UniConsent helps businesses comply with the Iowa Consumer Data Protection Act (ICDPA). Manage consumer opt-out requests, cookie consent banners, and sensitive data consent in one platform.
The Iowa Consumer Data Protection Act (ICDPA) was signed into law on March 28, 2023, and takes effect on January 1, 2025. Iowa became one of the growing number of US states to enact comprehensive consumer data privacy legislation.
The ICDPA grants Iowa residents rights over their personal data and places obligations on businesses that collect or process that data. Compared to many other state privacy laws, the ICDPA is relatively business-friendly, offering fewer consumer rights and broader exemptions.
The ICDPA applies to businesses that conduct business in Iowa or produce products or services targeted to Iowa residents, and during the prior calendar year either:
Iowa residents are entitled to:
Note: Unlike most other state privacy laws, the ICDPA does not include a right to correction or a right to opt out of profiling for significant decisions. The ICDPA is one of the most business-friendly state privacy laws in the US.
Businesses must respond to verified consumer requests within 90 days.
Unlike most other state privacy laws, Iowa uses an opt-out model for sensitive data — businesses are not required to obtain prior opt-in consent before processing sensitive data. Instead, consumers may opt out of such processing. Sensitive data under the ICDPA includes racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, sexual orientation, citizenship status, genetic or biometric data processed to uniquely identify an individual, precise geolocation data, and personal data of known children.
The Iowa Attorney General enforces the ICDPA. There is no private right of action. Businesses have a 90-day cure period upon receiving notice of a violation. Civil penalties of up to $7,500 per violation may be imposed for violations that are not cured.
UniConsent provides the tools businesses need to meet ICDPA requirements:
Get started with UniConsent or explore our features.
Compare different US State Privacy Laws
Get started to make your website and application compliant for EU GDPR, US CPRA, CA PIPEDA etc
Sign up