Law / Iowa

Iowa

age

Iowa requires operators of websites and apps with a substantial portion of content pornographic for minors to perform reasonable age verification, effective July 1, 2026. No social media age verification, app store accountability, or design code law has been enacted; bills addressing parental consent for minor social media accounts and app store age verification were introduced in the 2026 session but did not pass either chamber.

privacy

The Iowa Consumer Data Protection Act (ICDPA), Iowa Code ch. 715D, is Iowa's comprehensive consumer-privacy regime, and its codified caption reads 'CONSUMER DATA PROTECTIONS' rather than the popular bill name.

Enacted as Senate File 262 (90th General Assembly), signed March 28, 2023, effective January 1, 2025 per consistent secondary reporting; the underlying research did not independently pull an explicit effective-date sentence from the primary statute text in this pass, and the primary text confirms it prints no such sentence.

ICDPA is the weakest of the seven states researched in this wave on data-subject rights: it grants no right to correct inaccurate personal data, requires only an opt-out (not opt-in consent) for sensitive-data processing, and gives a 90-day base response window, double the 45-day window used by the other six states in this batch.

Iowa's definitions section is codified at Iowa Code section 715D.1, not 715D.2 as an earlier draft of this document cited throughout; 715D.2 is Scope and exemptions, a different section. Genetic or biometric data collected to identify a person is one of ICDPA's enumerated sensitive-data categories, so biometric data itself is a heightened category here, correcting the carried seed's False value on that question.

Separately, Iowa's biometric-data definition carries a blanket, unconditional exclusion for recording-derived data with no identification-purpose clawback, the same structure as Virginia's, so a voiceprint or faceprint extracted from a recording falls outside biometric, and therefore sensitive, data regardless of purpose.

A separate chapter, Iowa Code ch. 715C, governs breach notification; that chapter lets the Attorney General recover damages on an injured person's behalf but does not itself arm the person with a direct private right of action.

The ICDPA Attorney General has exclusive enforcement authority over the comprehensive act, with a mandatory 90-day cure notice carrying no sunset date in the text read, distinctively permanent relative to Connecticut's, Delaware's, and Montana's time-limited or eliminated cure rights. No active 2026 reform vehicle for ICDPA itself was found in the underlying research or in an independent check during review, so this document sets fast_moving to false, departing from the carried default.

9 instruments named 6 researched in detail As of 2026-08-27

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Adult content age verification (AV)

HF 864, age verification for websites and apps pornographic for minors

cite Iowa Code ch. 554J (2026 Iowa Acts, HF 864) stage NEW in force 59 days effective 2026-07-01 source official Iowa General Assembly enrolled bill text

Operators of internet sites, apps, or segments of apps containing a substantial portion (one third or more) of material pornographic for minors must perform reasonable age verification of Iowa users before granting access, and may not retain, sell, or disseminate identifying information. Signed June 1, 2026.

Note and primary source

Breach notification

Personal Information Security Breach Protection

cite Iowa Code § 715C.2 stage IMMINENT commencement not set source official Iowa statute text, Iowa Code chapter 715C

Notification of a breach of security must be made in the most expeditious manner possible and without unreasonable delay, consistent with the legitimate needs of law enforcement. A business subject to a breach requiring notification to more than 500 Iowa residents must also give written notice to the director of the consumer protection division of the Attorney General's office within five business days of notifying consumers.

A violation is an unlawful practice under section 714.16, and the Attorney General may recover damages on behalf of an injured person, but that recovery runs through the Attorney General rather than arming the person with a direct private right of action. This provision is in force under the current codified text; the underlying research did not establish a dated original commencement, so no effective_date is recorded here.

What it asks of an app

Comprehensive regime

Iowa Consumer Data Protection Act (ICDPA), general applicability and controller/processor duties

cite Iowa Code ch. 715D, §§ 715D.2, 715D.4, 715D.5 stage IN FORCE in force since 2025-01-01 source official Iowa statute text, Iowa Code chapter 715D

ICDPA governs private-sector processing of Iowa consumers' personal data. Enacted as Senate File 262 (90th General Assembly, 2023 session), signed March 28, 2023 (2023 Iowa Acts ch. 17), effective January 1, 2025 per consistent secondary reporting; the effective date was not independently pulled as an explicit sentence from the primary code text in this pass, since Iowa's official code PDF does not print effective dates inline the way some peer states' history lines do. Controller duties are allocated at section 715D.4 and processor duties at section 715D.5.

What it asks of an app

Data subject rights

Iowa Consumer Data Protection Act, consumer rights

cite Iowa Code § 715D.3 stage IN FORCE in force since 2025-01-01 source official Iowa statute text, Iowa Code chapter 715D

ICDPA gives an Iowa consumer the right to confirmation of processing, access, deletion, a portable copy, and opt-out of sale, targeted advertising, and profiling for solely-automated consequential decisions, but notably grants no right of correction, a real gap relative to the other six states researched in this batch.

A controller must respond without undue delay and within 90 days of receipt, double the 45-day window used elsewhere in this batch, with one 45-day extension available; an appeal of a refusal must be decided within 60 days.

What it asks of an app

Enforcement supervision

Iowa Consumer Data Protection Act, Attorney General enforcement

cite Iowa Code § 715D.8 stage IN FORCE in force since 2025-01-01 source official Iowa statute text, Iowa Code chapter 715D

The Iowa Attorney General has exclusive authority to enforce ICDPA. Before suing, the Attorney General must give a controller or processor 90 days' written notice identifying the specific provisions violated; unlike Connecticut's, Delaware's, and Montana's time-limited or eliminated cure rights, this 90-day cure right carries no sunset date in the text read. Civil penalties run up to $7,500 per violation, and the chapter creates no private right of action.

What it asks of an app

Sensitive categories

Iowa Consumer Data Protection Act, sensitive data and biometric data definitions

cite Iowa Code § 715D.1(4), (26) stage IN FORCE in force since 2025-01-01 source official Iowa statute text, Iowa Code chapter 715D

ICDPA classifies data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, or citizenship or immigration status (with a discrimination-avoidance carve-out not seen in the other six states in this batch), the processing of genetic or biometric data to uniquely identify a person, a known child's data, and precise geolocation data as sensitive data, but requires only an opt-out mechanism for sensitive-data processing rather than the opt-in consent every other state in this batch requires.

Genetic or biometric data collected to identify a person is itself an enumerated sensitive-data category (§ 715D.1(26)(b)), so biometric data is a heightened category here.

Separately, 'Biometric data' (§ 715D.1(4)) carries the same blanket, unconditional exclusion for recording-derived data as Virginia's VCDPA, word for word: no clawback for data generated to identify someone, so a voiceprint or faceprint extracted from a recording is not biometric data under ICDPA regardless of purpose, and therefore is not sensitive data either.

This document cites these definitions to § 715D.1, correcting an earlier draft's citation to § 715D.2, which is a different section (Scope and exemptions).

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.