Iowa Consumer Data Protection Act
Iowa CDPA Consumer Rights

Iowa Consumer Data Protection Act ICDPA-ConsumerRights-Access-Delete-Portability-OptOut-Sale-Appeal-90Day-NO-Right-To-Correction-Authorised-Agent: Iowa CDPA Consumer Rights - Access + Delete + Portability + Opt-Out of Sale + 90-Day Response + Appeal + Authorised Agent + NO Right to Correction + NO Profiling Opt-Out + Free First Per Year

Iowa CDPA grants Iowa consumers 5 core rights subject to verifiable consumer request procedures per Iowa Code 715D.4. Iowa CDPA rights are NARROWER than other US state privacy laws - notably NO Right to Correction (unique among major state privacy laws as of 2026) and NO Profiling Opt-Out for legal/significant effects. (1) Right to Confirm + Access (Iowa Code 715D.4-1): consumer may confirm whether or not a controller is processing the consumer personal data and to access such personal data. (2) Right to Delete (Iowa Code 715D.4-2): consumer may delete personal data provided by the consumer (note: only data PROVIDED BY consumer, not data OBTAINED ABOUT consumer - narrower than Virginia/Colorado/Connecticut). (3) Right to Portability (Iowa Code 715D.4-3): consumer may obtain a copy of consumer personal data that the consumer previously provided to the controller in a portable and to the extent technically feasible readily usable format. (4) Right to Opt-Out of Sale of Personal Data (Iowa Code 715D.4-4): consumer may opt out of the processing of personal data for purposes of (a) targeted advertising (Iowa Code 715D.4-4(a)); (b) sale of personal data (narrow monetary definition only). NO Profiling Opt-Out (distinguishes Iowa from VCDPA/CPA/CTDPA/INCDPA which all include profiling opt-out). (5) Right to Appeal (Iowa Code 715D.4-7): if controller declines to take action on a consumer rights request the consumer may appeal within reasonable period + controller shall respond within 60 days + provide written explanation + inform consumer of right to file complaint with Iowa Attorney General. Response Timelines: controller shall respond to consumer rights requests within 90 days of receipt + may extend by additional 45 days where reasonably necessary (135 days total maximum - longer than VCDPA/CPA/CTDPA 45+45 = 90 day max). Authorised Agent: consumer may designate authorised agent to exercise opt-out rights on their behalf + universal opt-out signal recognition NOT mandatory (distinguishes from Colorado CPA + Connecticut CTDPA which both mandate Global Privacy Control GPC recognition). Free of Charge: first consumer rights exercise per consumer per 12 month period free + subsequent requests within 12 months may incur reasonable fee or controller may decline. Identity Verification: controller may require verification of consumer identity. Anti-Discrimination (Iowa Code 715D.5-3): controller shall not discriminate against consumer for exercising rights + may NOT deny goods/services + charge different prices + provide different quality. Coordinates with GDPR Arts 15-22 + CCPA + UCPA + VCDPA + CPA + CTDPA + INCDPA + FTC Act Section 5. Iowa CDPA Consumer Rights applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 109 controls across 48 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

APPI · 4 controls

  • APPI-A27 Restriction on Provision to Third Parties
  • APPI-A31 Provision of Personally Referable Information
  • APPI-A41 Preparation and Handling of Pseudonymized Personal Information
  • APPI-A43 Preparation of Anonymized Personal Information

Bahrain PDPL · 4 controls

  • FFIEC-08 Application security controls
  • FFIEC-23 Regulatory reporting requirements
  • FFIEC-24 Customer notification procedures
  • FFIEC-25 Post-incident review and improvement

Indonesia PDP Law · 4 controls

API 1164 · 3 controls

BSI IT-Grundschutz · 3 controls

  • BSI-18 Incident response planning and testing
  • BSI-20 Incident reporting and notification
  • BSI-21 Forensic analysis capabilities
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-5 APP 12-13 Access and Correction of Personal Information
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response

APRA CPS 234 · 2 controls

  • CPS234-21 Implementation of Information Security Controls
  • CPS234-25 Internal Audit Review of Information Security Controls
  • ASD37-31 Hunt to discover incidents (Very Good)
  • ASD37-33 Capture network traffic (Limited)
  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities

ISO/IEC 27400:2022 · 2 controls

ISO/IEC 30111:2019 · 2 controls

  • PAKPDPB-3 Data Subject Rights
  • PAKPDPB-5 Security of Processing and Personal Data Breach Notification
  • 502 Interoperability with Assistive Technology
  • 707 Real-Time Text Functionality
  • D.1 Incident Response Planning
  • D.2 Incident Reporting
  • CYB-5 Cyber Incident Response Plan
  • USMTSA-2 Cybersecurity Assessment and CSO Designation
  • CPS230-13 Board Accountability for Operational Risk Management
  • 4.4.7 Emergency and Incident Response
  • DS-2 Ensure software supply chain security
  • CA-12 Deploys Through Policies and Procedures
  • DIQ-1 Data Integration and Interoperability

GDPR · 1 control

IEEE 1686 · 1 control

ISO/IEC 27010:2015 · 1 control

ISO/IEC 29147:2018 · 1 control

  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures
  • PSPF24-1 Security Culture, Governance, Risk Management
  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)
  • SGCYBER-1 Critical Information Infrastructure (CII) Designation and Registration
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 109 it maps to, and the evidence behind each claim, over MCP and REST.