Iowa Consumer Data Protection Act
Iowa CDPA Controller Obligations

Iowa Consumer Data Protection Act ICDPA-Controller-PrivacyNotice-PurposeLimitation-DataMinimisation-Sale-Disclosure-Transparency-LawfulBasis: Iowa CDPA Controller Obligations - Privacy Notice + Purpose Limitation + Data Minimisation + Sale Disclosure Statement + Targeted Advertising Disclosure + Privacy by Design + Lawful Processing

Per Iowa Code 715D.5 controllers operating subject to ICDPA must comply with core obligations. (1) Privacy Notice (Iowa Code 715D.5-1): controller shall provide consumers with a reasonably accessible + clear + and meaningful privacy notice that includes (a) the categories of personal data processed by the controller; (b) the purposes for processing personal data; (c) how consumers may exercise their consumer rights including how a consumer may appeal a controller decision; (d) the categories of personal data that the controller shares with third parties if any; (e) the categories of third parties if any with which the controller shares personal data. (2) Sale Disclosure (Iowa Code 715D.5-2): if a controller sells personal data to third parties or processes personal data for targeted advertising + the controller shall clearly and conspicuously disclose such processing and provide the manner in which the consumer may exercise the right to opt out. (3) Purpose Limitation: controller shall limit the collection of personal data to what is adequate + relevant + and reasonably necessary in relation to the purposes for which the data is processed. (4) Data Minimisation: controller shall not process personal data for purposes that are neither reasonably necessary to nor compatible with the disclosed purposes unless the controller obtains the consumer consent (NOT explicit consent like VCDPA/CPA - just consent). (5) Lawful Processing (Iowa Code 715D.5-3): controller shall not process personal data in violation of state or federal laws that prohibit unlawful discrimination against consumers and shall not discriminate against consumer for exercising rights. (6) Reasonable Security (Iowa Code 715D.5-1): controller shall establish + implement + and maintain reasonable administrative + technical + and physical data security practices to protect the confidentiality + integrity + and accessibility of personal data appropriate to the volume and nature of the personal data at issue (FTC reasonable security standard alignment). NOTE: Iowa CDPA does NOT require a Data Protection Assessment (DPA) like VCDPA Article 49 + CPA Section 6-1-1309 + CTDPA Section 5(a) + INCDPA - distinguishes Iowa CDPA as one of the most business-friendly state laws by omitting this requirement. Coordinates with FTC Act Section 5 + FTC Reasonable Security + state UDAP statutes + similar state privacy laws + GDPR Art 5 + DPDP Sec 8 + COPPA. ICDPA Controller Obligations applies.

What else in your programme already covers this

This control maps to 239 controls across 71 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 8 controls

  • GDPR-Art.10 Processing of personal data relating to criminal convictions
  • GDPR-Art.11 Processing which does not require identification
  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction
  • GDPR-Art.25 Data protection by design and by default
  • GDPR-Art.35 Data protection impact assessment
  • GDPR-Art.38 Position of the data protection officer
  • GDPR-Art.9 Processing of special categories of personal data

Bahrain PDPL · 7 controls

  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority
  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer
  • BB-DPA-4 Section 4 - Principles Relating to Processing

ISO/IEC 27011:2024 · 5 controls

  • AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement

APPI · 4 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • AZ-DPA-12 Article 13 - Cross-border transfer
  • AZ-DPA-14 Article 16 - Liability for violations
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection
  • DIQ-2 Data Quality Management
  • DIQ-3 Metadata Management
  • DSO-2 Data Security
  • DSO-3 Data Access Management

ISO/IEC 27400:2022 · 4 controls

API 1164 · 3 controls

  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information

BSI IT-Grundschutz · 3 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions

ISO/IEC 29100:2024 · 3 controls

ISO/IEC 29134:2023 · 3 controls

  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)

IEEE 7000 · 2 controls

ISO/IEC 27010:2015 · 2 controls

ISO/IEC 27014:2020 · 2 controls

Indonesia PDP Law · 2 controls

OWASP ASVS · 2 controls

  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security
  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data
  • ASD37-27 Outbound data loss prevention (Very Good)
  • DS-2 Ensure software supply chain security
  • CA-10 Selects and Develops Control Activities
  • 62351-8 Role-based access control (RBAC)

IEEE 1686 · 1 control

MITRE D3FEND · 1 control

  • 3.10 Encrypt Sensitive Data in Transit
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management

OWASP Top 10:2025 · 1 control

  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)

South Korea PIPA · 1 control

  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • USCOPPA-3 Data Minimisation, Retention, Erasure (Eraser Button)
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 239 it maps to, and the evidence behind each claim, over MCP and REST.