ICDPA · Opt-out model

Iowa Privacy Law (ICDPA): Compliance Guide

The Iowa Consumer Data Protection Act, effective January 1, 2025, is one of the most business-friendly comprehensive privacy laws in the country. It follows the Virginia/Utah model closely: an opt-out framework, no universal opt-out signal requirement, and thresholds aimed at large-scale data operations. For businesses already handling Virginia or Utah compliance, Iowa adds obligations in name more than in practice — but its opt-out rights still demand a working privacy choices link and a real process behind it.

Effective
January 1, 2025
GPC / universal opt-out
Not required
Required link text
Your Privacy Choices
Handle ICDPA compliance free

Last reviewed July 19, 2026 · Iowa Consumer Data Protection Act (ICDPA)

Applicability

Who must comply with the ICDPA

The Iowa Consumer Data Protection Act applies to businesses that meet the following criteria:

  • Controls or processes the personal data of 100,000 or more Iowa consumers, or
  • Controls or processes the personal data of 25,000 or more Iowa consumers and derives 50% or more of revenue from the sale of personal data

Consumer rights

What Iowa consumers can demand

  • Right to access personal data
  • Right to delete personal data
  • Right to data portability
  • Right to opt out of targeted advertising and the sale of personal data

Opt-out mechanics

Iowa opt-out & GPC requirements

Like every US state privacy law, the ICDPA uses an opt-out model: you do not need a GDPR-style cookie banner, but you must provide a clear and conspicuous opt-out link. The accepted text for Iowa is Your Privacy Choices.

Global Privacy Control: Not required

Iowa's ICDPA does not require honoring universal opt-out signals such as Global Privacy Control. The opt-out link remains the required mechanism.

Enforcement

ICDPA penalties & enforcement

  • Enforced by the Iowa Attorney General

Cure period: Our reference lists no specific cure period for Iowa; enforcement runs through the Iowa Attorney General.

State quirks

What makes Iowa different

Iowa stripped the state privacy framework to its essentials. There is no Global Privacy Control mandate, no sensitive-data opt-in, and no correction right in the base rights list — access, deletion, portability, and opt-out are the whole package. The 100,000-consumer threshold and 50% revenue-from-sales trigger keep the law pointed at large-scale data operations. For compliance teams, Iowa is the baseline against which stricter states add layers.

Targets large-scale operations

The 100,000-consumer threshold and 50% sales-revenue trigger keep the law aimed at large-scale data operations rather than small businesses.

Standard opt-out framework

A stripped-down version of the Virginia model — no universal opt-out signal mandate and no sensitive-data opt-in.

Automation

How ConsentKit handles Iowa

  • ConsentKit's widget is served from Cloudflare's edge and receives the visitor's US state server-side, so Iowa visitors are identified before any consent UI renders — no client-side geo-lookup delay.
  • Iowa visitors see a persistent Your Privacy Choices link — the exact statutory text — available to new and returning visitors alike.
  • Iowa does not legally require honoring Global Privacy Control. ConsentKit applies automatic GPC honoring in the 12 states that mandate it; in Iowa the opt-out link remains the visitor's control.
  • Every opt-out is recorded server-side with a timestamp and jurisdiction metadata, reviewable and exportable (CSV) from the dashboard — the audit trail regulators ask for.
  • Google Consent Mode v2 stays in sync: analytics and advertising tags update the moment a Iowa visitor makes a choice.

Iowa visitors see the standard “Your Privacy Choices” link; ConsentKit records each opt-out with a server-side timestamp and jurisdiction metadata for your audit log.

FAQ

Iowa ICDPA FAQ

Does Iowa's ICDPA apply to my business?

It applies if you control or process the personal data of 100,000 or more Iowa consumers, or 25,000 or more while deriving 50% or more of revenue from selling personal data. Both prongs target large-scale data operations, so many small businesses fall outside the law.

Does Iowa require a cookie banner?

No. Iowa uses an opt-out model — no GDPR-style banner is needed. The requirement is a clear opt-out link, for which “Your Privacy Choices” is the accepted text, covering targeted advertising and the sale of personal data.

Is Global Privacy Control required in Iowa?

No. Iowa is one of eight covered states with no universal opt-out signal mandate. Visitors opt out through the link; ConsentKit still records every choice with a timestamp for your records.

How is Iowa's law enforced?

Enforcement runs through the Iowa Attorney General. Our reference lists no specific per-violation dollar figure or cure period for Iowa.

This guide is for informational purposes and is not legal advice. Work with qualified counsel to confirm your obligations under the ICDPA.

Comply with Iowa's ICDPA — and the other 19 state laws

ConsentKit detects each visitor's state at the Cloudflare edge, renders the exact opt-out link their law requires, honors GPC automatically where mandated, and records every choice for your audit trail.