EnglishEspañol
Minnesota flag

Minnesota

Minnesota MCDPA Compliance Checklist (Minn. Stat. 325M)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 8 primary sources cited on this page. How we verify our legal content

Minnesota MCDPA Compliance Checklist (Minn. Stat. 325M)

Frequently Asked Questions

Does my business have to comply with the Minnesota MCDPA?

Under Minn. Stat. 325M.12, the MCDPA applies if you conduct business in Minnesota or target its residents and, in a calendar year, control or process the personal data of 100,000 or more consumers, or of 25,000 or more consumers while deriving over 25 percent of gross revenue from selling data. Small businesses as defined by the U.S. Small Business Administration are exempt, though they still need consent to sell sensitive data.

What is the Minnesota data inventory requirement?

Under Minn. Stat. 325M.18, a Minnesota controller must maintain an inventory of the personal data it manages and document its data privacy and security policies and procedures, including data minimization and retention practices and the contact information for its chief privacy officer. This documented data inventory is uncommon among state privacy laws and is the foundation for answering the specific-third-party list right.

When did the Minnesota MCDPA take effect for compliance?

The MCDPA took effect July 31, 2025 for most controllers. Postsecondary institutions regulated by the Office of Higher Education have a delayed compliance date of July 31, 2029. As of 2026, most covered businesses must already be compliant.

Do I need consent to process sensitive data in Minnesota?

Yes. The MCDPA requires opt-in consent before processing sensitive data, which includes data revealing racial or ethnic origin, religion, health conditions, sexual orientation, citizenship or immigration status, genetic or biometric data, precise geolocation, and a known child's data. Consent must be a clear affirmative act and cannot be inferred from inaction or a pre-checked box.

How fast must a Minnesota controller answer a request?

A controller generally must respond to a verified consumer request within 45 days. It may extend once by another 45 days when reasonably necessary, as long as it informs the consumer of the extension and the reason within the first 45 days. Up to two responses in a 12-month period are generally free, and a fee applies only when a request is manifestly unfounded or excessive.

What does Minnesota require for profiling decisions?

If you profile consumers in furtherance of decisions with legal or similarly significant effects, Minn. Stat. 325M.14 requires you to let a consumer question the result, learn the reason for the decision, learn what they might do to change it, and review and correct the data used. You need an operational and documented way to explain your automated decisions, which is unique to Minnesota among states as of 2026.

Do I need data protection assessments under the MCDPA?

Yes, for higher-risk processing. The MCDPA requires controllers to conduct and document data protection assessments for activities such as selling personal data, targeted advertising, certain profiling, and processing sensitive data. The Minnesota Attorney General may require disclosure of a relevant assessment during an investigation, so keep them current and retrievable.

Is there still a cure period under the Minnesota MCDPA, and can consumers sue?

The MCDPA's 30-day right to cure sunset January 31, 2026, so as of 2026 any cure opportunity is at the Minnesota Attorney General's discretion rather than guaranteed. There is also no private right of action: enforcement rests solely with the Attorney General under Minn. Stat. 325M.20, who may seek civil penalties of up to $7,500 per violation. Consumers file complaints with the Attorney General rather than suing directly.

Updates

Added the consent-revocation mechanism duty and its 15-day processing-stop deadline to the sensitive-data step.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Corrected the free-response allowance under Minn. Stat. 325M.14: the MCDPA entitles a consumer to up to two free responses per year, not one, and a fee applies only to manifestly unfounded or excessive requests, not simply to a second request.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Minnesota Statutes Chapter 325M: Consumer Data Privacy Act (Full Chapter)(revisor.mn.gov).gov
  2. Minn. Stat. 325M.12: Scope; Exclusions (Applicability Thresholds)(revisor.mn.gov).gov
  3. Minn. Stat. 325M.14: Consumer Personal Data Rights and Profiling(revisor.mn.gov).gov
  4. Minn. Stat. 325M.14: Controller Response and Appeals(revisor.mn.gov).gov
  5. Minn. Stat. 325M.18: Controller Duties, Data Inventory, and Security(revisor.mn.gov).gov
  6. Minn. Stat. 325M.20: Enforcement and Civil Penalties(revisor.mn.gov).gov
  7. Minnesota Attorney General: MCDPA Business Compliance(ag.state.mn.us).gov
  8. Minnesota Attorney General: MCDPA Business Enforcement Overview(ag.state.mn.us).gov
Share: