Iowa Consumer Data Protection Act
Iowa CDPA Security + Breach

Iowa Consumer Data Protection Act ICDPA-Security-ReasonablePractices-Breach-Notification-Iowa-Code-715C-Records-Encryption-Pseudonymisation: Iowa CDPA Security + Reasonable Practices + Iowa Personal Information Security Breach Notification Law (Iowa Code 715C) + Records + Encryption + Pseudonymisation

Per Iowa Code 715D.5-1 and Iowa Personal Information Security Breach Notification Law (Iowa Code 715C separate statute) controllers and processors must implement security + breach response + records discipline. (1) Reasonable Security (Iowa Code 715D.5-1): establish + implement + and maintain reasonable administrative + technical + and physical data security practices to protect the confidentiality + integrity + and accessibility of personal data + appropriate to the volume and nature of the personal data at issue (FTC reasonable security baseline + NIST CSF + ISO 27001 alignment). (2) Iowa Breach Notification (Iowa Code 715C): separately requires controllers (database owners) holding personal information of Iowa residents (including SSN + driver license + financial account + credit card with security code + medical info + ID number + biometric) to notify (a) affected Iowa residents in the most expeditious manner possible without unreasonable delay following discovery of a breach; (b) Iowa Attorney General within 5 days of discovery if breach affects more than 500 Iowa residents; (c) any consumer reporting agencies if the breach affects more than 1000 Iowa residents. Notification content: (a) description of breach; (b) approximate date of breach; (c) type of personal information disclosed; (d) toll-free numbers for credit reporting agencies; (e) advice to remain vigilant by reviewing account statements + credit reports. Substitute notice rules apply for very large affected populations. (3) Records of Processing: while ICDPA does not explicitly require ROPA like GDPR + controllers are expected to maintain records of consumer rights requests + contracts + breach notifications + security policies + audit. (4) Encryption: while ICDPA does not mandate encryption + reasonable security practices typically include encryption at rest + in transit + key management + secure software development lifecycle. (5) Pseudonymisation: ICDPA does not explicitly address pseudonymous data + controllers should treat as personal data unless qualifying as de-identified. (6) De-Identification: per Iowa Code 715D.1-13 de-identified data exempt from ICDPA upon attestation + public commitment + contractual prohibition on re-identification. Coordinates with Iowa Breach Notification Iowa Code 715C + FTC Reasonable Security + NIST CSF + GLBA Safeguards Rule (where overlapping) + HIPAA Security Rule (where overlapping) + state attorney general guidance + similar state privacy laws + India CERT-In Directions. ICDPA Security + Breach applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 27 controls across 14 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

Bahrain PDPL · 3 controls

  • DIQ-2 Data Quality Management
  • DIQ-3 Metadata Management
  • LOPDP-EC-Cross-Border-Transfers-Articles-59-65-Adequacy-SCC-BCR-EU-Schrems-LatAm-CBPR-Andean-Community Ecuador LOPDP Cross-Border + Articles 59-65 + Adequacy + Andean Community + LatAm
  • LOPDP-EC-Governance-DPO-ROPA-DPIA-Privacy-by-Design-Training-Articles-46-58-Compliance-Monitoring Ecuador LOPDP Governance + DPO + ROPA + DPIA + Privacy by Design + Training
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-FreeZones Coordination with DIFC, ADGM and sectoral data protection regimes

IEEE 7000 · 2 controls

  • IEEE7000-Operations-Lifecycle-OngoingMonitoring-Incident-Decommissioning IEEE 7000 - Operations + Lifecycle + Ongoing AI Risk Monitoring + Data Provenance + Retention + Privacy + Safe Deployment + Decommissioning + Disposal
  • IEEE7000-Values-Elicitation-Prioritisation-IEEE7000Family-Bias-Privacy-Transparency IEEE 7000 Clauses 6 + 6.1 - Ethical Values Elicitation + Prioritisation + IEEE 7000 Family Integration (Bias + Privacy + Transparency + Wellbeing)
  • INCDPA-Processor-Contracts-DPA-Subprocessor-Audit-Confidentiality-EndOfContract Indiana CDPA Processor Contracts - Data Processing Agreement (DPA) + Required Provisions + Subprocessor Approval + Confidentiality + End of Contract Deletion + Audit Rights + Assistance
  • INCDPA-Security-ReasonablePractices-Breach-Notification-Records-Encryption-Pseudonymisation Indiana CDPA Security + Reasonable Practices + Breach Notification + Indiana Breach Notification Law (IC 24-4.9) + Records + Encryption + Pseudonymisation + De-Identification
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement
  • AL-DPA-7 Right of Access

Indonesia PDP Law · 1 control

  • DOM172-Supervisory-Authority-Cooperation-Sanctions-Penalties-Articles-77-79-Awareness-Training-Retention-DPO-Designation Dominican Republic Law 172-13 Supervisory Authority + Sanctions + Articles 77-79 + DPO + Awareness
  • EHDS-HOLD-3 Dataset Descriptions and Catalogues
  • AIGF-1.3 Data Management

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 27 it maps to, and the evidence behind each claim, over MCP and REST.