Framework overlap

Does SSAE 18 cover Iowa Consumer Data Protection Act?

You hold SSAE 18 and have been told to do Iowa Consumer Data Protection Act. Here is how much overlaps, control by control.

88% of Iowa Consumer Data Protection Act you already have

SSAE 18 already covers about 88% of Iowa Consumer Data Protection Act, leaving 1 of 8 controls as genuinely new work.

Already covered 0 Likely covered 7 New work 1

No control in SSAE 18 maps directly to one in Iowa Consumer Data Protection Act. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in SSAE 18 reaches these. This is the list to scope.

ICDPA-Coord-USStatePrivacy-UCPA-Template-VCDPA-CPA-CTDPA-Federal-FTC-GDPR-International
Iowa CDPA Coordination - Utah CDPA Template Parent + US State Privacy Patchwork + Federal Sectoral (HIPAA/GLBA/FCRA/FERPA/COPPA) + FTC Section 5 + GDPR + India DPDP + International
Show the 7 you already have
ICDPA-ConsumerRights-Access-Delete-Portability-OptOut-Sale-Appeal-90Day-NO-Right-To-Correction-Authorised-Agent
Iowa CDPA Consumer Rights - Access + Delete + Portability + Opt-Out of Sale + 90-Day Response + Appeal + Authorised Agent + NO Right to Correction + NO Profiling Opt-Out + Free Fir
ICDPA-Controller-PrivacyNotice-PurposeLimitation-DataMinimisation-Sale-Disclosure-Transparency-LawfulBasis
Iowa CDPA Controller Obligations - Privacy Notice + Purpose Limitation + Data Minimisation + Sale Disclosure Statement + Targeted Advertising Disclosure + Privacy by Design + Lawfu
ICDPA-Enforcement-90DayCure-AttorneyGeneralOnly-NoPrivateRight-CivilPenalties-7500-PerViolation-Longest-Cure
Iowa CDPA Enforcement - Attorney General Exclusive + 90-Day Cure Period (LONGEST among US State Privacy Laws) + No Private Right of Action + Civil Penalties Up to USD 7500 Per Viol
ICDPA-Processor-Contracts-DPA-Subprocessor-Confidentiality-Audit-EndOfContract-Iowa-Code-715D-7
Iowa CDPA Processor Contracts - Data Processing Agreement (DPA) + Required Provisions + Subprocessor Approval + Confidentiality + End of Contract Deletion + Audit Rights + Assistan
ICDPA-Scope-SF262-2023-Kim-Reynolds-IA-Code-715D-Effective-1Jan2025-Applicability-100K-25K-50pct-Utah-Template
Iowa CDPA Scope + Senate File 262 + Governor Kim Reynolds 28 March 2023 + Iowa Code Chapter 715D + Effective 1 January 2025 + Applicability Thresholds + Utah CDPA Template Parent +
ICDPA-Security-ReasonablePractices-Breach-Notification-Iowa-Code-715C-Records-Encryption-Pseudonymisation
Iowa CDPA Security + Reasonable Practices + Iowa Personal Information Security Breach Notification Law (Iowa Code 715C) + Records + Encryption + Pseudonymisation
ICDPA-SensitiveData-Notice-OptOut-NotConsent-Children-COPPA-Alignment-De-Identification
Iowa CDPA Sensitive Data + Notice + Opt-Out (NOT Consent unlike VCDPA) + Children Under 13 + COPPA Alignment + De-Identification Standards + Heightened Risk Awareness

How this is calculated

Already covered means a mapping runs from a control in SSAE 18 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition