Iowa Consumer Data Protection Act
Iowa CDPA Sensitive Data + Children

Iowa Consumer Data Protection Act ICDPA-SensitiveData-Notice-OptOut-NotConsent-Children-COPPA-Alignment-De-Identification: Iowa CDPA Sensitive Data + Notice + Opt-Out (NOT Consent unlike VCDPA) + Children Under 13 + COPPA Alignment + De-Identification Standards + Heightened Risk Awareness

Per Iowa Code 715D.5-7 ICDPA imposes heightened obligations for sensitive data + children + de-identification. Unique among US state privacy laws Iowa CDPA requires NOTICE + OPT-OUT for sensitive data processing rather than OPT-IN CONSENT (other states VCDPA/CPA/CTDPA/INCDPA all require explicit opt-in consent for sensitive data) - distinguishes Iowa as most business-friendly approach. (1) Sensitive Data Definition: per Iowa Code 715D.1-28 sensitive data includes (a) personal data revealing racial or ethnic origin + religious beliefs + mental or physical health diagnosis + sexual orientation + citizenship or immigration status; (b) genetic or biometric data processed for the purpose of uniquely identifying a specific natural person; (c) personal data collected from a known child (under 13 per COPPA alignment); (d) precise geolocation data (within radius of 1750 feet). (2) Sensitive Data Notice + Opt-Out (Iowa Code 715D.5-7): controller shall not process sensitive data concerning a consumer without (a) presenting the consumer with clear notice and an opportunity to opt out; or (b) in the case of the processing of personal data concerning a known child processing such data in accordance with the federal Children Online Privacy Protection Act (COPPA 15 U.S.C. 6501 et seq.). NOTE: this is OPT-OUT not OPT-IN - distinguishes Iowa CDPA from VCDPA/CPA/CTDPA/INCDPA which all require OPT-IN CONSENT for sensitive data. (3) Children Under 13: data processing of known child requires verifiable parental consent per COPPA + no specific Iowa CDPA child age threshold beyond COPPA (no teen protections unlike Maryland MODPA or California). (4) De-Identification (Iowa Code 715D.1-13): de-identified data means data that cannot reasonably be linked to an identified or identifiable natural person or a device linked to such a person - exempt from ICDPA upon attestation by controller + public commitment + and contractual prohibition on re-identification + including for technical safeguards + retention controls + use restrictions + dataset characteristics + governance + accountability. (5) Pseudonymous Data: not specifically defined or exempted in ICDPA (less explicit than VCDPA/CPA - controllers should treat as personal data unless de-identified). Coordinates with COPPA + GDPR Art 9 (Iowa NARROWER opt-out vs GDPR opt-in) + similar state privacy laws + FTC Act Section 5. ICDPA Sensitive Data + Children applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 124 controls across 60 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

BSI IT-Grundschutz · 4 controls

  • BSI-08 Cryptographic protection of data
  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy
  • AWWA-1.2 Risk Assessment
  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection
  • CJIS-17 Risk Assessment
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection

FedRAMP Rev 5 · 3 controls

  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity

ISO/IEC 23837:2023 · 3 controls

  • 23837-1.2 Normative references
  • 23837-1.5.2 Cryptographic module requirements
  • 23837-1.5.3 Network device testing requirements

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure
  • NGCB-1 Regulation 5.260 Scope, Applicability, and Licensee Categories
  • NGCB-5 Technical Security Controls - Access + Network + Encryption + Vulnerability + Logging
  • NGCB-8 Annual Independent Cybersecurity Assessment + Reporting + Board Oversight
  • CH-FADP-13 Right to object and request blocking
  • CH-FADP-21 Data protection impact assessments
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)

API 1164 · 2 controls

  • API1164-07 Remote Access
  • API1164-24 Vulnerability assessment for critical systems

Bahrain PDPL · 2 controls

  • LOPDP-EC-Governance-DPO-ROPA-DPIA-Privacy-by-Design-Training-Articles-46-58-Compliance-Monitoring Ecuador LOPDP Governance + DPO + ROPA + DPIA + Privacy by Design + Training
  • LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • Sapin2-Pillar3-Risk-Mapping Pillar 3 - Corruption Risk Mapping (Cartographie des Risques)
  • Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A)
  • IATF16949-Clause6-Planning-Risk-Contingency-Objectives-Change IATF 16949 Clause 6 - Planning + Risks and Opportunities + Contingency Plans + Quality Objectives + Change
  • IATF16949-Clause8-Operation-APQP-Design-Production-ControlPlan-SpecialChars IATF 16949 Clause 8 - Operation Planning + APQP + Design + Special Characteristics + Production + Control Plan + Set-Up Verification
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain

IEEE 1686 · 2 controls

  • IEEE1686-IR-Recovery-Reporting-Exercises-Drills-RECOV IEEE 1686 - Incident Response + Recovery from Failed Update + Reporting to Authorities + Coordination with Sector-Specific Agencies + Exercises and Drills
  • IEEE1686-Section5.1-AccessControl-Accounts-Roles-Password-Session-Remote IEEE 1686 Section 5.1 - Electronic Access Account Management + Roles + Password + Failed Login + Session + Remote Access + Personnel
  • 27557-4.3 Individual impact consideration
  • 27557-6.3 Privacy risk assessment
  • INCDPA-Security-ReasonablePractices-Breach-Notification-Records-Encryption-Pseudonymisation Indiana CDPA Security + Reasonable Practices + Breach Notification + Indiana Breach Notification Law (IC 24-4.9) + Records + Encryption + Pseudonymisation + De-Identification
  • INCDPA-SensitiveData-Children-Consent-COPPA-DataProtectionAssessment-DPIA Indiana CDPA Sensitive Data + Consent for Sensitive Categories + Children Under 13 + COPPA Coordination + Data Protection Assessment (DPA) + High-Risk Processing

Indonesia PDP Law · 2 controls

  • DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification
  • DOM172-Supervisory-Authority-Cooperation-Sanctions-Penalties-Articles-77-79-Awareness-Training-Retention-DPO-Designation Dominican Republic Law 172-13 Supervisory Authority + Sanctions + Articles 77-79 + DPO + Awareness

OWASP ASVS · 2 controls

OWASP Top 10:2025 · 2 controls

  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)
  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan
  • CRM-1 AML/CFT Compliance
  • CRM-4 Business Risk Assessment
  • AMLCTF-PartA-RiskAssess ML/TF Risk Assessment

APPI · 1 control

  • APPI-A34 Request for Correction, Addition or Deletion
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • ASD37-17 TLS encryption between email servers (Limited)
  • 4.3.1 Risk Assessment and Impact Analysis
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • FFIEC-09 Encryption and key management

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

GDPR · 1 control

  • 62351-9 Cyber security key management

IEEE 7000 · 1 control

  • IEEE7000-EthicalRisk-Identification-Analysis-Treatment-ValidationOutcomes IEEE 7000 Clauses 8 + 8.1 + 8.2 - Ethical Risk Identification + Analysis + Treatment + Validation of Ethical Outcomes + AI Safety + Robustness + Adversarial Protection
  • IMO-MSC-FAL-Identify-AssetInventory-ThreatsVulnerabilities-CyberRiskAssessment-RolesResponsibilities IMO MSC-FAL Identify Function - OT/IT Asset Inventory + Threats + Vulnerabilities + Cyber Risk Assessment + Roles and Responsibilities + Crew + CSO + DPA

ISO/IEC 27010:2015 · 1 control

  • 27010-10.1 Cryptographic Protection

ISO/IEC 27011:2024 · 1 control

  • 27011-8.3 Cryptography and key management

ISO/IEC 27031:2011 · 1 control

  • 27031-7.2 Resource Requirements

ISO/IEC 27400:2022 · 1 control

  • 27400-6.2 Device Identity and Authentication
  • 29115-7.4 Level of Assurance 4 (LoA4)

ISO/IEC 29147:2018 · 1 control

  • 29147-5.11 Researcher Safe Harbour and Legal Posture

MITRE D3FEND · 1 control

  • PQC-2 FIPS 203 ML-KEM Implementation - Module-Lattice Key-Encapsulation Mechanism
  • NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment
  • OWASPAPI-6 Security Misconfiguration and Secure API Design

South Korea PIPA · 1 control

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • CPSC-RA.3 Lifecycle Risk Assessment
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure
  • VIETNAMCYBER-4 Incident Reporting and Cooperation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 124 it maps to, and the evidence behind each claim, over MCP and REST.