Privacy Law Library

Minnesota Consumer Data Privacy Act

MCDPA

Comprehensive privacy · Children · Biometric · Genetic · Location · Data security · Artificial intelligence

Minnesota's comprehensive consumer privacy law gives Minnesota residents rights to access, correct, delete, and port their personal data, to opt out of targeted advertising, sale, and significant-effect profiling, and to get a list of the specific third parties that received their data. It is unusual in giving consumers a right to question the result of a profiling decision, learn the reason for it, and have it reevaluated on corrected data, and it requires a data inventory and documented privacy policies. Enforcement is by the Attorney General only.

Where
Minnesota
Citation
Minn. Stat. 325M.10 to 325M.21
Status
In force
In force since
2025-07-31
Enforced by
Minnesota Attorney General (325M.20)
People can sue
No
Penalties
Injunction and civil penalty of up to $7,500 per violation, plus the state's reasonable litigation expenses (325M.20(b)-(c)). The mandatory 30-day warning-letter cure period expired January 31, 2026 (325M.20(a)). No private right of action, including under the private attorney general statute, 8.31, subd. 3a (325M.20(d)).
Applies to
  • Legal entities that conduct business in Minnesota or produce products or services targeted to Minnesota residents and, in a calendar year, control or process personal data of 100,000 or more consumers (excluding data processed solely to complete a payment), or derive over 25 percent of gross revenue from selling personal data and process data of 25,000 or more consumers (325M.12, subd. 1)
  • Processors acting on behalf of controllers (325M.13)
  • Small businesses as defined by the SBA are otherwise exempt but may not sell sensitive data without prior consent (325M.12, subd. 2(a)(19); 325M.17)
  • Postsecondary institutions regulated by the Office of Higher Education need not comply until July 31, 2029 (Laws 2024, ch. 121, art. 5, s. 14)
  • Exempt: government entities, federally recognized tribes, banks and credit unions and financial-activity affiliates, insurers and producers, data covered by HIPAA, GLBA, FCRA, FERPA, DPPA, Farm Credit Act, Minnesota Insurance Fair Information Reporting Act, and employee/applicant data (325M.12, subd. 2)

What a privacy notice must say

  • Post a privacy notice via a conspicuous 'privacy' link covering categories of data, purposes, rights and appeals, data sold or shared, categories of third parties, contact information, retention policies, and the last-updated date; provide it in each language the controller does business in and in an accessible form; notify consumers of material changes.Minn. Stat. 325M.16, subd. 1(a), (c)-(e), (g)
  • Controllers that sell data, do targeted advertising, or do significant-effect profiling must disclose it and provide a clear opt-out method outside the privacy notice, such as a 'Your Opt-Out Rights' or 'Your Privacy Rights' link.Minn. Stat. 325M.16, subd. 1(b) · Only if: Applies to controllers that sell personal data, process it for targeted advertising, or profile for significant decisions

Rights it gives people

  • Consumers may obtain a list of the specific third parties to which the controller disclosed their personal data (or, if not kept per consumer, a list of specific third parties that received any consumer's data).Minn. Stat. 325M.14, subd. 1(h)
  • When personal data is profiled in furtherance of a legal or similarly significant decision, the consumer may question the result, be told the reason for the decision and, if feasible, what actions could have secured a different result or could do so in the future, review the personal data used, and have inaccurate data corrected and the decision reevaluated.Minn. Stat. 325M.14, subd. 1(g) · Only if: Applies when profiling is in furtherance of decisions producing legal or similarly significant effects (as defined in 325M.11(i))
  • Consumers may confirm processing and access, correct, delete, and obtain a portable copy of their personal data, and opt out of targeted advertising, sale, and profiling in furtherance of automated decisions with legal or similarly significant effects.Minn. Stat. 325M.14, subd. 1(b)-(f)

Practices it requires

  • Respond to rights requests within 45 days (one 45-day extension with notice), free up to twice a year; comply with opt-out requests within 45 days; do not require creating a new account; do not disclose SSNs, ID numbers, financial account numbers, passwords, or biometric data in access responses.Minn. Stat. 325M.14, subd. 4
  • Provide a conspicuous appeal process, answer appeals within 45 days (extendable by 60), tell the consumer how to complain to the Attorney General, and keep appeal records for at least 24 months.Minn. Stat. 325M.14, subd. 5
  • Limit collection to what is adequate, relevant, and reasonably necessary; no incompatible secondary use without consent; do not retain data no longer reasonably necessary.Minn. Stat. 325M.16, subd. 2(a), (b), (g)
  • Obtain consent before processing sensitive data (including health, biometric and genetic data used for identification, citizenship or immigration status, and specific geolocation), obtain COPPA-compliant parental consent for a known child's data, let consumers revoke consent and stop processing within 15 days, and do not sell or use for targeted advertising the data of consumers known to be 13 to 16 without consent.Minn. Stat. 325M.11(v); 325M.16, subd. 2(d)-(f)
  • Do not process personal data in a way that unlawfully discriminates on protected characteristics in housing, employment, credit, education, or public accommodations, and do not retaliate against consumers for exercising rights (bona fide loyalty programs allowed).Minn. Stat. 325M.16, subd. 3
  • Honor opt-out preference signals (universal opt-out mechanisms) for targeted advertising and sale, and honor opt-outs from authorized agents, including browser settings or global device settings.Minn. Stat. 325M.14, subds. 2(d), 3

Security duties

  • Maintain reasonable administrative, technical, and physical data security practices, including an inventory of the personal data.Minn. Stat. 325M.16, subd. 2(c)

Other duties

  • Controller-processor contracts must set processing instructions, confidentiality duties, subcontractor controls, deletion or return of data, and audit or independent assessment rights; processors must help controllers with breach notice under 325E.61.Minn. Stat. 325M.13
  • Document written privacy policies and procedures (including a chief privacy officer or responsible individual) and conduct documented data privacy and protection assessments for targeted advertising, sale, sensitive data, heightened-risk processing, and risky profiling; provide assessments to the Attorney General on a civil investigative demand.Minn. Stat. 325M.18

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Research reference, not legal advice.