Government & public sector
Iowa public-sector information obligations
What Iowa law asks of a city, county, or other governmental subdivision · four statutes and one relationship
If your organization is an Iowa city, county, or other governmental subdivision holding personal information and public records, four Iowa statutes and one agency relationship set your obligations: Chapter 715C on breach notification, Chapter 22 on public records, Chapter 21 on open meetings, and the CJIS relationship with the Iowa Department of Public Safety. Iowa's own consumer privacy law exempts you, but it can still reach your vendors.
Breach notification — Chapter 715C
Notice to affected Iowa residents in the most expeditious manner possible and without unreasonable delay. When the breach reaches more than 500 Iowa residents, notice to the Attorney General within five business days of notifying consumers.
Iowa's definition of the persons covered reaches a governmental subdivision, agency, or instrumentality, so a city is squarely inside it. There is no encryption safe harbor in the ordinary sense: notice may be waived only where a documented investigation concludes there is no reasonable likelihood of financial harm, and that determination has to be made in writing and retained. In practice, plan to notify, and treat a no-notice decision as something you have to be able to defend on paper.
Public records — Chapter 22
Chapter 22 governs what the public may see, and it cuts both ways for a security program: a records request can reach your security documentation, and the statute also protects the sensitive parts of it.
| Provision | What it does |
|---|---|
| § 22.7(50) | Makes security-related information confidential, so the sensitive detail in your security documentation is shielded from disclosure |
| § 22.8(4) | Sets the outer bound on a delay for a confidentiality determination at twenty calendar days, and says it ordinarily should not exceed ten business days |
The practical point: keep your security documentation organized enough that you can respond to a request quickly and apply 22.7(50) to the right material, rather than over- or under-disclosing under time pressure.
Open meetings — Chapter 21
Chapter 21 governs official meetings open to the public: notice, minutes, and the narrow grounds for a closed session. Where a body needs to discuss security matters in closed session, the grounds and the record-keeping are set here, and they connect directly to the 22.7(50) confidentiality of the material discussed.
The CJIS relationship — Iowa Department of Public Safety
The Iowa Department of Public Safety is the CJIS Systems Agency for the state, which makes it the party a city police department reports incidents to and is audited by.
Assess the CJIS Security Policy itself — the sanction gates, the 5.9 and modernized requirements, the priorities — through the CJIS frameworks. This Iowa framework covers the state relationship around it: who you report to, who audits you, and how that fits the rest of your Iowa obligations.
Selling technology to an Iowa government
If you are a vendor rather than the government, your obligations arrive by contract, and they are often tighter than the statutes that bind the government itself.
Iowa's consumer privacy law, the Iowa Consumer Data Protection Act (Senate File 262, effective January 1, 2025), exempts government entities, so it is not part of a city's compliance picture. It can still reach the city's vendors, which is a contract question rather than a compliance percentage. On top of that, the State of Iowa's standard vendor security terms flow security obligations to the vendor directly, including breach reporting on much shorter timelines than Chapter 715C's statutory clock.
Iowa does not mandate GovRAMP (formerly StateRAMP), so a cloud-assurance status is a competitive help, not a legal gate. What a contract will hold you to is concrete: rapid breach reporting, security controls, ADA Title II accessibility for anything public-facing, and CJIS obligations for any justice system you touch. See ADA Title II and GovRAMP.
How Lavawall® helps
Lavawall maps these Iowa obligations to the technical controls and the evidence they actually require: breach-readiness and the records that prove your 715C timeline, security documentation organized so a Chapter 22 request is answerable and 22.7(50) is applied correctly, and the CJIS controls your police systems are audited on. It runs those controls across Windows, macOS, Linux, and Microsoft 365 / Google Workspace from one console and keeps the evidence current.
- Assess your Iowa obligations across 715C, Chapter 22, Chapter 21, and the CJIS relationship in one place.
- Remediate with the same platform — access control, breach detection, backups, and logging — not a separate project.
- Evidence everything with timestamped records that hold up to an Iowa DPS audit or a records request.
Related
Primary source: the Iowa Code (Chapters 715C, 22, and 21). Last verified August 27, 2026.
Frequently asked questions
What must an Iowa city do after a data breach?
Under Iowa Code Chapter 715C, notify affected Iowa residents in the most expeditious manner possible and without unreasonable delay. When the breach reaches more than 500 Iowa residents, also notify the Attorney General within five business days of notifying consumers. A governmental subdivision is squarely a covered person under Iowa's definition.
Is there an encryption safe harbor in Iowa?
Not in the ordinary sense. Notice may be waived only where a documented investigation concludes there is no reasonable likelihood of financial harm, and that determination has to be made in writing and retained. Assume you notify unless a written, retained analysis says otherwise.
Can a public-records request reach our security documentation?
It can reach it, but Chapter 22 protects the sensitive parts: section 22.7(50) makes security-related information confidential. Section 22.8(4) sets the outer bound on a delay for a confidentiality determination at twenty calendar days, and says it ordinarily should not exceed ten business days.
Does Iowa's consumer privacy law apply to a city?
No. The Iowa Consumer Data Protection Act, Senate File 262, effective January 1, 2025, exempts government entities. It can still reach your vendors, which is a contract question rather than a compliance percentage for the city itself.
Does Iowa require GovRAMP?
No. Iowa does not mandate GovRAMP (formerly StateRAMP) for its governments or their vendors. A cloud-assurance status may still help a vendor sell into Iowa, but it is not an Iowa legal requirement.
Who does a city police department report a CJIS incident to in Iowa?
The Iowa Department of Public Safety, which is the CJIS Systems Agency for the state. It is the party a city police department reports incidents to and is audited by. Assess the CJIS Security Policy itself through the CJIS frameworks; this framework covers the state relationship around it.
What does selling technology to an Iowa government involve?
Beyond the statutes that bind the government itself, the State of Iowa's standard vendor security terms flow obligations to the vendor by contract, including rapid breach reporting on tighter timelines than Chapter 715C. Accessibility under ADA Title II and any CJIS obligations for justice systems ride along in the same contract.