Iowa Consumer Data Protection Act ICDPA-SensitiveData-Notice-OptOut-NotConsent-Children-COPPA-Alignment-De-Identification: Iowa CDPA Sensitive Data + Notice + Opt-Out (NOT Consent unlike VCDPA) + Children Under 13 + COPPA Alignment + De-Identification Standards + Heightened Risk Awareness
Per Iowa Code 715D.5-7 ICDPA imposes heightened obligations for sensitive data + children + de-identification. Unique among US state privacy laws Iowa CDPA requires NOTICE + OPT-OUT for sensitive data processing rather than OPT-IN CONSENT (other states VCDPA/CPA/CTDPA/INCDPA all require explicit opt-in consent for sensitive data) - distinguishes Iowa as most business-friendly approach. (1) Sensitive Data Definition: per Iowa Code 715D.1-28 sensitive data includes (a) personal data revealing racial or ethnic origin + religious beliefs + mental or physical health diagnosis + sexual orientation + citizenship or immigration status; (b) genetic or biometric data processed for the purpose of uniquely identifying a specific natural person; (c) personal data collected from a known child (under 13 per COPPA alignment); (d) precise geolocation data (within radius of 1750 feet). (2) Sensitive Data Notice + Opt-Out (Iowa Code 715D.5-7): controller shall not process sensitive data concerning a consumer without (a) presenting the consumer with clear notice and an opportunity to opt out; or (b) in the case of the processing of personal data concerning a known child processing such data in accordance with the federal Children Online Privacy Protection Act (COPPA 15 U.S.C. 6501 et seq.). NOTE: this is OPT-OUT not OPT-IN - distinguishes Iowa CDPA from VCDPA/CPA/CTDPA/INCDPA which all require OPT-IN CONSENT for sensitive data. (3) Children Under 13: data processing of known child requires verifiable parental consent per COPPA + no specific Iowa CDPA child age threshold beyond COPPA (no teen protections unlike Maryland MODPA or California). (4) De-Identification (Iowa Code 715D.1-13): de-identified data means data that cannot reasonably be linked to an identified or identifiable natural person or a device linked to such a person - exempt from ICDPA upon attestation by controller + public commitment + and contractual prohibition on re-identification + including for technical safeguards + retention controls + use restrictions + dataset characteristics + governance + accountability. (5) Pseudonymous Data: not specifically defined or exempted in ICDPA (less explicit than VCDPA/CPA - controllers should treat as personal data unless de-identified). Coordinates with COPPA + GDPR Art 9 (Iowa NARROWER opt-out vs GDPR opt-in) + similar state privacy laws + FTC Act Section 5. ICDPA Sensitive Data + Children applies.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 124 controls across 60 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
INCDPA-SensitiveData-Children-Consent-COPPA-DataProtectionAssessment-DPIA Indiana CDPA Sensitive Data + Consent for Sensitive Categories + Children Under 13 + COPPA Coordination + Data Protection Assessment (DPA) + High-Risk Processing
PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33