Iowa
Iowa Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Iowa law requires businesses to notify affected consumers of a data breach in the most expedient time possible and without unreasonable delay under Iowa Code 715C.2. When a breach affects 500 or more Iowa residents, businesses must also notify the Attorney General within five business days of notifying consumers.
Iowa requires businesses to notify consumers when their personal information has been compromised in a data breach. The state's Personal Information Security Breach Protection Act, codified at Iowa Code Chapter 715C, establishes notification requirements, timelines, and enforcement mechanisms.
Iowa's breach notification framework is notable for two reasons. First, it includes biometric data in its definition of protected personal information. Second, violations are classified as unlawful practices under the state's consumer fraud statute, giving the Attorney General broad enforcement power to seek damages on behalf of affected consumers.
The state also enacted the Iowa Consumer Data Protection Act (Chapter 715D) in 2023, effective January 1, 2025, which adds a separate layer of protection for biometric data as sensitive consumer data.
This guide covers the notification requirements, timelines, penalties, and enforcement mechanisms under Iowa law.
For broader context on Iowa's overall privacy framework, see the parent guide to Iowa Data Privacy Laws.
Who Must Comply
Iowa's breach notification law applies to any person who owns or licenses computerized data that includes a consumer's personal information that is used in the course of the person's business, vocation, occupation, or volunteer activities (Iowa Code 715C.2).
The law also applies to any person who maintains or otherwise possesses personal information on behalf of another person. These third-party agents must notify the owner or licensor of the information immediately following discovery of a breach.
What Qualifies as Personal Information
Under Iowa Code 715C.1, "personal information" means an individual's first name or first initial and last name combined with one or more of the following data elements:
- Social Security number
- Driver's license number or other unique identification number issued by a government body
- Financial account number, credit card number, or debit card number combined with any required expiration date, security code, access code, or password that would permit access to a financial account
- Unique electronic identifier or routing code combined with any required security code, access code, or password that would permit access to a financial account
- Unique biometric data, including fingerprint, retina or iris image, or other unique physical representation or digital representation of biometric data
The definition excludes information that is lawfully obtained from publicly available sources or from federal, state, or local government records lawfully made available to the general public.
Biometric Data Coverage

Iowa's inclusion of "unique biometric data" is significant. The statute covers fingerprints, retina or iris images, and other unique physical or digital representations of biometric data. This means that if a breach exposes stored fingerprint templates, iris scans, or other biometric identifiers alongside a person's name, notification obligations are triggered.
What Triggers a Notification
A "breach of security" under Iowa law means the unauthorized acquisition of personal information maintained in computerized form by a person that compromises the security, confidentiality, or integrity of the personal information.
Good faith acquisition exception. The good faith acquisition of personal information by an employee or agent of the person for a legitimate purpose of the person is not a breach of security, provided the personal information is not used for an unauthorized purpose or subject to further unauthorized disclosure.
Encrypted data exception. If the breached data was encrypted, the notification requirements may not apply unless the encryption key was also compromised.
Notification Timeline and Requirements
Timeline
Iowa requires consumer notification "in the most expedient time possible and without unreasonable delay." The law specifies that the notification must be consistent with:
- The legitimate needs of law enforcement
- Any measures necessary to sufficiently determine contact information for affected consumers
- The measures needed to determine the scope of the breach
- The steps needed to restore the reasonable integrity, security, and confidentiality of the data
Iowa does not set a hard deadline in days for consumer notification, giving businesses flexibility to investigate while also creating potential for enforcement if a delay is deemed unreasonable.
Attorney General Notification

Any person who owns or licenses computerized data containing personal information that was subject to a breach affecting 500 or more Iowa residents must provide written notice to the director of the consumer protection division of the Iowa Attorney General's office within five business days after notifying affected consumers.

Methods of Notification
Businesses can provide notice through:
- Written notice sent by mail to the last known address of the consumer
- Electronic notice if the consumer has consented to receiving electronic communications
- Substitute notice if the cost of providing direct notice would exceed $250,000, the affected class exceeds 350,000 consumers, or the business does not have sufficient contact information. Substitute notice requires email notice (if addresses are available), conspicuous posting on the business's website, and notification to major statewide media.
Content of Notification
Notifications must include:
- A description of the breach of security
- The approximate date of the breach
- The type of personal information obtained as a result of the breach
- Contact information for consumer reporting agencies
- Advice to the consumer to report suspected identity theft to local law enforcement or the Attorney General
Penalties and Enforcement
Unlawful Practice Classification
A violation of Chapter 715C is an unlawful practice under Iowa Code 714.16, which is Iowa's consumer fraud and unfair practices statute. This classification gives the Attorney General significant enforcement power.

Attorney General Authority
The Attorney General may investigate potential violations and bring enforcement actions. In addition to the standard remedies available under Section 714.16 (including injunctive relief and civil penalties), the Attorney General may seek and obtain an order requiring a violating party to pay damages on behalf of consumers injured by the violation.
No Private Right of Action
Iowa's breach notification law does not create a private right of action for individual consumers. Only the Attorney General can bring enforcement actions under this statute.
Civil Penalty Cap
Section 714.16 sets a specific civil penalty cap: the Attorney General may request, and the court may impose, a civil penalty not to exceed $40,000 per violation against a person found to have engaged in an unlawful practice under the statute. A course of conduct is not treated as separate violations merely because it was repeated to more than one person. The court may also impose a civil penalty of up to $5,000 per day for intentional violation of a related injunction.
Iowa Consumer Data Protection Act (Chapter 715D)
In addition to the breach notification law, Iowa enacted the Consumer Data Protection Act (ICDPA) in 2023, effective January 1, 2025. This law adds important protections for biometric data.
Under the ICDPA, biometric data processed for the purpose of uniquely identifying a natural person is classified as sensitive data. Controllers that process sensitive data, including biometric information, must present consumers with clear notice and an opportunity to opt out of such processing.
The ICDPA is enforced exclusively by the Attorney General. It does not create a private right of action. However, it establishes a 90-day cure period: before bringing an enforcement action, the Attorney General must provide the controller with written notice identifying the specific violations, and the controller has 90 days to cure those violations.
How Iowa Compares to Other States
Iowa's breach notification law is middling in strength compared to other states.
Biometric data included. Iowa is ahead of states that do not include biometric data in their breach notification definitions.
AG notification required. The five-business-day AG notification requirement for breaches affecting 500 or more residents is faster than many states.
No hard deadline for consumer notice. The "most expedient time possible" standard lacks the certainty of states with specific deadlines such as 30, 45, or 60 days.
No private right of action. Unlike Hawaii, which allows individuals to sue for actual damages and attorney's fees, Iowa limits enforcement to the Attorney General.
ICDPA adds biometric protections. Iowa's separate consumer data protection law classifies biometric data as sensitive and requires opt-out rights, placing it ahead of states without comprehensive privacy laws.
This article provides general legal information about Iowa data breach notification laws. It is not legal advice. Laws and regulations change frequently, and this content may not reflect the most recent developments. Consult a qualified attorney licensed in Iowa for advice about your specific situation.
More Iowa Laws
Frequently Asked Questions
How quickly must a business notify me of a data breach in Iowa?
Iowa law requires notification 'in the most expedient time possible and without unreasonable delay' after discovering a breach. The state does not set a specific number of days. The timeline must account for law enforcement needs, the time to determine the scope of the breach, and restoring data security. However, businesses must notify the Iowa Attorney General within five business days after notifying affected consumers when a breach affects 500 or more Iowa residents.
Does Iowa's breach notification law cover biometric data?
Yes. Iowa Code 715C.1 defines personal information to include unique biometric data such as fingerprints, retina or iris images, and other unique physical or digital representations of biometric data. If a breach exposes this data alongside your name, the business must comply with the notification requirements.
Can I sue a company for a data breach in Iowa?
No. Iowa does not provide a private right of action for data breach notification violations. Only the Iowa Attorney General can bring enforcement actions under Chapter 715C. Violations are classified as unlawful practices under Iowa Code 714.16, and the Attorney General can seek damages on behalf of injured consumers.
What penalties do businesses face for failing to report a data breach in Iowa?
Violations of Iowa's breach notification law are treated as unlawful practices under Iowa Code 714.16. The Attorney General can seek injunctive relief, civil penalties, and damages on behalf of injured consumers. Section 714.16 caps civil penalties at $40,000 per violation, with a course of conduct not counted as separate violations merely because it affected more than one person.
Does Iowa have other laws that protect biometric data?
Yes. In addition to the breach notification law, Iowa enacted the Consumer Data Protection Act (Chapter 715D), effective January 1, 2025. This law classifies biometric data processed for uniquely identifying individuals as sensitive data and requires controllers to give consumers clear notice and an opportunity to opt out before processing it. The ICDPA is enforced exclusively by the Iowa Attorney General.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Governing law re-checked for recent changes
Corrected a claim that Iowa's breach-notification enforcement statute has no specific dollar cap; Iowa Code 714.16 actually caps civil penalties at $40,000 per violation.
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 4 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
Iowa Code, Chapter 714: THEFT, FRAUD, AND RELATED OFFENSES
§ 714.16Consumer frauds.In force
1. Definitions: a. The term “advertisement” includes the attempt by publication, dissemination, solicitation, or circulation to induce directly or indirectly any person to enter into any obligation or acquire any title or interest in any merchandise. b. “Contaminant” means any physical, chemical, biological, or radiological substance in water. c. “Deception” means an act or practice which has the tendency or capacity to mislead a substantial number of consumers as to a material fact or facts. d. “Health-related contaminant” means a contaminant which has a potentially adverse health effect and for which a maximum contaminant level or treatment technique requirement or an action level established in lieu of a maximum contaminant level has been specified in the national primary drinking water regulations. e. The term “merchandise” includes any objects, wares, goods, commodities, intangibles, securities, bonds, debentures, stocks, real estate or services. f.
Official text (excerpt) · as of 2026-07-29 · Read the full section at legis.iowa.gov
Iowa Code, Chapter 715C: PERSONAL INFORMATION SECURITY
§ 715C.1Definitions.In force
As used in this chapter, unless the context otherwise requires: 1. “Breach of security” means unauthorized acquisition of personal information maintained in computerized form by a person that compromises the security, confidentiality, or integrity of the personal information. “Breach of security” also means unauthorized acquisition of personal information maintained by a person in any medium, including on paper, that was transferred by the person to that medium from computerized form and that compromises the security, confidentiality, or integrity of the personal information. Good faith acquisition of personal information by a person or that person’s employee or agent for a legitimate purpose of that person is not a breach of security, provided that the personal information is not used in violation of applicable law or in a manner that harms or poses an actual threat to the security, confidentiality, or integrity of the personal information. 2. “Consumer” means an individual who is a resident of this state. 3. “Consumer reporting agency” means the same as defined by the federal Fair Credit Reporting Act, 15 U.S.C. §1681a. 4.
Official text (excerpt) · as of 2026-07-29 · Read the full section at legis.iowa.gov
§ 715C.2Security breach — notification requirements — remedies.In forcecited in 2 of our articles
1. Any person who owns or licenses computerized data that includes a consumer’s personal information that is used in the course of the person’s business, vocation, occupation, or volunteer activities and that was subject to a breach of security shall give notice of the breach of security following discovery of such breach of security, or receipt of notification under subsection 2, to any consumer whose personal information was included in the information that was breached. The consumer notification shall be made in the most expeditious manner possible and without unreasonable delay, consistent with the legitimate needs of law enforcement as provided in subsection 3, and consistent with any measures necessary to sufficiently determine contact information for the affected consumers, determine the scope of the breach, and restore the reasonable integrity, security, and confidentiality of the data. 2.
Official text (excerpt) · as of 2026-07-29 · Read the full section at legis.iowa.gov
Also relied on in: Iowa Data Privacy Laws: ICDPA Consumer Rights Guide (2026)
Iowa Code, Chapter 715D: CONSUMER DATA PROTECTIONS
§ 715D.1Definitions.In forcecited in 4 of our articles
As used in this chapter, unless the context otherwise requires: 1. “Affiliate” means a legal entity that controls, is controlled by, or is under common control with another legal entity or shares common branding with another legal entity. For the purposes of this definition, “control” or “controlled” means: a. Ownership of, or the power to vote, more than fifty percent of the outstanding shares of any class of voting security of a company. b. Control in any manner over the election of a majority of the directors or of individuals exercising similar functions. c. The power to exercise controlling influence over the management of a company. 2. “Aggregate data” means information that relates to a group or category of consumers, from which individual consumer identities have been removed, that is not linked or reasonably linkable to any consumer. 3. “Authenticate” means verifying through reasonable means that a consumer, entitled to exercise their consumer rights in section 715D.3, is the same consumer exercising such consumer rights with respect to the personal data at issue. 4.
Official text (excerpt) · as of 2026-07-29 · Read the full section at legis.iowa.gov
Also relied on in: ICDPA Consumer Rights: What Iowans Can and Cannot Do, What Is the ICDPA? Iowa's Data Privacy Law Explained
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- Iowa Code Chapter 715C Personal Information Security Breach Protection(legis.iowa.gov).gov
- Iowa Code 715C.1 definitions including biometric data(legis.iowa.gov).gov
- Iowa Code 715C.2 breach notification requirements and remedies(legis.iowa.gov).gov
- Iowa Attorney General security breach notifications page(iowaattorneygeneral.gov).gov
- Iowa Code 714.16 consumer fraud and unfair practices enforcement(legis.iowa.gov).gov
- Iowa Consumer Data Protection Act (Chapter 715D)(legis.iowa.gov).gov
- Iowa Code 715D.1 definitions including sensitive data and biometric data(legis.iowa.gov).gov