🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-IA · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 11 sources retrieved model claude-sonnet-5 ·

United States – Iowa

US-IA schema gdpri-v2 trajectory: not recordedhybrid regimeoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 39 claims · 11 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
39Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core instrument is in force, regulator identity and enforcement pathway are well documented from primary AG sources and secondary legal trackers.

Primary frameworkIowa Consumer Data Protection Act (Senate File 262), Iowa Code ch. 715D
Supervisory authorityIowa Attorney General
Traffic-light rationale — GreenCore instrument is in force, regulator identity and enforcement pathway are well documented from primary AG sources and secondary legal trackers.

Sub-modules (5)

Regulator And AuthorityGreen

The Iowa Attorney General holds exclusive enforcement authority over the ICDPA via civil investigative demands; there is no dedicated privacy agency and no private right of action.

Claims (1):

  • The Iowa Attorney General holds exclusive enforcement authority over the ICDPA through civil investigative demands, and the statute provides no private right of action for consumers.

Act And InstrumentsGreen

ICDPA (SF 262) signed March 28, 2023; effective January 1, 2025.

Claims (1):

  • The Iowa Consumer Data Protection Act (Senate File 262) was signed into law on March 28, 2023 and entered into effect on January 1, 2025.

Material ScopeGreen

Scope is defined by consumer-count and revenue-mix thresholds rather than a blanket applicability test.

Claims (1):

  • The ICDPA applies to entities that control or process personal data of at least 100,000 Iowa consumers, or that derive more than 50% of gross revenue from the sale of personal data while controlling/processing data of at least 25,000 Iowa consumers.

Territorial ScopeGreen

Applies to entities conducting business in Iowa or targeting Iowa consumers with products/services, regardless of physical establishment in the state.

Claims (1):

  • The ICDPA applies to entities that conduct business in Iowa or produce products or services targeted to Iowa consumers, without an independent revenue threshold as a scope trigger.

Regulator Registration And FilingAmber

No controller registration or pre-processing filing regime exists under the ICDPA; the only filing-type duty is post-breach notice to the AG under the separate breach-notification statute.

Claims (1):

  • The ICDPA imposes no controller registration or advance-filing obligation with the Attorney General; the only regulator-facing filing duty identified is post-breach written notice under Iowa's Personal Information Security Breach Protection Act.
Category narrative67 words

Iowa's data-protection regime is anchored in the Iowa Consumer Data Protection Act (ICDPA, Senate File 262), a comprehensive consumer-privacy statute enforced exclusively by the Iowa Attorney General, with no dedicated data-protection authority. The Act is layered over pre-existing sectoral instruments (notably the Personal Information Security Breach Protection Act, Iowa Code ch. 715C) and federal sectoral overlays (HIPAA, GLBA, FERPA, COPPA), producing a hybrid rather than omnibus regime.

Sources and claims (5)
  1. ConfirmedInternational Association of Privacy ProfessionalsThe Iowa Attorney General holds exclusive enforcement authority over the ICDPA through civil investigative demands, and the statute provides no private right of action for consumers.observed
  2. ConfirmedOneTrust DataGuidanceThe Iowa Consumer Data Protection Act (Senate File 262) was signed into law on March 28, 2023 and entered into effect on January 1, 2025.observed
  3. ConfirmedInternational Association of Privacy ProfessionalsThe ICDPA applies to entities that control or process personal data of at least 100,000 Iowa consumers, or that derive more than 50% of gross revenue from the sale of personal data while controlling/processing data of at least 25,000 Iowa consumers.observed
  4. ConfirmedInternational Association of Privacy ProfessionalsThe ICDPA applies to entities that conduct business in Iowa or produce products or services targeted to Iowa consumers, without an independent revenue threshold as a scope trigger.observed
  5. ProbableState of Iowa Office of the Attorney GeneralThe ICDPA imposes no controller registration or advance-filing obligation with the Attorney General; the only regulator-facing filing duty identified is post-breach written notice under Iowa's Personal Information Security Breach Protection Act.observed

#

Consent and sensitive-data protections are materially weaker than GDPR-analogue peer states (no opt-in for sensitive data, no purpose limitation/data-minimization duty).

Primary frameworkIowa Consumer Data Protection Act (Iowa Code ch. 715D)
Supervisory authorityIowa Attorney General
Traffic-light rationale — AmberConsent and sensitive-data protections are materially weaker than GDPR-analogue peer states (no opt-in for sensitive data, no purpose limitation/data-minimization duty).

Sub-modules (4)

Lawful BasesAmber

No closed enumerated list of lawful bases; processing must be reasonably necessary and proportionate to disclosed purposes.

Claims (1):

  • Controllers may process personal data that is reasonably necessary and proportionate to the purposes disclosed to the consumer, in lieu of an enumerated closed list of lawful bases analogous to GDPR Article 6.

Special CategoriesAmber

Sensitive data processing uses a notice-and-opt-out model rather than opt-in consent, diverging from Colorado, Connecticut and Virginia.

Claims (1):

  • Unlike Colorado, Connecticut and Virginia, the ICDPA does not require opt-in consent for sensitive-data processing; it instead requires clear notice and an opportunity for the consumer to opt out.

Pseudonymisation And AnonymisationGreen

Deidentified/aggregate data are excluded from 'personal data'; opt-out rights do not extend to pseudonymous data.

Claims (1):

  • The ICDPA excludes deidentified and aggregate data from the definition of personal data, and consumer opt-out rights do not extend to pseudonymous data, in contrast to Colorado, Connecticut, Virginia and Utah.
Category narrative49 words

The ICDPA lacks a GDPR-style enumerated list of lawful bases, relying instead on a purpose-and-proportionality standard disclosed via privacy notice. Consent must be freely given, specific, informed and unambiguous. Uniquely among early-wave state laws, Iowa does not require opt-in consent for sensitive data, relying on an opt-out/notice model instead.

Sources and claims (4)
  1. ConfirmedInternational Association of Privacy ProfessionalsControllers may process personal data that is reasonably necessary and proportionate to the purposes disclosed to the consumer, in lieu of an enumerated closed list of lawful bases analogous to GDPR Article 6.observed
  2. ConfirmedInternational Association of Privacy ProfessionalsThe ICDPA requires consent to be a clear affirmative act indicating a consumer's freely given, specific, informed and unambiguous agreement to processing.observed
  3. ConfirmedInternational Association of Privacy ProfessionalsUnlike Colorado, Connecticut and Virginia, the ICDPA does not require opt-in consent for sensitive-data processing; it instead requires clear notice and an opportunity for the consumer to opt out.observed
  4. ConfirmedInternational Association of Privacy ProfessionalsThe ICDPA excludes deidentified and aggregate data from the definition of personal data, and consumer opt-out rights do not extend to pseudonymous data, in contrast to Colorado, Connecticut, Virginia and Utah.observed

#

Materially narrower rights basket than peer comprehensive state laws; longer statutory response windows reduce consumer-facing responsiveness.

Primary frameworkIowa Consumer Data Protection Act (Iowa Code ch. 715D)
Supervisory authorityIowa Attorney General
Traffic-light rationale — AmberMaterially narrower rights basket than peer comprehensive state laws; longer statutory response windows reduce consumer-facing responsiveness.

Sub-modules (5)

Access RightGreen

Consumers may confirm whether their data is processed and access it.

Claims (1):

  • The ICDPA provides consumers with the right to access their personal data held by a controller.

Rectification And ErasureAmber

Deletion right exists; no right to correct/rectify inaccurate data.

Claims (1):

  • The ICDPA provides a right to delete personal data but does not provide a right to rectification/correction of inaccurate personal data, unlike most peer state privacy statutes.

Restriction And ObjectionAmber

No general opt-out of targeted advertising/profiling in the rights section, though disclosure of targeted-advertising opt-out mechanics is mandated.

Claims (1):

  • The ICDPA does not provide a general consumer-rights-section opt-out for targeted advertising or profiling, though controllers engaging in targeted advertising must clearly and conspicuously disclose that activity and how to opt out.

Data PortabilityGreen

Consumers have a portability right to obtain their data in portable form.

Claims (1):

  • Consumers have a right to data portability under the ICDPA.

Deadlines And Response WindowsAmber

90-day response window with a potential 45-day extension.

Claims (1):

  • Controllers must respond to consumer rights requests within 90 days, with a potential 45-day extension, longer than the standard 45-day (extendable by 45 days) window found in most peer state statutes.
Category narrative43 words

The ICDPA provides four core consumer rights (access, deletion, portability, opt-out of sale) but deliberately omits a right to rectification and an automated-decision-making opt-out found in most peer statutes. Response windows (90 days, extendable 45 days) are longer than the 45-day/45-day-extension norm elsewhere.

Sources and claims (5)
  1. ConfirmedInternational Association of Privacy ProfessionalsThe ICDPA provides consumers with the right to access their personal data held by a controller.observed
  2. ConfirmedOneTrust DataGuidanceThe ICDPA provides a right to delete personal data but does not provide a right to rectification/correction of inaccurate personal data, unlike most peer state privacy statutes.observed
  3. ConfirmedInternational Association of Privacy ProfessionalsThe ICDPA does not provide a general consumer-rights-section opt-out for targeted advertising or profiling, though controllers engaging in targeted advertising must clearly and conspicuously disclose that activity and how to opt out.observed
  4. ConfirmedInternational Association of Privacy ProfessionalsConsumers have a right to data portability under the ICDPA.observed
  5. ConfirmedInternational Association of Privacy ProfessionalsControllers must respond to consumer rights requests within 90 days, with a potential 45-day extension, longer than the standard 45-day (extendable by 45 days) window found in most peer state statutes.observed

#

Core accountability tooling (DPIA, DPO, ROPA) is absent; security and breach-notice duties are present and well documented from primary AG sources.

Primary frameworkIowa Consumer Data Protection Act (Iowa Code ch. 715D); Personal Information Security Breach Protection Act (Iowa Code ch. 715C)
Supervisory authorityIowa Attorney General
Traffic-light rationale — AmberCore accountability tooling (DPIA, DPO, ROPA) is absent; security and breach-notice duties are present and well documented from primary AG sources.

Sub-modules (7)

Accountability And DpiaRed

No DPIA/risk-assessment obligation exists under the ICDPA.

Claims (1):

  • The ICDPA does not contain provisions requiring privacy/data-protection risk assessments, a notable divergence from Colorado, Connecticut, Virginia and Indiana.

Dpo RequirementsRed

No statutory DPO-appointment requirement found across reviewed sources.

Claims (1):

  • No statutory requirement for controllers to appoint a data protection officer was identified under the ICDPA.

Ropa RequirementsRed

No formal records-of-processing-activity obligation found.

Claims (1):

  • No formal records-of-processing-activities (ROPA) obligation is imposed on controllers or processors under the ICDPA.

Joint Controller ArrangementsGreen

Controllers must maintain binding processor contracts covering instructions, purpose, data types, duration, and subcontractor accountability.

Claims (1):

  • Controllers must have a contract with processors clearly setting forth processing instructions, nature and purpose of processing, data types, processing duration, and the rights and duties of both parties, including retention, deletion, access and subcontractor accountability.

Security MeasuresGreen

Reasonable administrative, technical and physical security practices are required, scaled to data volume/nature.

Claims (1):

  • Controllers must implement reasonable administrative, technical and physical data-security practices appropriate to the volume and nature of personal data, to protect confidentiality, integrity and availability.

Breach NotificationGreen

Breaches affecting 500+ Iowa residents require AG notice within 5 business days of consumer notification, under the separate 715C statute.

Claims (1):

  • Under the Personal Information Security Breach Protection Act (Iowa Code ch. 715C), any breach affecting 500 or more Iowa residents must be reported in writing to the Attorney General's Consumer Protection Division within five business days of notifying affected individuals.

Retention And DisposalAmber

No explicit retention-limitation or data-minimization duty; consistent with the Act's omission of purpose limitation.

Claims (1):

  • The ICDPA does not impose a data-minimization or retention-limitation obligation on controllers, consistent with its omission of purpose-limitation duties found in peer state statutes.
Category narrative53 words

The ICDPA omits data protection impact assessments, DPO appointment, and formal records-of-processing obligations entirely -- a notable divergence from Colorado, Connecticut, Virginia and Indiana. It does mandate baseline security measures, binding processor contracts, and breach notification (the latter sourced from the separate, pre-existing Personal Information Security Breach Protection Act, Iowa Code ch. 715C).

Sources and claims (7)
  1. ConfirmedOneTrust DataGuidanceThe ICDPA does not contain provisions requiring privacy/data-protection risk assessments, a notable divergence from Colorado, Connecticut, Virginia and Indiana.observed
  2. ProbableOneTrust DataGuidanceNo statutory requirement for controllers to appoint a data protection officer was identified under the ICDPA.observed
  3. ProbableOneTrust DataGuidanceNo formal records-of-processing-activities (ROPA) obligation is imposed on controllers or processors under the ICDPA.observed
  4. ConfirmedInternational Association of Privacy ProfessionalsControllers must have a contract with processors clearly setting forth processing instructions, nature and purpose of processing, data types, processing duration, and the rights and duties of both parties, including retention, deletion, access and subcontractor accountability.observed
  5. ConfirmedInternational Association of Privacy ProfessionalsControllers must implement reasonable administrative, technical and physical data-security practices appropriate to the volume and nature of personal data, to protect confidentiality, integrity and availability.observed
  6. ConfirmedState of Iowa Office of the Attorney GeneralUnder the Personal Information Security Breach Protection Act (Iowa Code ch. 715C), any breach affecting 500 or more Iowa residents must be reported in writing to the Attorney General's Consumer Protection Division within five business days of notifying affected individuals.observed
  7. ProbableInternational Association of Privacy ProfessionalsThe ICDPA does not impose a data-minimization or retention-limitation obligation on controllers, consistent with its omission of purpose-limitation duties found in peer state statutes.observed

#

No cross-border transfer framework exists in the operative Iowa statute; absence confirmed across all reviewed primary and secondary sources.

Traffic-light rationale — RedNo cross-border transfer framework exists in the operative Iowa statute; absence confirmed across all reviewed primary and secondary sources.

Sub-modules (6)

Transfer MechanismsRed

No transfer-mechanism regime found.

Claims (1):

  • The ICDPA contains no cross-border data-transfer mechanism, adequacy determination, SCC/BCR framework, or data-localisation mandate; such transfer-restriction regimes are a feature of omnibus regimes such as the GDPR and are not present in current Iowa state law.

Adequacy ReceivedRed

Not applicable; US states do not receive adequacy decisions under foreign frameworks.

Adequacy GrantedRed

Not applicable; Iowa does not issue adequacy determinations.

Sccs And BcrsRed

No SCC/BCR analogue exists in the ICDPA.

Transfer Impact AssessmentRed

No TIA requirement exists in the ICDPA.

Data LocalisationRed

No data-localisation mandate exists in the ICDPA.

Category narrative53 words

As a US state consumer-privacy statute, the ICDPA does not create an adequacy, SCC/BCR, transfer-impact-assessment, or data-localisation regime analogous to GDPR Chapter V; such transfer-restriction machinery is characteristic of omnibus regimes and has no counterpart in current Iowa law. This module is populated with an explicit absence finding rather than left silently empty.

Sources and claims (1)
  1. ConfirmedOneTrust DataGuidanceThe ICDPA contains no cross-border data-transfer mechanism, adequacy determination, SCC/BCR framework, or data-localisation mandate; such transfer-restriction regimes are a feature of omnibus regimes such as the GDPR and are not present in current Iowa state law.observed

#

Exemption structure well documented; several declared sub-modules (telecoms/eprivacy, credit_and_scoring, insurance) carry no Iowa-specific findings.

Primary frameworkIowa Consumer Data Protection Act (Iowa Code ch. 715D)
Supervisory authorityIowa Attorney General
Traffic-light rationale — AmberExemption structure well documented; several declared sub-modules (telecoms/eprivacy, credit_and_scoring, insurance) carry no Iowa-specific findings.

Sub-modules (7)

Financial Sector OverlayGreen

GLBA-covered financial institutions and affiliates are exempt from ICDPA scope.

Claims (1):

  • The ICDPA exempts financial institutions and their affiliates, and entities and data subject to the Gramm-Leach-Bliley Act, from its scope.

Health Sector OverlayGreen

HIPAA/HITECH-covered entities and health records are exempt from ICDPA scope.

Claims (1):

  • The ICDPA exempts entities and personal data covered by HIPAA and the Health Information Technology for Economic and Clinical Health Act, as well as protected health records, from its scope.

Telecoms And EprivacyRed

No Iowa-specific telecoms/eprivacy overlay identified.

Employment DataAmber

Employment-context personal data is exempt from ICDPA scope.

Claims (1):

  • The ICDPA exempts personal data processed or maintained in the employment context from its scope, leaving Iowa employees without ICDPA-based rights over employment records.

Credit And ScoringRed

No Iowa-specific credit-scoring overlay identified beyond federal FCRA, which is outside ICDPA scope.

EducationGreen

FERPA-covered education records are exempt from ICDPA scope.

Claims (1):

  • The ICDPA exempts personal data covered by the Family Educational Rights and Privacy Act (FERPA) from its scope.

InsuranceRed

No Iowa-specific insurance-sector data overlay identified.

Category narrative50 words

The ICDPA carves out broad sectoral exemptions rather than layering sector-specific overlays: GLBA-covered financial institutions, HIPAA/HITECH-covered entities and health records, FERPA-covered education records, and employment-context data are all excluded from scope, leaving those sectors governed solely by their respective federal frameworks. No Iowa-specific credit-scoring, telecoms/eprivacy, or insurance overlay was identified.

Sources and claims (4)
  1. ConfirmedInternational Association of Privacy ProfessionalsThe ICDPA exempts financial institutions and their affiliates, and entities and data subject to the Gramm-Leach-Bliley Act, from its scope.observed
  2. ConfirmedInternational Association of Privacy ProfessionalsThe ICDPA exempts entities and personal data covered by HIPAA and the Health Information Technology for Economic and Clinical Health Act, as well as protected health records, from its scope.observed
  3. ConfirmedInternational Association of Privacy ProfessionalsThe ICDPA exempts personal data processed or maintained in the employment context from its scope, leaving Iowa employees without ICDPA-based rights over employment records.observed
  4. ConfirmedInternational Association of Privacy ProfessionalsThe ICDPA exempts personal data covered by the Family Educational Rights and Privacy Act (FERPA) from its scope.observed

#

Partial adtech coverage (disclosure + sale opt-out) with explicit gaps on universal signals, dark patterns and clean rooms.

Primary frameworkIowa Consumer Data Protection Act (Iowa Code ch. 715D)
Supervisory authorityIowa Attorney General
Traffic-light rationale — AmberPartial adtech coverage (disclosure + sale opt-out) with explicit gaps on universal signals, dark patterns and clean rooms.

Sub-modules (6)

Cookies And TrackersRed

No Iowa-specific cookie/tracker consent regime identified beyond general disclosure duties.

Dark PatternsRed

No dark-pattern prohibition identified in the ICDPA.

Opt Out SignalsAmber

No requirement to recognize universal opt-out mechanisms.

Claims (1):

  • The ICDPA, like Virginia's law, does not require controllers to recognize universal opt-out mechanisms such as the Global Privacy Control.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room provisions identified.

Cross Context AdvertisingAmber

Controllers engaging in targeted advertising must disclose the activity and opt-out mechanics.

Claims (1):

  • Controllers engaging in targeted advertising must clearly and conspicuously disclose that activity and the manner in which a consumer may exercise the right to opt out, and consumers may opt out of the sale of personal data exchanged for monetary consideration.

Direct MarketingAmber

Consumers may opt out of the sale of personal data for monetary consideration, which functions as the Act's principal direct-marketing-adjacent control.

Claims (1):

  • Controllers engaging in targeted advertising must clearly and conspicuously disclose that activity and the manner in which a consumer may exercise the right to opt out, and consumers may opt out of the sale of personal data exchanged for monetary consideration.
Category narrative43 words

The ICDPA regulates commercial/adtech data use narrowly: it mandates disclosure of targeted-advertising activity and opt-out mechanics and grants an opt-out-of-sale right, but does not require recognition of universal opt-out signals (e.g., Global Privacy Control), nor does it contain dark-pattern prohibitions or clean-room/data-collaboration provisions.

Sources and claims (2)
  1. ConfirmedInternational Association of Privacy ProfessionalsControllers engaging in targeted advertising must clearly and conspicuously disclose that activity and the manner in which a consumer may exercise the right to opt out, and consumers may opt out of the sale of personal data exchanged for monetary consideration.observed
  2. ConfirmedInternational Association of Privacy ProfessionalsThe ICDPA, like Virginia's law, does not require controllers to recognize universal opt-out mechanisms such as the Global Privacy Control.observed

#

No ADM transparency right, no dedicated AI-risk-assessment law, no biometric-specific statute; coverage is indirect via the general sensitive-data opt-out.

Primary frameworkIowa Consumer Data Protection Act (Iowa Code ch. 715D)
Supervisory authorityIowa Attorney General
Traffic-light rationale — RedNo ADM transparency right, no dedicated AI-risk-assessment law, no biometric-specific statute; coverage is indirect via the general sensitive-data opt-out.

Sub-modules (6)

Profiling RestrictionsRed

No profiling-specific restriction beyond the general targeted-advertising disclosure duty.

Automated Decision Making TransparencyRed

No right to be free from solely automated decision-making exists under the ICDPA.

Claims (1):

  • The ICDPA does not provide consumers a right not to be subject to solely automated decision-making, a right present in most other comprehensive state privacy statutes.

Ai Risk AssessmentsRed

No Iowa-specific AI-risk-assessment statute identified; AG has pursued multistate advocacy on AI harms rather than binding state rulemaking.

Biometric RegimeAmber

Biometric data processed to identify a specific individual falls within the ICDPA's general sensitive-data opt-out model rather than a dedicated biometric statute.

Claims (1):

  • Iowa's sensitive-data definition, mirrored in Indiana's subsequently enacted statute, includes genetic and biometric data processed for the purpose of identifying a specific individual, as well as precise geolocation data within a defined radius.

Genetic DataAmber

Genetic data is treated as sensitive data under the general opt-out model; no dedicated genetic-data statute identified.

Claims (1):

  • Iowa's sensitive-data definition, mirrored in Indiana's subsequently enacted statute, includes genetic and biometric data processed for the purpose of identifying a specific individual, as well as precise geolocation data within a defined radius.

State Surveillance CarveoutsRed

No Iowa-specific state-surveillance carve-out provisions were identified in the ICDPA beyond the standard government-entity exemption.

Category narrative62 words

The ICDPA notably omits an Article 22-style right against solely automated decision-making, and Iowa has no dedicated AI-risk-assessment or biometric-specific statute at present. Sensitive-data protections (opt-out only) extend by definition to biometric/genetic data processed for identification purposes and to precise geolocation, per comparative peer-state drafting. The AG's office has, however, engaged AI governance issues through multistate advocacy rather than binding Iowa rulemaking.

Sources and claims (2)
  1. ConfirmedOneTrust DataGuidanceThe ICDPA does not provide consumers a right not to be subject to solely automated decision-making, a right present in most other comprehensive state privacy statutes.observed
  2. ProbableInternational Association of Privacy ProfessionalsIowa's sensitive-data definition, mirrored in Indiana's subsequently enacted statute, includes genetic and biometric data processed for the purpose of identifying a specific individual, as well as precise geolocation data within a defined radius.observed

#

Core ICDPA sensitive-data treatment of children's data is confirmed; HF 712's precise enactment/effective status remains unverified from primary sources in this pass.

Primary frameworkIowa Consumer Data Protection Act (Iowa Code ch. 715D); Iowa House File 712 (status unverified)
Supervisory authorityIowa Attorney General
Traffic-light rationale — AmberCore ICDPA sensitive-data treatment of children's data is confirmed; HF 712's precise enactment/effective status remains unverified from primary sources in this pass.

Sub-modules (5)

Age VerificationAmber

No dedicated Iowa age-verification statute identified beyond HF 712's parental-consent reporting.

Claims (1):

  • Iowa House File 712 is reported to mandate parental consent for social-media platforms' collection of personal data from minors under age 18, with penalties for noncompliance.

Minor Profiling BansAmber

Personal data collected from a known child is treated as sensitive data under the ICDPA's opt-out model.

Claims (1):

  • Personal data collected from a known child falls within the sensitive-data category under Iowa's comprehensive privacy framework, triggering the general notice-and-opt-out duties applicable to sensitive data.

Education SettingsRed

FERPA-covered education records are exempt from ICDPA scope (see sectoral_watch.education); no additional Iowa-specific education-privacy statute identified in this module.

Dependent AdultsRed

No Iowa-specific dependent-adult/elder data-protection provision was identified within the ICDPA or related statutes reviewed.

Category narrative76 words

Beyond the ICDPA's general treatment of 'personal data collected from a known child' as sensitive data (opt-out model), Iowa has pursued child-specific legislation (House File 712) reported to mandate parental consent for social-media platforms' collection of minors' data, and the Attorney General has been active in child-safety enforcement (the TikTok litigation) and multistate advocacy defending state social-media-minors laws. Enactment/effective-date confirmation for HF 712 could not be independently verified from primary legislative text in this research pass.

Sources and claims (2)
  1. UncertainOneTrust DataGuidanceIowa House File 712 is reported to mandate parental consent for social-media platforms' collection of personal data from minors under age 18, with penalties for noncompliance.observed
  2. ProbableInternational Association of Privacy ProfessionalsPersonal data collected from a known child falls within the sensitive-data category under Iowa's comprehensive privacy framework, triggering the general notice-and-opt-out duties applicable to sensitive data.observed

#

Enforcement powers and penalty structure for the ICDPA itself are narrow (capped fines, mandatory cure, no private right of action); the AG's broader consumer-protection enforcement record is more active but is grounded in adjacent statutes rather than the ICDPA.

Primary frameworkIowa Consumer Data Protection Act (Iowa Code ch. 715D); Iowa Consumer Fraud Act (Iowa Code § 714.16); Personal Information Security Breach Protection Act (Iowa Code ch. 715C)
Supervisory authorityIowa Attorney General
Traffic-light rationale — AmberEnforcement powers and penalty structure for the ICDPA itself are narrow (capped fines, mandatory cure, no private right of action); the AG's broader consumer-protection enforcement record is more active but is grounded in adjacent statutes rather than the ICDPA.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

AG enforcement via civil investigative demand, mandatory 90-day cure notice, and civil penalties up to $7,500 per ICDPA violation.

Claims (1):

  • The Attorney General must provide violating parties written notice of ICDPA violations and a 90-day non-sunsetting cure period before initiating civil proceedings; violators found in breach are subject to civil penalties of up to $7,500 per violation, paid into the consumer education and litigation fund.

Enforcement Activity IndexAmber

Recent major AG actions (TikTok/ByteDance; Change Healthcare) were brought under the Consumer Fraud Act and breach-notification statute rather than the ICDPA itself.

Claims (2):

  • In January 2024, the Iowa Attorney General filed suit against TikTok and related ByteDance entities alleging deceptive age-rating practices and unlawful features affecting minors, litigated under the Iowa Consumer Fraud Act rather than the ICDPA.
  • The Iowa Attorney General sued Change Healthcare under the Iowa Consumer Fraud Act and the Personal Information Security Breach Protection Act (Iowa Code ch. 715C) over a data breach affecting approximately 2.2 million Iowans, seeking remedies including civil penalties of up to $40,000 per violation under the Consumer Fraud Act.

Regulator Funding And CapacityRed

No specific headcount/budget figures for ICDPA enforcement capacity were identified within the Consumer Protection Division in this research pass.

Collective Redress And Class ActionsRed

No collective-redress or class-action mechanism specific to the ICDPA was identified; enforcement is AG-exclusive.

Claims (1):

  • No collective-redress or class-action mechanism specific to ICDPA violations exists; redress is channeled exclusively through Attorney General civil enforcement.

Private Right Of ActionRed

The ICDPA does not provide consumers with a private right of action.

Claims (1):

  • The ICDPA does not provide consumers with a private right of action; enforcement runs exclusively through the Iowa Attorney General.

Recent Developments 180DAmber

In early August 2026, the Iowa AG led a multistate coalition demanding transparency from OpenAI following a reported AI data breach; Senate Bill 143, proposing ICDPA amendments, remains pending.

Claims (2):

  • In early August 2026, Iowa Attorney General Brenna Bird led a multistate coalition demanding that OpenAI preserve records and provide transparency following a reported AI-related data breach, citing potential violations of state consumer-protection and data-privacy statutes.
  • Iowa Senate Bill 143, introduced in a recent legislative session, proposes amendments to the ICDPA that would redefine key terms and expand certain consumer rights; enactment status remains pending as of this research pass.
Category narrative89 words

Enforcement runs exclusively through the Iowa Attorney General with a mandatory 90-day cure period and a per-violation penalty ceiling of $7,500 payable to a consumer education and litigation fund for ICDPA violations; there is no private right of action. Separately, the AG has exercised broader consumer-fraud and breach-notification authority (Iowa Code ch. 714.16 and ch. 715C) in major actions against TikTok/ByteDance and Change Healthcare, and has engaged in multistate AI-governance advocacy (including an August 2026 coalition letter to OpenAI), though these actions predate or sit outside the ICDPA itself.

Sources and claims (7)
  1. ConfirmedInternational Association of Privacy ProfessionalsThe Attorney General must provide violating parties written notice of ICDPA violations and a 90-day non-sunsetting cure period before initiating civil proceedings; violators found in breach are subject to civil penalties of up to $7,500 per violation, paid into the consumer education and litigation fund.observed
  2. ConfirmedOneTrust DataGuidanceThe ICDPA does not provide consumers with a private right of action; enforcement runs exclusively through the Iowa Attorney General.observed
  3. ConfirmedState of Iowa Office of the Attorney General / Iowa District Court for Polk CountyIn January 2024, the Iowa Attorney General filed suit against TikTok and related ByteDance entities alleging deceptive age-rating practices and unlawful features affecting minors, litigated under the Iowa Consumer Fraud Act rather than the ICDPA.observed
  4. ConfirmedState of Iowa Office of the Attorney General / Iowa District Court for Polk CountyThe Iowa Attorney General sued Change Healthcare under the Iowa Consumer Fraud Act and the Personal Information Security Breach Protection Act (Iowa Code ch. 715C) over a data breach affecting approximately 2.2 million Iowans, seeking remedies including civil penalties of up to $40,000 per violation under the Consumer Fraud Act.observed
  5. ConfirmedState of Iowa Office of the Attorney GeneralIn early August 2026, Iowa Attorney General Brenna Bird led a multistate coalition demanding that OpenAI preserve records and provide transparency following a reported AI-related data breach, citing potential violations of state consumer-protection and data-privacy statutes.observed
  6. UncertainOneTrust DataGuidanceIowa Senate Bill 143, introduced in a recent legislative session, proposes amendments to the ICDPA that would redefine key terms and expand certain consumer rights; enactment status remains pending as of this research pass.observed
  7. ProbableInternational Association of Privacy ProfessionalsNo collective-redress or class-action mechanism specific to ICDPA violations exists; redress is channeled exclusively through Attorney General civil enforcement.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Iowa
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 39 claim(s), 11 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacyadequacy granted
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacysccs and bcrs
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redressprivate right of action
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, sectoral_watch, adtech_and_commercial_privacy and enforcement_and_redress each carry at least one T1 (Iowa Attorney General primary source) or T2 (IAPP/DataGuidance legal-tracker) anchor with corroborated claims. cross_border_and_adequacy is populated with a T1/T2-supported absence finding rather than substantive claims, reflecting that no such regime exists in current Iowa law. algorithmic_biometric_and_surveillance_governance and children_and_vulnerable_groups rely partly on a T3 comparative source (Indiana coverage referencing Iowa) and one unverified secondary headline (HF 712), flagged Uncertain/Speculative and routed to escalation.

Unresolved questions (4):

  • Has Iowa House File 712 (parental consent for minors' social media data) been signed into law, and if so what is its effective date and precise scope? Primary Iowa legislature text was not retrievable in this pass.
  • What is the current enactment status of Iowa Senate Bill 143 (proposed ICDPA amendments) -- has it passed committee, either chamber, or been signed?
  • Does the Iowa Attorney General's Consumer Protection Division maintain any published headcount/budget figures specific to ICDPA enforcement capacity?
  • Has the Iowa Attorney General brought any enforcement action specifically under the ICDPA (as opposed to the Consumer Fraud Act or breach-notification statute) since the Act took effect January 1, 2025?

Escalate to primary-source review: yes