Iowa Privacy Law (ICDPA): Compliance Guide
The Iowa Consumer Data Protection Act, effective January 1, 2025, is one of the most business-friendly comprehensive privacy laws in the country. It follows the Virginia/Utah model closely: an opt-out framework, no universal opt-out signal requirement, and thresholds aimed at large-scale data operations. For businesses already handling Virginia or Utah compliance, Iowa adds obligations in name more than in practice — but its opt-out rights still demand a working privacy choices link and a real process behind it.
- Effective
- January 1, 2025
- GPC / universal opt-out
- Not required
- Required link text
- “Your Privacy Choices”
Last reviewed July 19, 2026 · Iowa Consumer Data Protection Act (ICDPA)
Applicability
Who must comply with the ICDPA
The Iowa Consumer Data Protection Act applies to businesses that meet the following criteria:
- Controls or processes the personal data of 100,000 or more Iowa consumers, or
- Controls or processes the personal data of 25,000 or more Iowa consumers and derives 50% or more of revenue from the sale of personal data
Consumer rights
What Iowa consumers can demand
- Right to access personal data
- Right to delete personal data
- Right to data portability
- Right to opt out of targeted advertising and the sale of personal data
Opt-out mechanics
Iowa opt-out & GPC requirements
Like every US state privacy law, the ICDPA uses an opt-out model: you do not need a GDPR-style cookie banner, but you must provide a clear and conspicuous opt-out link. The accepted text for Iowa is “Your Privacy Choices”.
Global Privacy Control: Not required
Iowa's ICDPA does not require honoring universal opt-out signals such as Global Privacy Control. The opt-out link remains the required mechanism.
Enforcement
ICDPA penalties & enforcement
- Enforced by the Iowa Attorney General
Cure period: Our reference lists no specific cure period for Iowa; enforcement runs through the Iowa Attorney General.
State quirks
What makes Iowa different
Iowa stripped the state privacy framework to its essentials. There is no Global Privacy Control mandate, no sensitive-data opt-in, and no correction right in the base rights list — access, deletion, portability, and opt-out are the whole package. The 100,000-consumer threshold and 50% revenue-from-sales trigger keep the law pointed at large-scale data operations. For compliance teams, Iowa is the baseline against which stricter states add layers.
Targets large-scale operations
The 100,000-consumer threshold and 50% sales-revenue trigger keep the law aimed at large-scale data operations rather than small businesses.
Standard opt-out framework
A stripped-down version of the Virginia model — no universal opt-out signal mandate and no sensitive-data opt-in.
Automation
How ConsentKit handles Iowa
- ConsentKit's widget is served from Cloudflare's edge and receives the visitor's US state server-side, so Iowa visitors are identified before any consent UI renders — no client-side geo-lookup delay.
- Iowa visitors see a persistent “Your Privacy Choices” link — the exact statutory text — available to new and returning visitors alike.
- Iowa does not legally require honoring Global Privacy Control. ConsentKit applies automatic GPC honoring in the 12 states that mandate it; in Iowa the opt-out link remains the visitor's control.
- Every opt-out is recorded server-side with a timestamp and jurisdiction metadata, reviewable and exportable (CSV) from the dashboard — the audit trail regulators ask for.
- Google Consent Mode v2 stays in sync: analytics and advertising tags update the moment a Iowa visitor makes a choice.
Iowa visitors see the standard “Your Privacy Choices” link; ConsentKit records each opt-out with a server-side timestamp and jurisdiction metadata for your audit log.
FAQ
Iowa ICDPA FAQ
Does Iowa's ICDPA apply to my business?
It applies if you control or process the personal data of 100,000 or more Iowa consumers, or 25,000 or more while deriving 50% or more of revenue from selling personal data. Both prongs target large-scale data operations, so many small businesses fall outside the law.
Does Iowa require a cookie banner?
No. Iowa uses an opt-out model — no GDPR-style banner is needed. The requirement is a clear opt-out link, for which “Your Privacy Choices” is the accepted text, covering targeted advertising and the sale of personal data.
Is Global Privacy Control required in Iowa?
No. Iowa is one of eight covered states with no universal opt-out signal mandate. Visitors opt out through the link; ConsentKit still records every choice with a timestamp for your records.
How is Iowa's law enforced?
Enforcement runs through the Iowa Attorney General. Our reference lists no specific per-violation dollar figure or cure period for Iowa.
This guide is for informational purposes and is not legal advice. Work with qualified counsel to confirm your obligations under the ICDPA.
Comply with Iowa's ICDPA — and the other 19 state laws
ConsentKit detects each visitor's state at the Cloudflare edge, renders the exact opt-out link their law requires, honors GPC automatically where mandated, and records every choice for your audit trail.