Per Iowa Code 715D.5-7 ICDPA imposes heightened obligations for sensitive data + children + de-identification. Unique among US state privacy laws Iowa CDPA requires NOTICE + OPT-OUT for sensitive data processing rather than OPT-IN CONSENT (other states VCDPA/CPA/CTDPA/INCDPA all require explicit opt-in consent for sensitive data) - distinguishes Iowa as most business-friendly approach. (1) Sensitive Data Definition: per Iowa Code 715D.1-28 sensitive data includes (a) personal data revealing racial or ethnic origin + religious beliefs + mental or physical health diagnosis + sexual orientation + citizenship or immigration status; (b) genetic or biometric data processed for the purpose of uniquely identifying a specific natural person; (c) personal data collected from a known child (under 13 per COPPA alignment); (d) precise geolocation data (within radius of 1750 feet). (2) Sensitive Data Notice + Opt-Out (Iowa Code 715D.5-7): controller shall not process sensitive data concerning a consumer without (a) presenting the consumer with clear notice and an opportunity to opt out; or (b) in the case of the processing of personal data concerning a known child processing such data in accordance with the federal Children Online Privacy Protection Act (COPPA 15 U.S.C. 6501 et seq.). NOTE: this is OPT-OUT not OPT-IN - distinguishes Iowa CDPA from VCDPA/CPA/CTDPA/INCDPA which all require OPT-IN CONSENT for sensitive data. (3) Children Under 13: data processing of known child requires verifiable parental consent per COPPA + no specific Iowa CDPA child age threshold beyond COPPA (no teen protections unlike Maryland MODPA or California). (4) De-Identification (Iowa Code 715D.1-13): de-identified data means data that cannot reasonably be linked to an identified or identifiable natural person or a device linked to such a person - exempt from ICDPA upon attestation by controller + public commitment + and contractual prohibition on re-identification + including for technical safeguards + retention controls + use restrictions + dataset characteristics + governance + accountability. (5) Pseudonymous Data: not specifically defined or exempted in ICDPA (less explicit than VCDPA/CPA - controllers should treat as personal data unless de-identified). Coordinates with COPPA + GDPR Art 9 (Iowa NARROWER opt-out vs GDPR opt-in) + similar state privacy laws + FTC Act Section 5. ICDPA Sensitive Data + Children applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.