Iowa Consumer Data Protection Act (Iowa Code ch. 715D)
Below is what the official text of Iowa Consumer Data Protection Act (Iowa Code ch. 715D) states about whom it covers, when it applies to a business and since when. Where the pages we read do not say, the row says "not stated".
The wording shown is taken from the official page named in each row. The duties of a business and the contents of a privacy notice are in the paid checklist.
Typical situations, run through the same conditions as the check
- A for-profit US business with 150,000 people in Iowa and $30 million revenue: Applies, or may apply: conditions to check.
- The same business with 8,000 people in Iowa: Not triggered by these answers.
- A US business with no users in Iowa: Not triggered by these answers.
Judged on 2026-10-06. Our law data was last verified on 2026-10-06; a law that took effect after that date is not in it. These situations leave other answers blank or neutral: use the check for your own.
What the official text states
| Question | What the official text states | Source |
|---|---|---|
| What it covers | Chapter 715D binds persons conducting business in Iowa or producing products or services targeted to Iowa-resident consumers that meet the stated consumer-count thresholds, and gives those consumers rights over their personal data.Official wordingThis chapter applies to a person conducting business in the state or producing products or services that are targeted to consumers who are residents of the state | www.legis.iowa.gov read 2026-10-06 |
| When it applies to a business | Applies to a person conducting business in Iowa or producing products or services targeted to Iowa residents that during a calendar year controls or processes personal data of at least 100,000 consumers, or of at least 25,000 consumers while deriving over 50% of gross revenue from the sale of personal data. Conditions to check: Under 715D.2(2) the chapter does not apply to the state or political subdivisions, financial institutions and their affiliates or GLBA data, persons subject to and complying with HIPAA/HITECH rules, nonprofit organizations, and institutions of higher education (so for-profit status is effectively required); 715D.2(3) exempts many categories of information. 'Conducting business in the state' and 'targeted' are not defined in the quoted text. Official wordinga. Controls or processes personal data of at least one hundred thousand consumers. b. Controls or processes personal data of at least twenty-five thousand consumers and derives over fifty percent of gross revenue from the sale of personal data. | www.legis.iowa.gov read 2026-10-06 |
| In force from | 2025-01-01 Enrolled SF 262 (2023 Acts, ch. 17), section 10: this Act takes effect January 1, 2025. Official wordingEFFECTIVE DATE. This Act takes effect January 1, 37 2025. | www.legis.iowa.gov read 2026-10-06 |
| Privacy notice | Included in the paid checklist. See the checklist | — |
| Consent and opt-out | Included in the paid checklist. See the checklist | — |
| Rights of individuals | Included in the paid checklist. See the checklist | — |
| Data protection officer | Not stated on the official pages we read. the text we read does not say whether a data protection officer must be appointed | — |
| Breach notification | Not stated on the official pages we read. separate breach-notification statute not read | — |
| What the privacy notice must contain | Included in the paid checklist. See the checklist | — |
What we do not cover
These areas are outside this site, so nothing on this page says anything about them:
- Privacy laws for particular sectors (for example health care, banking and credit, education)
- Rules specific to children's online privacy
- Cookie and electronic-communications rules (including consent for cookies and marketing messages)
- Employee, job applicant and contractor data
- Rules on sending personal data to other countries
- US state data-breach notification laws (a separate set of state laws)
- US state privacy laws that are not yet in force, and state laws on particular topics (for example biometric or health data)
- Privacy laws of countries that are not listed here
- Planned changes to the laws listed here