Iowa’s consumer data privacy law went into effect on January 1, 2025, but Ai’s advances in 2027 will open a new can of worms for Iowa business owners. Dentons Davis Brown data privacy and cyber law pro Scott Murphy says if your business collects any data, even an email address or social media plugin, you are almost certainly in a legally vulnerable position.
Murphy shares the grim details for Iowa business owners and explains that even if your website has a social media tool or plugin that is collecting data you’re not even aware of, that still makes you legally liable. Murphy also shares some basic steps you can do today to take yourself out of the crosshairs of blood thirsty lawyers looking for their next payday.

Small business owners utilizing website analytics, chatbots, or social media tracking pixels face escalating legal exposure under evolving state privacy legislation. Murphy outlined the legal liabilities businesses face under state privacy statutes and aggressive out-of-state litigation.
The Scope of Iowa Privacy Law and Exposure
Iowa’s Data Privacy Act establishes strict guidelines around consumer data collection, usage, and third-party marketing. While the law contains population thresholds—governing entities collecting data on roughly 25,000 Iowa residents—it broadly defines personal data, where simply pairing an email address with a name triggers statutory protections. “And what it’s really designed to do is to create some buffers around how companies collect information, how they use our information, and whether they can sell or market it to third parties,” Murphy explained. Although exemptions exist for nonprofits, healthcare, and financial institutions, non-compliant commercial entities face enforcement from Iowa Attorney General Matt Bird.
Hear from Iowans directly. No algorithms.
Don’t let the algorithms choose your news. Enter your email address to hear directly from Iowans leading news in politics, community, agriculture and business. No editing. No clickbait. No rage. No agenda.
Out-of-State Demands and Controller Responsibilities
Legal risks extend far beyond state lines due to California’s 1967 wiretap statute, which requires dual consent for website data tracking. Law firms target midwestern companies whose websites log visits from California residents without explicit tracking disclosures, issuing demand letters seeking $10,000 to $15,000 settlements. “For the most part, your average Iowa business, California may have a fearsome reputation, especially when they get a letter from a lawyer out there, and it’s really shakedown, for lack of a better term,” Murphy noted.
Furthermore, reliance on third-party marketing tools or website plugins does not insulate owners, as businesses act as data controllers rather than mere processors. “You are in the seat of the boss,” Murphy warned, emphasizing that while companies can replace data processors, “you’re still responsible, and you could be on the hook for whatever they’ve done.” To mitigate exposure, businesses should inventory active plugins, post clear privacy notices, and deploy explicit cookie management banners.
(515) 288-2500
Interview Transcript
This transcript was created with help from Ai. Please report errors to us and always refer to the video as your primary source.
Justin Brady: [00:00:00] From Iowapodcast.com, I’m Justin Brady, and if you have chatbots, business owners, if you have chatbots on your site, or maybe you have social media tracking pixels, ’cause, you know, social media strategies, or maybe you have analytics, Google Analytics or WordPress analytics or anything like that running on your site.
Perhaps you’re running digital ads somewhere. There are new laws, and you could actually be at legal risk if you’re doing any of that, what are you supposed to do about it? This is the whole topic with Scott Murphy, a data privacy and cyber law guy over at Dentons Davis Brown, and of course, we appreciate your, uh, collaboration over there. We love working with you guys.
So welcome to the studio.
Scott Murphy: Thanks, Justin. I appreciate the invitation
Justin Brady: will be super fun. Um, it’s a hairy issue, and I, I’ll be honest, I was reading some of the materials and research on this, and I’m like, “Eh, you know, this is probably a, a big deal for some Fortune 100s and 500s. This is not gonna be a big deal for a, a Iowa business owner.” [00:01:00] I am very, very wrong.
I am extremely wrong. So can you break this down for us? The consumer privacy law, uh, AI, there’s a new law that started in January of 2025, but now AI is actually not changing, but almost we have to reinterpret what that law looks like now because of AI. Can you break that down for us?
Scott Murphy: the Iowa law went into effect, I won’t get into the details as far as the actual code or anything like that, but it is Iowa’s version of a d- uh, the Data Privacy Act for personal information, your information, my information. And what it’s really designed to do is to create some buffers around how companies collect information, how they use our information, and whether they can sell or market it to third parties, and what our rights are with respect to restricting their use or ability to, um, work with our information.
And it’s modeled after the California law, which went into effect in 2018, but it’s a much lighter, more business-friendly version than the California [00:02:00] Privacy Acts, as well as different acts that have sprung in states like Texas, Washington, uh, Colorado, Virginia. So it’s much more business-friendly, but it also does offer some robust protections to Iowa consumers.
And to your earlier point with respect to risk, it also creates some obligations for businesses that don’t comply with the act, and they might fall under the, uh, the gaze of the attorney general, Matt Bird. So
Justin Brady: Yeah. And so this is basically anybody collecting data could be at risk here, right? Any business at all almost
Scott Murphy: Ar-arguably, there are some population thresholds in all these respective state acts, but there are some states out there, for example, Texas, where if you are not– if you collect data on even one Texas resident, you’re governed by that act.
Justin Brady: Oof. Seriously?
Scott Murphy: And the Iowa thresholds, I believe, are 25,000 Iowa residents.
I may be wrong on that. I haven’t really looked at the, looked at it recently, but it is– there’s, there’s a threshold. [00:03:00] So your average mom-and-pop operation that’s a small business may or may not be covered, but if they do collect that data and they’re f- under the, uh, coverage of the act, then they would have certain obligations with respect to the protection and usage of your, your personal information, your personal data
Justin Brady: So who does this actually… Uh, this is what business owners are wondering because they’re like, “What’s the data?” Like, you know, how do you d- how do we define data? Could it be something as simple as I just collected an email address for a newsletter?
Scott Murphy: Arguably, yes.
Justin Brady: So it’s that simple. It could be that simple.
Scott Murphy: you know, the b- the ba- the baseline is really something where if it collects two pieces of information that it can identify an individual, for example, your name, not necessarily, uh, personal data. It’s personal to you, but it’s also in public records and things of that nature, media.
But if you also f- to your email example, if you connect the email to Justin, that could be considered personal data under the act and subject to a s- level of protection with respect to they can’t [00:04:00] sell it. If there’s a breach, they may have notification requirements, things of that nature. And but, you know, when it is a very low threshold, more sensitive information, for example, your health information, your Social Security number, uh, your bank account information, that’s governed by a higher threshold of protection.
And, you know, that’s really what the act is designed to do is make sure that if you collect that information as a business owner or any o- any or, you know, s- generally it pr- impacts businesses. But if you collect that information, you have an obligation to protect that information and also to abide by s- requests with respect to how that information is handled on behalf by the c- customer, consumer, I should say.
Justin Brady: Now I’m gonna ask later ’cause people are probably wondering, like,
Scott Murphy: Mm-hmm.
Justin Brady: well, I have a… I’ll, I’ll use an example, not throwing anybody un- under the bus, but like MailChimp, Beehiiv, Jetpack for WordPress, um, I, I… They collect the data. I don’t actually collect it, but we’re– Well, then we’ll talk about this later because it still might actually be you in the letter of the law collecting [00:05:00] the data.
But before we get to that, um, who does this apply to? Is it like a small Etsy shop owner that’s making $10,000 a year, they could be liable? Is it over $100,000 a year? Is it a corporation? Is it an LLC? Who’s actually potentially on the hook for this?
Scott Murphy: Conceivably all of the above. There are- Good. There are, there there are- This is getting personal. It is. I mean, and, and, you know, while, you know, the Iowa law does have its own requirements, it does exempt, for example, nonprofits, educational institutions, uh, healthcare organizations, financial institutions such as banks that are covered by other privacy requirements.
So it is, while it is broadened scope, it is not exactly scorched earth where any entity doing business in Iowa or collecting information on Iowa consumers is covered by the act, but it is very broad-based. And it, you know, I haven’t heard of the, the attorney general doing any enforcement actions, but it is something to keep in mind that if you are collecting data of customers, [00:06:00] consumers who might be inquiring about certain information or your services, your goods, whatever, and you collect their data, then you would have those legal obligations to maintain and protect that data
Justin Brady: And so what’s interesting is, ’cause I’m trying to drill down here because the more I drill down, the more wide this thing gets. Because you know what people are thinking, which is they’re looking for an excuse to not have to deal with it, right?
Scott Murphy: Right
Justin Brady: And so does this, uh, I think it, it… Help me understand this, but it also includes if you even put like a Facebook or Google or social media tracking pixel on your website just for ad purposes, that also qualifies as collecting personal data, right?
Scott Murphy: It can, definitely. And what– the thing about the third-party trackers or third-party cookies is, is that that data may not necessarily be transmitted back to your business. It may provide some analytics, but the com- the usage [00:07:00] on your website, for example, tracks your movements. It may track you across different websites.
That could be subject to I-Iowa’s data privacy law. It’s more re- um, the risk is greater, for example, in California, because California has a 1967 law that is basically a wiretap law, which is dual consent, and there’s litigation claims going on out there, including some that have hit Iowa businesses, where they allege that by virtue of the fact you did not disclose those third-party trackers or you did not disclose who’s gonna handle your information, you violated California’s wiretap statute.
And there’s a lot of litigation, and, uh, to be honest, I have handled a few claims recently in the state of Iowa against Iowa businesses. They have no physical presence in California, but their site was accessed in California, and somebody did some analytics and said, “Oh, by the way, those trackers violate this,” and they would send a demand letter
Justin Brady: That’s crazy. Like, just ’cause people are thinking, ’cause the California [00:08:00] law is basically any cookies, any chatbots, any tracking pixels, and this is CEPA, California Invasion of Privacy Act is what you’re talking about. Um, it’s, um, people are like, “Wow, Justin knows a lot.” No, he sent this ahead of time. Um,
Scott Murphy: I’m here to help. Yeah. But basically
Justin Brady: But basically what’s happening is law firms are kind of using Calif- I don’t wanna use the, there’s, I’m sure there’s a legal term for this, but Iowa businesses are not safe from this California law, which some may consider to be very wide, because people can just say, “Look, bro, if your website even got hit by one person in California, now a lawyer can use California as a way to get to an Iowa
Scott Murphy: Arguably, and that true in many cases they don’t necessarily sue, but they will send a demand. If you pay us X, which is anywhere between maybe f- 10 to $15,000, we won’t sue you for violating California law. Now, from a legal perspective, there may be issues with respect to jurisdiction, which I won’t get into, but for the most part, your average Iowa business, California is a big, you know, has, may [00:09:00] have a fearsome reputation, especially when they get a letter from a lawyer out there, and it’s really shakedown, for lack of a better term.
I mean, it is really just drive-by lawyering, but at the same time, sometimes it’s cheaper just to pay them off rather than go through basically paying people like me to defend what was obviously a dubious claim, but it can still run in, you know, into a lot more money than paying them 5 or $10,000 just to go away.
And to that end, I had been working with other businesses in bolstering their website presence as far as the proper disclosures, having an inventory as far as what kind of cookies or trackers they may be using. And to be honest, most business owners don’t really think about that because they’re thinking, “Well, okay, I’m, I’m gonna build a website.
I’ve got Google Ads or whatever services I use, drives traffic.” But at the same time, that may create some, you know, a tailing risk that they were not necessarily aware of until they get a registered letter from some law firm in California they’ve never heard of that says, “Oh, by the way, we’re alleging that you violated our law even [00:10:00] though you’ve never set foot in this state, but your business was accessed in our state and somebody has been harmed.”
Justin Brady: sometimes if you set up something on Webflow or WordPress or some- it comes with some plugins that are doing things that you don’t even know it’s doing.
So as a local business, you could be liable for something you don’t even know exists on your website. Obviously there’s a point where if someone’s in trouble or they think they’re, uh, may be in trouble, call you, get it sorted out, but what do we do right now to stop the bleeding and make sure we at least cut as much risk as possible?”
What are some of the things people can do
Scott Murphy: any business that has a website will need a, a privacy notice that actually reflects how they collect data, how they use it, how they process it. If you are using third-party services for SEO, for example, AdSense, for example, or Meta Pixel, you should disclose on your site or on a cookies policy that this is, these cookies are available and, or they may hit your s- they may hit your device, and this is something that you should be aware of, and then give them the option to either opt out of it through a cookie [00:11:00] manager.
Sometimes you see those banners that say, “Reject all but essential cookies,” or something like that. And that re- that’s prophylactic, but at the same time, it makes you a harder target than if you have no privacy b- notice whatsoever or it doesn’t reflect how you actually collect data. And to be honest, I was working with another client a few months ago, and I did a quick survey of some well-known business around Des Moines, locally owned places, and I was amazed at how many did not even have a privacy policy. And some of these businesses have been around for a while. I’m sure they have a third party, you know, doing the r- handling their website- Sure … handling traffic, you know, traffic monitoring, marketing. But I was just… And I’m not one to go driving around with, you know, a billboard or something like that and say, “Hey, talk to me.”
But at the same time, it is really one of those things where, oh, there’s, you know, what I’m trying to do is get ahead of that curve. And so, if there are businesses that do have concerns, talk to me or another lawyer who works in this space, and really try to get set up and try to make yourself a harder target for these California and other [00:12:00] state atto- l- lawyers that come in and basically say, “Well, your site violated our law,” that most c- most business owners around Iowa never knew it existed until they get a demand letter
Justin Brady: Right. Right. If you don’t know what you’re doing, get help. But first, at least get some privacy policy on your website, and just, like, go through your plugins, go through your website, find out what data’s being collected, and at least disclose it somewhere.
Is that a good first step? Does that help us a little?
Scott Murphy: I think so. And at the very least, it makes you a harder target ’cause you’ve, at the very least, you’ve disclosed- Well, you’ve disclosed that, yeah
Justin Brady: disclosed it. Yeah, yeah
Scott Murphy: And so that kinda takes away the knowledge and dual consent piece because, to your point, if somebody w- goes on there, sees this, sees these disclosures, and decides they want to proceed with a site, for example, they want to order a product or service from you, arguably they’ve effectively consented to that, so that takes def- effectively defangs that risk
Justin Brady: Sure. So last question would be, uh, earlier, um, if you think that, well, this [00:13:00] is just this third party thing and they’re collecting the data and I’m not actually collecting it, so I am legally not liable, there’s a difference, and this would just be a short answer probably. There’s a difference between controller and processor, like someone like me using an AI tool or something would be the controller, and then the company that is making the tool would be the processor.
Even though they’re the processor, I, the controller, am still liable?
Scott Murphy: You are, ’cause you are the controller. You c- you are, you are, you are in the seat of the boss. You can fire the person, you know, the entity that’s processing your data. You can have them conform to certain requirements. But to your point, they are only the processor. They throw things out there that you may not be aware of, but you’re still responsible, and you could be on the hook for whatever they’ve done
Justin Brady: Scott Murphy, the data privacy cyber law guy over at Dentons Davis Brown. The, the data privacy cyber… you so– This is absolutely fascinating, and I have a 100% guarantee that most, uh, [00:14:00] of you listening out there were probably horrified today. So if they, if they wanna get in touch with you, read your blog, send you an email, call and ask for a quick checkup, something like that, how do they do that?
Scott Murphy: my email ***. Our main phone number is (515) 288-2500. I’m also on LinkedIn as well, and I post up there fairly regularly on these types of topics.
Justin Brady: Oh my gosh, so that’s one thing. Follow you on LinkedIn. We’ll make sure on Iowapodcast.com/business you can find all the Dentons Davis Brown, um, interviews there. We’ll make sure to put your contact information and LinkedIn on that page. Definitely the personal cell phone. No, just kidding, not gonna do that. Uh, Scott Scott Murphy, thank you so much for coming on Iowapodcast.com.
Scott Murphy: Justin. Thanks for the invite. I’m happy to be here, and I’m willing to come back. All right.





