Law / United States / Iowa
Tort Liability for Cybersecurity Programs, affirmative defense for a reasonable security program
Iowa Code ch. 554G (554G.1 to 554G.4, added by 2023 Acts, ch. 63 (H.F. 553))
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 1 July 2023.
A security baseline statutes rule binding private bodies.
As of 14 September 2026.
What it requires
- This affirmative defense is available to a covered entity, a business, defined to include a financial institution and an entity organized under chapter 28E, that accesses, receives, stores, maintains, communicates, or processes personal information or restricted information in or through a system, network, or service located in or outside Iowa; a municipality is excluded from the definition of business, and the chapter creates no independent duty to adopt a cybersecurity program.
- To claim the defense against a tort claim alleging that a failure to implement reasonable information security controls resulted in a data breach of personal information or restricted information, create, maintain, and comply with a written cybersecurity program containing administrative, technical, operational, and physical safeguards, designed to continually evaluate and mitigate reasonably anticipated threats, evaluate the maximum probable loss from a data breach at least annually, and communicate to affected parties the extent of any risk and steps to reduce damages once a breach is known to have occurred.
- Fund the program at a scale and scope that is appropriate if the cost to operate it is no less than the covered entity's most recently calculated maximum probable loss value.
- Satisfy the framework requirement by reasonably conforming the program to a named industry-recognized cybersecurity framework (the NIST framework for improving critical infrastructure cybersecurity, NIST SP 800-171, NIST SP 800-53 and 800-53A, the FedRAMP Security Assessment Framework, the CIS Critical Security Controls, or the ISO/IEC 27000 family), or, where already regulated under one, by conforming the program to the entirety of HIPAA's Security Rule, Gramm-Leach-Bliley Title V, the federal Information Security Modernization Act of 2014, HITECH, Iowa's own Insurance Data Security Act (chapter 507F), or applicable federal critical-infrastructure-protection rules, or by combining PCI Data Security Standard compliance with one of the named frameworks; conform the program to a revised framework or amended regulation within one year of its publication or effective date.
- This section creates no private right of action, including a class action, for a person's failure to comply with it: it is a defense available in litigation another statute or the common law already permits, never an independent basis to sue.
If you get it wrong
Criminal exposureNo
Private right of actionNo
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A covered entity is a business that accesses, receives, stores, maintains, communicates, or processes personal information or restricted information in or through a system, network, or service located in or outside Iowa. Business is defined to include a financial institution and an entity organized under Iowa Code chapter 28E, but not a municipality.
A covered entity that satisfies this chapter's requirements gains an affirmative defense to a tort claim alleging that a failure to implement reasonable information security controls caused a data breach concerning personal information or restricted information. To satisfy those requirements, a covered entity must create, maintain, and comply with a written cybersecurity program that reasonably conforms to a named industry framework or an applicable regulatory regime.
The program's scale and scope is appropriate if it is funded at or above the covered entity's own most recently calculated maximum probable loss from a data breach. The chapter imposes no independent duty to adopt a program and creates no private right of action of its own for failing to comply with it.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product