Iowa — Comprehensive Law

Iowa Privacy Law

Iowa enacted the narrowest comprehensive privacy statute in the country and paired it with one of the more aggressive consumer-fraud regimes. Chapter 715D gives Iowans four rights — access, deletion, portability and an opt-out of sale — with no correction right, no targeted-advertising opt-out and no profiling opt-out, and it carves an exception into portability itself that no other state has: data meeting the breach statute’s definition of “personal information” is excluded from the portable copy. Controllers get ninety days to answer a consumer, and another ninety to cure before the Attorney General may sue. Against that, § 714.16 authorises civil penalties of up to $40,000 per violation, several times the ceiling most states apply to privacy conduct, and the office used both statutes together in March 2026 to sue the largest health-data clearinghouse in the country.

The Iowa Consumer Data Protection Act (ICDPA)

Chapter 715D was added by chapter 17 of the 2023 Acts. Section 715D.2 applies it to a person conducting business in Iowa or producing products or services targeted to Iowa residents that, during a calendar year, either controls or processes the personal data of at least 100,000 consumers, or controls or processes the data of at least 25,000 consumers while deriving over fifty percent of gross revenue from the sale of personal data. Entity exemptions cover the state and its political subdivisions, financial institutions and their affiliates and Gramm-Leach-Bliley data, HIPAA and HITECH compliers, nonprofit organisations, and institutions of higher education. Section 715D.3(1) lists the rights and the list is short: confirmation and access; deletion of personal data the consumer provided; a copy of personal data the consumer previously provided, in a portable and readily usable format — except as to data defined as “personal information” under § 715C.1 and therefore subject to breach protection; and an opt-out of the sale of personal data. There is no right to correct, no opt-out of targeted advertising and no opt-out of profiling. Section 715D.3(2)(a) sets the response deadline at ninety days from receipt, extendable once by forty-five additional days where reasonably necessary given the complexity and number of requests, provided the consumer is told of the extension and its reason within the initial ninety-day window. Responses are free up to twice annually per consumer, and a controller declining to act must give its justification without undue delay and instructions for appeal.

Effective dateJanuary 1, 2025
CitationIowa Code ch. 715D
Enforced byIowa Attorney General
Maximum penaltyUp to $7,500 per violation under Iowa Code § 715D.8(3), paid into the consumer education and litigation fund established under § 714.16C
Private right of actionNo, enforcement by the state only
Right to cure90 days (permanent)

Who Must Comply

The ICDPA reaches a business that controls or processes the personal data of at least 100,000 Iowa consumers during a calendar year, or controls or processes the personal data of at least 25,000 consumers and derives over 50% of gross revenue from the sale of personal data.

The portability right at § 715D.3(1)(c) expressly excludes data that meets the § 715C.1 definition of “personal information” — Social Security numbers, driver’s licence numbers, financial account and card numbers with their access codes, unique electronic identifiers or routing codes with their codes, and unique biometric data. No other state privacy statute carves its own breach-statute categories out of the portable copy. The ninety-day consumer response window and the ninety-day cure period are both the longest in the country

Consumer Rights Under the ICDPA

Residents of Iowa can confirm whether a business is processing their data and obtain a copy of it, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format and opt out of the sale of their personal data.

notice and opportunity to opt out

Sector-Specific Privacy Laws in Iowa

Personal Information Security Breach Protection (Iowa Code ch. 715C)

Chapter 715C reaches further than most breach statutes in one respect and is stricter than most in another. Section 715C.1(1) defines a breach of security as unauthorized acquisition of personal information maintained in computerized form, and then adds a second limb: unauthorized acquisition of personal information maintained “in any medium, including on paper, that was transferred by the person to that medium from computerized form”. Section 715C.1(11)(a) lists five data elements that, unencrypted or unredacted and combined with a name, make information personal: a Social Security number; a driver’s licence number or other unique identification number created or collected by a government body; a financial account, credit card or debit card number with any required expiration date, security code, access code or password permitting access; a unique electronic identifier or routing code with any required security code, access code or password permitting access; and unique biometric data such as a fingerprint, retina or iris image, or other unique physical or digital representation of biometric data. Section 715C.2(6) supplies a risk-of-harm exception, but conditions it: notice is not required where, after an appropriate investigation or consultation with the relevant law enforcement agencies, the person determines there is no reasonable likelihood of financial harm, and “such a determination must be documented in writing and the documentation must be maintained for five years”. Substitute notice becomes available where the cost of notice would exceed $250,000 or the affected class exceeds 350,000 persons. Section 715C.2(5) requires the notice itself to carry a description of the breach, its approximate date, the type of personal information obtained, contact information for consumer reporting agencies, and advice to the consumer to report suspected identity theft to local law enforcement or the Attorney General.

Consumer Frauds Act (Iowa Code § 714.16)

Section 714.16 is Iowa’s unfair-practices statute and carries penalties well above the norm for privacy conduct. Subsection (7) authorises the Attorney General to seek an injunction against a practice declared unlawful, and provides that in addition to other remedies the court may impose a civil penalty not to exceed forty thousand dollars per violation against a person found to have engaged in a method, act or practice declared unlawful. The court may separately impose a civil penalty of not more than five thousand dollars for each day of intentional violation of a temporary restraining order, preliminary injunction or permanent injunction. Civil penalties are paid to the treasurer of state for deposit in the general fund. Section 715C.2(9)(a) ties the two chapters together: a violation of the breach chapter is an unlawful practice under § 714.16 and, in addition to the remedies § 714.16(7) provides, the Attorney General may obtain an order that a party held to violate the section pay damages to the Attorney General on behalf of a person injured by the violation. Venue for a § 714.16 action lies where the defendant resides or does business or “where one or more of the victims reside” under § 714.16(10).

Data Breach Notification in Iowa

Iowa keys its regulator clock to the consumer notice rather than to discovery, which is unusual. Section 715C.2(8) requires a person whose breach requires notification to more than five hundred Iowa residents to give written notice to the director of the consumer protection division of the office of the Attorney General “within five business days after giving notice of the breach of security to any consumer”. The consumer notice itself is due in the most expeditious manner possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, after determining contact information for affected consumers, determining the scope of the breach, and restoring the reasonable integrity, security and confidentiality of the data. A person who merely maintains or possesses personal information on another’s behalf notifies the owner or licensor immediately following discovery. Notice may be written to the last available address, electronic where that is the person’s customary method of communication or where it complies with chapter 554D and 15 U.S.C. § 7001, or substitute where the cost would exceed $250,000, the affected class exceeds 350,000 persons, or contact information is insufficient. The chapter does not apply to a person who complies with the breach procedures of their primary or functional federal regulator, or with a state or federal law, that provide greater protection and at least as thorough disclosure requirements, nor to those subject to and complying with Title V of the Gramm-Leach-Bliley Act or the HIPAA and HITECH rules.

Residents must be notified in the most expeditious manner possible and without unreasonable delay. Written notice to the director of the consumer protection division of the Attorney General’s office within five business days after giving notice to any consumer, where notification to more than 500 Iowa residents is required. Complaints are taken by the Iowa Attorney General, which enforces the statute.

How the ICDPA Is Enforced

Civil investigative demands, then ninety days to cure. Section 715D.8(1) gives the Attorney General exclusive authority to enforce chapter 715D and, where the office has reasonable cause to believe a person has engaged in, is engaging in, or is about to engage in a violation, empowers it to issue a civil investigative demand, with § 685.6 supplying the procedure. Section 715D.8(2) then requires ninety days’ written notice identifying the specific provisions alleged to have been violated before any action is initiated; if the controller or processor cures the noticed violation within that period and provides an express written statement that the alleged violations have been cured and that no further such violations will occur, no action may be brought. Section 715D.8(3) allows an injunction and civil penalties of up to $7,500 per violation where violations continue after the cure period or the written statement is breached, with monies collected paid into the consumer education and litigation fund under § 714.16C.

Breach violations are prosecuted as consumer fraud, with damages for victims. Section 715C.2(9)(a) provides that a violation of the breach chapter is an unlawful practice pursuant to § 714.16 and that, in addition to the remedies § 714.16(7) gives the Attorney General, the office may seek and obtain an order that a party held to violate the section pay damages to the Attorney General on behalf of a person injured by the violation. Subsection (9)(b) states that the rights and remedies are cumulative to each other and to any others available under law. That is a materially different posture from chapter 715D, which forecloses private claims and caps the penalty at $7,500: the breach route carries the $40,000 per-violation ceiling of § 714.16(7) and a mechanism for compensating individuals.

Recent Enforcement in Iowa

State of Iowa v. Change Healthcare, UnitedHealth Group and Optum — filed March 31, 2026. On March 31, 2026 the Attorney General announced a lawsuit over the February 2024 Change Healthcare breach, which the office describes as affecting nearly 2.2 million Iowans. The petition was filed in the Iowa District Court for Polk County as State of Iowa ex rel. Brenna Bird, Attorney General v. Change Healthcare Inc., UnitedHealth Group Incorporated, and Optum, Inc., and pleads counts under the Consumer Fraud Act at Iowa Code § 714.16 et seq. and the Personal Information Security Breach Protection Act at chapter 715C. It cites §§ 714.16(7) and 715C.2(9) as the sources of enforcement authority and lays venue in Polk County under § 714.16(10), which permits venue “where one or more of the victims reside”. The State alleges a hacker entered through a basic user-level customer support account on the company’s Citrix portal that had no multi-factor authentication for remote network access, moved undetected for ten days from February 11 to February 21, 2024, created privileged administrator accounts, installed malware and exfiltrated Social Security numbers, driver’s licence numbers, health insurance information, medical records and billing details, and that the company did not notify affected residents for roughly five months, contrary to § 715C.2(1). The State seeks stronger data security measures, restoration of ill-gotten gains, and penalties and damages for the harm to Iowa residents and health care providers.

Pending Privacy Legislation

Iowa’s comprehensive statute was enacted as chapter 17 of the 2023 Acts and took effect January 1, 2025 without amendment in the intervening sessions, leaving the four-right structure, the ninety-day response window and the ninety-day cure period as originally drafted. The breach chapter at 715C has a longer amendment history — enacted by chapter 1154 of the 2008 Acts and amended in 2013, 2014 and 2018 — and it is the older statute that has carried the state’s enforcement activity, including the Attorney General’s March 2026 petition against Change Healthcare. Section 715D.9 preempts local regulation of the subject matter. The chapter’s own bar on private claims at § 715D.8(4) is drafted in the broad form Virginia uses: nothing in the chapter provides the basis for, or is subject to, a private right of action for violations of the chapter “or under any other law”.

Federal Privacy Laws That Apply in Iowa

Federal privacy law applies in Iowa by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The ICDPA sits alongside those rules rather than displacing them: the Iowa Attorney General enforces the state law, while the federal regulators continue to reach the sectors and activities they cover.

Iowa Privacy Law FAQ

Why is some data excluded from Iowa’s data portability right?
Because the statute says so in terms. Section 715D.3(1)(c) gives a consumer the right to obtain a copy of personal data previously provided to the controller in a portable and readily usable format, “except as to personal data that is defined as ‘personal information’ pursuant to section 715C.1 that is subject to security breach protection”. That excludes Social Security numbers, driver’s licence and government identification numbers, financial account and card numbers with their access codes, unique electronic identifiers or routing codes with their codes, and unique biometric data. No other state comprehensive privacy law carves its own breach-statute categories out of the portable copy.
How long does an Iowa controller have to answer a consumer request?
Ninety days, the longest window in any state comprehensive privacy law. Section 715D.3(2)(a) requires a response without undue delay but in all cases within ninety days of receipt, extendable once by forty-five additional days where reasonably necessary given the complexity and number of the consumer’s requests, provided the controller informs the consumer of the extension and its reason within the initial ninety-day period. Information is provided free of charge up to twice annually per consumer; where a request is manifestly unfounded, excessive, repetitive or technically unfeasible, or the controller reasonably believes its primary purpose is not to exercise a right, the controller may respond differently.
What rights does the Iowa Consumer Data Protection Act not grant?
Three that most other comprehensive statutes do. Section 715D.3(1) lists confirmation and access, deletion of data the consumer provided, a portable copy with the breach-data carve-out, and an opt-out of the sale of personal data. There is no right to correct inaccuracies, no opt-out of processing for targeted advertising, and no opt-out of profiling in furtherance of decisions producing legal or similarly significant effects. A known child’s parent or legal guardian may invoke the rights that do exist on the child’s behalf.
When must an Iowa breach be reported to the Attorney General?
Within five business days of notifying consumers, not of discovering the breach. Section 715C.2(8) requires a person whose breach requires notification to more than five hundred Iowa residents to give written notice to the director of the consumer protection division of the office of the Attorney General within five business days after giving notice of the breach to any consumer. Keying the clock to the consumer notice rather than to discovery is unusual: it means the regulator deadline cannot be reached before the consumer notice has gone out, but it also starts running from the first consumer notified.
Can an Iowa business skip notice if it concludes there is no harm?
Section 715C.2(6) permits it on conditions. Notice is not required where, after an appropriate investigation or after consultation with the relevant federal, state or local law enforcement agencies, the person determined that no reasonable likelihood of financial harm to the affected consumers has resulted or will result from the breach. The statute then adds a documentation requirement most states omit: “Such a determination must be documented in writing and the documentation must be maintained for five years.”
What is the maximum civil penalty for privacy conduct in Iowa?
It depends which statute is used, and the difference is large. Section 715D.8(3) sets the Consumer Data Protection Act penalty at up to $7,500 for each violation, paid into the consumer education and litigation fund established under § 714.16C. But a breach-notification violation is an unlawful practice under § 714.16 by operation of § 715C.2(9)(a), and § 714.16(7) authorises a civil penalty not to exceed forty thousand dollars per violation, plus up to five thousand dollars for each day of intentional violation of a restraining order or injunction, with those penalties deposited in the state general fund.
Does Iowa’s breach law cover paper records?
Only in one specific circumstance, and the drafting is deliberate. Section 715C.1(1) defines a breach of security as unauthorized acquisition of personal information maintained in computerized form, and then extends it to unauthorized acquisition of personal information maintained in any medium, including on paper, “that was transferred by the person to that medium from computerized form”. A printout of a computerized customer file is within the chapter; a paper record that never existed in computerized form is not.
Has Iowa sued anyone over a data breach?
Yes. On March 31, 2026 the Attorney General announced a suit against Change Healthcare over the February 2024 breach affecting nearly 2.2 million Iowans. The petition, filed in the Iowa District Court for Polk County as State of Iowa ex rel. Brenna Bird, Attorney General v. Change Healthcare Inc., UnitedHealth Group Incorporated, and Optum, Inc., pleads violations of the Consumer Fraud Act at Iowa Code § 714.16 et seq. and the Personal Information Security Breach Protection Act at chapter 715C, invoking §§ 714.16(7) and 715C.2(9) as the sources of the Attorney General’s enforcement authority. The State alleges the intrusion began February 11, 2024 through a user-level customer support account on the company’s Citrix portal that lacked multi-factor authentication for remote network access, went undetected until February 21, and that consumers were not notified for roughly five months.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.