This bill (HSB 665) creates a process for individuals whose personal information was misused in business filings to request removal. It allows people to submit a sworn affidavit if their name, address, or email was listed as a registered agent or business address without authorization. The Secretary of State must then remove the unauthorized information from the filing and notify the business. Additionally, the bill empowers the Secretary to issue interrogatories to investigate potential fraud, with businesses facing administrative dissolution if they fail to respond or admit violations. This directly affects business owners and individuals whose personal data was improperly included in Iowa business records.
HF 2685 establishes Iowa's first statewide standards for student instructional technology in elementary schools (K-5). It limits digital instruction to 60 minutes daily, excluding uses like IEP-required technology, teacher demonstrations, assessments, and computer science classes. School districts must adopt written policies detailing daily limits, digital tools used, and parental opt-out rights for reduced screen time, and publish these policies online. The bill also requires transparency around one-to-one device programs, including data practices and parental choice options, but excludes online learning programs.
This bill appropriates $500,000 from Iowa's water quality infrastructure fund for the 2026-2027 fiscal year to Iowa State University of Science and Technology. The funds will support the Iowa Nutrient Research Center in administering the Iowa Water Quality Information Systems, specifically using sensor technology to collect data on nutrient impacts. The primary purpose is to monitor how nutrients affect the state's surface waters, including rivers and lakes. This directly affects the data collection and monitoring capabilities of the Iowa Nutrient Research Center and the state's water quality management efforts.
HF 2048 requires companies processing personal data for 5,000+ Iowa residents annually to obtain clear consent before using data, disclose how data will be used (including for automated decisions), and limit collection to what’s necessary. It grants Iowa residents the right to access, correct, delete their data, and revoke consent at any time. Companies must implement security measures to protect data and face civil penalties of up to $7,500 per violation for breaches or noncompliance. The bill applies to commercial data processing but exempts law enforcement, de-identified data, and public information.
This Iowa bill (5534XD) creates a process for removing unauthorized personal information from business filings. It allows individuals whose name, address, or email was used without permission as a business's registered agent or office to submit a sworn affidavit, prompting the Secretary of State to remove that information from public records. The bill also grants the Secretary authority to investigate suspected fraudulent filings by sending written questions (interrogatories) to businesses, with non-response or admission of violations leading to administrative dissolution. It directly affects business entities (specifically partnerships and limited partnerships) and individuals whose personal data was misused in filings.
HF 2204 regulates chatbot developers and companies (called "deployers") that make AI chatbots publicly available. It requires deployers to implement safety protocols to detect and mitigate harm, limit user data collection to what's necessary, and verify users' ages to prevent minors from accessing certain chatbots. Specifically, it bans AI companions that simulate emotional bonds from being used by minors without age verification, prohibits impersonating people without permission (with limited exceptions), and sets strict rules for therapeutic chatbots (like mental health tools) to include disclaimers, professional recommendations, and safety testing. Violations can result in civil penalties up to $2,500 per incident or allow minors to sue for damages. The law does not apply to generic chatbots offering only basic responses without creating emotional connections.
This Iowa bill (SSB 3085) regulates how private businesses handle biometric data - such as fingerprints, facial scans, or voice recordings - of individuals. It requires private entities to create public retention policies (capping data storage at 3 years), obtain written consent before collecting data, and prohibit selling or profiting from such data. Businesses must also secure biometric data using industry-standard protections equivalent to those for passwords. The law excludes employer use of employee biometric data and imposes escalating civil penalties: $1,000 for a first violation, up to $10,000 for repeated violations.
This bill restricts Iowa's Department of Transportation (DOT) from sharing personal driver information (like name, address, or phone number) with out-of-state individuals or agencies, except in specific cases. It prohibits releasing such data to prevent out-of-state enforcement of traffic violations (e.g., fines or penalties), unless a court orders it or the driver provides written consent. Exceptions allow law enforcement, licensed investigators, or state agencies within Iowa to access the data for official duties. Violating this law is a misdemeanor punishable by up to 30 days in jail and a $105-$855 fine. The bill directly affects Iowa drivers whose data could be misused by out-of-state entities and the DOT's data-sharing practices.
HF 201 creates a new criminal offense for sharing someone's personal information without consent to harass them. It prohibits purposefully distributing details like home addresses, phone numbers, email, social media, or work locations with intent to threaten, intimidate, or alarm the person or encourage others to do so. Violations are classified as aggravated misdemeanors, punishable by fines up to $8,540 or up to two years in jail. This law directly affects individuals who share others' private details online or offline to cause harm, providing a specific legal remedy for this form of harassment.
SF 35 expands the definition of harassment to include the unauthorized sharing of personal information. This bill directly affects individuals whose private contact or identity details are shared without their consent, as well as those who engage in such actions. It specifies that a person commits harassment if they purposefully disseminate, publish, distribute, or post another person's personal information without consent, intending to threaten, intimidate, annoy, or alarm them or encourage others to do so. "Personal information" is broadly defined to include contact details like home address, phone numbers, email, social media profiles, place of employment, and photographic depictions. Violations of this provision are classified as harassment in the first degree, an aggravated misdemeanor.