Iowa Consumer Data Protection Act
Iowa CDPA Coordination

Iowa Consumer Data Protection Act ICDPA-Coord-USStatePrivacy-UCPA-Template-VCDPA-CPA-CTDPA-Federal-FTC-GDPR-International: Iowa CDPA Coordination - Utah CDPA Template Parent + US State Privacy Patchwork + Federal Sectoral (HIPAA/GLBA/FCRA/FERPA/COPPA) + FTC Section 5 + GDPR + India DPDP + International

Coordination positions ICDPA within the broader US and international privacy regulatory landscape. (1) Utah UCPA Template Parent: Iowa CDPA most closely follows Utah CDPA (UCPA effective 31 December 2023) template - shared narrow Sale definition + opt-out (NOT opt-in) for sensitive data + no Right to Correction + no profiling opt-out + no DPA requirement + business-friendly + AG-only enforcement + long cure period (Utah 30-day, Iowa 90-day). (2) US State Privacy Law Patchwork: 20+ comprehensive US state privacy laws as of 2026 (California CCPA/CPRA + Virginia VCDPA + Colorado CPA + Utah UCPA + Connecticut CTDPA + Iowa ICDPA + Indiana INCDPA + Tennessee TIPA + Montana MCDPA + Texas TDPSA + Oregon OCPA + Delaware DPDPA + New Jersey NJDPA + New Hampshire NHCDPA + Kentucky KCDPA + Maryland MODPA + Minnesota MNCDPA + Rhode Island RIDPCPA + Nebraska NDPA + Maine MCDPA) - Iowa is the second-most business-friendly after Utah + Multi-state compliance program needed addressing all + Privacy Notice template + Consumer Rights portal + Multi-state response timeline (90 days Iowa-compatible) + Opt-out mechanisms + GPC voluntary recognition for Iowa + Multi-state enforcement coordination. (3) Federal Sectoral Carve-Outs: HIPAA (health) + GLBA (financial) + FCRA (consumer reporting) + FERPA (education) + COPPA (children) + DPPA (drivers) + Federal Common Rule (clinical trials) + entities/data subject to those laws exempt from ICDPA. (4) FTC Federal Backstop: Federal Trade Commission Act Section 5 + UDAP enforcement applies to deceptive privacy notices + unreasonable security + algorithm bias + dark patterns. (5) Multi-Cloud + Multi-Regulator: cloud service providers (AWS + Azure + GCP + Oracle Cloud) regional + ICDPA + multi-state + multi-federal coordination. (6) International: GDPR (EU) + UK GDPR + India DPDP Act + Brazil LGPD + Japan APPI + South Korea PIPA + Singapore PDPA + Australia Privacy Act + Canada PIPEDA. (7) Standards + Frameworks: NIST Privacy Framework + ISO 27701 PIMS + ISO 27001 + NIST CSF + ISO 31700 Privacy by Design. (8) Industry Self-Regulation: NAI Network Advertising Initiative + DAA Digital Advertising Alliance + IAB Interactive Advertising Bureau + GPC Global Privacy Control + IAB CCPA Compliance Framework + IAB TCF. (9) State AG Coordination: National Association of Attorneys General (NAAG) Privacy Working Group + Multistate AG investigations + privacy AG enforcement actions. Coordinates with all aforementioned US state + federal + international + standards bodies + industry frameworks + AG networks. ICDPA Coordination applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.