Iowa Consumer Data Protection Act ICDPA-Controller-PrivacyNotice-PurposeLimitation-DataMinimisation-Sale-Disclosure-Transparency-LawfulBasis: Iowa CDPA Controller Obligations - Privacy Notice + Purpose Limitation + Data Minimisation + Sale Disclosure Statement + Targeted Advertising Disclosure + Privacy by Design + Lawful Processing
Per Iowa Code 715D.5 controllers operating subject to ICDPA must comply with core obligations. (1) Privacy Notice (Iowa Code 715D.5-1): controller shall provide consumers with a reasonably accessible + clear + and meaningful privacy notice that includes (a) the categories of personal data processed by the controller; (b) the purposes for processing personal data; (c) how consumers may exercise their consumer rights including how a consumer may appeal a controller decision; (d) the categories of personal data that the controller shares with third parties if any; (e) the categories of third parties if any with which the controller shares personal data. (2) Sale Disclosure (Iowa Code 715D.5-2): if a controller sells personal data to third parties or processes personal data for targeted advertising + the controller shall clearly and conspicuously disclose such processing and provide the manner in which the consumer may exercise the right to opt out. (3) Purpose Limitation: controller shall limit the collection of personal data to what is adequate + relevant + and reasonably necessary in relation to the purposes for which the data is processed. (4) Data Minimisation: controller shall not process personal data for purposes that are neither reasonably necessary to nor compatible with the disclosed purposes unless the controller obtains the consumer consent (NOT explicit consent like VCDPA/CPA - just consent). (5) Lawful Processing (Iowa Code 715D.5-3): controller shall not process personal data in violation of state or federal laws that prohibit unlawful discrimination against consumers and shall not discriminate against consumer for exercising rights. (6) Reasonable Security (Iowa Code 715D.5-1): controller shall establish + implement + and maintain reasonable administrative + technical + and physical data security practices to protect the confidentiality + integrity + and accessibility of personal data appropriate to the volume and nature of the personal data at issue (FTC reasonable security standard alignment). NOTE: Iowa CDPA does NOT require a Data Protection Assessment (DPA) like VCDPA Article 49 + CPA Section 6-1-1309 + CTDPA Section 5(a) + INCDPA - distinguishes Iowa CDPA as one of the most business-friendly state laws by omitting this requirement. Coordinates with FTC Act Section 5 + FTC Reasonable Security + state UDAP statutes + similar state privacy laws + GDPR Art 5 + DPDP Sec 8 + COPPA. ICDPA Controller Obligations applies.
What else in your programme already covers this
This control maps to 239 controls across 71 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.