Law / United States /
Iowa
Iowa Consumer Data Protection Act, Attorney General enforcement
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 January 2025.
An enforcement supervision rule binding private bodies.
As of 27 August 2026.
What it requires
- Expect ICDPA violations to be enforced exclusively by the Iowa Attorney General, never by a private plaintiff.
- Cure a noticed violation and provide a written statement of cure within 90 days of Attorney General notice to avoid an enforcement action. Unlike some peer states, this cure right carries no sunset date in the statutory text.
If you get it wrong
Private right of actionNo
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Iowa Attorney General has exclusive authority to enforce ICDPA. Before suing, the Attorney General must give a controller or processor 90 days' written notice identifying the specific provisions violated; unlike Connecticut's, Delaware's, and Montana's time-limited or eliminated cure rights, this 90-day cure right carries no sunset date in the text read. Civil penalties run up to $7,500 per violation, and the chapter creates no private right of action.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
official Iowa statute text, Iowa Code chapter 715D
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.