Skip to content

Evidence request lists

Iowa Consumer Data Protection Act

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Iowa CDPA Consumer Rights

ICDPA-ConsumerRights-Access-Delete-Portability-OptOut-Sale-Appeal-90Day-NO-Right-To-Correction-Authorised-Agent
Iowa CDPA Consumer Rights - Access + Delete + Portability + Opt-Out of Sale + 90-Day Response + Appeal + Authorised Agent + NO Right to Correction + NO Profiling Opt-Out + Free First Per Year

Iowa CDPA grants Iowa consumers 5 core rights subject to verifiable consumer request procedures per Iowa Code 715D.4. Iowa CDPA rights are NARROWER than other US state privacy laws - notably NO Right to Correction (unique among major state privacy laws as of 2026) and NO Profiling Opt-Out for legal/significant effects. (1) Right to Confirm + Access (Iowa Code 715D.4-1): consumer may confirm whether or not a controller is processing the consumer personal data and to access such personal data. (2) Right to Delete (Iowa Code 715D.4-2): consumer may delete personal data provided by the consumer (note: only data PROVIDED BY consumer, not data OBTAINED ABOUT consumer - narrower than Virginia/Colorado/Connecticut). (3) Right to Portability (Iowa Code 715D.4-3): consumer may obtain a copy of consumer personal data that the consumer previously provided to the controller in a portable and to the e

Artefacts an auditor will ask for
  • 5 consumer rights portal + Access + Delete + Portability + Opt-Out Sale + Appeal + records
  • 90-day response SLA + 45-day extension + 60-day appeal + tracking + records
  • Authorised agent procedure + GPC voluntary recognition + identity verification + records
  • Free of charge policy + 12-month tracking + subsequent fee + records
  • Anti-discrimination policy + no penalty for rights exercise + records + audit
Where this commonly fails
  • Right to Correction claimed (Iowa does NOT have - confusion with other states)
  • Profiling opt-out claimed (Iowa does NOT have)
  • 90-day SLA missed (treating as 45 day)
  • GPC not honoured even voluntarily (privacy-tech alignment missed)
  • Discrimination claimed by consumers for exercising rights

Iowa CDPA Controller Obligations

ICDPA-Controller-PrivacyNotice-PurposeLimitation-DataMinimisation-Sale-Disclosure-Transparency-LawfulBasis
Iowa CDPA Controller Obligations - Privacy Notice + Purpose Limitation + Data Minimisation + Sale Disclosure Statement + Targeted Advertising Disclosure + Privacy by Design + Lawful Processing

Per Iowa Code 715D.5 controllers operating subject to ICDPA must comply with core obligations. (1) Privacy Notice (Iowa Code 715D.5-1): controller shall provide consumers with a reasonably accessible + clear + and meaningful privacy notice that includes (a) the categories of personal data processed by the controller; (b) the purposes for processing personal data; (c) how consumers may exercise their consumer rights including how a consumer may appeal a controller decision; (d) the categories of personal data that the controller shares with third parties if any; (e) the categories of third parties if any with which the controller shares personal data. (2) Sale Disclosure (Iowa Code 715D.5-2): if a controller sells personal data to third parties or processes personal data for targeted advertising + the controller shall clearly and conspicuously disclose such processing and provide the mann

Artefacts an auditor will ask for
  • Privacy notice + 5 required elements + sale disclosure + records + version control
  • Purpose limitation + per processing activity + adequate/relevant + records
  • Data minimisation + new purpose + consent procedure + records
  • Reasonable security TOMs + Admin + Technical + Physical + records
  • Multi-state DPA assessment + Iowa exempt + still recommended for VCDPA/INCDPA + records
Where this commonly fails
  • Privacy notice missing elements (e.g. no appeal procedure)
  • Purpose limitation not enforced (overbroad data collection)
  • Data minimisation absent (legacy purposes never re-assessed)
  • Reasonable security pro forma (no TOMs assessment)
  • DPA practice not maintained for Iowa-only thinking (multi-state compliance needed)

Iowa CDPA Coordination

ICDPA-Coord-USStatePrivacy-UCPA-Template-VCDPA-CPA-CTDPA-Federal-FTC-GDPR-International
Iowa CDPA Coordination - Utah CDPA Template Parent + US State Privacy Patchwork + Federal Sectoral (HIPAA/GLBA/FCRA/FERPA/COPPA) + FTC Section 5 + GDPR + India DPDP + International

Coordination positions ICDPA within the broader US and international privacy regulatory landscape. (1) Utah UCPA Template Parent: Iowa CDPA most closely follows Utah CDPA (UCPA effective 31 December 2023) template - shared narrow Sale definition + opt-out (NOT opt-in) for sensitive data + no Right to Correction + no profiling opt-out + no DPA requirement + business-friendly + AG-only enforcement + long cure period (Utah 30-day, Iowa 90-day). (2) US State Privacy Law Patchwork: 20+ comprehensive US state privacy laws as of 2026 (California CCPA/CPRA + Virginia VCDPA + Colorado CPA + Utah UCPA + Connecticut CTDPA + Iowa ICDPA + Indiana INCDPA + Tennessee TIPA + Montana MCDPA + Texas TDPSA + Oregon OCPA + Delaware DPDPA + New Jersey NJDPA + New Hampshire NHCDPA + Kentucky KCDPA + Maryland MODPA + Minnesota MNCDPA + Rhode Island RIDPCPA + Nebraska NDPA + Maine MCDPA) - Iowa is the second-mos

Artefacts an auditor will ask for
  • Utah template recognition + Iowa most business-friendly + Board awareness + records
  • Multistate compliance program + 20+ state privacy laws + Privacy Notice + GPC + records
  • Federal sectoral carve-out mapping + per data type + records + audit
  • FTC Section 5 + UDAP + settlements monitoring + alignment + records
  • International privacy compliance + GDPR + DPDP + LGPD + SCCs + records
Where this commonly fails
  • Iowa-only compliance (other states ignored + multistate gaps)
  • Federal sectoral overlaps unmanaged (HIPAA-covered entity unaware of ICDPA carve-out)
  • FTC enforcement risk unmonitored (Section 5 + UDAP + settlements)
  • International compliance fragmented (GDPR + DPDP + LGPD treated as separate)
  • Multi-state opt-in vs Iowa opt-out approach not reconciled

Iowa CDPA Enforcement + Penalties

ICDPA-Enforcement-90DayCure-AttorneyGeneralOnly-NoPrivateRight-CivilPenalties-7500-PerViolation-Longest-Cure
Iowa CDPA Enforcement - Attorney General Exclusive + 90-Day Cure Period (LONGEST among US State Privacy Laws) + No Private Right of Action + Civil Penalties Up to USD 7500 Per Violation

Per Iowa Code 715D.8 + 715D.9 ICDPA enforcement is exclusively vested in the Iowa Attorney General with no private right of action and offers the LONGEST cure period among US state privacy laws (90 days vs 30 days in Virginia/Indiana/Utah + 60 days original in Connecticut sunset). (1) Attorney General Exclusive (Iowa Code 715D.8): the Iowa Attorney General shall have exclusive authority to enforce a violation of this chapter + no private cause of action permitted (distinguishes ICDPA from California CCPA which has limited private right for breach + similar approach as Virginia + Connecticut + Utah + Indiana + Texas). (2) Right to Cure (Iowa Code 715D.8-2): before initiating any action for a violation the Attorney General SHALL provide a controller or processor 90 days written notice identifying the specific provisions of this chapter the Attorney General alleges have been or are being vi

Artefacts an auditor will ask for
  • AG investigation cooperation procedure + production capability + records + retention
  • 90-day cure procedure + express written statement + remediation + records
  • Industry self-regulation membership (NAI/DAA/IAB CCPA/IAB TCF) + records
  • Civil penalty risk assessment + per violation USD 7500 + portfolio + Board awareness
  • Voluntary compliance + AG informal guidance + best practices integration + records
Where this commonly fails
  • AG cooperation untested (would not respond timely)
  • 90-day cure capability absent (would forfeit cure opportunity)
  • Industry self-regulation not pursued (compliance posture isolated)
  • Civil penalty not Board-level (multiple-violation exposure unmanaged)
  • Voluntary compliance not used (no AG informal guidance leveraged)

Iowa CDPA Processor Contracts

ICDPA-Processor-Contracts-DPA-Subprocessor-Confidentiality-Audit-EndOfContract-Iowa-Code-715D-7
Iowa CDPA Processor Contracts - Data Processing Agreement (DPA) + Required Provisions + Subprocessor Approval + Confidentiality + End of Contract Deletion + Audit Rights + Assistance

Per Iowa Code 715D.7 ICDPA imposes contractual requirements on the relationship between controller and processor. (1) Processor Obligations: a processor shall adhere to the instructions of a controller and shall assist the controller in meeting the controller obligations under this chapter by following the directions of the controller. (2) Contract Required: a contract between a controller and a processor shall govern the processor data processing procedures with respect to processing performed on behalf of the controller. The contract shall be binding and clearly set forth: (a) instructions for processing data; (b) the nature and purpose of processing; (c) the type of data subject to processing; (d) the duration of processing; (e) the rights and obligations of both parties. (3) Confidentiality: contract shall require that the processor shall ensure that each person processing personal d

Artefacts an auditor will ask for
  • DPA in place with each processor + 5 required provisions + records + version control
  • Confidentiality + personnel binding + records + audit
  • Subprocessor list + approval procedure + objection rights + written contract cascade + records
  • Audit rights + information provision + audit reports + at-cost + records
  • End of contract + deletion or return + records + statutory retention exceptions
Where this commonly fails
  • No DPA with processors (or out of date)
  • Confidentiality not cascaded to subprocessors
  • Subprocessor approval bypassed (cloud vendors substitute without notice)
  • Audit rights not exercised (clauses paper-only)
  • End-of-contract deletion not enforced (data retained indefinitely)

Iowa CDPA Scope + SF 262

ICDPA-Scope-SF262-2023-Kim-Reynolds-IA-Code-715D-Effective-1Jan2025-Applicability-100K-25K-50pct-Utah-Template
Iowa CDPA Scope + Senate File 262 + Governor Kim Reynolds 28 March 2023 + Iowa Code Chapter 715D + Effective 1 January 2025 + Applicability Thresholds + Utah CDPA Template Parent + Exemptions

Iowa Consumer Data Protection Act (ICDPA) enacted as Senate File 262 (SF 262) of the 90th Iowa General Assembly + signed by Governor Kim Reynolds on 28 March 2023 + codified at Iowa Code Chapter 715D. Effective date: 1 January 2025. Iowa 6th US state to enact comprehensive consumer data privacy law (after California CCPA/CPRA + Virginia VCDPA + Colorado CPA + Utah UCPA + Connecticut CTDPA). Modeled closely on Utah Consumer Privacy Act (UCPA) template - among the most business-friendly US state privacy laws + narrower than VCDPA template + omits some consumer rights provisions. Applicability per Iowa Code 715D.2: applies to persons that conduct business in Iowa or produce products or services that are targeted to Iowa consumers and that during a calendar year (a) control or process personal data of at least 100000 Iowa consumers; or (b) control or process personal data of at least 25000 I

Artefacts an auditor will ask for
  • Applicability assessment + Iowa consumer count + revenue from sale + annual + records
  • Exemption mapping + GLBA/HIPAA/FCRA/FERPA + employee + B2B carve-outs + records
  • Utah template recognition + multi-state compliance program alignment + records
  • Sale narrow definition + monetary-only + records + audit + opt-out trigger awareness
  • 1 January 2025 readiness + program + governance + records + verification
Where this commonly fails
  • Applicability not assessed (operating without count tracking)
  • Exemptions claimed without validation (e.g. HIPAA covers some not all data)
  • Treating Iowa as VCDPA equivalent (broader rights assumed)
  • Sale-of-data definition broad (Iowa narrower interpretation missed)
  • 1 January 2025 effective date missed (no readiness program)

Iowa CDPA Security + Breach

ICDPA-Security-ReasonablePractices-Breach-Notification-Iowa-Code-715C-Records-Encryption-Pseudonymisation
Iowa CDPA Security + Reasonable Practices + Iowa Personal Information Security Breach Notification Law (Iowa Code 715C) + Records + Encryption + Pseudonymisation

Per Iowa Code 715D.5-1 and Iowa Personal Information Security Breach Notification Law (Iowa Code 715C separate statute) controllers and processors must implement security + breach response + records discipline. (1) Reasonable Security (Iowa Code 715D.5-1): establish + implement + and maintain reasonable administrative + technical + and physical data security practices to protect the confidentiality + integrity + and accessibility of personal data + appropriate to the volume and nature of the personal data at issue (FTC reasonable security baseline + NIST CSF + ISO 27001 alignment). (2) Iowa Breach Notification (Iowa Code 715C): separately requires controllers (database owners) holding personal information of Iowa residents (including SSN + driver license + financial account + credit card with security code + medical info + ID number + biometric) to notify (a) affected Iowa residents in t

Artefacts an auditor will ask for
  • Reasonable security TOMs + Admin/Technical/Physical + volume-appropriate + NIST/ISO alignment + records
  • Iowa Code 715C breach notification + 5-day AG + 500 threshold + CRA 1000 threshold + records
  • Records of consumer rights + DPA + contracts + breach + audit + retention + records
  • Encryption + key management + SDLC + EDR + records
  • De-identification + attestation + public commitment + re-ID prohibition + contracts + records
Where this commonly fails
  • Reasonable security pro forma (no TOMs or NIST CSF alignment)
  • Iowa Code 715C breach procedure not coordinated with ICDPA
  • Records absent for consumer rights/contracts/breach (audit failure risk)
  • Encryption partial (e.g. at rest only, not in transit)
  • De-identification claimed without attestation + public commitment

Iowa CDPA Sensitive Data + Children

ICDPA-SensitiveData-Notice-OptOut-NotConsent-Children-COPPA-Alignment-De-Identification
Iowa CDPA Sensitive Data + Notice + Opt-Out (NOT Consent unlike VCDPA) + Children Under 13 + COPPA Alignment + De-Identification Standards + Heightened Risk Awareness

Per Iowa Code 715D.5-7 ICDPA imposes heightened obligations for sensitive data + children + de-identification. Unique among US state privacy laws Iowa CDPA requires NOTICE + OPT-OUT for sensitive data processing rather than OPT-IN CONSENT (other states VCDPA/CPA/CTDPA/INCDPA all require explicit opt-in consent for sensitive data) - distinguishes Iowa as most business-friendly approach. (1) Sensitive Data Definition: per Iowa Code 715D.1-28 sensitive data includes (a) personal data revealing racial or ethnic origin + religious beliefs + mental or physical health diagnosis + sexual orientation + citizenship or immigration status; (b) genetic or biometric data processed for the purpose of uniquely identifying a specific natural person; (c) personal data collected from a known child (under 13 per COPPA alignment); (d) precise geolocation data (within radius of 1750 feet). (2) Sensitive Data

Artefacts an auditor will ask for
  • Sensitive data inventory + per category + processing activities + records
  • Sensitive data notice + opt-out mechanism + UX + records + audit (NOT consent UX)
  • Children under 13 + COPPA verifiable parental consent + records
  • De-identification attestation + public commitment + contractual + records
  • Multi-state compliance program + Iowa opt-out + other states opt-in + records + privacy by design
Where this commonly fails
  • Sensitive data inventory absent (categories not mapped)
  • Iowa treated as opt-in like other states (over-compliance with consumer friction)
  • Children under 13 processed without COPPA compliance
  • De-identification claimed without attestation + public commitment
  • Multi-state compliance fragmented (Iowa opt-out cherry-picked vs full compliance)
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Iowa Consumer Data Protection Act framework page.