The Iowa Consumer Data Protection Act (ICDPA, Iowa Code § 715D) has privacy notice requirements very similar to Utah's UCPA, with one important operational difference: the response deadline for consumer requests is 90 days, not 45.
This page covers one piece of the picture. For the full scope of the ICDPA — who must comply, the thresholds, the consumer rights and the penalties — start with our complete guide to the ICDPA and cookies.
For the Privacy Policy, this means the process described in the document for exercising rights must reflect this longer deadline. Iowa consumers will have to wait up to three months to receive a response, and the notice must be clear about this.
This article focuses exclusively on what the ICDPA requires from the Privacy Policy.
The law uses the term "privacy notice." Under § 715D.4(5), the controller must provide a notice that is "reasonably accessible, clear, and meaningful."
The notice must list the categories of personal data the controller processes (§ 715D.4(5)(a)).
Personal data under the ICDPA is any information linked or reasonably linkable to an identified or identifiable natural person (§ 715D.1(18)). This includes identifiers such as name, email, IP address, browsing history, and data that allows tracking a person.
De-identified data, aggregate data, and publicly available information are excluded.
The notice must explain the purpose for which data is processed (§ 715D.4(5)(b)).
The law does not specify that purposes must be highly detailed, but the requirement that the notice be "clear and meaningful" implies that generalities like "improve services" are insufficient.
The notice must describe how consumers can exercise the rights guaranteed by the ICDPA, including how to appeal a controller decision (§ 715D.4(5)(c)).
The four rights under the ICDPA are:
Confirm and access: confirm whether the controller processes data and access that data (§ 715D.3(1)(a)).
Deletion: request deletion of data the consumer provided to the controller (§ 715D.3(1)(b)).
Portability: obtain a copy of the data in a portable format (§ 715D.3(1)(c)).
Opt-out from data sales: refuse the sale of personal data (§ 715D.3(1)(d)).
The deadline that must be described: 90 days to respond from receipt of the request, with a possible extension of 45 more days with notification within the initial period (§ 715D.3(2)(a)).
The appeal process: the notice must describe how the consumer can appeal a denial decision, with a 60-day response deadline for appeals (§ 715D.3(3)). If the appeal is denied, the consumer must be informed of how to contact the Attorney General online.
The notice must identify the categories of personal data the controller shares with third parties, if any (§ 715D.4(5)(d)).
The notice must identify the categories of third parties with whom data is shared, if any (§ 715D.4(5)(e)).
The ICDPA does not require the level of detail about how each third party may process data that the OCPA demands. Identifiable categories are sufficient.
If the business sells data or engages in targeted advertising, § 715D.4(6) requires clear and conspicuous disclosure of that activity, with description of the method by which the consumer can exercise the opt-out for each activity.
Targeted advertising, per § 715D.1(28), consists of ads selected based on data obtained from the consumer's activities over time and across non-affiliated websites or applications.
Although opt-out from targeted advertising is not listed as a formal right in § 715D.3, the disclosure obligation in § 715D.4(6) creates the practical requirement to offer this opt-out in the privacy notice.
Under § 715D.4(7), the controller must establish secure and reliable means for consumers to submit rights requests, and describe those means in the privacy notice.
These means must:
Consider how consumers normally interact with the controller.
Ensure secure and reliable communication.
Allow authentication of the consumer's identity.
The controller may not require the consumer to create a new account to exercise their rights. It may require use of an existing account (§ 715D.4(7)).
Under § 715D.4(2), the controller may not process sensitive data without first presenting the consumer with a clear notice and offering an opt-out opportunity.
Sensitive data includes: racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data for unique identification, data of known children, and precise geolocation data.
This opt-out model for sensitive data is identical to the UCPA's. It is less restrictive than the opt-in required by the CPRA, OCPA, VCDPA, and CTDPA.
For data of known children, the business must comply with COPPA (§ 715D.2(2)(r) and 715D.4(2)).
The Privacy Policy must:
Identify whether the business processes sensitive data.
Describe how the sensitive data notice is presented to consumers.
Explain how the consumer can exercise the opt-out from sensitive data processing.
Comparing with other laws:
No mandatory retention periods. The CPRA requires specifying how long each data category is retained. The ICDPA has no such requirement.
No detail about third parties. The OCPA requires describing how each third party may process data. The ICDPA requires only categories.
No right to correct to describe. Since the ICDPA does not provide this right, the policy does not need to describe it.
The 90-day deadline must be clearly described. Consumers familiar with VCDPA, OCPA, and CTDPA expect responses within 45 days. A notice that clearly states the ICDPA's 90-day deadline avoids unnecessary complaints.
Under § 715D.4(3), the business may not discriminate against consumers who exercise their rights. This includes denying goods or services, charging different prices, or offering different quality.
The exception is voluntary loyalty programs and situations where the consumer opted out of targeted advertising and the business adjusted prices accordingly.
Before initiating any action, the Iowa Attorney General must notify the controller and grant 90 days to cure (§ 715D.8(2)). This is the longest cure period of all US state privacy laws.
An outdated or incomplete Privacy Policy can be corrected within 90 days with the right processes. But structuring it correctly from the start is always more efficient.
AdOpt ensures that what is written in the Policy has real correspondence with what actually happens on the site.
The automatic scan identifies all active technologies, feeding the list of data categories and third parties. The consent management platform ensures the opt-out mechanism works as described.
Every interaction is logged. If the Attorney General requests evidence, the record is available.
Over 60,000 websites already run with AdOpt.
Privacy is not a banner. It is a position.
Want to build a Privacy Policy for your site that complies with the ICDPA? Talk to our team.
Visible and accessible link on all pages of the site.
Categories of personal data processed (§ 715D.4(5)(a)).
Purpose for processing each category (§ 715D.4(5)(b)).
How to exercise the 4 rights with channel and 90-day deadline (§ 715D.4(5)(c)).
Appeal process with 60-day response deadline (§ 715D.3(3)).
How to contact the Attorney General if appeal is denied (§ 715D.3(3)).
Categories of personal data shared with third parties (§ 715D.4(5)(d)).
Categories of third parties with whom data is shared (§ 715D.4(5)(e)).
Disclosure of data sales or targeted advertising with opt-out method (§ 715D.4(6)).
Request submission channel described, without requiring new account (§ 715D.4(7)).
Sensitive data treatment: clear notice and opt-out before processing (§ 715D.4(2)).
COPPA compliance for children's data (§ 715D.4(2)).
Non-discrimination policy (§ 715D.4(3)).
Free service for 2 requests per year per consumer (§ 715D.3(2)(c)).
1. Why must the ICDPA Privacy Policy clearly state the 90-day deadline?
Most consumers who have interacted with privacy notices from other jurisdictions expect responses within 45 days. The ICDPA establishes 90 days as the standard deadline (§ 715D.3(2)(a)), which is significantly different. A Policy that clearly describes this deadline helps manage expectations and avoids complaints from consumers expecting a faster response. Describing the correct deadline also demonstrates that the business knows its specific legal obligations.
2. Does the privacy notice need to mention the ICDPA's appeal process?
Yes. § 715D.4(5)(c) requires the notice to describe how consumers can exercise their rights "including how a consumer may appeal a controller's decision with regard to the consumer's request." This means the appeal process, with a 60-day response deadline (§ 715D.3(3)), must be described. If the appeal is denied, the notice should also indicate how the consumer can contact the Attorney General.
3. Does the ICDPA have the same free-service policy as the UCPA?
Not exactly. The ICDPA guarantees free service for 2 requests per consumer per 12-month period (§ 715D.3(2)(c)). The UCPA guarantees free service for only 1 request per 12-month period. The VCDPA also guarantees 2 free requests per year. The Privacy Policy must correctly reflect this number, as stating "free once per year" when the law guarantees 2 would be an inaccuracy that could generate complaints.
4. Does the ICDPA use the same opt-out model for sensitive data as the UCPA?
Yes. Both the ICDPA (§ 715D.4(2)) and the UCPA require only a clear notice and opt-out opportunity before processing sensitive data, without requiring active prior consent. This model differs from the opt-in required by the CPRA, OCPA, VCDPA, and CTDPA. A business already compliant with the UCPA on this point will be compliant with the ICDPA as well.
5. Does the ICDPA require the same level of detail about third parties as the OCPA?
No. The OCPA requires describing third parties at a level of detail that enables the consumer to understand what type of entity each third party is and how it may process data. The ICDPA (§ 715D.4(5)(d) and (e)) requires only the categories of data shared and the categories of third parties, without the additional detail the OCPA demands. Categories such as "digital advertising platforms" and "analytics tools" are sufficient under the ICDPA.
Ready to build a Privacy Policy for your site that complies with the ICDPA? Talk to our team.
Discover the 5 common **cookie consent mistakes** that risk your **compliance** and learn how to avoid heavy **fines**. Simplify your **data privacy** strategy using a reliable **[Cookie notice/banner](https://goadopt.io/en/blog/why-the-cookie-banner/)**.
What the Connecticut CTDPA requires from your Cookies Policy: opt-out link, opt-out preference signal from January 2025, 15-day consent revocation, teen protections, and targeted advertising definition.
Now that we have the data flow within your company, we need to highlight 2 aspects of LGPD that will help you determine the extent of your responsibility in relation to the many points listed in the company. I'm talking about the difference between Data Controller and Data Processor.
Learn the essential steps for creating GDPR-compliant cookie banners in 2025, ensuring user consent and privacy protection.
How does your website handle LGPD? What strategies does it use to comply with the General Data Protection Law? Have you thought about using a cookie notice but don't know if your site has cookies or if it's enough? If you can't answer these questions, be cautious! Your page may be exposed to fines and other sanctions.
LGPD is in effect. Despite that, there are still many companies ignoring it, but is that possible? How long can we ignore LGPD?
How to handle DSARs under the California CCPA/CPRA: 7 consumer rights, 45-day deadline, toll-free number required, 12-month lookback, private right of action for breaches, and CPPA enforcement.
Have you ever thought that your marketing agency could find a great business opportunity in LGPD? Well, unlike what many think, it brings changes that can accelerate the demand for the services of these companies.
Learn what your Privacy Policy must contain under the NHDPA. We break down the 8 mandatory elements and how to comply with New Hampshire's data privacy law.
Having a cookie banner on your brand's website has become indispensable for many. However, for e-commerce websites, it has practically become an obligation to have one. This is because this type of website has a technological composition in which cookies are a structural part. Login flow, items in the shopping cart, recommendation showcases, remarketing... Most of them rely on cookies.
California CPRA explained: CCPA vs CPRA timeline and key differences, sensitive personal information, sharing of data, CPPA enforcement, GPC requirement, and tripled penalties for minors.
Find out if the MTCDPA applies to your site, key compliance deadlines, and new rules for cookies and consent in Montana
Iowa ICDPA DSAR guide: 90-day response deadline, 45-day extension, 60-day appeal process, limited deletion scope, opt-out from data sales, targeted advertising disclosure requirement, and 90-day cure period.
Utah UCPA DSAR guide: four consumer rights, limited deletion scope, no right to correct, no formal appeal process, no opt-out of profiling, 45-day deadline, and the guaranteed 30-day cure period.
Learn what your MTCDPA Privacy Policy must include after Montana's SB 297 amendments from the conspicuous "privacy" hyperlink and last-updated date requirements to sale disclosures, minor protections, and how to keep your notice operationally aligned with your stack.
A privacy policy is a document that outlines how an organization collects, uses, discloses, and manages a customer's data. It's essential for building trust with users and complying with legal requirements. However, if you're not familiar with it, don't worry as we're here to help you.
Here is a step-by-step explanation of how consent registration works in AdOpt.
The Texas Data Privacy and Security Act (TDPSA) introduces sweeping changes to how businesses collect, use, and disclose personal data—and your privacy policy is now a frontline compliance tool. This article is a comprehensive guide for any company serving Texas residents, explaining how to align your privacy practices with the new legal standards.
In the end, our goal has never been to predict doom for companies or to be part of the LGPD's Apocalypse Cavalry. But, since we've been in the market for some time, these kinds of issues always catch our attention when we start data mapping and having conversations with colleagues.
What is a DSAR under NHDPA? Complete guide to consumer rights, response deadlines, and building a compliant Privacy Portal for your site.
Learn how to build a defensible TIPA Cookies Policy for Tennessee compliance covering consent architecture, opt-out requirements, the NIST affirmative defense, and how your cookie banner, privacy notice, and vendor management must work together under the Tennessee Information Protection Act.
The Connecticut Data Privacy Act (CTDPA) is a state regulation designed to protect the privacy of Connecticut residents. It also regards cookies, so in this article we will help you understand all about this new privacy regulation.
Everything you need to know about the Florida Digital Bill of Rights (FDBR): who must comply, the $1 billion threshold, 7 consumer rights, FIPA vs FDBR explained, penalties, and cookies.
What the Colorado CPA requires from your Cookies Policy: mandatory Universal Opt-Out Mechanism from July 2024, targeted advertising definition, dark pattern rules, and the 24-month consent refresh.
Everything about the Oregon OCPA: who must comply, the payment transaction exclusion, 25% revenue threshold, derived data in scope, GPC requirement from January 2026, and elimination of the cure period.
In this article, you will have a great introduction to the topic, as well as various other variations that revolve around the subject: Cookies and LGPD.
What the California CPRA requires from your Privacy Policy: SPI category, two mandatory links, data retention periods, sharing disclosure, right to correct, GPC, and minor protections.
What the Florida FDBR requires from your Cookies Policy: targeted advertising across affiliated sites, opt-out for sensitive data and voice recognition, dark patterns, and tripled penalties.
Google Consent Mode (GCM) is nothing more than a way for you to integrate the consent you collect from your visitors into Google technologies. In this way, upon receiving this consent information, collection can only occur with authorization, thus complying with the legislation and having direct evidence of compliance as defense for both you and Google.
With the data mapping we have a clear understanding of the 5 stages that every data goes through in a company.
Learn how to build a TIPA-compliant Privacy Portal for Tennessee. Understand DSAR deadlines, consumer rights, opt-out mechanisms, and the affirmative defense that sets TIPA apart from every other US state privacy law.
The Colorado Consumer Privacy Act went into effect July 1, 2023 (CPA). CPA is a vital piece of legislation designed to protect the privacy of residents in Colorado. Understanding its requirements is essential for any business operating in the state. This act is all about giving control back to the consumers regarding their personal data. But what does this mean for you and your business, especially when it comes to managing cookies on your website?
What the Florida FDBR requires from your Privacy Policy: annual updates, 6 mandatory content categories, specific notices for sensitive and biometric data sales, and the 7 consumer rights.
What the California CCPA/CPRA requires from your Privacy Policy: 12-month lookback, annual updates, Do Not Sell link, sensitive PI disclosures, toll-free number, and the 7 consumer rights.
What the Connecticut CTDPA requires from your Privacy Policy: active email contact, opt-out link, 15-day consent revocation, opt-out preference signal from January 2025, and teen protections.
What the Colorado CPA requires from your Privacy Policy: 5 mandatory elements, purpose specification duty, secondary use prohibition, 24-month consent refresh, and Universal Opt-Out Mechanism disclosure.
Utah UCPA explained: the most business-friendly US state privacy law, dual threshold requirement, opt-out for sensitive data, no right to correct, guaranteed 30-day cure period, and key differences from other state laws.
What the Oregon OCPA requires from your Cookies Policy: opt-out link, GPC from January 2026, opt-out without authentication, derived data in scope, teen protections, and the elimination of the cure period.
California CPRA DSAR guide: new rights to correct and limit SPI, opt-out without multiple steps, GPC as valid opt-out, 12-month minor rule, private right of action, and CPPA enforcement.
Your website have users accessing from Texas? So be ready… the Texas Data Privacy and Security Act is here to shake things up. Don't worry; we've got your back. This guide will walk you through everything you need to know to ensure your website complies with the new regulations.
How to handle DSARs under the Virginia VCDPA: consumer rights, 45-day response deadlines, the appeal process, free requests twice per year, and how to build a compliant Privacy Portal.
The Data Protection Officer, or DPO, is a new position that emerged all over the globe with the new privacy regulations, and more recently at the LGPD. Although it already existed in other international legislations, such as the EU's GDPR, it is still a novelty here since 2020. Along with it comes the possibility of outsourcing, known as DPO as a Service (DPOaaS).
In this article, we'll explore the GDPR foundations and provide practical insights from the basics to more advanced concepts of its legal basis.
How to handle DSARs under the Florida FDBR: 7 consumer rights, two required submission channels, 45-day deadline with only 15-day extension, tripled penalties for children, and compliance guide.
What the Iowa ICDPA requires from your Cookies Policy: opt-out for data sales and targeted advertising, opt-out model for sensitive data, no GPC requirement, no specific link text required, and the 90-day cure period.
09 Jun 2026
Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819
15 Rue du Général Campredon, 34000 Montpellier, France
207 Rue de Bercy, 75012 Paris, France
EIN: 86-3965064
Phone: +1 (407) 768-3792
AdOpt
Resources
Product
Certifications