Traffic-light rationale — GreenCore instrument is in force, regulator identity and enforcement pathway are well documented from primary AG sources and secondary legal trackers.
Sub-modules (5)
Regulator And AuthorityGreen
The Iowa Attorney General holds exclusive enforcement authority over the ICDPA via civil investigative demands; there is no dedicated privacy agency and no private right of action.
Claims (1):
The Iowa Attorney General holds exclusive enforcement authority over the ICDPA through civil investigative demands, and the statute provides no private right of action for consumers.
Act And InstrumentsGreen
ICDPA (SF 262) signed March 28, 2023; effective January 1, 2025.
Claims (1):
The Iowa Consumer Data Protection Act (Senate File 262) was signed into law on March 28, 2023 and entered into effect on January 1, 2025.
Material ScopeGreen
Scope is defined by consumer-count and revenue-mix thresholds rather than a blanket applicability test.
Claims (1):
The ICDPA applies to entities that control or process personal data of at least 100,000 Iowa consumers, or that derive more than 50% of gross revenue from the sale of personal data while controlling/processing data of at least 25,000 Iowa consumers.
Territorial ScopeGreen
Applies to entities conducting business in Iowa or targeting Iowa consumers with products/services, regardless of physical establishment in the state.
Claims (1):
The ICDPA applies to entities that conduct business in Iowa or produce products or services targeted to Iowa consumers, without an independent revenue threshold as a scope trigger.
Regulator Registration And FilingAmber
No controller registration or pre-processing filing regime exists under the ICDPA; the only filing-type duty is post-breach notice to the AG under the separate breach-notification statute.
Claims (1):
The ICDPA imposes no controller registration or advance-filing obligation with the Attorney General; the only regulator-facing filing duty identified is post-breach written notice under Iowa's Personal Information Security Breach Protection Act.
Category narrative67 words
Iowa's data-protection regime is anchored in the Iowa Consumer Data Protection Act (ICDPA, Senate File 262), a comprehensive consumer-privacy statute enforced exclusively by the Iowa Attorney General, with no dedicated data-protection authority. The Act is layered over pre-existing sectoral instruments (notably the Personal Information Security Breach Protection Act, Iowa Code ch. 715C) and federal sectoral overlays (HIPAA, GLBA, FERPA, COPPA), producing a hybrid rather than omnibus regime.
Sources and claims (5)
ConfirmedInternational Association of Privacy Professionals — The Iowa Attorney General holds exclusive enforcement authority over the ICDPA through civil investigative demands, and the statute provides no private right of action for consumers.observed
ConfirmedOneTrust DataGuidance — The Iowa Consumer Data Protection Act (Senate File 262) was signed into law on March 28, 2023 and entered into effect on January 1, 2025.observed
ConfirmedInternational Association of Privacy Professionals — The ICDPA applies to entities that control or process personal data of at least 100,000 Iowa consumers, or that derive more than 50% of gross revenue from the sale of personal data while controlling/processing data of at least 25,000 Iowa consumers.observed
ConfirmedInternational Association of Privacy Professionals — The ICDPA applies to entities that conduct business in Iowa or produce products or services targeted to Iowa consumers, without an independent revenue threshold as a scope trigger.observed
ProbableState of Iowa Office of the Attorney General — The ICDPA imposes no controller registration or advance-filing obligation with the Attorney General; the only regulator-facing filing duty identified is post-breach written notice under Iowa's Personal Information Security Breach Protection Act.observed
Consent and sensitive-data protections are materially weaker than GDPR-analogue peer states (no opt-in for sensitive data, no purpose limitation/data-minimization duty).
Primary frameworkIowa Consumer Data Protection Act (Iowa Code ch. 715D)
Traffic-light rationale — AmberConsent and sensitive-data protections are materially weaker than GDPR-analogue peer states (no opt-in for sensitive data, no purpose limitation/data-minimization duty).
Sub-modules (4)
Lawful BasesAmber
No closed enumerated list of lawful bases; processing must be reasonably necessary and proportionate to disclosed purposes.
Claims (1):
Controllers may process personal data that is reasonably necessary and proportionate to the purposes disclosed to the consumer, in lieu of an enumerated closed list of lawful bases analogous to GDPR Article 6.
Consent ThresholdsGreen
Consent must be a clear affirmative act reflecting freely given, specific, informed, unambiguous agreement.
Claims (1):
The ICDPA requires consent to be a clear affirmative act indicating a consumer's freely given, specific, informed and unambiguous agreement to processing.
Special CategoriesAmber
Sensitive data processing uses a notice-and-opt-out model rather than opt-in consent, diverging from Colorado, Connecticut and Virginia.
Claims (1):
Unlike Colorado, Connecticut and Virginia, the ICDPA does not require opt-in consent for sensitive-data processing; it instead requires clear notice and an opportunity for the consumer to opt out.
Pseudonymisation And AnonymisationGreen
Deidentified/aggregate data are excluded from 'personal data'; opt-out rights do not extend to pseudonymous data.
Claims (1):
The ICDPA excludes deidentified and aggregate data from the definition of personal data, and consumer opt-out rights do not extend to pseudonymous data, in contrast to Colorado, Connecticut, Virginia and Utah.
Category narrative49 words
The ICDPA lacks a GDPR-style enumerated list of lawful bases, relying instead on a purpose-and-proportionality standard disclosed via privacy notice. Consent must be freely given, specific, informed and unambiguous. Uniquely among early-wave state laws, Iowa does not require opt-in consent for sensitive data, relying on an opt-out/notice model instead.
Sources and claims (4)
ConfirmedInternational Association of Privacy Professionals — Controllers may process personal data that is reasonably necessary and proportionate to the purposes disclosed to the consumer, in lieu of an enumerated closed list of lawful bases analogous to GDPR Article 6.observed
ConfirmedInternational Association of Privacy Professionals — The ICDPA requires consent to be a clear affirmative act indicating a consumer's freely given, specific, informed and unambiguous agreement to processing.observed
ConfirmedInternational Association of Privacy Professionals — Unlike Colorado, Connecticut and Virginia, the ICDPA does not require opt-in consent for sensitive-data processing; it instead requires clear notice and an opportunity for the consumer to opt out.observed
ConfirmedInternational Association of Privacy Professionals — The ICDPA excludes deidentified and aggregate data from the definition of personal data, and consumer opt-out rights do not extend to pseudonymous data, in contrast to Colorado, Connecticut, Virginia and Utah.observed
Traffic-light rationale — AmberMaterially narrower rights basket than peer comprehensive state laws; longer statutory response windows reduce consumer-facing responsiveness.
Sub-modules (5)
Access RightGreen
Consumers may confirm whether their data is processed and access it.
Claims (1):
The ICDPA provides consumers with the right to access their personal data held by a controller.
Rectification And ErasureAmber
Deletion right exists; no right to correct/rectify inaccurate data.
Claims (1):
The ICDPA provides a right to delete personal data but does not provide a right to rectification/correction of inaccurate personal data, unlike most peer state privacy statutes.
Restriction And ObjectionAmber
No general opt-out of targeted advertising/profiling in the rights section, though disclosure of targeted-advertising opt-out mechanics is mandated.
Claims (1):
The ICDPA does not provide a general consumer-rights-section opt-out for targeted advertising or profiling, though controllers engaging in targeted advertising must clearly and conspicuously disclose that activity and how to opt out.
Data PortabilityGreen
Consumers have a portability right to obtain their data in portable form.
Claims (1):
Consumers have a right to data portability under the ICDPA.
Deadlines And Response WindowsAmber
90-day response window with a potential 45-day extension.
Claims (1):
Controllers must respond to consumer rights requests within 90 days, with a potential 45-day extension, longer than the standard 45-day (extendable by 45 days) window found in most peer state statutes.
Category narrative43 words
The ICDPA provides four core consumer rights (access, deletion, portability, opt-out of sale) but deliberately omits a right to rectification and an automated-decision-making opt-out found in most peer statutes. Response windows (90 days, extendable 45 days) are longer than the 45-day/45-day-extension norm elsewhere.
ConfirmedOneTrust DataGuidance — The ICDPA provides a right to delete personal data but does not provide a right to rectification/correction of inaccurate personal data, unlike most peer state privacy statutes.observed
ConfirmedInternational Association of Privacy Professionals — The ICDPA does not provide a general consumer-rights-section opt-out for targeted advertising or profiling, though controllers engaging in targeted advertising must clearly and conspicuously disclose that activity and how to opt out.observed
ConfirmedInternational Association of Privacy Professionals — Controllers must respond to consumer rights requests within 90 days, with a potential 45-day extension, longer than the standard 45-day (extendable by 45 days) window found in most peer state statutes.observed
Traffic-light rationale — AmberCore accountability tooling (DPIA, DPO, ROPA) is absent; security and breach-notice duties are present and well documented from primary AG sources.
Sub-modules (7)
Accountability And DpiaRed
No DPIA/risk-assessment obligation exists under the ICDPA.
Claims (1):
The ICDPA does not contain provisions requiring privacy/data-protection risk assessments, a notable divergence from Colorado, Connecticut, Virginia and Indiana.
Dpo RequirementsRed
No statutory DPO-appointment requirement found across reviewed sources.
Claims (1):
No statutory requirement for controllers to appoint a data protection officer was identified under the ICDPA.
Ropa RequirementsRed
No formal records-of-processing-activity obligation found.
Claims (1):
No formal records-of-processing-activities (ROPA) obligation is imposed on controllers or processors under the ICDPA.
Joint Controller ArrangementsGreen
Controllers must maintain binding processor contracts covering instructions, purpose, data types, duration, and subcontractor accountability.
Claims (1):
Controllers must have a contract with processors clearly setting forth processing instructions, nature and purpose of processing, data types, processing duration, and the rights and duties of both parties, including retention, deletion, access and subcontractor accountability.
Security MeasuresGreen
Reasonable administrative, technical and physical security practices are required, scaled to data volume/nature.
Claims (1):
Controllers must implement reasonable administrative, technical and physical data-security practices appropriate to the volume and nature of personal data, to protect confidentiality, integrity and availability.
Breach NotificationGreen
Breaches affecting 500+ Iowa residents require AG notice within 5 business days of consumer notification, under the separate 715C statute.
Claims (1):
Under the Personal Information Security Breach Protection Act (Iowa Code ch. 715C), any breach affecting 500 or more Iowa residents must be reported in writing to the Attorney General's Consumer Protection Division within five business days of notifying affected individuals.
Retention And DisposalAmber
No explicit retention-limitation or data-minimization duty; consistent with the Act's omission of purpose limitation.
Claims (1):
The ICDPA does not impose a data-minimization or retention-limitation obligation on controllers, consistent with its omission of purpose-limitation duties found in peer state statutes.
Category narrative53 words
The ICDPA omits data protection impact assessments, DPO appointment, and formal records-of-processing obligations entirely -- a notable divergence from Colorado, Connecticut, Virginia and Indiana. It does mandate baseline security measures, binding processor contracts, and breach notification (the latter sourced from the separate, pre-existing Personal Information Security Breach Protection Act, Iowa Code ch. 715C).
Sources and claims (7)
ConfirmedOneTrust DataGuidance — The ICDPA does not contain provisions requiring privacy/data-protection risk assessments, a notable divergence from Colorado, Connecticut, Virginia and Indiana.observed
ProbableOneTrust DataGuidance — No statutory requirement for controllers to appoint a data protection officer was identified under the ICDPA.observed
ProbableOneTrust DataGuidance — No formal records-of-processing-activities (ROPA) obligation is imposed on controllers or processors under the ICDPA.observed
ConfirmedInternational Association of Privacy Professionals — Controllers must have a contract with processors clearly setting forth processing instructions, nature and purpose of processing, data types, processing duration, and the rights and duties of both parties, including retention, deletion, access and subcontractor accountability.observed
ConfirmedInternational Association of Privacy Professionals — Controllers must implement reasonable administrative, technical and physical data-security practices appropriate to the volume and nature of personal data, to protect confidentiality, integrity and availability.observed
ConfirmedState of Iowa Office of the Attorney General — Under the Personal Information Security Breach Protection Act (Iowa Code ch. 715C), any breach affecting 500 or more Iowa residents must be reported in writing to the Attorney General's Consumer Protection Division within five business days of notifying affected individuals.observed
ProbableInternational Association of Privacy Professionals — The ICDPA does not impose a data-minimization or retention-limitation obligation on controllers, consistent with its omission of purpose-limitation duties found in peer state statutes.observed
No cross-border transfer framework exists in the operative Iowa statute; absence confirmed across all reviewed primary and secondary sources.
Traffic-light rationale — RedNo cross-border transfer framework exists in the operative Iowa statute; absence confirmed across all reviewed primary and secondary sources.
Sub-modules (6)
Transfer MechanismsRed
No transfer-mechanism regime found.
Claims (1):
The ICDPA contains no cross-border data-transfer mechanism, adequacy determination, SCC/BCR framework, or data-localisation mandate; such transfer-restriction regimes are a feature of omnibus regimes such as the GDPR and are not present in current Iowa state law.
Adequacy ReceivedRed
Not applicable; US states do not receive adequacy decisions under foreign frameworks.
Adequacy GrantedRed
Not applicable; Iowa does not issue adequacy determinations.
Sccs And BcrsRed
No SCC/BCR analogue exists in the ICDPA.
Transfer Impact AssessmentRed
No TIA requirement exists in the ICDPA.
Data LocalisationRed
No data-localisation mandate exists in the ICDPA.
Category narrative53 words
As a US state consumer-privacy statute, the ICDPA does not create an adequacy, SCC/BCR, transfer-impact-assessment, or data-localisation regime analogous to GDPR Chapter V; such transfer-restriction machinery is characteristic of omnibus regimes and has no counterpart in current Iowa law. This module is populated with an explicit absence finding rather than left silently empty.
Sources and claims (1)
ConfirmedOneTrust DataGuidance — The ICDPA contains no cross-border data-transfer mechanism, adequacy determination, SCC/BCR framework, or data-localisation mandate; such transfer-restriction regimes are a feature of omnibus regimes such as the GDPR and are not present in current Iowa state law.observed
Traffic-light rationale — AmberExemption structure well documented; several declared sub-modules (telecoms/eprivacy, credit_and_scoring, insurance) carry no Iowa-specific findings.
Sub-modules (7)
Financial Sector OverlayGreen
GLBA-covered financial institutions and affiliates are exempt from ICDPA scope.
Claims (1):
The ICDPA exempts financial institutions and their affiliates, and entities and data subject to the Gramm-Leach-Bliley Act, from its scope.
Health Sector OverlayGreen
HIPAA/HITECH-covered entities and health records are exempt from ICDPA scope.
Claims (1):
The ICDPA exempts entities and personal data covered by HIPAA and the Health Information Technology for Economic and Clinical Health Act, as well as protected health records, from its scope.
Telecoms And EprivacyRed
No Iowa-specific telecoms/eprivacy overlay identified.
Employment DataAmber
Employment-context personal data is exempt from ICDPA scope.
Claims (1):
The ICDPA exempts personal data processed or maintained in the employment context from its scope, leaving Iowa employees without ICDPA-based rights over employment records.
Credit And ScoringRed
No Iowa-specific credit-scoring overlay identified beyond federal FCRA, which is outside ICDPA scope.
EducationGreen
FERPA-covered education records are exempt from ICDPA scope.
Claims (1):
The ICDPA exempts personal data covered by the Family Educational Rights and Privacy Act (FERPA) from its scope.
InsuranceRed
No Iowa-specific insurance-sector data overlay identified.
Category narrative50 words
The ICDPA carves out broad sectoral exemptions rather than layering sector-specific overlays: GLBA-covered financial institutions, HIPAA/HITECH-covered entities and health records, FERPA-covered education records, and employment-context data are all excluded from scope, leaving those sectors governed solely by their respective federal frameworks. No Iowa-specific credit-scoring, telecoms/eprivacy, or insurance overlay was identified.
Sources and claims (4)
ConfirmedInternational Association of Privacy Professionals — The ICDPA exempts financial institutions and their affiliates, and entities and data subject to the Gramm-Leach-Bliley Act, from its scope.observed
ConfirmedInternational Association of Privacy Professionals — The ICDPA exempts entities and personal data covered by HIPAA and the Health Information Technology for Economic and Clinical Health Act, as well as protected health records, from its scope.observed
ConfirmedInternational Association of Privacy Professionals — The ICDPA exempts personal data processed or maintained in the employment context from its scope, leaving Iowa employees without ICDPA-based rights over employment records.observed
Traffic-light rationale — AmberPartial adtech coverage (disclosure + sale opt-out) with explicit gaps on universal signals, dark patterns and clean rooms.
Sub-modules (6)
Cookies And TrackersRed
No Iowa-specific cookie/tracker consent regime identified beyond general disclosure duties.
Dark PatternsRed
No dark-pattern prohibition identified in the ICDPA.
Opt Out SignalsAmber
No requirement to recognize universal opt-out mechanisms.
Claims (1):
The ICDPA, like Virginia's law, does not require controllers to recognize universal opt-out mechanisms such as the Global Privacy Control.
Clean Rooms And DcrRed
No clean-room/data-collaboration-room provisions identified.
Cross Context AdvertisingAmber
Controllers engaging in targeted advertising must disclose the activity and opt-out mechanics.
Claims (1):
Controllers engaging in targeted advertising must clearly and conspicuously disclose that activity and the manner in which a consumer may exercise the right to opt out, and consumers may opt out of the sale of personal data exchanged for monetary consideration.
Direct MarketingAmber
Consumers may opt out of the sale of personal data for monetary consideration, which functions as the Act's principal direct-marketing-adjacent control.
Claims (1):
Controllers engaging in targeted advertising must clearly and conspicuously disclose that activity and the manner in which a consumer may exercise the right to opt out, and consumers may opt out of the sale of personal data exchanged for monetary consideration.
Category narrative43 words
The ICDPA regulates commercial/adtech data use narrowly: it mandates disclosure of targeted-advertising activity and opt-out mechanics and grants an opt-out-of-sale right, but does not require recognition of universal opt-out signals (e.g., Global Privacy Control), nor does it contain dark-pattern prohibitions or clean-room/data-collaboration provisions.
Sources and claims (2)
ConfirmedInternational Association of Privacy Professionals — Controllers engaging in targeted advertising must clearly and conspicuously disclose that activity and the manner in which a consumer may exercise the right to opt out, and consumers may opt out of the sale of personal data exchanged for monetary consideration.observed
ConfirmedInternational Association of Privacy Professionals — The ICDPA, like Virginia's law, does not require controllers to recognize universal opt-out mechanisms such as the Global Privacy Control.observed
No ADM transparency right, no dedicated AI-risk-assessment law, no biometric-specific statute; coverage is indirect via the general sensitive-data opt-out.
Primary frameworkIowa Consumer Data Protection Act (Iowa Code ch. 715D)
Traffic-light rationale — RedNo ADM transparency right, no dedicated AI-risk-assessment law, no biometric-specific statute; coverage is indirect via the general sensitive-data opt-out.
Sub-modules (6)
Profiling RestrictionsRed
No profiling-specific restriction beyond the general targeted-advertising disclosure duty.
Automated Decision Making TransparencyRed
No right to be free from solely automated decision-making exists under the ICDPA.
Claims (1):
The ICDPA does not provide consumers a right not to be subject to solely automated decision-making, a right present in most other comprehensive state privacy statutes.
Ai Risk AssessmentsRed
No Iowa-specific AI-risk-assessment statute identified; AG has pursued multistate advocacy on AI harms rather than binding state rulemaking.
Biometric RegimeAmber
Biometric data processed to identify a specific individual falls within the ICDPA's general sensitive-data opt-out model rather than a dedicated biometric statute.
Claims (1):
Iowa's sensitive-data definition, mirrored in Indiana's subsequently enacted statute, includes genetic and biometric data processed for the purpose of identifying a specific individual, as well as precise geolocation data within a defined radius.
Genetic DataAmber
Genetic data is treated as sensitive data under the general opt-out model; no dedicated genetic-data statute identified.
Claims (1):
Iowa's sensitive-data definition, mirrored in Indiana's subsequently enacted statute, includes genetic and biometric data processed for the purpose of identifying a specific individual, as well as precise geolocation data within a defined radius.
State Surveillance CarveoutsRed
No Iowa-specific state-surveillance carve-out provisions were identified in the ICDPA beyond the standard government-entity exemption.
Category narrative62 words
The ICDPA notably omits an Article 22-style right against solely automated decision-making, and Iowa has no dedicated AI-risk-assessment or biometric-specific statute at present. Sensitive-data protections (opt-out only) extend by definition to biometric/genetic data processed for identification purposes and to precise geolocation, per comparative peer-state drafting. The AG's office has, however, engaged AI governance issues through multistate advocacy rather than binding Iowa rulemaking.
Sources and claims (2)
ConfirmedOneTrust DataGuidance — The ICDPA does not provide consumers a right not to be subject to solely automated decision-making, a right present in most other comprehensive state privacy statutes.observed
ProbableInternational Association of Privacy Professionals — Iowa's sensitive-data definition, mirrored in Indiana's subsequently enacted statute, includes genetic and biometric data processed for the purpose of identifying a specific individual, as well as precise geolocation data within a defined radius.observed
Core ICDPA sensitive-data treatment of children's data is confirmed; HF 712's precise enactment/effective status remains unverified from primary sources in this pass.
Primary frameworkIowa Consumer Data Protection Act (Iowa Code ch. 715D); Iowa House File 712 (status unverified)
Traffic-light rationale — AmberCore ICDPA sensitive-data treatment of children's data is confirmed; HF 712's precise enactment/effective status remains unverified from primary sources in this pass.
Iowa House File 712 is reported to mandate parental consent for social-media platforms' collection of personal data from minors under age 18, with penalties for noncompliance.
Parental ConsentAmber
HF 712 is reported to mandate parental consent for social-media collection of data from minors under 18.
Claims (1):
Iowa House File 712 is reported to mandate parental consent for social-media platforms' collection of personal data from minors under age 18, with penalties for noncompliance.
Minor Profiling BansAmber
Personal data collected from a known child is treated as sensitive data under the ICDPA's opt-out model.
Claims (1):
Personal data collected from a known child falls within the sensitive-data category under Iowa's comprehensive privacy framework, triggering the general notice-and-opt-out duties applicable to sensitive data.
Education SettingsRed
FERPA-covered education records are exempt from ICDPA scope (see sectoral_watch.education); no additional Iowa-specific education-privacy statute identified in this module.
Dependent AdultsRed
No Iowa-specific dependent-adult/elder data-protection provision was identified within the ICDPA or related statutes reviewed.
Category narrative76 words
Beyond the ICDPA's general treatment of 'personal data collected from a known child' as sensitive data (opt-out model), Iowa has pursued child-specific legislation (House File 712) reported to mandate parental consent for social-media platforms' collection of minors' data, and the Attorney General has been active in child-safety enforcement (the TikTok litigation) and multistate advocacy defending state social-media-minors laws. Enactment/effective-date confirmation for HF 712 could not be independently verified from primary legislative text in this research pass.
Sources and claims (2)
UncertainOneTrust DataGuidance — Iowa House File 712 is reported to mandate parental consent for social-media platforms' collection of personal data from minors under age 18, with penalties for noncompliance.observed
ProbableInternational Association of Privacy Professionals — Personal data collected from a known child falls within the sensitive-data category under Iowa's comprehensive privacy framework, triggering the general notice-and-opt-out duties applicable to sensitive data.observed
Enforcement powers and penalty structure for the ICDPA itself are narrow (capped fines, mandatory cure, no private right of action); the AG's broader consumer-protection enforcement record is more active but is grounded in adjacent statutes rather than the ICDPA.
Primary frameworkIowa Consumer Data Protection Act (Iowa Code ch. 715D); Iowa Consumer Fraud Act (Iowa Code § 714.16); Personal Information Security Breach Protection Act (Iowa Code ch. 715C)
Traffic-light rationale — AmberEnforcement powers and penalty structure for the ICDPA itself are narrow (capped fines, mandatory cure, no private right of action); the AG's broader consumer-protection enforcement record is more active but is grounded in adjacent statutes rather than the ICDPA.
Sub-modules (6)
Regulator Powers And PenaltiesAmber
AG enforcement via civil investigative demand, mandatory 90-day cure notice, and civil penalties up to $7,500 per ICDPA violation.
Claims (1):
The Attorney General must provide violating parties written notice of ICDPA violations and a 90-day non-sunsetting cure period before initiating civil proceedings; violators found in breach are subject to civil penalties of up to $7,500 per violation, paid into the consumer education and litigation fund.
Enforcement Activity IndexAmber
Recent major AG actions (TikTok/ByteDance; Change Healthcare) were brought under the Consumer Fraud Act and breach-notification statute rather than the ICDPA itself.
Claims (2):
In January 2024, the Iowa Attorney General filed suit against TikTok and related ByteDance entities alleging deceptive age-rating practices and unlawful features affecting minors, litigated under the Iowa Consumer Fraud Act rather than the ICDPA.
The Iowa Attorney General sued Change Healthcare under the Iowa Consumer Fraud Act and the Personal Information Security Breach Protection Act (Iowa Code ch. 715C) over a data breach affecting approximately 2.2 million Iowans, seeking remedies including civil penalties of up to $40,000 per violation under the Consumer Fraud Act.
Regulator Funding And CapacityRed
No specific headcount/budget figures for ICDPA enforcement capacity were identified within the Consumer Protection Division in this research pass.
Collective Redress And Class ActionsRed
No collective-redress or class-action mechanism specific to the ICDPA was identified; enforcement is AG-exclusive.
Claims (1):
No collective-redress or class-action mechanism specific to ICDPA violations exists; redress is channeled exclusively through Attorney General civil enforcement.
Private Right Of ActionRed
The ICDPA does not provide consumers with a private right of action.
Claims (1):
The ICDPA does not provide consumers with a private right of action; enforcement runs exclusively through the Iowa Attorney General.
Recent Developments 180DAmber
In early August 2026, the Iowa AG led a multistate coalition demanding transparency from OpenAI following a reported AI data breach; Senate Bill 143, proposing ICDPA amendments, remains pending.
Claims (2):
In early August 2026, Iowa Attorney General Brenna Bird led a multistate coalition demanding that OpenAI preserve records and provide transparency following a reported AI-related data breach, citing potential violations of state consumer-protection and data-privacy statutes.
Iowa Senate Bill 143, introduced in a recent legislative session, proposes amendments to the ICDPA that would redefine key terms and expand certain consumer rights; enactment status remains pending as of this research pass.
Category narrative89 words
Enforcement runs exclusively through the Iowa Attorney General with a mandatory 90-day cure period and a per-violation penalty ceiling of $7,500 payable to a consumer education and litigation fund for ICDPA violations; there is no private right of action. Separately, the AG has exercised broader consumer-fraud and breach-notification authority (Iowa Code ch. 714.16 and ch. 715C) in major actions against TikTok/ByteDance and Change Healthcare, and has engaged in multistate AI-governance advocacy (including an August 2026 coalition letter to OpenAI), though these actions predate or sit outside the ICDPA itself.
Sources and claims (7)
ConfirmedInternational Association of Privacy Professionals — The Attorney General must provide violating parties written notice of ICDPA violations and a 90-day non-sunsetting cure period before initiating civil proceedings; violators found in breach are subject to civil penalties of up to $7,500 per violation, paid into the consumer education and litigation fund.observed
ConfirmedOneTrust DataGuidance — The ICDPA does not provide consumers with a private right of action; enforcement runs exclusively through the Iowa Attorney General.observed
ConfirmedState of Iowa Office of the Attorney General / Iowa District Court for Polk County — In January 2024, the Iowa Attorney General filed suit against TikTok and related ByteDance entities alleging deceptive age-rating practices and unlawful features affecting minors, litigated under the Iowa Consumer Fraud Act rather than the ICDPA.observed
ConfirmedState of Iowa Office of the Attorney General / Iowa District Court for Polk County — The Iowa Attorney General sued Change Healthcare under the Iowa Consumer Fraud Act and the Personal Information Security Breach Protection Act (Iowa Code ch. 715C) over a data breach affecting approximately 2.2 million Iowans, seeking remedies including civil penalties of up to $40,000 per violation under the Consumer Fraud Act.observed
ConfirmedState of Iowa Office of the Attorney General — In early August 2026, Iowa Attorney General Brenna Bird led a multistate coalition demanding that OpenAI preserve records and provide transparency following a reported AI-related data breach, citing potential violations of state consumer-protection and data-privacy statutes.observed
UncertainOneTrust DataGuidance — Iowa Senate Bill 143, introduced in a recent legislative session, proposes amendments to the ICDPA that would redefine key terms and expand certain consumer rights; enactment status remains pending as of this research pass.observed
ProbableInternational Association of Privacy Professionals — No collective-redress or class-action mechanism specific to ICDPA violations exists; redress is channeled exclusively through Attorney General civil enforcement.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for United States – Iowa
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 39 claim(s), 11 source(s) in the cumulative register.
GDPR article map
Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).
regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, sectoral_watch, adtech_and_commercial_privacy and enforcement_and_redress each carry at least one T1 (Iowa Attorney General primary source) or T2 (IAPP/DataGuidance legal-tracker) anchor with corroborated claims. cross_border_and_adequacy is populated with a T1/T2-supported absence finding rather than substantive claims, reflecting that no such regime exists in current Iowa law. algorithmic_biometric_and_surveillance_governance and children_and_vulnerable_groups rely partly on a T3 comparative source (Indiana coverage referencing Iowa) and one unverified secondary headline (HF 712), flagged Uncertain/Speculative and routed to escalation.
Unresolved questions (4):
Has Iowa House File 712 (parental consent for minors' social media data) been signed into law, and if so what is its effective date and precise scope? Primary Iowa legislature text was not retrievable in this pass.
What is the current enactment status of Iowa Senate Bill 143 (proposed ICDPA amendments) -- has it passed committee, either chamber, or been signed?
Does the Iowa Attorney General's Consumer Protection Division maintain any published headcount/budget figures specific to ICDPA enforcement capacity?
Has the Iowa Attorney General brought any enforcement action specifically under the ICDPA (as opposed to the Consumer Fraud Act or breach-notification statute) since the Act took effect January 1, 2025?