, not legal advice.

When staying on top of the law isn't enough, DataGrail automates the work.
DSR automation and regulatory tracking — handled by the platform behind this reference.
How DataGrail helps
Back to the Regulations Hub Reference only — not legal advice. Published Sep 29, 2026