Iowa Consumer Data Protection Act (ICDPA) Compliance: Iowa Data Privacy Law and the 90-Day Deadline
The Iowa Consumer Data Protection Act is the most forgiving comprehensive privacy law in the country. Iowa gives you 90 days to answer a consumer request instead of the usual 45, grants no right to correct data, and keeps a permanent 90-day cure period. That leniency is exactly what makes it a trap: almost nobody serves only Iowa residents, and a process built to Iowa's clock is 45 days late everywhere else. Obtainer finds where a person's data lives across your systems, compiles one reviewable manifest, drafts the response, and tracks each state's clock separately.
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
In short
The Iowa Consumer Data Protection Act (ICDPA), Iowa Code chapter 715D, took effect January 1, 2025. It applies to a controller that conducts business in Iowa or produces products or services targeted to Iowa residents and, during a calendar year, either controls or processes the personal data of at least 100,000 Iowa consumers, or controls or processes the data of at least 25,000 consumers while deriving more than 50 percent of gross revenue from the sale of personal data. There is no revenue floor, so a company can be pulled in on consumer count alone. Iowa consumers can confirm whether you process their personal data and access it, delete personal data they provided to you, obtain a portable copy, and opt out of the sale of personal data. Two rights other states grant are missing: Iowa has no right to correct inaccurate personal data, which makes it the only comprehensive state law without one, and no right to opt out of profiling. Targeted advertising is handled as a disclosure and opt-out obligation rather than a standalone consumer right. The response deadline is 90 days from receipt of an authenticated request, extendable once by 45 more days when reasonably necessary given the complexity and number of requests, provided you notify the consumer inside the original window. That 90-day base is the longest of any US state privacy law, and the 135-day ceiling is the longest total window in the country. Enforcement sits with the Iowa Attorney General exclusively, there is no private right of action, and civil penalties run up to $7,500 per violation. Iowa also keeps a 90-day right to cure with no sunset date, the most generous cure window in the United States. Obtainer handles the operational side of an ICDPA request: intake, discovery of where the person's data lives, a source-system manifest, a drafted deadline-safe response, and per-state deadline tracking so an Iowa request is not accidentally treated like a Virginia one, or the reverse. Nothing is disclosed or erased automatically; a human reviews, redacts, and approves. Obtainer helps you comply. It is not legal advice, so scope and exemption calls stay with your team. Self-serve from $49/mo.
Why it fits
Iowa businesses and out-of-state SaaS, ecommerce, insurance, and agriculture-adjacent firms that serve Iowa residents at scale, plus multi-state privacy teams that need Iowa's 90-day clock tracked separately from the 45-day clock running in nineteen other states.
The 90-day deadline is the longest in the country, and that is the risk
Every other Virginia-model state gives you 45 days. Iowa gives you 90, plus a 45-day extension, for a 135-day ceiling. If you build one process around Iowa's clock you will blow the deadline in Virginia, Texas, Colorado, Connecticut, and fifteen other states, and you will be a full 75 days past Florida's 60-day ceiling. The safe design is per-request, per-state clocks, not one company-wide number. Iowa's generosity is a reason to track states separately, not a reason to slow down.
Iowa is the only state with no right to correct
Nineteen of the twenty comprehensive state laws now grant a correction right, including Utah, which switched its on with House Bill 418 on July 1, 2026. Iowa did not follow. A correction request from an Iowa resident is not an ICDPA obligation, but it may still be one under another law that covers the same person, and refusing it outright is a judgment call your counsel should make rather than your intake form. Knowing which statute a request actually falls under is the whole point of routing it correctly on arrival.
Deletion in Iowa is narrower than deletion elsewhere
The ICDPA deletion right covers personal data the consumer provided to you. It does not reach data you derived, inferred, or bought from a third party the way Colorado and California do. That sounds like less work, and it is, but only if you can tell the two buckets apart across a warehouse, a CRM, and an enrichment vendor. Obtainer's discovery pass shows the source system behind every record it finds, which is what makes the distinction answerable rather than assumed.
The 90-day cure is permanent, and documentation is what earns it
Most states have let their cure windows expire. Iowa did not, and at 90 days it is the longest guaranteed window in the United States. The Attorney General must give written notice and let you fix a violation before seeking penalties of up to $7,500 each. A cure only helps if you can show what happened: a timestamped intake record, a manifest of what you found, and a dated approval on what went out. Obtainer keeps that record as a by-product of doing the work.
More use cases
Related features
Questions
Common questions about this
Who has to comply with the Iowa Consumer Data Protection Act?
A controller doing business in Iowa or targeting Iowa residents that, in a calendar year, either processes the personal data of at least 100,000 Iowa consumers, or processes the data of at least 25,000 consumers while deriving more than 50 percent of gross revenue from selling personal data. There is no revenue floor, so consumer volume alone can bring you in scope. Financial institutions subject to the Gramm-Leach-Bliley Act, HIPAA-covered entities, nonprofits, and government bodies are exempt.
How long do I have to respond to an Iowa data subject request?
Ninety days from receipt of an authenticated request, extendable once by 45 additional days when reasonably necessary given the complexity and number of requests, provided you notify the consumer within the initial 90 days. That is the longest response window of any US state privacy law, where nearly every other state uses 45 days plus a 45-day extension and Florida caps its extension at 15 days.
Does Iowa have a right to correct personal data?
No. Iowa is the only comprehensive US state privacy law that does not grant consumers a right to correct inaccurate personal data. It also does not grant a right to opt out of profiling. Iowa consumers can confirm and access their data, delete data they provided, obtain a portable copy, and opt out of the sale of their personal data.
What are the penalties for violating the ICDPA?
Civil penalties reach $7,500 per violation, sought by the Iowa Attorney General, who has exclusive enforcement authority. There is no private right of action, so consumers cannot sue you directly. Iowa also requires a 90-day cure period with no sunset date, so the Attorney General must give written notice and an opportunity to fix the violation before penalties can attach.
Does Iowa require honoring Global Privacy Control?
No. The ICDPA does not require controllers to recognize universal opt-out mechanisms such as Global Privacy Control, unlike California, Colorado, Connecticut, Texas, and eight other states. If you already honor the signal for those states, honoring it for Iowa traffic costs nothing and avoids maintaining a state-by-state exception in your consent layer.
Is deletion under the ICDPA the same as under the CCPA?
No, it is narrower. The Iowa right to delete covers personal data the consumer provided to the controller. It does not extend to data you inferred, derived, or obtained from third-party sources, which California and Colorado deletion requests do reach. In practice you still have to locate every copy to answer the request, because you cannot tell which bucket a record belongs in until you know which system it came from.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.