iQ Cookie State Law Series
Cookie & Privacy Law in Iowa
Educational purposes only — not legal advice. This guide is intended to help you understand Iowa’s data privacy law as it relates to cookie consent and website compliance. Laws change, and your specific situation may vary. Always consult a qualified legal professional before making compliance decisions. iQ Cookie is a technology tool, not a law firm.
The short version
Iowa was the sixth state to pass a comprehensive privacy law, taking effect January 1, 2025. It is also, by a fair margin, the most business-friendly law in this series so far — a permanent 90-day cure period, no data protection assessment requirement, and a consumer rights list that is noticeably shorter than its peers. If you have already built compliance for California, Colorado, or Connecticut, Iowa will feel like the easy stop on the tour.
Iowa does not have a separate cookie law. Cookie compliance flows from the ICDPA itself — and because Iowa’s obligations are lighter than most, so is the cookie-specific workload.
Who does it apply to?
The ICDPA covers businesses that conduct business in Iowa or target Iowa residents, and meet at least one of these thresholds:
Controls or processes personal data of 100,000 or more Iowa consumers during a calendar year.
Controls or processes data of 25,000 or more consumers AND derives more than 50% of gross revenue from selling personal data.
Nonprofits are exempt. GLBA and HIPAA-regulated data carry their usual exemptions as well.
Consumer rights
Iowa residents whose data is covered by the ICDPA have a narrower set of rights than most states in this series:
Two notable omissions. Iowa does not give consumers a right to correct inaccurate data, and there is no right to opt out of profiling. Both are standard in most other state laws — Iowa deliberately left them out.
Businesses have 90 days to respond to consumer requests — longer than the 45-day standard elsewhere — plus a 60-day window to respond to appeals. There is no private right of action; only the Attorney General can enforce.
What makes Iowa different
Permanent 90-day cure period. The longest cure window of any state in this series, and it never sunsets. Businesses always get three full months to fix a violation before the AG can pursue penalties.
No data protection assessments required. Unlike California, Colorado, and Connecticut, Iowa does not require controllers to conduct formal risk assessments before high-risk processing activities.
No GPC requirement. Iowa does not require businesses to recognize or honor Global Privacy Control or any universal opt-out mechanism.
No right to correct, no right to opt out of profiling. Both are standard consumer rights in nearly every other state law — Iowa is one of the few to leave them out entirely.
Widely considered the most business-friendly state privacy law. Taken together — the long cure period, no assessments, narrower rights, no GPC — Iowa asks less of covered businesses than almost any other state on this list.
Sensitive data & children
Processing sensitive data requires opt-in consent before any collection begins. Sensitive data includes:
Known children’s data is handled in accordance with COPPA — if you already have COPPA-compliant parental consent in place, that satisfies the ICDPA. Iowa does not layer on additional teen-specific protections the way Colorado or Delaware do.
What this means for your cookies
| Cookie type | Requirement | What to do |
|---|---|---|
| Sensitive data cookies (geolocation, biometric, health) | Opt-in required | Gate these behind affirmative consent before they fire. |
| Targeted advertising cookies | Opt-out required | Provide a clear opt-out mechanism for sale and targeted ads. |
| Profiling cookies | No opt-out right | Iowa does not require a profiling opt-out — disclose the practice in your policy regardless. |
| GPC / opt-out signals | Not required | No ICDPA obligation, but honoring it keeps you consistent with other states you may also serve. |
| Analytics & functional cookies | No specific requirement | Disclose in your privacy policy. Confirm they are not building profiles that count as "sale." |
Enforcement
The Iowa Attorney General has exclusive enforcement authority, with penalties up to $7,500 per violation. With a permanent 90-day cure period and no assessment requirements to trip over, Iowa is a lower-risk compliance target than most states in this series — but the underlying obligations around sensitive data and opt-out rights still apply in full.
Your action checklist
Iowa is lighter-touch than most, but these still need to be in place:
Check your thresholds. Do you process data on 100,000+ Iowa consumers, or 25,000+ while earning over half your revenue from data sales? If yes, you are in scope.
Audit your cookies. Identify which cookies touch sensitive data or power targeted advertising — those are the categories with specific compliance obligations.
Set up opt-in for sensitive data. Cookies collecting precise geolocation, biometric, or health data must be blocked until the user affirmatively consents.
Add a targeted advertising opt-out. A clear "Do Not Sell or Share" link or equivalent mechanism satisfies this requirement.
Update your privacy policy. Cover data categories, purposes, consumer rights, and whether data is sold or used for targeted advertising — note that "correct" is not a right you need to build a workflow for here.
Review vendor contracts. Any processor handling Iowa resident data must be covered by a written agreement specifying processing instructions and confidentiality obligations.
iQ Cookie scans your site, flags gaps, and deploys a lightweight US-built consent banner.
iQ Cookie State Law Series · Guide 9 of 25 · Next: Kentucky →