Skip to main content
Explainer · Reviewed September 2026

What Is the Iowa Consumer Data Protection Act?

ICDPA applies to persons conducting business in Iowa or producing products or services targeted to Iowa residents that meet either the 100,000-consumer branch or the 25,000-consumer-plus-more-than-50%-sale-revenue branch, subject to statutory exemptions. Rights include access, deletion of personal data provided by the consumer, portability, and sale opt-out; the cited chapter does not list a correction or profiling opt-out right and does not require a universal opt-out mechanism. Controllers generally have 90 days to respond, with a possible 45-day extension. The AG has exclusive enforcement authority and a separate 90-day written notice-and-cure process.

Rahul Kandoriya
Written byRahul Kandoriya·Founder, OfflistMe·Last updated September 7, 2026

At a glance

Full name
Iowa Consumer Data Protection Act
Short code
ICDPA
Effective date
January 1, 2025
Response reference
90 days in this snapshot
Cure period
90 days in this snapshot
Private right of action
No
Enforcement
Iowa Attorney General. Consumer Protection Division
Penalty reference
Up to $7,500 per violation under the Iowa Consumer Fraud Act
Statutory citation
Iowa Code § 715D.1 et seq.

Who ICDPA applies to

A business is covered if it meets the applicability thresholds set out in Iowa Code § 715D.1 et seq.. The thresholds listed below are the research record for this law. Whether one or more applies depends on the current statute, its exceptions, and the business's facts; do not assume a universal threshold structure.

  • Conducts business in Iowa or produces products or services targeted to Iowa residents and, during a calendar year, controls or processes personal data of at least 100,000 consumers
  • Conducts business in Iowa or produces products or services targeted to Iowa residents and, during a calendar year, controls or processes personal data of at least 25,000 consumers and derives more than 50% of gross revenue from the sale of personal data

Consumer rights under ICDPA

Delete personal data provided by the consumer, access, port, and opt-out of sale

No correction right listed in §715D.3

No profiling opt-out listed in §715D.3

90-day response window (longer than peers)

Notable features (vs. CCPA)

ICDPA provides access, deletion of personal data provided by the consumer, portability, and sale opt-out rights. Section 715D.3 does not list a correction or profiling opt-out right, and Chapter 715D does not require a universal opt-out mechanism. Controllers generally have 90 days to respond to a consumer request, subject to a possible 45-day extension, and the Attorney General has a separate 90-day enforcement notice-and-cure process.

Enforcement and penalty reference

Enforcing agency: Iowa Attorney General. Consumer Protection Division

Penalty reference: Up to $7,500 per violation under the Iowa Consumer Fraud Act

Cure period: Before initiating an enforcement action, the Attorney General must give a controller or processor 90 days' written notice identifying the alleged violations. If the noticed violation is cured and the controller or processor provides an express written statement that the violations are cured and will not recur, the Attorney General may not initiate the action; this is separate from the consumer-response period.

Private right of action: ICDPA has no private right of action. Enforcement is exclusive to the Iowa Attorney General. Consumer Protection Division.

Where to file a complaint: Iowa Attorney General. Consumer Protection Division

How to exercise your ICDPA rights

  1. 1

    Identify the business that holds your data. OfflistMe can help you review a provider route across 1,034 US/global workflow profiles in the 1,052-record research universe; it does not decide whether a law applies to a specific request.

  2. 2

    Submit a request to the business's designated contact using the provider's current verification instructions. Include only the information reasonably needed to match your record and check the applicable Iowa residency, scope, exemption, and verification rules before sending.

  3. 3

    This research snapshot records a 90-day reference window for the modeled request. Confirm the current statute, request type, controller scope, extension rule, and verification date before treating it as a deadline.

  4. 4

    If the provider does not respond or disputes the request, preserve the request and response record, review the applicable exceptions, and consider the Iowa Attorney General. Consumer Protection Division complaint route at https://www.iowaattorneygeneral.gov/for-consumers/file-a-consumer-complaint. A complaint route does not itself guarantee deletion or a particular enforcement result.

Generate requests in under 60 seconds

Generate a ICDPA privacy request, $9 one-time

Review the provider route, applicable law, and information you intend to send before dispatch. You remain in control of the request and any evidence kept.

FAQ

How does Iowa's ICDPA differ from some state laws?+

The ICDPA has a defined set of access, deletion, portability, and opt-out rights, along with its own response and enforcement rules. Compare the current statute and controller notice before assuming that a correction, profiling, cure, or deletion rule from another state applies in Iowa.

Official sources & citations

Compare with sibling state laws

ICDPA is one of 18 comprehensive US state privacy laws. Its closest peers by effective date, useful when tracking how this law influenced or was influenced by neighboring legislation:

Related concepts & guides