Senior Content Marketing Manager II
April 28, 2023â˘9 min read
Preparing for Iowa Privacy Act compliance
Passed on March 29, 2023, the Iowa Privacy Act (IPA) is the sixth state privacy law in the US. Though the IPA doesnât go into force until January 1, 2025, Iowa businesses under the billâs scope should start working towards compliance now.
Iowaâs new privacy law closely models the five other states (California, Virginia, Colorado, Utah, and Connecticut) that have passed privacy laws in recent years. Though the IPA's overall framework is largely the sameâconsumer rights, new obligations for businesses, etcâkey differences make it one of the most business-friendly privacy laws to date.
Because the IPA doesnât require that businesses conduct data protection assessments or give consumers a way to opt-out of targeted advertising, some experts argue the law doesnât adequately protect consumersâ data.
This rest of this guide outlines who falls under the IPAâs scope, consumer rights granted by the law, differences between the IPA and other states laws, and steps businesses should take to prepare for compliance.
Like most privacy laws in the US, doing business in Iowa or marketing goods or services to Iowa residents is the baseline threshold for who falls under the lawâs scope. In addition, a business must also:
Similar to Colorado, Connecticut, and Virginia, Iowaâs privacy law doesnât establish a revenue threshold. Businesses that meet the criteria above, regardless of their revenue, are beholden to IPA requirements.Â
This stands in contrast to the California Privacy Rights Act (CPRA) and Utah Consumer Privacy Act (UCPA), both of which sport a $25 million annual revenue threshold.Â
Ensuring effective compliance is crucial in today's regulatory environment, but state privacy laws are not uniform and what works in one state may not apply in others. As data privacy regulations become more stringent, itâs important that businesses get it right from the start.
As noted earlier, the IPA doesnât apply a revenue threshold. By contrast, the CPRA and UCPA both have a $25 million threshold, though each applies it differently.
Additionally, all US state privacy laws have criteria around revenue gained from selling personal data. Iowaâs privacy law falls in line with the majority here, mirroring the revenue percentages outlined in Utah, Virginia, and California.Â
In all four of these states, any business that receives 50% of its revenue from the sale of personal data and controls personal data for over 25,000 consumers falls under the lawâs purview.Â
Under the Iowa Privacy Act, businesses have 90 days to cure compliance issues. For reference, a cure period refers to a set length of time in which businesses can correct compliance issues following notice from the stateâs attorney general.Â
Compared to other state laws, a 90 day cure period is the longest by far. Connecticut and Colorado offer 60 days, while Virginia and Utah only offer 30.Â
Under the California Consumer Privacy Act (CCPA), businesses had a guaranteed 30 day cure period, but when the CPRA came into forceâthat cure period became discretionary. The California Privacy Protection Agency (CPPA) can choose to apply it, or not.
Similar to California, the cure periods allowed under Colorado and Connecticutâs privacy laws will eventually also become discretionary. Though for both states, this wonât occur until January 1, 2025, so businesses do have a bit of breathing room.Â
Similar to Utah, Colorado, and Virginia, Iowa residents may file an appeal if a business refuses to fulfill the consumer rights outlined by the IPA.
Barring Utah, and now Iowa, most state privacy laws do require businesses to conduct data protection assessments (DPA) for risky data processing activities. Examples of risky data processing includes selling, or in California sharing, personal data, certain profiling activities, processing sensitive personal information (SPI), or using personal data for targeted advertising.Â
This omission is one reason why the IPA has been dubbed a more business friendly privacy law.Â
In laws that do require DPAs, the language usually states that the intent is not necessarily to throttle certain types of data processing. Rather, itâs to encourage businesses to actively consider why theyâre engaging in risky data processing, as well as weigh risks to the consumer against any potential benefits.
Consumers in Iowa may ask to see the personal data a business has collected about them.
Iowa residents may ask a business to delete any personal data the business has collected about them.
Consumers in Iowa may ask for a copy of their data and the business must send the data in an easily transmittable format.
Similar to the Virginia Consumer Data Protection Act (VCDPA), consumers may only request a copy of the data they themselves provided.
In Iowa, only the state's attorney general is authorized to take legal action against businesses that violate the IPA.Â
Iowaâs privacy law is similar to those in Virginia, Colorado, Utah, and Connecticut in that it doesnât offer a private right of action, which would allow consumers to pursue civil litigation on their own behalf.Â
Like all state privacy laws, the IPA does exempt certain organizations and data types. Exempted data includes personal information thatâs covered by the:
Organization exempt from Iowaâs privacy law include:Â
As with any new privacy law, the first step for compliance is understanding whether the law applies to your organization. As a reminder, the IPA applies to organizations that:Â
If an organization meets these thresholds, the Iowa Privacy Act likely applies. That said, as listed above, there are several exceptions, so be sure to review those.Â
Once youâre sure the IPA applies to your business, you should start working towards compliance. Though the bill doesnât go into effect until January 1, 2025, building a privacy program from scratch takes timeâso itâs best to get started while you still have a little breathing room.
While the Iowa Privacy Act doesnât explicitly require a data map, creating one is crucial to achieving complianceâoffering your organization a clear look into the personal data youâre collecting, where itâs located, and with whom itâs being shared.
To assess your organizationâs compliance, whether youâre just starting out or have a mature privacy program, youâll need to conduct a thorough gap analysis. Through this process, you can compare your current data processing practices to the IPAâs requirements.
But to conduct this analysis, youâll need to understand your companyâs data processing activities. Your data map should, at a high level, include:
If youâre using manual methods to build your data map, make sure you have enough bandwidth to conduct assessments with each data silo owner and make continual updates to your central data map document. Â
An automated tool like Transcend Data Mapping will speed this process up significantly.Â
The Iowa Privacy Act requires that organizations give consumers the chance to opt out of the sale of personal data and the processing of sensitive data. Notably, the law doesnât provide the right to opt out of processing for the purposes of targeted advertising.
In addition, businesses must get consent to process data for minors under 13. Â
With this melange of various opt out requirements, youâll need to implement a process for managing consent across your web properties.Â
The IPA gives consumers the right to request access and deletion of their personal data. This means your business needs to implement a workflow for fulfilling consumer privacy requests at scale.Â
Though itâs possible to manually fulfill consumer requests, the process can be complex. Someone will need to identify any data silo thatâs storing personal data, find all the personal data on that specific individual, and then send everything back to the consumer in an easily understandable format.Â
When youâre only fielding a handful of requests, the manual process is feasible. But as requests increase, it becomes difficult and largely unsustainable. This is where an automated privacy request solution comes into play.
The IPA requires that businesses give consumers a way to appeal in the event their privacy request is rejected. This means you need to establish a workflow that enables your team to field, track, and fulfill appeals as they come in.
This workflow doesn't need to be elaborate, a simple web form should suffice in many cases. However, when creating this mechanism, you should try to consider how it will function at a scale.
Though businesses have some time to prepare for Iowa's privacy law, savvy companies will start working towards compliance now. Building out key components like a data map, mechanisms for privacy request fulfillment, and an appeals process don't happen overnightâbetter to start now and be prepared well ahead of enforcement.
Transcend is the platform that helps companies put privacy on autopilot by making it easy to encode privacy across an entire tech stack.
Transcend Data Mapping is the only solution that goes beyond observability to power your privacy program with smart governance suggestions. Get unified data management through automated scanning, data silo discovery and advanced data classification, all in a collaborative platform.
Ensure nothing is tracked without user consent using Transcend Consent, automate data subject request workflows with Privacy Requests, and mitigate risk with smarter privacy Assessments.
Senior Content Marketing Manager II