Iowa Consumer Data Protection Act (SF 262) state silhouette

Iowa Consumer Data Protection Act (SF 262)

Effective Date: 2025-01-01

The Iowa Consumer Data Protection Act covers businesses that control or process personal data of at least 100,000 Iowa consumers, or 25,000 if more than half of revenue comes from selling personal data. It is the most business-friendly of the state privacy laws.

What the Iowa Consumer Data Protection Act Requires

Consumers get rights to access, delete, and port data and to opt out of data sales and targeted advertising, but there is no right to correct, and sensitive data requires notice and an opportunity to opt out rather than opt-in consent. No data protection assessments are required. Website owners covered by the law still need a compliant privacy notice describing data categories, purposes, sharing, and how to exercise rights.

Enforcement and Penalties

The Attorney General enforces exclusively with a generous 90-day cure period and civil penalties up to $7,500 per violation. There is no universal opt-out signal requirement, so covered sites do not have to build Global Privacy Control support for Iowa alone.

Source: Iowa Legislature: SF 262, Iowa Code Chapter 715D

Report a violation: If you believe a business is violating this law, you can file a complaint with the Iowa Attorney General Consumer Protection Division.

More Rules & Regulations