Home
IOWA ICDPA: Cookies Policy

IOWA ICDPA: Cookies Policy

3 months ago
João Bruno Soares
12 minutes

The Iowa Consumer Data Protection Act (ICDPA, Iowa Code § 715D) has a specific requirement for advertising cookies worth highlighting from the start.

This page covers one piece of the picture. For the full scope of the ICDPA — who must comply, the thresholds, the consumer rights and the penalties — start with our complete guide to the ICDPA and cookies.

The law formally lists only the opt-out from data sales as a consumer right (§ 715D.3(1)(d)). But § 715D.4(6) requires that, if the business engages in targeted advertising, it must clearly disclose this and describe how the consumer can exercise an opt-out from that activity.

In practice, any site with advertising pixels must offer an opt-out from targeted advertising, even though it is technically a transparency obligation rather than a formally listed right.

This article focuses exclusively on what the ICDPA requires from a Cookies Policy.

Cookies Policy vs. cookie banner: the necessary distinction

The cookie banner is the consent interface. It is what the visitor sees when they first access the site.

The Cookies Policy is the detailed document. It is where the user finds complete information about each technology: what it collects, what it is for, who receives the data.

Both need to exist. Both need to be aligned. And the Cookies Policy must be accessible from a clear link within the consent notice itself.

What the ICDPA specifically requires for cookies

Specific purpose for each tracker category

Under § 715D.4(5)(b), the privacy notice must include the purpose for processing personal data. For cookies, this translates into describing the purpose of each tracker category clearly.

What does not work: "cookies to improve your experience."

What works: "Analytics cookies: collect browsing behavior data to identify content improvement opportunities. Data is not sold to third parties."

"Advertising cookies: collect behavioral identifiers sent to advertising platforms for targeted advertising on non-affiliated websites. Consumers may opt out via the mechanism described in the privacy notice."

Cookie categories present on the site

The Policy must list the tracker categories:

Necessary cookies: essential for basic functionality. Do not constitute targeted advertising or data sale. Must be documented.

Analytics cookies: measure browsing behavior. Depending on the tool, may constitute targeted advertising if data is sent to third parties for targeting on other sites.

Advertising cookies: feed ad pixels for targeted advertising on non-affiliated sites. Require disclosure and opt-out per § 715D.4(6).

Functional cookies: remember user preferences. Generally do not constitute targeted advertising or data sale.

Third-party cookies: fired by external services. Correct tag categorization is what makes accurate documentation possible.

Targeted advertising: the ICDPA criterion

Under § 715D.1(28), targeted advertising consists of ads selected based on data obtained from the consumer's activities over time and across non-affiliated websites or online applications.

What does not constitute targeted advertising:

Ads based on activities within the controller's own site or affiliated sites.

Ads based on the context of the current search query or current visit.

Ads in response to consumer information requests or feedback.

Processing solely to measure advertising performance, reach, or frequency.

Retargeting campaigns using consumer behavior data from other sites almost always constitute targeted advertising.

The distinction between "sale" and "targeted advertising" under the ICDPA

The ICDPA distinguishes:

Sale of data (§ 715D.1(25)): exchange for monetary consideration to third parties. Consumer has a formal opt-out right.

Targeted advertising (§ 715D.1(28)): use of behavior data from non-affiliated sites to select ads. Not a formally listed opt-out right in § 715D.3, but the controller is required to disclose and offer opt-out per § 715D.4(6).

This creates an operational distinction: the business must offer opt-out from targeted advertising as part of transparency obligations, even though the consumer cannot formally "invoke" this opt-out in the same way they can invoke opt-out from data sales.

Categories of third parties receiving data via cookies

Under § 715D.4(5)(d) and (e), the privacy notice must identify categories of data shared with third parties and categories of third parties with whom data is shared.

For cookies, this includes digital advertising platforms, analytics tools that send data to third parties, and any partner receiving behavioral data from site users.

Retention period

The ICDPA does not require the Cookies Policy to specify data retention periods. This is a CPRA requirement, but not an ICDPA requirement.

Including retention information is a best practice for sites serving consumers in other jurisdictions, but it is not required by Iowa law.

The opt-out mechanism for sales and targeted advertising

Under § 715D.4(6), the controller must clearly describe how the consumer can opt out of both data sales and targeted advertising.

The format of the opt-out mechanism is not specified. It may be a footer link, a button in the cookie notice, or an online form described in the privacy notice.

The Cookies Policy must identify this mechanism and describe what happens when the consumer exercises the opt-out: which technologies are deactivated.

A well-configured consent management platform ensures that when the user exercises opt-out, all advertising pixels and trackers automatically stop firing.

Sensitive data collected via cookies

Under § 715D.1(26), sensitive data includes precise geolocation data (within 1,750 feet) and biometric data for identification.

If the site collects precise geolocation data via cookies, that is sensitive data under the ICDPA.

For sensitive data, the ICDPA requires (§ 715D.4(2)):

Presenting the consumer with a clear notice before processing.

Offering an opt-out opportunity.

This is the same opt-out model as the UCPA. It does not require prior consent, only notice and opt-out.

Do analytics cookies constitute targeted advertising under the ICDPA?

If Google Analytics sends user behavior data to Google and that data is used for advertising on other sites, this may constitute targeted advertising under the ICDPA.

The ANPD Cookie Guidance has documented how major analytics providers can cross-reference data for advertising purposes.

The safest approach: include Google Analytics in the category of cookies that may constitute targeted advertising, offer opt-out, and document this categorization in the Cookies Policy.

When to update the Cookies Policy

Situations requiring an update:

Adding a new advertising pixel or tracker.

A new analytics tool sending data to third parties for targeting.

A new partner receiving behavioral data from site users.

Change in the use of cookie data for new purposes.

Any modification to opt-out mechanisms.

Continuous data mapping is what keeps the cookie inventory synchronized with the document.

The 90-day cure period and the Cookies Policy

The AG must grant 90 guaranteed days to cure before initiating any action (§ 715D.8(2)). An inadequate Cookies Policy can be corrected within that period if the business has structured processes.

If the violation continues after 90 days, penalties can reach US$ 7,500 per violation.

How AdOpt helps with the Cookies Policy under the ICDPA

AdOpt's automatic scan identifies all active technologies on the site, feeding the list of categories that must appear in the Cookies Policy.

The cookie notice configured through AdOpt blocks non-necessary trackers, presents categories with clear descriptions, offers opt-out from data sales and targeted advertising, and logs every interaction for audit purposes.

Over 60,000 websites already run with AdOpt.

Privacy is not a banner. It is a position.

Want to build a Cookies Policy for your site that complies with the ICDPA? Talk to our team.

Checklist: what your Cookies Policy needs for the ICDPA

Visible link in the footer and in the cookie banner.

Listing of cookie categories with a description of what each does.

Specific purpose for each category (§ 715D.4(5)(b)).

Identification of cookies constituting targeted advertising (§ 715D.1(28)).

Identification of cookies constituting data sales (§ 715D.1(25)).

Categories of third parties receiving data via cookies (§ 715D.4(5)(e)).

Opt-out mechanism for data sales, clear and accessible (§ 715D.3(1)(d) and 715D.4(6)).

Opt-out mechanism for targeted advertising, clear and accessible (§ 715D.4(6)).

Notice and opt-out for sensitive data collected via cookies (§ 715D.4(2)).

Accessible language, without legal jargon.

FAQ: ICDPA and Cookies Policy

1. Does the ICDPA require a formal opt-out right from targeted advertising?
Not as a formally listed right in § 715D.3, but required in practice. § 715D.4(6) requires that if the controller engages in targeted advertising, it must clearly disclose this and describe the opt-out method. This creates a practical obligation equivalent to a right, even though it is technically a transparency obligation rather than a formally listed right. The Cookies Policy must offer this opt-out.

2. What is the difference between opt-out from "sales" and opt-out from "targeted advertising" under the ICDPA?
"Sale of data" (§ 715D.1(25)) is the exchange for monetary consideration, and opt-out is a formal consumer right in § 715D.3(1)(d). "Targeted advertising" (§ 715D.1(28)) is the use of behavior data from non-affiliated sites to select ads, and opt-out is a controller transparency obligation in § 715D.4(6), not a formally listed right. In practice, the Cookies Policy must offer opt-out for both activities, but the legal bases are different.

3. Do analytics cookies like Google Analytics constitute targeted advertising under the ICDPA?
It depends on the configuration. If Google Analytics only generates internal usage reports, it generally does not constitute targeted advertising. If data is used by Google for advertising on other sites, it may. The ICDPA defines targeted advertising as ads based on data obtained "from the consumer's activities over time and across non-affiliated websites or online applications" (§ 715D.1(28)). The specific GA4 configuration and privacy options activated determine whether targeted advertising is occurring.

4. Does the ICDPA use the same opt-out model for sensitive data as the UCPA?
Yes. Both the ICDPA (§ 715D.4(2)) and the UCPA use the opt-out model for sensitive data: clear notice and opt-out opportunity before processing, without requiring prior consent. This model differs from the opt-in required by the CPRA, OCPA, VCDPA, and CTDPA. For precise geolocation data collected via cookies, the Cookies Policy must inform and offer opt-out before activating those trackers.

5. What happens with opt-out from targeted advertising after the consumer exercises it?
The ICDPA does not specify a separate cessation deadline after opt-out from targeted advertising, beyond the general 90-day response deadline for requests (§ 715D.3(2)(a)). In practice, a well-configured consent management platform processes the opt-out from targeted advertising immediately, deactivating corresponding trackers at the moment the consumer exercises the option, without waiting 90 days.

Ready to build a Cookies Policy for your site that complies with the ICDPA? Talk to our team.

Tags

CMP
Controller and Operator
Cookie Banner
Cookies
Data Mapping

Related posts

5 Common Cookie Consent Mistakes Hurting Your Compliance

Discover the 5 common **cookie consent mistakes** that risk your **compliance** and learn how to avoid heavy **fines**. Simplify your **data privacy** strategy using a reliable **[Cookie notice/banner](https://goadopt.io/en/blog/why-the-cookie-banner/)**.

AdOpt post

Connecticut CTDPA: Cookies Policy

What the Connecticut CTDPA requires from your Cookies Policy: opt-out link, opt-out preference signal from January 2025, 15-day consent revocation, teen protections, and targeted advertising definition.

AdOpt post

The Differences Between Data Controller and Data Processor - LGPD

Now that we have the data flow within your company, we need to highlight 2 aspects of LGPD that will help you determine the extent of your responsibility in relation to the many points listed in the company. I'm talking about the difference between Data Controller and Data Processor.

AdOpt post

7 Steps to GDPR-Compliant Cookie Banners in 2025

Learn the essential steps for creating GDPR-compliant cookie banners in 2025, ensuring user consent and privacy protection.

AdOpt post

5 Signs Your Website Needs an Cookie Consent Strategy

How does your website handle LGPD? What strategies does it use to comply with the General Data Protection Law? Have you thought about using a cookie notice but don't know if your site has cookies or if it's enough? If you can't answer these questions, be cautious! Your page may be exposed to fines and other sanctions.

AdOpt post

How long can we ignore LGPD?

LGPD is in effect. Despite that, there are still many companies ignoring it, but is that possible? How long can we ignore LGPD?

AdOpt post

California CCPA: DSAR Privacy Portal

How to handle DSARs under the California CCPA/CPRA: 7 consumer rights, 45-day deadline, toll-free number required, 12-month lookback, private right of action for breaches, and CPPA enforcement.

AdOpt post

LGPD: An Opportunity for Digital Marketing Agencies!

Have you ever thought that your marketing agency could find a great business opportunity in LGPD? Well, unlike what many think, it brings changes that can accelerate the demand for the services of these companies.

AdOpt post

Why Give Consent on Every Website I Visit?

Have you ever noticed that every time you sign up for a service to access information or register on a website for purchases, you need to give consent? If you're wondering why you have to give consent on every website you visit, you'll find the answer here.

AdOpt post

New Hampshire NHDPA: Privacy Policy

Learn what your Privacy Policy must contain under the NHDPA. We break down the 8 mandatory elements and how to comply with New Hampshire's data privacy law.

AdOpt post

The Impact of Cookie Banners on Your E-commerce - LGPD

Having a cookie banner on your brand's website has become indispensable for many. However, for e-commerce websites, it has practically become an obligation to have one. This is because this type of website has a technological composition in which cookies are a structural part. Login flow, items in the shopping cart, recommendation showcases, remarketing... Most of them rely on cookies.

AdOpt post

California CPRA and Cookies: All you need to know

California CPRA explained: CCPA vs CPRA timeline and key differences, sensitive personal information, sharing of data, CPPA enforcement, GPC requirement, and tripled penalties for minors.

AdOpt post

MTCDPA Montana and Cookies: All you need to know

Find out if the MTCDPA applies to your site, key compliance deadlines, and new rules for cookies and consent in Montana

AdOpt post

IOWA ICDPA: DSAR and Privacy Portal

Iowa ICDPA DSAR guide: 90-day response deadline, 45-day extension, 60-day appeal process, limited deletion scope, opt-out from data sales, targeted advertising disclosure requirement, and 90-day cure period.

AdOpt post

Utah UCPA: DSAR and Privacy Portal

Utah UCPA DSAR guide: four consumer rights, limited deletion scope, no right to correct, no formal appeal process, no opt-out of profiling, 45-day deadline, and the guaranteed 30-day cure period.

AdOpt post

Montana MTCDPA: Privacy Policy

Learn what your MTCDPA Privacy Policy must include after Montana's SB 297 amendments from the conspicuous "privacy" hyperlink and last-updated date requirements to sale disclosures, minor protections, and how to keep your notice operationally aligned with your stack.

AdOpt post

How does a cookie banner operate?

Here is a step-by-step explanation of how consent registration works in AdOpt.

AdOpt post

New Hampshire NHDPA: DSAR Privacy Portal

What is a DSAR under NHDPA? Complete guide to consumer rights, response deadlines, and building a compliant Privacy Portal for your site.

AdOpt post

Tenesse TIPA: Cookies Policy

Learn how to build a defensible TIPA Cookies Policy for Tennessee compliance covering consent architecture, opt-out requirements, the NIST affirmative defense, and how your cookie banner, privacy notice, and vendor management must work together under the Tennessee Information Protection Act.

AdOpt post

Connecticut CTDPA and Cookies: All You Need to Know

The Connecticut Data Privacy Act (CTDPA) is a state regulation designed to protect the privacy of Connecticut residents. It also regards cookies, so in this article we will help you understand all about this new privacy regulation.

AdOpt post

Florida FDBR and Cookies: All You Need to Know

Everything you need to know about the Florida Digital Bill of Rights (FDBR): who must comply, the $1 billion threshold, 7 consumer rights, FIPA vs FDBR explained, penalties, and cookies.

AdOpt post

Colorado CPA: Cookies Policy

What the Colorado CPA requires from your Cookies Policy: mandatory Universal Opt-Out Mechanism from July 2024, targeted advertising definition, dark pattern rules, and the 24-month consent refresh.

AdOpt post

Oregon OCPA and Cookies: All You Need to Know

Everything about the Oregon OCPA: who must comply, the payment transaction exclusion, 25% revenue threshold, derived data in scope, GPC requirement from January 2026, and elimination of the cure period.

AdOpt post

LGPD and Cookies all do you need to know?

In this article, you will have a great introduction to the topic, as well as various other variations that revolve around the subject: Cookies and LGPD.

AdOpt post

California CPRA: Privacy Policy

What the California CPRA requires from your Privacy Policy: SPI category, two mandatory links, data retention periods, sharing disclosure, right to correct, GPC, and minor protections.

AdOpt post

Florida FDBR: Cookies Policy

What the Florida FDBR requires from your Cookies Policy: targeted advertising across affiliated sites, opt-out for sensitive data and voice recognition, dark patterns, and tripled penalties.

AdOpt post

Google Consent Mode: Beginner to Advanced Guide.

Google Consent Mode (GCM) is nothing more than a way for you to integrate the consent you collect from your visitors into Google technologies. In this way, upon receiving this consent information, collection can only occur with authorization, thus complying with the legislation and having direct evidence of compliance as defense for both you and Google.

AdOpt post

Data Mapping or Data Inventory - a life jacket for the DPO!

With the data mapping we have a clear understanding of the 5 stages that every data goes through in a company.

AdOpt post

Tenesse TIPA: DSAR Privacy Portal

Learn how to build a TIPA-compliant Privacy Portal for Tennessee. Understand DSAR deadlines, consumer rights, opt-out mechanisms, and the affirmative defense that sets TIPA apart from every other US state privacy law.

AdOpt post

Colorado CPA and Cookies: All You Need to Know

The Colorado Consumer Privacy Act went into effect July 1, 2023 (CPA). CPA is a vital piece of legislation designed to protect the privacy of residents in Colorado. Understanding its requirements is essential for any business operating in the state. This act is all about giving control back to the consumers regarding their personal data. But what does this mean for you and your business, especially when it comes to managing cookies on your website?

AdOpt post

Florida FDBR: Privacy Policy

What the Florida FDBR requires from your Privacy Policy: annual updates, 6 mandatory content categories, specific notices for sensitive and biometric data sales, and the 7 consumer rights.

AdOpt post

California CCPA: Privacy Policy

What the California CCPA/CPRA requires from your Privacy Policy: 12-month lookback, annual updates, Do Not Sell link, sensitive PI disclosures, toll-free number, and the 7 consumer rights.

AdOpt post

Connecticut CTDPA: Privacy Policy

What the Connecticut CTDPA requires from your Privacy Policy: active email contact, opt-out link, 15-day consent revocation, opt-out preference signal from January 2025, and teen protections.

AdOpt post

Colorado CPA: Privacy Policy

What the Colorado CPA requires from your Privacy Policy: 5 mandatory elements, purpose specification duty, secondary use prohibition, 24-month consent refresh, and Universal Opt-Out Mechanism disclosure.

AdOpt post

Utah UCPA and Cookies: All you need to know

Utah UCPA explained: the most business-friendly US state privacy law, dual threshold requirement, opt-out for sensitive data, no right to correct, guaranteed 30-day cure period, and key differences from other state laws.

AdOpt post

Oregon OCPA: Cookies Policy

What the Oregon OCPA requires from your Cookies Policy: opt-out link, GPC from January 2026, opt-out without authentication, derived data in scope, teen protections, and the elimination of the cure period.

AdOpt post

California CPRA: DSAR and Privacy Portal

California CPRA DSAR guide: new rights to correct and limit SPI, opt-out without multiple steps, GPC as valid opt-out, 12-month minor rule, private right of action, and CPPA enforcement.

AdOpt post

Texas TDPSA and Cookies: All You Need to Know

Your website have users accessing from Texas? So be ready… the Texas Data Privacy and Security Act is here to shake things up. Don't worry; we've got your back. This guide will walk you through everything you need to know to ensure your website complies with the new regulations.

AdOpt post

Outsourcing the DPO (DPOaaS), Is It a Good Idea?

The Data Protection Officer, or DPO, is a new position that emerged all over the globe with the new privacy regulations, and more recently at the LGPD. Although it already existed in other international legislations, such as the EU's GDPR, it is still a novelty here since 2020. Along with it comes the possibility of outsourcing, known as DPO as a Service (DPOaaS).

AdOpt post

Virginia VCDPA: DSAR Privacy Portal

How to handle DSARs under the Virginia VCDPA: consumer rights, 45-day response deadlines, the appeal process, free requests twice per year, and how to build a compliant Privacy Portal.

AdOpt post

GDPR Legal Basis: An Introduction

In this article, we'll explore the GDPR foundations and provide practical insights from the basics to more advanced concepts of its legal basis.

AdOpt post

Florida FDBR: DSAR Privacy Portal

How to handle DSARs under the Florida FDBR: 7 consumer rights, two required submission channels, 45-day deadline with only 15-day extension, tripled penalties for children, and compliance guide.

AdOpt post

Best practices in tag categorization

It's time to talk about one of the most impactful tasks, both for the company and for the visitors of your websites: tag categorization. But why is it so impactful? What is the relevance of this configuration and how can it affect us? It is precisely because of these common questions we receive from our clients that we have written this article on best practices in tag categorization.

AdOpt post

Montana MTCDPA: DSAR Policy

Rights, Policy and how to understand about the DSAR Montana MTCDPA

AdOpt post

What is the difference between cookies, local storage, and session storage?

Despite cookies being more well-known, what is the main difference between cookies and session storage and local storage? Why choose one over the other? This article will help you with these doubts!

AdOpt logoAdOpt logo

Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819

15 Rue du Général Campredon, 34000 Montpellier, France

207 Rue de Bercy, 75012 Paris, France

EIN: 86-3965064

Phone: +1 (407) 768-3792

AdOpt

Resources

Product

Certifications

Google CMP PartnerIAB Europe TCF Registered Vendor

© GO ADOPT, LLC since 2020 - Made by people who love🍪