Data subject rights under the ICDPA
Similar to other state acts, Iowa’s law provides consumers with:
- The right to confirm whether a controller is processing personal data and its access to personal data.
- The right to delete personal data. This right is limited to data obtained from the consumer.
- The right to request a copy of their personal data in a readily usable format.
- The right to opt out of the sale of personal data.
In contrast with other state privacy laws, ICDPA does not explicitly provide consumers the right to opt out of the use of their personal data for targeted advertising. However, it does require businesses to clearly and conspicuously disclose the use of personal data for targeted advertising and give consumers a means of opting out. This just isn’t framed as a consumer right, per se.
Another difference is that Iowa’s law does not provide the right to correct personal data or the right to opt out of profiling, both of which seem like unusual omissions. Incorrect data can cause consumers plenty of issues, but profiling is a much trickier subject. Any form of automated processing of consumer data to predict an individual’s behavior, interests, preferences, and the like is considered profiling. Most data privacy laws ban this practice since its easy for biased decision-making to take place.
Another departure from other laws’ data subject rights practices is the timeline for data subject access requests (DSARs). Under the ICDPA, businesses must respond to requests from consumers within 90 days. An additional 45 days are allowed when “reasonably necessary upon considering the complexity and number of the consumer’s requests,” as long as the consumer is notified of the extension during the initial 90-day response period.
Lastly, information must be supplied free of charge up to twice annually per consumer (except if the request is “manifestly unfounded, excessive, repetitive, or technically unfeasible;” however, the burden of proof is on the business).
ICDPA enforcement and penalties
Iowa’s data privacy law will be enforced by the state attorney general. The regulation is somewhat more lenient than other state laws in that it provides a perpetual 90-day “cure period” for those found to be in violation of the law. Other states provide shorter cure periods or only offered cure periods temporarily to permit businesses time to adjust to the law. Since the ICDPA’s cure period will be permanent, it’s fair to say that the law is somewhat more business-friendly than other state data privacy laws.
If the controller or processor cures the noticed violation within the 90-day period and provides an “express written statement that the alleged violations have been cured and that no further such violations shall occur,” no action will be initiated. If not, the business is subject to a fine of $7,500 per violation.
The fine structure is the same as in Virginia and Utah. Connecticut’s cap is $5,000 per violation, California has a range of $2,500 to $7,500, and Colorado can fine violators up to $20,000 per instance (though the CPA’s fine structure has a ceiling of $500k). Iowa’s law does not stipulate a private right of action that enables consumers to file lawsuits for violations, but consumers can report violations to the attorney general.
Staying compliant in a changing data privacy landscape
Companies that are already complying with other state data privacy regulations (and international regulations like the GDPR) are in a good position to quickly become compliant with the ICDPA. However, it’s always best practice to review the text of the law, seek guidance from legal counsel, and learn what you can from subject matter experts.
This is especially true as the ICDPA is a relatively new law, and data privacy advocates are already calling on the state to strengthen it with additional protections.
“While the law includes some basic consumer rights for Iowans, such as the right to know the information companies have collected about them, the right to delete that information, and the right to limit some data disclosures, those rights are undercut by weak definitions of what constitutes a sale and targeted advertising,” said Consumer Reports said in a press release the day after the law was passed.
Among the criticisms include the lack of provisions covering universal opt-out mechanisms, such as the Global Privacy Control (GPC). Its enforcement has been criticized as being weak, and it also allows businesses to discriminate against consumers who opt out by denying services or charging extra.
Since the ICDPA is (as of this writing) the most recent addition to the U.S.’s data privacy landscape, we can expect that there will be at least some future changes to the law, either via rulemaking or an amendment (as was the case with the CCPA and CPRA).
To become compliant with the ICDPA as well as the numerous data privacy bills currently making their way through state legislatures, check out our checklist for 2023’s state privacy laws. Although we developed this resource before the ICDPA hit the scene, the guidance within will still apply.
And if you want to investigate how to comply with the technical and tedious aspects of the ICDPA or other state privacy laws, why not try a demo of the Osano platform? We’re happy to help with everything ranging from consent management to subject rights management and beyond.
2024 U.S. Data Privacy Checklist
The U.S. now has 12 data privacy laws with many others potentially on the way. Managing the complexity of such a dispersed landscape can be challenging, however, there are common steps any organization can take to prepare.
Download Your Copy
