Does Iowa's Consumer Data Protection Act apply to your business?
Iowa's Consumer Data Protection Act applies to businesses that operate in Iowa or target its residents and, in a calendar year, control or process personal data of at least 100,000 consumers, or at least 25,000 consumers while deriving over 50 percent of gross revenue from selling personal data. Nonprofits and HIPAA data are exempt.
Applies to: Businesses that conduct business in Iowa or target Iowa residents and meet either the 100,000-consumer threshold or the 25,000-consumer-plus-data-sales threshold, and that are not otherwise exempt.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanFounding 30% off with code FOUNDING until 15 August 2026
Iowa's privacy law took effect on January 1, 2025, and it borrows its applicability test almost word for word from Virginia. If you are trying to work out whether it reaches your business, the first thing to know is that Iowa does not look at your revenue at all. The test is about how many Iowans' data you handle.
Who the Iowa Consumer Data Protection Act covers
Under Iowa Code 715D.2, the chapter applies to a person conducting business in Iowa, or producing products or services targeted to Iowa residents, that during a calendar year either controls or processes the personal data of at least 100,000 consumers, or controls or processes the personal data of at least 25,000 consumers and derives over 50 percent of gross revenue from the sale of personal data. A consumer here means an Iowa resident acting in a personal capacity, so business-to-business contacts and your own employees do not count toward the total.
The 25,000 shortcut, and who hits it first
Most product companies reach coverage through the 100,000 figure. The 25,000 prong targets businesses whose model is selling data. If more than half your gross revenue comes from selling personal data, the bar drops to 25,000 consumers, which a data broker or ad-tech intermediary can pass quickly. If you never sell data in the statutory sense, this second prong will rarely be what pulls you in.
Who is carved out
Section 715D.2(2) exempts whole categories of organization: the state and its political subdivisions, financial institutions and data subject to the Gramm-Leach-Bliley Act, entities that comply with HIPAA, nonprofit organizations, and institutions of higher education. These are entity-level exemptions, so a covered nonprofit sits outside the chapter even if it processes data for large numbers of people. The statute also exempts specific data types, including protected health information and Fair Credit Reporting Act data.
What covered businesses owe
Iowa's obligations are lighter than most other state laws. Covered controllers publish a privacy notice, honor rights to access, delete, and obtain a copy of personal data, and let consumers opt out of the sale of personal data and targeted advertising. Iowa does not grant a right to correct data, and it keeps a permanent 90-day cure period before the Attorney General can act. The structure will look familiar if you have read the Virginia VCDPA, which uses the same thresholds, or the Colorado Privacy Act. The US state privacy laws hub shows how the thresholds line up.
Next step
Because Iowa counts people rather than dollars, the honest answer to "does it apply?" usually needs a real count of your Iowa users. The free 2-minute Obligation Scan runs the 715D.2 thresholds against your business and flags the notice, opt-out, and consent duties that follow, so you spend your time on the obligations rather than the arithmetic.
Compliance checklist
- Count the Iowa consumers whose personal data you controlled or processed over the calendar year, keeping the 100,000 and 25,000 figures in view.
- If you are near 25,000, work out whether over 50 percent of your gross revenue comes from selling personal data, since that lowers the trigger.
- Check the Section 715D.2(2) entity exemptions before assuming you are covered: nonprofits, GLBA financial institutions, HIPAA entities, and higher education are out.
- If covered, publish a privacy notice, and honor consumer rights to access, delete, and opt out of the sale of personal data and targeted advertising.
- Get consent before processing sensitive data, and note that Iowa gives the Attorney General a 90-day cure period before enforcement.
Sources
- Iowa Code § 715D.2 (Scope and exemptions), official Iowa Code
- Iowa Code Chapter 715D (Consumer Data Protections), official Iowa Code
Last verified: 2026-07-22
Informational, not legal advice.