Iowa
ICDPA Consumer Rights: What Iowans Can and Cannot Do
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 7 primary sources cited on this page. How we verify our legal content

Under the Iowa Consumer Data Protection Act (Iowa Code Chapter 715D), Iowa residents have four privacy rights: to confirm and access their personal data, to delete data they provided, to obtain a portable copy of that data, and to opt out of the sale of personal data. These rights are set out in Section 715D.3 and took effect with the rest of the law on January 1, 2025.
As of 2026, a covered business must respond within 90 days of receiving a request under Section 715D.3(2), one of the longest response windows in the country. Iowans cannot sue a business directly to enforce these rights; Section 715D.8(4) bars any private right of action, leaving enforcement to the Iowa Attorney General.
Jurisdiction scope: This covers Iowa's Consumer Data Protection Act (Iowa Code Chapter 715D). It is general legal information, not legal advice.
The four rights Iowans have under Section 715D.3
The Iowa Consumer Data Protection Act gives Iowa residents a short, defined list of rights. Section 715D.3(1) requires a controller to comply with an authenticated consumer request to exercise each of four rights, and no more.
The first right is the right to confirm and access. Under Section 715D.3(1)(a), a consumer may ask a controller to confirm whether it is processing the consumer's personal data and to access that data. This is the entry point for the other rights, because it lets a consumer see what a company holds.
The second is the right to delete. Under Section 715D.3(1)(b), a consumer may request deletion of "personal data provided by the consumer." This is narrower than the deletion rights in some states, which extend to data a company collected from other sources; in Iowa, the deletion right reaches data the consumer themselves provided.
The third is the right to data portability. Under Section 715D.3(1)(c), a consumer may obtain a copy of the personal data they previously provided, in a portable and, to the extent technically practicable, readily usable format. That format must let the consumer transmit the data to another controller without hindrance where processing is automated. The statute carves out data subject to the security-breach rules in Section 715C.1.
The fourth is the right to opt out of the sale of personal data. Under Section 715D.3(1)(d), a consumer may direct a controller to stop selling their personal data. A "sale" is defined in Section 715D.1 as the exchange of personal data for monetary consideration to a third party, a narrower definition than California's, which also covers other valuable consideration.
What Iowans cannot do: the missing rights
The gaps in Iowa's rights list are as important as the rights themselves, and they are the reason the ICDPA is widely described as the weakest comprehensive state privacy law as of 2026.
There is no right to correct. Section 715D.3 does not include a right to fix inaccurate personal data, unlike Virginia, Colorado, Connecticut, Texas, and California. An Iowan who finds an error in the data a company holds about them cannot demand a correction under the ICDPA, although they can request deletion of data they provided.
There is no right to opt out of targeted advertising. The statute defines "targeted advertising" in Section 715D.1 and requires a controller that engages in it to disclose that activity and explain how to opt out under Section 715D.4(6). But the enumerated rights in Section 715D.3 do not include a targeted-advertising opt-out, so the disclosure duty is not paired with an enforceable consumer right to stop the practice.
There is no right to opt out of profiling. Several states let consumers opt out of profiling in furtherance of decisions that produce legal or similarly significant effects. Iowa grants no such right. The ICDPA neither defines a profiling opt-out nor lists one among the Section 715D.3 rights.
The practical effect is a rights set built around access, deletion, portability, and a data-sale opt-out, with the broader behavioral-advertising and correction protections that consumers have in neighboring states simply absent in Iowa.

How to exercise your rights and the 90-day response window
To exercise a right, a consumer submits a request to the controller through the method the controller specifies under Section 715D.4. A controller must establish secure and reliable means for submitting requests and, under Section 715D.4(7), may not require a consumer to create a new account to do so, though it may require use of an existing account. A known child's parent or legal guardian may submit a request on the child's behalf.
The controller must first authenticate the request. "Authenticate" is defined in Section 715D.1 as verifying through reasonable means that the requester is the consumer entitled to exercise the right. If a controller cannot authenticate the request using commercially reasonable efforts, Section 715D.3(2)(d) allows it to decline and to ask for additional information.
Under Section 715D.3(2)(a), a controller must respond without undue delay and in all cases within 90 days of receipt of the request. The 90-day clock runs from receipt, not from the date the controller finishes authenticating the requester. The controller may extend the period once by 45 additional days when reasonably necessary, given the complexity and number of requests, if it tells the consumer of the extension and the reason within the initial 90 days.
That 90-day baseline is the longest response window among state privacy laws. Many states, including California and Virginia, require a response within 45 days. Iowans should expect a slower turnaround than consumers in most other states.
Responses are free up to twice a year per consumer under Section 715D.3(2)(c). A controller may charge a reasonable fee or decline only when a request is manifestly unfounded, excessive, repetitive, or technically unfeasible, and the controller bears the burden of proving that.
Appeals: the Section 715D.3(3) process
If a controller declines to act on a request, the consumer has a built-in appeal right. Under Section 715D.3(2)(b), a controller that declines must inform the consumer of the justification without undue delay and provide instructions for appealing, unless it suspects a fraudulent request.
The appeal process itself is governed by Section 715D.3(3). A controller must establish a conspicuously available appeal process that is similar to the process for submitting the original request. Within 60 days of receiving an appeal, the controller must inform the consumer in writing of any action taken or not taken, with a written explanation of the reasons.
If the appeal is denied, the controller must give the consumer an online mechanism to contact the Iowa Attorney General and submit a complaint. This is the practical escalation path under the ICDPA, because there is no private right of action and the Attorney General is the sole enforcer.

Sensitive data: the opt-out path under Section 715D.4(2)
Iowa treats sensitive data through an opt-out model rather than the opt-in consent most states require. Under Section 715D.4(2), a controller "shall not process sensitive data collected from a consumer for a nonexempt purpose without the consumer having been presented with clear notice and an opportunity to opt out." For a known child, the controller must instead process the data in accordance with the federal Children's Online Privacy Protection Act.
In practice, this means the burden is on the Iowan to say no. A company may begin processing sensitive data after giving notice and an opt-out opportunity; it does not have to obtain affirmative consent first. This is the same lighter standard Utah uses and a key reason both states are considered business-friendly.
Sensitive data is defined in Section 715D.1 to include racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data processed to uniquely identify a person, the personal data of a known child, and precise geolocation data accurate within 1,750 feet. An Iowan who wants to limit this processing should look for the controller's sensitive-data notice and use the opt-out it provides.
Discrimination protection and how to file a complaint
The ICDPA includes an anti-retaliation rule. Under Section 715D.4(3), a controller may not discriminate against a consumer for exercising a right, including by denying goods or services, charging different prices, or providing a different quality of service. The statute preserves an exception for bona fide loyalty, rewards, or club-card programs and for offers tied to data the controller does not collect.
Any contract clause that purports to waive or limit a consumer's rights under Section 715D.3 is void and unenforceable as against public policy under Section 715D.4(4). A business cannot make an Iowan sign away these rights.
Because Section 715D.8(4) bars a private right of action, an Iowan who believes a business is not honoring these rights cannot sue under the ICDPA. Instead, after exhausting the controller's appeal process, the consumer can submit a complaint to the Iowa Attorney General, who holds exclusive enforcement authority under Section 715D.8. The Attorney General's office accepts consumer complaints through its consumer-protection division.
Related guides
- Iowa Data Privacy Laws (ICDPA hub)
- What Is the ICDPA? Iowa's Data Privacy Law Explained
- ICDPA Compliance Checklist for Businesses
- US State Privacy Laws Comparison
- What Is the CCPA? California's Privacy Law Explained
More Iowa Laws
Frequently Asked Questions
What rights do Iowans have under the ICDPA?
Section 715D.3 grants four rights: to confirm and access personal data, to delete data the consumer provided, to obtain a portable copy of that data, and to opt out of the sale of personal data. There is no right to correct data, no targeted-advertising opt-out, and no profiling opt-out, which makes Iowa's rights set the narrowest among comprehensive state privacy laws.
Can I correct inaccurate data under Iowa's privacy law?
No. The ICDPA does not include a right to correct inaccurate personal data. Section 715D.3 lists only access, deletion of data the consumer provided, portability, and a sale opt-out. If you find an error, you cannot demand a correction under the ICDPA, although you may request deletion of data you provided.
Can I opt out of targeted advertising in Iowa?
Not as an enforceable right. The ICDPA defines targeted advertising in Section 715D.1 and requires controllers to disclose it under Section 715D.4(6), but the consumer rights in Section 715D.3 do not include a targeted-advertising opt-out. This is a key difference from Virginia, Colorado, Connecticut, Texas, and California.
How long does a business have to respond to my request?
Under Section 715D.3(2)(a), a controller must respond without undue delay and within 90 days of receiving your request. The period can be extended once by 45 additional days when reasonably necessary, if the controller notifies you within the first 90 days. This is the longest standard response window among state privacy laws.
Is there a fee to make a privacy request in Iowa?
Usually not. Under Section 715D.3(2)(c), a controller must respond free of charge up to twice a year per consumer. A controller may charge a reasonable fee or decline only when a request is manifestly unfounded, excessive, repetitive, or technically unfeasible, and the controller bears the burden of showing that.
What can I do if a company refuses my request?
You can appeal. Under Section 715D.3(3), a controller must provide an appeal process and respond in writing within 60 days. If the appeal is denied, the controller must give you an online mechanism to contact the Iowa Attorney General and submit a complaint. Because there is no private right of action, the Attorney General is the enforcement route.
How does Iowa handle sensitive data requests?
Iowa uses an opt-out model. Under Section 715D.4(2), a controller must present clear notice and an opportunity to opt out before processing sensitive data, rather than obtaining opt-in consent. For a known child, the controller must comply with the federal Children's Online Privacy Protection Act. Look for the controller's sensitive-data notice to exercise the opt-out.
Can I sue a company under the ICDPA?
No. Section 715D.8(4) states the chapter does not provide a private right of action. Only the Iowa Attorney General may enforce the ICDPA, under Section 715D.8. An Iowan who believes a business is violating the law can submit a complaint to the Attorney General's consumer-protection division rather than filing a lawsuit.
Updates
Corrected the response deadline: the 90-day clock under Iowa Code 715D.3(2)(a) runs from receipt of your request, not from the date the business finishes authenticating it.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Iowa Code, Chapter 715D: CONSUMER DATA PROTECTIONS
§ 715D.3Consumer data rights.In forcecited in 4 of our articles
1. A consumer may invoke the consumer rights authorized pursuant to this section at any time by submitting a request to the controller, through the means specified by the controller pursuant to section 715D.4, subsection 6, specifying the consumer rights the consumer wishes to invoke. A known child’s parent or legal guardian may invoke such consumer rights on behalf of the known child regarding processing personal data belonging to the child. A controller shall comply with an authenticated consumer request to exercise all of the following: a. To confirm whether a controller is processing the consumer’s personal data and to access such personal data. b. To delete personal data provided by the consumer. c. To obtain a copy of the consumer’s personal data, except as to personal data that is defined as “personal information” pursuant to section 715C.1 that is subject to security breach protection, that the consumer previously provided to the controller in a portable and, to the extent technically practicable, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means. d.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at legis.iowa.gov
Also relied on in: ICDPA Compliance Checklist for Businesses (Iowa), What Is the ICDPA? Iowa's Data Privacy Law Explained, Iowa Data Privacy Laws: ICDPA Consumer Rights Guide (2026)
§ 715D.4Data controller duties.In forcecited in 5 of our articles
1. A controller shall adopt and implement reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data. Such data security practices shall be appropriate to the volume and nature of the personal data at issue. 2. A controller shall not process sensitive data collected from a consumer for a nonexempt purpose without the consumer having been presented with clear notice and an opportunity to opt out of such processing, or, in the case of the processing of sensitive data concerning a known child, without processing such data in accordance with the federal Children’s Online Privacy Protection Act, 15 U.S.C. §6501 et seq. 3. A controller shall not process personal data in violation of state and federal laws that prohibit unlawful discrimination against a consumer. A controller shall not discriminate against a consumer for exercising any of the consumer rights contained in this chapter, including denying goods or services, charging different prices or rates for goods or services, or providing a different level of quality of goods and services to the consumer.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at legis.iowa.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2023
Opinions citing this section in our collection:
- Calabretto Building Group v. Tradesmen International, LLC. (Court of Appeals of Iowa 2023)“…s); see also 2023 Iowa Acts ch. 17, § 4 (to be codified at Iowa Code § 715D.4(4)) (voiding terms that “waive or limi…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Iowa Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 715D.1Definitions.In forcecited in 6 of our articles
As used in this chapter, unless the context otherwise requires: 1. “Affiliate” means a legal entity that controls, is controlled by, or is under common control with another legal entity or shares common branding with another legal entity. For the purposes of this definition, “control” or “controlled” means: a. Ownership of, or the power to vote, more than fifty percent of the outstanding shares of any class of voting security of a company. b. Control in any manner over the election of a majority of the directors or of individuals exercising similar functions. c. The power to exercise controlling influence over the management of a company. 2. “Aggregate data” means information that relates to a group or category of consumers, from which individual consumer identities have been removed, that is not linked or reasonably linkable to any consumer. 3. “Authenticate” means verifying through reasonable means that a consumer, entitled to exercise their consumer rights in section 715D.3, is the same consumer exercising such consumer rights with respect to the personal data at issue. 4.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at legis.iowa.gov
Also relied on in: Iowa Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 715D.8Enforcement — penalties.In forcecited in 3 of our articles
1. The attorney general shall have exclusive authority to enforce the provisions of this chapter. Whenever the attorney general has reasonable cause to believe that any person has engaged in, is engaging in, or is about to engage in any violation of this chapter, the attorney general is empowered to issue a civil investigative demand. The provisions of section 685.6 shall apply to civil investigative demands issued under this chapter. 2. Prior to initiating any action under this chapter, the attorney general shall provide a controller or processor ninety days’ written notice identifying the specific provisions of this chapter the attorney general alleges have been or are being violated. If within the ninety-day period, the controller or processor cures the noticed violation and provides the attorney general an express written statement that the alleged violations have been cured and that no further such violations shall occur, no action shall be initiated against the controller or processor. 3.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at legis.iowa.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Iowa Code Chapter 715D: Consumer Data Protections (Full Text)(legis.iowa.gov).gov
- Iowa Code Section 715D.3: Consumer Data Rights(legis.iowa.gov).gov
- Iowa Code Section 715D.4: Data Controller Duties (Sensitive Data Opt-Out)(legis.iowa.gov).gov
- Iowa Code Section 715D.1: Definitions (Sensitive Data, Sale of Personal Data)(legis.iowa.gov).gov
- Iowa Code Section 715D.8: Enforcement and Penalties (No Private Right of Action)(legis.iowa.gov).gov
- Iowa Attorney General: File a Consumer Complaint(iowaattorneygeneral.gov).gov
- Iowa Senate File 262 (2023): Consumer Data Protection Act(legis.iowa.gov).gov
- Iowa Code Section 715D.3: Consumer Data Rights (official section text)(legis.iowa.gov)