Law / United States / Iowa

Iowa

United States law applies in Iowa Iowa is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Iowa, described on this page below, applies here too.

All 12 named instruments researched to a stage, across five of the six areas of law we track: 10 in force and 2 enacted but not yet in force. As of 14 September 2026.

When they take effect9 of 12 carry a date, 3 do not. Earlier is before 2015.
Before 2015: 1 instrument (1 in force) earlier 2015: 0 instruments 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 1 instrument (1 in force) 2024: 0 instruments 2025: 5 instruments (5 in force) ’25 2026: 1 instrument (1 in force) 2027: 1 instrument (1 enacted but not yet in force) ’27 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 3
  2. Privacy law 5
  3. Scraping law 2
  4. Cybersecurity law 1
  5. Age gating law 1
  6. News aggregation law none researched

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law3 instruments, 2 in force, 1 enacted but not yet in force

Research summary (197 words)

Iowa diverges from the federal baseline chiefly through two criminal code extensions that reach AI-generated and manipulated imagery, plus a 2026 conversational-AI consumer-protection statute that is not yet in force. Iowa Code 728.12's sexual-exploitation-of-a-minor offense reaches a visual depiction created, adapted, or modified to give the appearance that an identifiable minor is engaged in a prohibited sexual act, covering AI-generated child sexual abuse material.

Iowa Code 708.7's harassment offense similarly reaches a visual depiction manipulated to falsely place an identifiable person in a state of nudity or a sex act, covering nonconsensual synthetic intimate images of any person.

Senate File 2417 (2026), enacted as Iowa Code chapter 554J, will require an operator of a conversational AI service to disclose AI status to users and to minors, restrict sexualized or human-simulating content directed at minors, and adopt a suicide and self-harm referral protocol, but its own applicability section defers every duty in the chapter to July 1, 2027.

Iowa has not enacted an election-deepfake disclosure statute: Iowa Code chapter 68A (campaign practices) contains no synthetic-media disclosure duty, and a House study bill on the subject, HSB 294, has not advanced past a committee vote taken in March 2025.

AI prohibited practices

Harassment, nonconsensual and synthetic intimate images

Iowa Code 708.7(1)(a)(5)official Iowa Code, live codified text, legis.iowa.gov

In force. Binds public and private bodies.

What this law does

Iowa's harassment offense reaches a person who disseminates, publishes, distributes, or posts a visual depiction showing another person in a state of full or partial nudity or engaged in a sex act, without that person's consent, and defines the other person to include an individual who is recognizable by face, likeness, or other distinguishing features whose image is used to create, adapt, or modify a visual depiction to depict them in that manner, reaching a nonconsensual synthetic or deepfake intimate image.

A violation is harassment in the first degree, an aggravated misdemeanor, and an offender eighteen or older must register as a sex offender. Exceptions apply to voluntary exposure in public or commercial settings, disclosures made in the public interest, and disclosures by an interactive computer service under 47 U.S.C. 230.

The provision binds any person and is not limited to an AI developer or platform; a private civil action under this section is available only for a different subparagraph, the false reporting of a crime, not for this one. The provision's own amendment history in the Iowa Code names the amending Acts by year only, without a single commencement date for this language.

Note and primary source

Sexual exploitation of a minor, AI-generated and manipulated depictions

Iowa Code 728.12(3)official Iowa Code, live codified text, legis.iowa.gov

In force. Binds public and private bodies.

What this law does

Iowa's sexual-exploitation-of-a-minor offense reaches a visual depiction that has been created, adapted, or modified to give the appearance that an identifiable minor is engaged in a prohibited sexual act, which extends the offense to AI-generated and digitally manipulated depictions and does not require proof of the actual identity of the depicted minor.

Purchasing or possessing such a depiction is a class D felony for a first offense and a class C felony for a second or subsequent offense; knowingly promoting one is a class C felony; employing, using, or causing a minor to engage in the underlying act is a class B felony, with a court-imposable fine of up to fifty thousand dollars per offense in addition to any other sentence. The provision binds any person and is not limited to an AI developer or platform.

The provision's own amendment history in the Iowa Code names the amending Acts by year only, without a single commencement date for this language.

Note and primary source

AI transparency

Conversational AI Services Act (Senate File 2417)

Iowa Code ch. 554J (2026 Iowa Acts, ch. 1068)enrolled act text, Iowa Legislature

In force in 281 days, effective 1 July 2027. Binds public and private bodies.

What this law does

An operator of a conversational AI service accessible to the public must clearly and conspicuously disclose to a minor account holder that the minor is interacting with artificial intelligence, and must disclose to any user that the service is artificial intelligence whenever a reasonable person could otherwise believe they are interacting with a human.

An operator may not give a minor user points or similar rewards at unpredictable intervals intended to increase engagement, must take reasonable measures to prevent the service from producing sexual content involving a minor account holder, urging a minor toward sexual conduct, sexually objectifying a minor, claiming to be sentient or human, or simulating a romantic or emotionally dependent relationship with a minor.

An operator must offer minor account holders, and the parents or guardians of minors under thirteen, tools to manage privacy and account settings, must adopt a protocol for responding to suicidal ideation or self-harm, and may not represent that the service provides licensed psychology or behavioral health services.

The Act was signed into law on May 2, 2026 as 2026 Iowa Acts chapter 1068, but its own applicability section defers every duty in the chapter to July 1, 2027, and it does not create a private right of action.

The chapter does not limit an operator to a private actor, and Iowa's general definitions statute includes a government or governmental subdivision or agency within the word person unless a chapter otherwise provides, so a government body operating a covered conversational AI service is bound in the same way as a private one.

What it requires

Privacy law5 instruments, 4 in force, 1 enacted but not yet in force

Research summary (294 words)

The Iowa Consumer Data Protection Act (ICDPA), Iowa Code ch. 715D, is Iowa's comprehensive consumer-privacy regime, and its codified caption reads 'CONSUMER DATA PROTECTIONS' rather than the popular bill name. Enacted as Senate File 262 (90th General Assembly), signed March 28, 2023, effective January 1, 2025 per consistent secondary reporting; the primary statute text prints no explicit effective-date sentence of its own.

ICDPA is the weakest of the seven states researched on data-subject rights: it grants no right to correct inaccurate personal data, requires only an opt-out (not opt-in consent) for sensitive-data processing, and gives a 90-day base response window, double the 45-day window used by the other six states in this batch. Iowa's definitions section is codified at Iowa Code section 715D.1, not 715D.2, which is Scope and exemptions, a different section.

Genetic or biometric data collected to identify a person is one of ICDPA's enumerated sensitive-data categories, so biometric data itself is a heightened category here. Separately, Iowa's biometric-data definition carries a blanket, unconditional exclusion for recording-derived data with no identification-purpose clawback, the same structure as Virginia's, so a voiceprint or faceprint extracted from a recording falls outside biometric, and therefore sensitive, data regardless of purpose.

A separate chapter, Iowa Code ch. 715C, governs breach notification; that chapter lets the Attorney General recover damages on an injured person's behalf but does not itself arm the person with a direct private right of action.

The ICDPA Attorney General has exclusive enforcement authority over the comprehensive act, with a mandatory 90-day cure notice carrying no sunset date in the text read, distinctively permanent relative to Connecticut's, Delaware's, and Montana's time-limited or eliminated cure rights. No active 2026 reform vehicle for ICDPA itself is identified, so this jurisdiction is recorded as settled rather than fast-moving.

Breach notification

Personal Information Security Breach Protection

Iowa Code § 715C.2official Iowa statute text, Iowa Code chapter 715C

Commencement not set. Binds public and private bodies.

What this law does

Notification of a breach of security must be made in the most expeditious manner possible and without unreasonable delay, consistent with the legitimate needs of law enforcement. A business subject to a breach requiring notification to more than 500 Iowa residents must also give written notice to the director of the consumer protection division of the Attorney General's office within five business days of notifying consumers.

A violation is an unlawful practice under section 714.16, and the Attorney General may recover damages on behalf of an injured person, but that recovery runs through the Attorney General rather than arming the person with a direct private right of action. This provision is in force under the current codified text; no dated original commencement is established, so no effective date is recorded here.

What it requires

Comprehensive regime

Iowa Consumer Data Protection Act (ICDPA), general applicability and controller/processor duties

Iowa Code ch. 715D, §§ 715D.2, 715D.4, 715D.5official Iowa statute text, Iowa Code chapter 715D

In force since 1 January 2025. Binds private bodies.

What this law does

ICDPA governs private-sector processing of Iowa consumers' personal data. Enacted as Senate File 262 (90th General Assembly, 2023 session), signed March 28, 2023 (2023 Iowa Acts ch. 17), effective January 1, 2025 per consistent secondary reporting; the effective date was not independently pulled as an explicit sentence from the primary code text, since Iowa's official code PDF does not print effective dates inline the way some peer states' history lines do. Controller duties are allocated at section 715D.4 and processor duties at section 715D.5.

What it requires

Data subject rights

Iowa Consumer Data Protection Act, consumer rights

Iowa Code § 715D.3official Iowa statute text, Iowa Code chapter 715D

In force since 1 January 2025. Binds private bodies.

What this law does

ICDPA gives an Iowa consumer the right to confirmation of processing, access, deletion, a portable copy, and opt-out of sale, targeted advertising, and profiling for solely-automated consequential decisions, but notably grants no right of correction, a real gap relative to the other six states researched in this batch.

A controller must respond without undue delay and within 90 days of receipt, double the 45-day window used elsewhere in this batch, with one 45-day extension available; an appeal of a refusal must be decided within 60 days.

What it requires

Enforcement supervision

Iowa Consumer Data Protection Act, Attorney General enforcement

Iowa Code § 715D.8official Iowa statute text, Iowa Code chapter 715D

In force since 1 January 2025. Binds private bodies.

What this law does

The Iowa Attorney General has exclusive authority to enforce ICDPA. Before suing, the Attorney General must give a controller or processor 90 days' written notice identifying the specific provisions violated; unlike Connecticut's, Delaware's, and Montana's time-limited or eliminated cure rights, this 90-day cure right carries no sunset date in the text read. Civil penalties run up to $7,500 per violation, and the chapter creates no private right of action.

What it requires

Sensitive categories

Iowa Consumer Data Protection Act, sensitive data and biometric data definitions

Iowa Code § 715D.1(4), (26)official Iowa statute text, Iowa Code chapter 715D

In force since 1 January 2025. Binds private bodies.

What this law does

ICDPA classifies data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, or citizenship or immigration status (with a discrimination-avoidance carve-out not seen in the other six states in this batch), the processing of genetic or biometric data to uniquely identify a person, a known child's data, and precise geolocation data as sensitive data, but requires only an opt-out mechanism for sensitive-data processing rather than the opt-in consent every other state in this batch requires.

Genetic or biometric data collected to identify a person is itself an enumerated sensitive-data category (§ 715D.1(26)(b)), so biometric data is a heightened category here.

Separately, 'Biometric data' (§ 715D.1(4)) carries the same blanket, unconditional exclusion for recording-derived data as Virginia's VCDPA, word for word: no clawback for data generated to identify someone, so a voiceprint or faceprint extracted from a recording is not biometric data under ICDPA regardless of purpose, and therefore is not sensitive data either. These definitions sit at § 715D.1, not at § 715D.2, which is a different section (Scope and exemptions).

What it requires

Scraping law2 instruments, 2 in force

Research summary (171 words)

Iowa diverges from federal scraping law in the computer_misuse and personal_data families. Its computer-trespass statute uses the same knowingly and without authorization wording found across several peer states, and distinctively creates its own express civil cause of action alongside criminal penalties.

The Iowa Consumer Data Protection Act (ICDPA) excludes publicly available information from its definition of personal data on the same model as several peer states, so scraped public-record or public-media personal data falls outside the Act's scope by definition.

Notably, unlike Colorado, Connecticut, and Virginia, the ICDPA grants Iowa consumers no right to opt out of automated profiling used in consequential decisions, a meaningful gap relative to those states, though that gap concerns automated decision-making rather than scraping specifically. Copyright, text-and-data-mining, and database rights add nothing beyond the federal position.

ToS enforceability and unfair competition (the Iowa Consumer Fraud Act) rest on general contract and consumer-protection law with no Iowa case applying either to scraping, so neither earns its own instrument here. robots.txt carries no independent legal weight in Iowa.

Computer misuse

Iowa Unauthorized Computer Access, with a private civil cause of action

Iowa Code § 716.6Bofficial text, Iowa Legislature (legis.iowa.gov)

In force since 1 July 2000. Binds public and private bodies.

What this law does

Section 716.6B, titled Unauthorized computer access, penalties, civil cause of action, provides that a person who knowingly and without authorization accesses a computer, computer system, or computer network commits an offense graded from simple misdemeanor to aggravated misdemeanor depending on what is accessed, with the aggravated tier applying where the data accessed is a confidential record under Iowa Code section 22.7 or utility operational or support data.

The statute's own text confirms it creates a private civil cause of action for injunctive and other relief, the same structural feature Delaware's computer crime statute carries. No published Iowa decision applies section 716.6B to scraping of a public-facing page.

What it requires

Personal data

Iowa Consumer Data Protection Act (ICDPA), publicly available information exemption

Iowa Code ch. 715D (Senate File 262, 2023)official text, Iowa Legislature (legis.iowa.gov)

In force since 1 January 2025. Binds private bodies.

What this law does

Section 715D.1(18) defines personal data to exclude de-identified or aggregate data or publicly available information, and section 715D.1(24) defines publicly available information as information lawfully made available through federal, state, or local government records, or information a business has a reasonable basis to believe is lawfully made available to the general public through widely distributed media, by the consumer, or by a person to whom the consumer disclosed it to the general public via a channel of mass media without restricting it to a specific audience.

As in several peer states, this exemption is built into the definition of personal data itself, so scraped public-record or public-media personal data falls outside the ICDPA's scope by definition. The Act applies to persons conducting business in Iowa or targeting Iowa residents who, during a calendar year, control or process the personal data of at least 100,000 consumers, with a second, lower-threshold prong for entities deriving a substantial share of revenue from data sales.

Notably, unlike Colorado, Connecticut, and Virginia, the ICDPA does not grant Iowa consumers a right to opt out of automated profiling used in consequential decisions, a meaningful gap relative to those states.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (604 words)

Iowa's private-sector security posture rests on a cybersecurity tort-liability affirmative defense, Iowa Code chapter 554G (554G.1 to 554G.4, added by 2023 Acts, ch. 63 (H.F. 553)), reaching a covered entity, a business defined to include a financial institution and an entity organized under chapter 28E but not a municipality, that accesses, receives, stores, maintains, communicates, or processes personal information or restricted information.

A covered entity that creates, maintains, and complies with a written cybersecurity program with administrative, technical, operational, and physical safeguards, funded at or above its own calculated maximum probable loss from a data breach, and that reasonably conforms to a named industry-recognized framework (the NIST Cybersecurity Framework, NIST SP 800-171, NIST SP 800-53 and 800-53A, the FedRAMP Security Assessment Framework, the CIS Critical Security Controls, or the ISO/IEC 27000 family) or an applicable regulatory regime (Health Insurance Portability and Accountability Act (HIPAA)'s Security Rule, Gramm-Leach-Bliley Title V, the federal Information Security Modernization Act, HITECH, or Iowa's own Insurance Data Security Act, chapter 507F) gains an affirmative defense to a tort claim alleging that a failure to implement reasonable information security controls caused a data breach.

The chapter imposes no duty to adopt a program, names no regulator and no penalty, and, under 554G.4, creates no private right of action of its own: it is a defendant's shield raised in litigation another statute or the common law already permits, never a plaintiff's remedy.

Separately, the Insurance Data Security Act, Iowa Code chapter 507F (2021 Acts, ch. 79), requires a licensee under Iowa's insurance laws (with carve-outs for a licensee already compliant with HIPAA or Gramm-Leach-Bliley) to develop, implement, and maintain a risk-assessment-based information security program, investigate a cybersecurity event, and notify the commissioner of insurance within three business days of confirming a reportable event; a licensee with fewer than twenty workers, under five million dollars in gross annual revenue, or under ten million dollars in year-end total assets is exempt.

Because 507F's bound party, an insurance licensee, is a role the LexLint activity vocabulary cannot yet express, it is deferred rather than flagged on a guess (#6740): no instrument for it is filed here, and it is recorded in this summary so a reader knows it exists.

No Iowa statute setting security requirements a connected device or software product must meet before or after it reaches the market, comparable to California's, Oregon's, or the Cyber Resilience Act's connected-device or product duties, is described here; none was located across the source dossier already researched for this jurisdiction (Iowa Code chapters 103A, 335, 414, 423, 455B, 476, 507F, 554G, 700 through 728) or in a further search for one, so this is a researched absence rather than a gap in coverage.

No general Iowa statute requires a private business to report an exploited vulnerability or a security incident to an authority, a CSIRT, or users, outside the insurance-sector duty above; none was located. Iowa's breach-of-security notification duty, Iowa Code 715C.2 (Personal Information Security Breach Protection), is already this jurisdiction's privacy row and is not repeated here.

The Iowa Consumer Data Protection Act's own security-of-processing clause, Iowa Code 715D.4(1), requiring a controller to adopt and implement reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal data at issue, is a section of that comprehensive privacy regime and stays with this jurisdiction's privacy row rather than being researched a second time here.

Iowa Code 716.6B, unauthorized computer access, is an offense committed by the person accessing a system rather than a duty on the system's operator or manufacturer, so it belongs to this jurisdiction's scraping row and is not a security-topic presence on its own.

Security baseline statutes

Tort Liability for Cybersecurity Programs, affirmative defense for a reasonable security program

Iowa Code ch. 554G (554G.1 to 554G.4, added by 2023 Acts, ch. 63 (H.F. 553))Official statute text, Iowa Code chapter 554G

In force since 1 July 2023. Binds private bodies.

What this law does

A covered entity is a business that accesses, receives, stores, maintains, communicates, or processes personal information or restricted information in or through a system, network, or service located in or outside Iowa. Business is defined to include a financial institution and an entity organized under Iowa Code chapter 28E, but not a municipality.

A covered entity that satisfies this chapter's requirements gains an affirmative defense to a tort claim alleging that a failure to implement reasonable information security controls caused a data breach concerning personal information or restricted information. To satisfy those requirements, a covered entity must create, maintain, and comply with a written cybersecurity program that reasonably conforms to a named industry framework or an applicable regulatory regime.

The program's scale and scope is appropriate if it is funded at or above the covered entity's own most recently calculated maximum probable loss from a data breach. The chapter imposes no independent duty to adopt a program and creates no private right of action of its own for failing to comply with it.

What it requires

Age gating law1 instrument, 1 in force

Research summary (66 words)

Iowa requires operators of websites and apps with a substantial portion of content pornographic for minors to perform reasonable age verification, effective July 1, 2026. No social media age verification, app store accountability, or design code law has been enacted; bills addressing parental consent for minor social media accounts and app store age verification were introduced in the 2026 session but did not pass either chamber.

Adult content age verification (AV)

HF 864, age verification for websites and apps pornographic for minors

Iowa Code ch. 554J (2026 Iowa Acts, HF 864)official Iowa General Assembly enrolled bill text

In force 84 days, effective 1 July 2026. Binds private bodies.

What this law does

Operators of internet sites, apps, or segments of apps containing a substantial portion (one third or more) of material pornographic for minors must perform reasonable age verification of Iowa users before granting access, and may not retain, sell, or disseminate identifying information. Signed June 1, 2026.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.