Iowa Consumer Data Protection Act

Iowa Consumer Data Protection Act - Mandatly Inc.

Overview

The Iowa Consumer Data Protection Act (ICDPA) marks a pivotal turning point in data privacy for the state, ushering in a new era of consumer control, transparency, and business accountability. After Connecticut, Utah, Virginia, Colorado, and California, Iowa became the sixth state in the country to pass comprehensive privacy legislation. With the ICDPA’s effective date set for January 1, 2025, businesses must now adapt to the law’s stringent requirements, ensuring responsible data governance practices. This legislation aligns with a broader national movement, echoing the objectives of data protection laws in California and Virginia, signaling a nationwide shift towards prioritizing consumer data privacy.

 

Key Objectives

The ICDPA’s primary objectives are to:

  1. Empower Consumers: Grant consumers greater control over their personal data, including the right to access, correct, and delete their data.
  2. Promote Transparency: Require businesses to provide clear and transparent information about their data collection, use, and sharing practices.
  3. Hold Businesses Accountable: Establish obligations and restrictions on businesses that collect and process consumer data.

 

Comparison with Other State Privacy Laws

The ICDPA joins a growing number of state privacy laws, including the California Consumer Privacy Act (CCPA), the Virginia Consumer Data Protection Act (VCDPA), and the Utah Consumer Privacy Act (UCPA). While these laws share similar goals, they differ in their specific requirements and scope. The ICDPA, for instance, has a higher threshold for personal data processing, requiring controllers to process data from at least 100,000 Iowa consumers or derive 50% of their revenue from personal data sales.

 

Effective Date and Enforcement

The Iowa Consumer Data Privacy Act takes effect on January 1, 2025, giving businesses ample time to prepare for compliance. The Iowa Attorney General holds the enforcement authority, with the power to issue fines of up to $7,500 per violation.

Scope and Key terms in IOWA Privacy Act

The Iowa data protection law applies to entities that:

  1. Conduct business or target consumers in Iowa.
  2. Process or control the personal data of at least 100,000 Iowa consumers.
  3. Derive more than 50% of their gross revenue from selling personal data of at least 25,000 Iowa consumers.

Key definitions used in the ICDPA

  • Controller: A business that determines the purposes and means of processing personal data.
  • Processor: A business processing personal data on behalf of a controller.
  • Consumer: Defined as a natural person residing in the state acting in an individual or household context.
  • Personal data: Any information that relates to or is identifiable to an individual, including but not limited to name, email address, physical address, purchase history, and browsing activity.
  • Sensitive Data: Personal data that reveals racial or ethnic origin, political opinions, religious beliefs, sexual orientation, or union membership.
  • Sale of personal data: The exchange of personal data for monetary consideration by the controller to a third party.
  • Consent: A clear affirmative act signifying a consumer’s freely given, specific, informed, and unambiguous agreement to process personal data relating to the consumer. “Consent” may include a written statement, including a statement written by electronic means, or any other unambiguous affirmative action.

Consumer Rights

Iowa’s data subject response provision contains a potential 45-day extension to the 90-day response period, contrasting from the standard 45-day response period other states carry.

The data subject rights under Iowa’s data privacy law are as follows:

Right to Access

A consumer has the right to know whether a controller is processing the consumer’s personal data and access that data.

Right to Deletion

A consumer has the right to ask for the deletion of their personal data that the consumer provided to the controller.

Right to Data Portability

A consumer has the right to obtain a copy of the consumer’s personal data, that the consumer previously provided to the controller, in a format that is portable, readily usable and allows the consumer to transmit the data to another controller without impediment, where the processing is carried out by automated means.

Right to Opt-Out

A consumer has the right to opt out of the processing of the consumer’s personal data for the purpose of targeted advertising, the sale of personal data or profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the consumer.

Obligations of Controllers

Purpose Limitation

Controllers can process personal data that is reasonably necessary and proportional to the purposes listed in the Iowa privacy law if it is adequate, relevant, and limited to what is necessary in relation to the specific purposes listed in the law.

Transparency

A controller shall provide consumers with reasonably accessible, clear, and meaningful privacy notice that includes:

  • The categories and purpose of personal data processed by the controller;
  • How consumers may exercise their consumer rights, including how a consumer may appeal a controller’s decision about the consumer’s request;
  • The categories of personal data that the controller shares with third parties, if any;
  • The categories of third parties, if any, with which the controller shares personal data; and
  • An active electronic mail address that the consumer may use to contact the controller.

Security

The controller must establish, implement, maintain and update reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity and accessibility relevant to the volume and nature of the personal data at issue.

Consent Requirements

Controllers should not process sensitive data concerning a consumer without obtaining the consumer’s consent, or, in the case of the processing of sensitive data concerning a known child, without processing such data in accordance with Children’s Online Privacy Protection Act.Additionally, controllers are required to “provide an effective mechanism” for consumers to revoke consent that is at least as easy as the mechanism used to provide it.

Nondiscrimination

A controller may not discriminate against a consumer for exercising a right by denying a good or service to the consumer or charging the consumer a different price.

Data processing contracts

Controllers must have a contract with their processors that clearly sets forth instructions for processing personal data, the nature and purpose for processing, the type of data subject to processing, the duration of processing, and the rights and duties of both parties. The contract must also lay out processes for retention, deletion, access, and subcontractor accountability.

Enforcement

The Iowa Attorney General will have the exclusive power to enforce the provisions of the bill. Businesses found to have violated the law will be subject to monetary penalties of up to $7500 per violation.

There is a 90-day cure period under the new bill that does not have a sunset clause.

There is no private right of action.

Impact and Challenges

The ICDPA is expected to have a significant impact on businesses and consumers, requiring businesses to adapt their data practices and consumers to become more aware of their rights. The law presents challenges for businesses in terms of compliance costs and potential changes to their data collection and use practices.

Conclusion

The Iowa Consumer Data Protection Act (ICDPA) marks a pivotal turning point in data privacy for the state, ushering in a new era of consumer control, transparency, and business accountability. With the ICDPA’s effective date set for January 1, 2025, businesses must now adapt to the law’s stringent requirements, ensuring responsible data governance practices. This legislation aligns with a broader national movement, echoing the objectives of data protection laws in California and Virginia, signaling a nationwide shift towards prioritizing consumer data privacy.

Related Blogs

Data Mapping Requirement for CPRA & CCPA Compliance20240501045009

Data Mapping Requirement for CPRA & CCPA Compliance

Data Mapping Requirement for CPRA & CCPA ComplianceWhat are the CPRA Data Mapping Requirements?The California Consumer Pr...
The Role of Employee Training in GDPR Compliance and Data Security20240205100131

The Role of Employee Training in GDPR Compliance and Data Security

The Role of Employee Training in GDPR Compliance and Data SecurityOverview: GDPR Training For EmployeesIn today's rapidly evo...
Explore the Link Between Cybersecurity and GDPR Compliance20240201044003

Explore the Link Between Cybersecurity and GDPR Compliance

The Intersection of GDPR & CybersecurityWhat is GDPR?Enforced since May 2018, GDPR is a comprehensive set of regulations ...
International Data Transfers: Understanding Legal Frameworks20240125043450

International Data Transfers: Understanding Legal Frameworks

Cross Border Data Transfer & Legal FrameworkA Legal Framework For Data ProtectionBefore delving into the legal mechanisms...
EU-U.S. Data Privacy & GDPR: A Symbiotic Bond20240110045117

EU-U.S. Data Privacy & GDPR: A Symbiotic Bond

The GDPR and the EU-US Data Privacy Framework: A Symbiotic RelationshipEU-US Data Privacy Shield FrameworkThe EU US Data Priv...
PIA Software: Streamlining Privacy Impact Assessments20231229045248

PIA Software: Streamlining Privacy Impact Assessments

Conducting Privacy Impact Assessments with PIA Software: Benefits and Best PracticesAbout Privacy Impact AnalysisIn today's d...
Getting Started with Privacy Impact Assessment (PIA) Software20231221064257

Getting Started with Privacy Impact Assessment (PIA) Software

Getting Started with PIA Software: Step-by-Step Implementation GuideIntroductionPrivacy Impact Assessment (PIA) software has ...
LGPD Compliance: Checklist & Best Practices20231109071852

LGPD Compliance: Checklist & Best Practices

Preparing for LGPD: Compliance Checklist and Best PracticesOverview Of LGPDThe LGPD, or Brazil's General Data Protection Law,...
Brazilian Data Protection Law (LGPD)20231030043222

Brazilian Data Protection Law (LGPD)

Data Subject Rights Under LGPD Access, Rectification, and ErasureIntroductionThe LGPD, or the Brazilian General Data Protecti...
Brazils’ LGPD Compliance Guide You Must Read20231025062215

Brazils’ LGPD Compliance Guide You Must Read

Everything You Need to Know About Brazil LGPD: Penalty For Non-Compliance of LGPDWhat is Brazil’s LGPD?The LGPD, or Lei Geral...
Key GDPR Compliance Privacy Software Features20230906043009

Key GDPR Compliance Privacy Software Features

5 Key Features to Look for in Privacy Management Software for GDPR ComplianceAbout The Features Of GDPR Management Compliance...
Virginia Consumer Data Protection Act – All about CDPA20230104044820

Virginia Consumer Data Protection Act – All about CDPA

Virginia Consumer Data Protection Act – All about CDPAWhat is VCPDA?The Virginia Consumer Data Protection Act CDPA is a...
Difference between CDPA, CCPA, CPRA and CPA20210722111718

Difference between CDPA, CCPA, CPRA and CPA

Difference between CDPA, CCPA, CPRA and CPAUnderstanding CDPA, CPA, CCPA & CPRAOn March 2, 2021, Governor Ralph Northam s...
Colorado Privacy Act (CPA)20210713052349

Colorado Privacy Act (CPA)

Colorado Privacy Act (CPA)Colorado is officially the third U.S state to adopt privacy legislation, after California and Virgi...
CDPA, CCPA and CPRA : Key Difference & Similarities20210705113837

CDPA, CCPA and CPRA : Key Difference & Similarities

CDPA, CCPA and CPRA : Key DifferencesAll About California’s CDPA, CPRA VS CCPAOn March 2, 2021, Governor Ralph Northam signed...
General Data Protection Regulation (GDPR)20210601103221

General Data Protection Regulation (GDPR)

General Data Protection Regulation (GDPR)What is General Data Protection Regulation (GDPR)?In December 2016, the EU Parliamen...
What is California Consumer Privacy Act?20210601090127

What is California Consumer Privacy Act?

What is California Consumer Privacy Act?The California Consumer Privacy Act (CCPA) is a state-wide data privacy law that regu...
Understanding the 7 Foundational Principles of Privacy by Design20210331035135

Understanding the 7 Foundational Principles of Privacy by Design

7 Foundational Principles of Privacy by DesignAbout Privacy By DesignIn our rapidly evolving digital landscape, where data fl...