iQ Cookie  State Law Series

State 9 of 25 · Iowa

Cookie & Privacy Law in Iowa

Published August 2026
Law in effect
Since January 1, 2025

Educational purposes only — not legal advice. This guide is intended to help you understand Iowa’s data privacy law as it relates to cookie consent and website compliance. Laws change, and your specific situation may vary. Always consult a qualified legal professional before making compliance decisions. iQ Cookie is a technology tool, not a law firm.

LAW
ICDPA
SF 262
SIGNED
Mar 28, 2023
Gov. Kim Reynolds
EFFECTIVE
Jan 1, 2025
In effect 18+ months
STATE RANK
#6
To enact a law

The short version

Iowa was the sixth state to pass a comprehensive privacy law, taking effect January 1, 2025. It is also, by a fair margin, the most business-friendly law in this series so far — a permanent 90-day cure period, no data protection assessment requirement, and a consumer rights list that is noticeably shorter than its peers. If you have already built compliance for California, Colorado, or Connecticut, Iowa will feel like the easy stop on the tour.

Iowa does not have a separate cookie law. Cookie compliance flows from the ICDPA itself — and because Iowa’s obligations are lighter than most, so is the cookie-specific workload.

Iowa Legislature — Official Text
Iowa Consumer Data Protection Act, SF 262 — Iowa Code Chapter 715D

Who does it apply to?

The ICDPA covers businesses that conduct business in Iowa or target Iowa residents, and meet at least one of these thresholds:

THRESHOLD 1

Controls or processes personal data of 100,000 or more Iowa consumers during a calendar year.

THRESHOLD 2

Controls or processes data of 25,000 or more consumers AND derives more than 50% of gross revenue from selling personal data.

Nonprofits are exempt. GLBA and HIPAA-regulated data carry their usual exemptions as well.

Consumer rights

Iowa residents whose data is covered by the ICDPA have a narrower set of rights than most states in this series:

Access
Confirm processing and receive a copy of their data
Delete
Limited to consumer-provided data
Portability
Receive data in a usable, portable format
Opt out
Sale and targeted advertising only

Two notable omissions. Iowa does not give consumers a right to correct inaccurate data, and there is no right to opt out of profiling. Both are standard in most other state laws — Iowa deliberately left them out.

Businesses have 90 days to respond to consumer requests — longer than the 45-day standard elsewhere — plus a 60-day window to respond to appeals. There is no private right of action; only the Attorney General can enforce.

What makes Iowa different

Permanent 90-day cure period. The longest cure window of any state in this series, and it never sunsets. Businesses always get three full months to fix a violation before the AG can pursue penalties.

No data protection assessments required. Unlike California, Colorado, and Connecticut, Iowa does not require controllers to conduct formal risk assessments before high-risk processing activities.

No GPC requirement. Iowa does not require businesses to recognize or honor Global Privacy Control or any universal opt-out mechanism.

No right to correct, no right to opt out of profiling. Both are standard consumer rights in nearly every other state law — Iowa is one of the few to leave them out entirely.

Widely considered the most business-friendly state privacy law. Taken together — the long cure period, no assessments, narrower rights, no GPC — Iowa asks less of covered businesses than almost any other state on this list.

Sensitive data & children

Processing sensitive data requires opt-in consent before any collection begins. Sensitive data includes:

Racial / ethnic origin
Religious beliefs
Mental / physical health diagnosis
Sexual orientation
Citizenship / immigration status
Genetic data
Biometric data
Precise geolocation
Children’s data

Known children’s data is handled in accordance with COPPA — if you already have COPPA-compliant parental consent in place, that satisfies the ICDPA. Iowa does not layer on additional teen-specific protections the way Colorado or Delaware do.

What this means for your cookies

Cookie typeRequirementWhat to do
Sensitive data cookies (geolocation, biometric, health)Opt-in requiredGate these behind affirmative consent before they fire.
Targeted advertising cookiesOpt-out requiredProvide a clear opt-out mechanism for sale and targeted ads.
Profiling cookiesNo opt-out rightIowa does not require a profiling opt-out — disclose the practice in your policy regardless.
GPC / opt-out signalsNot requiredNo ICDPA obligation, but honoring it keeps you consistent with other states you may also serve.
Analytics & functional cookiesNo specific requirementDisclose in your privacy policy. Confirm they are not building profiles that count as "sale."

Enforcement

$7,500
Max penalty per violation
90 days
Cure period — permanent, longest in series
AG only
No private right of action

The Iowa Attorney General has exclusive enforcement authority, with penalties up to $7,500 per violation. With a permanent 90-day cure period and no assessment requirements to trip over, Iowa is a lower-risk compliance target than most states in this series — but the underlying obligations around sensitive data and opt-out rights still apply in full.

Your action checklist

Iowa is lighter-touch than most, but these still need to be in place:

1

Check your thresholds. Do you process data on 100,000+ Iowa consumers, or 25,000+ while earning over half your revenue from data sales? If yes, you are in scope.

2

Audit your cookies. Identify which cookies touch sensitive data or power targeted advertising — those are the categories with specific compliance obligations.

3

Set up opt-in for sensitive data. Cookies collecting precise geolocation, biometric, or health data must be blocked until the user affirmatively consents.

4

Add a targeted advertising opt-out. A clear "Do Not Sell or Share" link or equivalent mechanism satisfies this requirement.

5

Update your privacy policy. Cover data categories, purposes, consumer rights, and whether data is sold or used for targeted advertising — note that "correct" is not a right you need to build a workflow for here.

6

Review vendor contracts. Any processor handling Iowa resident data must be covered by a written agreement specifying processing instructions and confidentiality obligations.

Not sure where your site stands with Iowa?

iQ Cookie scans your site, flags gaps, and deploys a lightweight US-built consent banner.

iQ Cookie State Law Series  ·  Guide 9 of 25  ·  Next: Kentucky →