Iowa Data Privacy & Data Broker Removal

Iowa has a comprehensive privacy law that gives you the right to access, delete, and control your personal data. Here's how those rights work in practice and how to remove yourself from data brokers.

At a glance
Comprehensive privacy law? Yes. Iowa Consumer Data Protection Act (Iowa CDPA)
In effect since January 1, 2025
Your core rights Access, delete, data portability, opt out of sale
Honors Global Privacy Control? No
Data-broker registry? No
Can you sue? (private right of action) No
Enforced by Iowa Attorney General
Last verified June 2026 Reviewed quarterly

Your rights in Iowa

Iowa residents are protected by the Iowa Consumer Data Protection Act (Iowa CDPA), codified at Iowa Code chapter 715D.

Sensitive data, and what Iowa leaves out. Iowa is one of the more business-friendly state privacy laws. It does not require your up-front consent to process sensitive information like health, precise location, biometric data, race or ethnicity, and sexual orientation. Instead, a company only has to give you a clear chance to opt out. Iowa also grants no right to correct inaccurate data and no standalone right to opt out of targeted advertising.

Does this cover the company that has my data?

Most companies that collect or sell personal data in Iowa are likely covered.

The law applies to companies doing business in Iowa that, in a calendar year, control or process the personal data of at least 100,000 consumers, or at least 25,000 consumers while deriving more than half of their gross revenue from selling personal data.

The short version. The Iowa CDPA took effect January 1, 2025. It is widely seen as one of the most business-friendly state privacy laws: no right to correct, no data-protection-assessment requirement, and no requirement to honor Global Privacy Control.

How to remove yourself from data brokers in Iowa

Your state law gives you the right to request deletion, but exercising it takes real effort. We don't work from a fixed list of sites; your information is scattered across data brokers, people-search sites, and beyond. Here are the most effective steps, in order.

1. Enable Global Privacy Control

Global Privacy Control is a free browser setting that automatically tells every website you visit not to sell or share your data. It takes about two minutes to turn on. Iowa does not mandate it yet, but many major companies honor it anyway because they already comply with California's law.

2. Submit direct opt-out requests

Iowa has no data-broker registry, so you submit requests to each company directly. Look for the "Do not sell my personal information" link in the website footer; most major brokers have one. You can also send formal access or deletion requests through each company's privacy policy page.

Under Iowa's law, covered companies must respond within 90 days. If they don't, you have grounds to file a complaint with the Iowa attorney general.

3. Automate ongoing removal

Here's what most guides skip: even after you finish every step above, brokers re-ingest your information from public records, data-sharing networks, and commercial databases. Within a few months, your profiles reappear. Staying removed is an ongoing job, not a one-time task, and it is hard to keep up with by hand.

Delist finds your exposed data and files removals on your behalf, then re-runs a full scan every month so it stays down. Start with a free scan to see where your information shows up, including what AI assistants can surface about you. It takes under a minute.

Run a free scan

Iowa's data broker law: what it means for you

Iowa does not have a dedicated data-broker registry. Most national data brokers are registered in California and honor opt-out requests from residents of any state, but without an Iowa-specific law requiring it, you have little legal recourse if a broker ignores your request. Delist handles the requests across brokers in one place, so you don't have to chase each one.

Other privacy protections in Iowa

Beyond the comprehensive privacy law, Iowa has additional protections that may apply to you:

How to file a privacy complaint in Iowa

File with the Iowa attorney general, Consumer Protection Division: https://www.iowaattorneygeneral.gov/for-consumers

Most state agencies enforce privacy laws in the aggregate — they investigate patterns of violations rather than resolving individual disputes. Filing a complaint still matters: it creates a record that helps trigger enforcement actions.

Frequently asked questions

Does Iowa have a data privacy law?
Yes. Iowa residents are protected by the Iowa Consumer Data Protection Act (Iowa CDPA), which gives you rights to access, delete, and control your personal data.
Can I sue a company for violating my privacy in Iowa?
Generally no. Privacy enforcement in Iowa is handled by the Iowa attorney general, not private lawsuits. You cannot sue for most violations.
How do I opt out of data brokers in Iowa?
Enable Global Privacy Control, submit direct opt-out requests to each broker, and consider a removal service to automate the process. Iowa has no broker registry.
Does Iowa require websites to honor Global Privacy Control?
Not yet mandated statewide, but many companies honor GPC voluntarily. Enable it in your browser settings. It costs nothing and signals your opt-out preference automatically.

Sources

This page is privacy-rights information, not legal advice. Privacy law changes frequently; verify current rules with your state privacy agency or a licensed attorney before acting. Last verified June 22, 2026. We re-check state privacy laws quarterly.

Take back your privacy in Iowa

Delist finds your exposed data and files removals on your behalf, then re-runs a full scan every month so it stays down.

Run a free scan