Iowa's Privacy Law Just Turned One Year Old — Here's What Shopify Sellers Actually Need to Know
Iowa's consumer privacy law has been quietly active for over a year now, and it's easy to miss if you're mostly tracking California or Virginia. That's a mistake worth correcting, because Iowa's law works differently in ways that actually matter if you sell to Iowa customers.
Here's what's actually in it, and where it diverges from the states you've probably already heard more about.
Who It Applies To
The Iowa Consumer Data Protection Act, codified under Iowa Code Chapter 715D, took effect January 1, 2025. Unlike some state privacy laws, it has no revenue threshold at all. Applicability depends entirely on how many Iowa residents' data you process in a year: either 100,000 or more Iowa consumers, or 25,000 or more consumers combined with deriving over 50% of your revenue from selling personal data.
For most independent Shopify sellers, the 100,000-consumer path is the one that matters. Revenue size alone, no matter how high, doesn't trigger this law on its own.
A Narrower Set of Rights Than You Might Expect
This is the detail most likely to surprise anyone who's already familiar with California's CCPA or Virginia's VCDPA. Iowa grants consumers exactly four rights: access, deletion, data portability, and the ability to opt out of the sale of their personal information.
Notice what's missing. Iowa does not include a right to correction, unlike almost every other comprehensive state privacy law. If a customer asks you to fix inaccurate information Iowa's law holds about them, there's no statutory right compelling you to do so, though it's still good practice regardless.
Sensitive Data Gets Lighter Treatment Too
Most comprehensive privacy laws, including California's and Virginia's, require opt-in consent before processing sensitive data like health information, precise location, or biometric data. Iowa takes a different approach: sensitive data processing requires clear notice and an opportunity to opt out, but not advance consent.
That's a real practical difference. A business collecting sensitive data from Iowa customers needs to disclose that it's happening and let people say no, but doesn't need a yes in advance the way it would under CCPA.
Enforcement and the Cure Period
The Iowa Attorney General holds exclusive enforcement authority. There's no private right of action, meaning individual consumers can't sue directly. Civil penalties can reach up to $7,500 per violation.
Iowa also gives businesses a 90-day cure period before enforcement action, longer than the 30-day windows common in states like Virginia and Indiana. That's meaningful breathing room if a compliance gap gets flagged.
Why This Gets Called "Business-Friendly"
Legal commentators consistently describe Iowa's law as one of the more business-friendly comprehensive privacy statutes in the country, and the details above explain why: fewer consumer rights to fulfill, a lighter sensitive-data standard, and a longer cure period all add up to a lower compliance burden than California's or Colorado's frameworks.
That doesn't mean it's optional to ignore. It means the compliance bar, once you cross the threshold, is genuinely lower to clear.
Check Your Iowa Exposure
All information in this article is sourced from Iowa Code Chapter 715D, the Iowa Attorney General's published guidance, and independent legal analysis from Akin Gump and Privacy Rights Clearinghouse. Regulens is informational only and this article is not legal advice. Speak to a licensed privacy attorney about your specific compliance situation.
Regulens tracks Iowa as part of its ongoing state-by-state privacy coverage. Your store's readiness is calculated based on your actual inputs and current policy documents.
Free to check, takes three minutes, no credit card needed. Not legal advice. Informational only.
Further Reading
Kentucky's New Privacy Law Already Has Its First Lawsuit — Here's What Sellers Should Know
Kentucky's consumer privacy law took effect January 1, 2026. Eight days later, the state's Attorney General filed its first enforcement action, and skipped the standard cure period to do it. Here's what the KCDPA actually requires.
Indiana's Privacy Law Looks Like Virginia's — But Don't Assume It's Identical
Indiana's consumer privacy law took effect January 1, 2026, modeled closely on Virginia's framework. But the details that differ, especially around sensitive data and cure periods, are worth knowing if you sell into the state.