Iowa Data Privacy & Data Broker Removal
Iowa has a comprehensive privacy law that gives you the right to access, delete, and control your personal data. Here's how those rights work in practice and how to remove yourself from data brokers.
At a glance
- Comprehensive privacy law? Yes. Iowa Consumer Data Protection Act (Iowa CDPA)
- In effect since January 1, 2025
- Your core rights Access, delete, data portability, opt out of sale
- Honors Global Privacy Control? No
- Data-broker registry? No
- Can you sue? (private right of action) No
- Enforced by Iowa Attorney General
What Delist can do for you in Iowa
Iowa has a comprehensive privacy law, the Iowa Consumer Data Protection Act (ICDPA), but it does not recognize authorized agents. We submit your requests on your behalf and say so in each one. A broker may decline and ask you to submit and verify directly; when that happens we tell you and show you exactly what to send.
Basis: Iowa Code § 715D (ICDPA). Reviewed September 1, 2026. How the three groups work: our authorized-agent framework.
Your rights in Iowa
Iowa residents are protected by the Iowa Consumer Data Protection Act (Iowa CDPA), codified at Iowa Code chapter 715D.
- Right to access and know: request a copy of the personal information a company holds about you.
- Right to delete: ask a company to delete your personal information.
- Right to data portability: get your data in a portable format you can take to another service.
- Right to opt out of sale: tell a company to stop selling your personal information.
Does this cover the company that has my data?
Most companies that collect or sell personal data in Iowa are likely covered.
The law applies to companies doing business in Iowa that, in a calendar year, control or process the personal data of at least 100,000 consumers, or at least 25,000 consumers while deriving more than half of their gross revenue from selling personal data.
How to remove yourself from data brokers in Iowa
Your state law gives you the right to request deletion, but exercising it takes real effort. We don't work from a fixed list of sites; your information is scattered across data brokers, people-search sites, and beyond. Here are the most effective steps, in order.
1. Enable Global Privacy Control
Global Privacy Control is a free browser setting that automatically tells every website you visit not to sell or share your data. It takes about two minutes to turn on. Iowa does not mandate it yet, but many major companies honor it anyway because they already comply with California's law.
2. Submit direct opt-out requests
Iowa has no data-broker registry, so you submit requests to each company directly. Look for the "Do not sell my personal information" link in the website footer; most major brokers have one. You can also send formal access or deletion requests through each company's privacy policy page.
Under Iowa's law, covered companies must respond within 90 days. If they don't, you have grounds to file a complaint with the Iowa attorney general.
3. Automate ongoing removal
A broker may later ingest a new record from public records, data-sharing networks, or commercial databases. Re-listing timing varies by broker and source, so periodic checks matter.
Delist finds your exposed data and files removals on your behalf, then re-runs a full scan every month and re-files when a listing comes back. Start with a free scan to see where your information shows up, including what AI assistants can surface about you. It takes under a minute.
Run a free scan →Iowa's data broker law: what it means for you
Iowa does not have a dedicated data-broker registry. Most national data brokers are registered in California and honor opt-out requests from residents of any state, but without an Iowa-specific law requiring it, you have little legal recourse if a broker ignores your request. Delist handles the requests across brokers in one place, so you don't have to chase each one.
Other privacy protections in Iowa
Beyond the comprehensive privacy law, Iowa has additional protections that may apply to you:
- Address Confidentiality Program (Safe at Home), run by the Iowa Secretary of State for survivors of domestic violence, sexual assault, or stalking.
- Data-breach notification (Iowa Code § 715C).
- No Daniel's Law-style statute shielding specific professions' home addresses.
- Biometric data: no standalone biometric-privacy statute with a private right of action.
How to file a privacy complaint in Iowa
File with the Iowa attorney general, Consumer Protection Division: https://www.iowaattorneygeneral.gov/for-consumers
Most state agencies enforce privacy laws in the aggregate — they investigate patterns of violations rather than resolving individual disputes. Filing a complaint still matters: it creates a record that helps trigger enforcement actions.
Frequently asked questions
Does Iowa have a data privacy law?
Yes. Iowa residents are protected by the Iowa Consumer Data Protection Act (Iowa CDPA), which gives you rights to access, delete, and control your personal data.
Can I sue a company for violating my privacy in Iowa?
Generally no. Privacy enforcement in Iowa is handled by the Iowa attorney general, not private lawsuits. You cannot sue for most violations.
How do I opt out of data brokers in Iowa?
Enable Global Privacy Control, submit direct opt-out requests to each broker, and consider a removal service to automate the process. Iowa has no broker registry.
Does Iowa require websites to honor Global Privacy Control?
Not yet mandated statewide, but many companies honor GPC voluntarily. Enable it in your browser settings. It costs nothing and signals your opt-out preference automatically.
This page is privacy-rights information, not legal advice. Privacy law changes frequently; verify current rules with your state privacy agency or a licensed attorney before acting. Last verified June 22, 2026. We re-check state privacy laws quarterly.