Minnesota
What Is the Minnesota Consumer Data Privacy Act (MCDPA)?
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 8 primary sources cited on this page. How we verify our legal content

The Minnesota Consumer Data Privacy Act (MCDPA), codified at Minnesota Statutes sections 325M.10 to 325M.21, took effect July 31, 2025 for most controllers, with a delayed compliance date of July 31, 2029 for postsecondary institutions regulated by the Office of Higher Education. Enacted in 2024 as part of an omnibus measure (HF 4757) and signed by Governor Tim Walz, it gives Minnesota residents a full slate of data rights plus two features that few other states match: the right to obtain a list of the specific third parties that received their data, and the right to question the result of an automated profiling decision.
As of 2026, the Minnesota Attorney General holds exclusive enforcement authority and may seek civil penalties of up to $7,500 per violation under Minn. Stat. 325M.20. The 30-day right to cure that controllers relied on through 2025 sunset January 31, 2026, so a business can no longer count on a guaranteed grace period before the state acts.
Jurisdiction scope: This covers Minnesota's Consumer Data Privacy Act (Minn. Stat. 325M.10 to 325M.21). It is general legal information, not legal advice.
What the MCDPA is: statute, enactment, and effective dates
The Minnesota Consumer Data Privacy Act is Minnesota's first comprehensive consumer data privacy law. It is codified at Minnesota Statutes sections 325M.10 through 325M.21. Section 325M.10 limits the act's own citation clause to those sections, which matters because the earlier part of chapter 325M, sections 325M.01 to 325M.09, is a separate 2002 internet service provider privacy law that defines a consumer as an ISP subscriber. The MCDPA was passed in the 2024 legislative session as part of a large omnibus measure, House File 4757. Governor Tim Walz signed it into law, and most of its substantive obligations took effect July 31, 2025.
The law uses a delayed compliance date for one category of organization. Under the act's effective-date provision, postsecondary institutions regulated by the Office of Higher Education are not required to comply until July 31, 2029. Every other covered controller has been subject to the MCDPA since July 31, 2025.
As of 2026, the MCDPA places Minnesota among the roughly twenty states that have enacted comprehensive consumer privacy statutes. What makes Minnesota stand out is not the breadth of its rights, which track the now-common Virginia model, but two distinctive additions: a specific-third-party list right and a one-of-a-kind right to question automated profiling decisions.
For the full controller and processor obligations, privacy notice content rules, and data protection assessment requirements, see the Minnesota data privacy laws parent page.
Who the MCDPA covers: applicability thresholds
The MCDPA's applicability test lives in Minn. Stat. 325M.12. The law applies to a person that conducts business in Minnesota, or that produces products or services targeted to residents of Minnesota, and that during a calendar year meets one of two data-volume tests.
The first trigger is controlling or processing the personal data of 100,000 or more consumers. Data processed solely to complete a payment transaction does not count toward this figure, so a retailer is not pushed over the threshold by single-purchase card data alone.
The second trigger is controlling or processing the personal data of 25,000 or more consumers while deriving over 25 percent of gross revenue from the sale of personal data. This lower headcount captures data-driven businesses whose model depends on selling personal information.
Minnesota also exempts small businesses as defined by the United States Small Business Administration, although even an exempt small business may not sell a consumer's sensitive data without first obtaining consent. Unlike many peer states, Minnesota's nonprofit exemption is unusually narrow, covering only nonprofits established to detect and prevent insurance fraud (Minn. Stat. 325M.12), so an ordinary nonprofit that meets the thresholds is covered. The MCDPA additionally carries the familiar entity-level and data-level exemptions for data and entities regulated under the Gramm-Leach-Bliley Act and the Health Insurance Portability and Accountability Act, among others.

The specific third-party list right
The MCDPA's first headline feature is the ability to learn exactly which third parties received a consumer's data. Under Minn. Stat. 325M.14, a Minnesota consumer may obtain a list of the specific third parties to which the controller has disclosed the consumer's personal data. The statute allows one narrow fallback: if the controller does not maintain that information in a format specific to the consumer, it may instead provide a list of the specific third parties to whom it has disclosed any consumers' personal data. That is a condition on how the record is kept, not a free choice for the controller.
This is meaningfully different from the disclosure most state privacy laws require. Under the more common model, a consumer can learn only the categories of third parties, such as "advertising partners" or "analytics vendors." Minnesota, like Oregon, goes further and lets the consumer ask for the named, specific entities.
For businesses, the specific-third-party list right is one of the harder MCDPA obligations to engineer, because it requires tracking disclosures at the level of named recipients rather than broad categories. For consumers, it offers far more transparency about where their data actually traveled. The Minnesota MCDPA consumer rights guide covers this right and the response procedure in depth.
The right to question a profiling result: Minnesota's signature feature
The MCDPA's most distinctive right had no parallel in any other state privacy law when it took effect, and only Connecticut has since matched it. When a consumer is subject to profiling in furtherance of decisions that produce legal or similarly significant effects, Minn. Stat. 325M.14 gives the consumer four interlocking rights tied to that profiling.
The consumer may question the result of the profiling. The consumer may be informed of the reason that the profiling resulted in the decision, and, if feasible, be informed of what actions the consumer might take to secure a different decision in the future. The consumer may review the personal data used in the profiling, and may have that data corrected and the decision reevaluated if it was based on inaccurate data.
Minnesota was the first state to give a consumer an affirmative right to challenge the outcome of an automated decision and demand the reasoning behind it. Connecticut has since adopted a closely modeled version: 2025 Conn. Pub. Act 25-113, Sec. 8 repealed and substituted Conn. Gen. Stat. 42-518 effective July 1, 2026, and the new subdivision (a)(6) lets a consumer whose data was profiled in furtherance of an automated decision with legal or similarly significant effect question the result of the profiling, be informed of the reason it produced the decision, and review the personal data used. The two states differ on the remedy: Connecticut allows the consumer to correct incorrect data and have the decision reevaluated only where the profiling decision concerned housing, while Minnesota allows correction and reevaluation for any profiling decision shown to rest on inaccurate data. Most other comprehensive state laws still stop at letting a consumer opt out of profiling, so Minnesota remains at the leading edge of automated-decision regulation.

The data inventory duty: an uncommon affirmative obligation
The MCDPA also imposes a documentation duty that few other state privacy laws require. Under Minn. Stat. 325M.18, a controller must establish, implement, and maintain reasonable administrative, technical, and physical data security practices, and as part of that program must maintain an inventory of the personal data it must manage to carry out its obligations.
Controllers must also document and maintain a description of the policies and procedures the controller has adopted to comply with the act, including a description of data minimization and retention practices and the name and contact information for the controller's chief privacy officer or other responsible individual. This is sometimes described as the first state requirement to mandate a documented data inventory of this kind, an obligation long familiar under the European Union's General Data Protection Regulation.
The practical consequence is that a Minnesota controller cannot treat privacy as a set of one-off responses to consumer requests. It must build and document an ongoing governance program. The Minnesota MCDPA compliance checklist walks through building that inventory and program.
MCDPA vs. CCPA: the key differences
Minnesota's MCDPA and California's CCPA are often compared by companies that operate nationally. The state data privacy law comparison page covers the broader multistate picture, but several differences between the MCDPA and California's CCPA stand out.
| Feature | Minnesota MCDPA | California CCPA/CPRA |
|---|---|---|
| Coverage threshold | 100,000 consumers, or 25,000 plus over 25% of revenue from data sales; SBA small businesses exempt | $25M revenue, 100,000 consumers, or 50% revenue from data sales |
| Question a profiling result | Yes (Minn. Stat. 325M.14), first in the nation | No |
| Third-party disclosure right | Specific named third parties (Minn. Stat. 325M.14) | Categories of third parties |
| Data inventory duty | Required (Minn. Stat. 325M.18) | Not required as a standalone duty |
| Sensitive data | Opt-in consent required | Right to limit use; opt-out model |
| Private right of action | None | Limited, for certain data breaches |
The most consequential differences are the profiling-question right and the third-party list right, neither of which the CCPA provides, and the affirmative data inventory duty. The two laws also differ on sensitive data: California uses an opt-out "right to limit," while Minnesota requires opt-in consent before sensitive data may be processed at all.
Related guides
- Minnesota data privacy laws parent hub
- Minnesota MCDPA consumer rights
- Minnesota MCDPA compliance checklist
- State data privacy law comparison
- What is the CCPA?
More Minnesota Laws
Frequently Asked Questions
What is the Minnesota Consumer Data Privacy Act (MCDPA)?
The MCDPA is Minnesota's comprehensive consumer data privacy law, codified at Minn. Stat. 325M.10 to 325M.21. It was enacted in 2024 as part of omnibus bill HF 4757, signed by Governor Tim Walz, and took effect July 31, 2025 for most controllers. It gives Minnesota residents rights over their personal data and requires covered businesses to be transparent about how they collect, use, and disclose it. Note that Minnesota shares the MCDPA initials with Montana's law, so this guide always means the Minnesota act.
When did the Minnesota MCDPA take effect?
The MCDPA took effect July 31, 2025 for most controllers. Postsecondary institutions regulated by the Office of Higher Education have a delayed compliance date of July 31, 2029. As of 2026, the general effective date has passed, so most covered businesses are fully subject to the law.
Who has to comply with the Minnesota MCDPA?
Under Minn. Stat. 325M.12, the MCDPA covers a controller doing business in Minnesota or targeting Minnesota residents that, in a calendar year, controls or processes the personal data of 100,000 or more consumers, or of 25,000 or more consumers while deriving over 25 percent of gross revenue from selling personal data. Small businesses as defined by the U.S. Small Business Administration are exempt, though they still need consent to sell sensitive data.
What is Minnesota's right to question a profiling result?
Under Minn. Stat. 325M.14, when a consumer is subject to profiling that produces legal or similarly significant effects, the consumer may question the result of the profiling, be informed of the reason it reached that result, learn what actions they might take to secure a different decision in the future, and review and correct the data used. Minnesota was the first state to grant this right; Connecticut adopted a closely modeled version effective July 1, 2026 (Conn. Gen. Stat. 42-518(a)(6), as amended by 2025 Conn. Pub. Act 25-113, Sec. 8), though Connecticut limits the correction-and-reevaluation step to housing decisions while Minnesota's applies to any profiling decision based on inaccurate data.
What is the Minnesota specific third-party list right?
Under Minn. Stat. 325M.14, a Minnesota consumer may obtain a list of the specific third parties to which the controller has disclosed the consumer's personal data. Only if the controller does not maintain that information in a format specific to the consumer may it instead provide a list of the specific third parties to whom it has disclosed any consumers' personal data. This is broader than the category-level disclosure most state laws require, because it identifies named recipients rather than broad groups. Only a handful of states, including Oregon, grant this right.
Does the Minnesota MCDPA require a data inventory?
Yes. Under Minn. Stat. 325M.18, a controller must maintain an inventory of the personal data it manages and document its data privacy and security policies and procedures, including data minimization and retention practices and the contact information for its chief privacy officer. This documented inventory and governance duty is uncommon among U.S. state privacy laws and is often described as a first.
How is the Minnesota MCDPA different from the CCPA?
Key differences: Minnesota lets consumers question the result of an automated profiling decision and request a list of specific named third parties, neither of which California's CCPA provides; Minnesota imposes an affirmative data inventory duty; Minnesota requires opt-in consent for sensitive data while California uses an opt-out right to limit; and California has a limited private right of action for certain breaches while Minnesota has none.
Who enforces the Minnesota MCDPA?
The Minnesota Attorney General has exclusive enforcement authority under Minn. Stat. 325M.20. There is no private right of action. Civil penalties run up to $7,500 per violation. The 30-day right to cure that controllers relied on through 2025 sunset January 31, 2026, so a guaranteed cure window no longer exists as of 2026.
Updates
Corrected the claim that Minnesota is the only state allowing a consumer to question the result of an automated profiling decision, since Connecticut adopted a closely modeled right effective July 1, 2026; clarified that the specific-third-party list fallback is conditional rather than a controller option; and narrowed the citation of the act from all of chapter 325M to Minn. Stat. 325M.10 to 325M.21.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Removed an unsupported claim that nonprofit corporations governed by Chapter 317A also get the delayed July 31, 2029 MCDPA compliance date. The effective-date notes on Minn. Stat. 325M.11, 325M.12, and 325M.20 all state the delayed date applies only to postsecondary institutions regulated by the Office of Higher Education; none mentions nonprofits or Chapter 317A, and the article's own KeyTakeaways/FAQ never repeated the nonprofit claim, consistent with it being an unsupported addition to the opening sentence.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Minnesota Statutes, Chapter 325M: CONSUMER DIGITAL AND DATA PRIVACY
§ 325M.14CONSUMER PERSONAL DATA RIGHTSIn forcecited in 5 of our articles
Subdivision 1. Consumer rights provided. (a) Except as provided in sections 325M.10 to 325M.21, a controller must comply with a request to exercise the consumer rights provided in this subdivision. (b) A consumer has the right to confirm whether or not a controller is processing personal data concerning the consumer and access the categories of personal data the controller is processing. (c) A consumer has the right to correct inaccurate personal data concerning the consumer, taking into account the nature of the personal data and the purposes of the processing of the personal data. (d) A consumer has the right to delete personal data concerning the consumer. (e) A consumer has the right to obtain personal data concerning the consumer, which the consumer previously provided to the controller, in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at revisor.mn.gov
Also relied on in: Minnesota MCDPA Compliance Checklist (Minn. Stat. 325M), Minnesota Data Privacy Laws: Consumer Rights Guide (2026), Minnesota Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 325M.12SCOPE; EXCLUSIONSIn forcecited in 5 of our articles
Subdivision 1. Scope. (a) Sections 325M.10 to 325M.21 apply to legal entities that conduct business in Minnesota or produce products or services that are targeted to residents of Minnesota, and that satisfy one or more of the following thresholds: (1) during a calendar year, controls or processes personal data of 100,000 consumers or more, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or (2) derives over 25 percent of gross revenue from the sale of personal data and processes or controls personal data of 25,000 consumers or more. (b) A controller or processor acting as a technology provider under section 13.32 shall comply with sections 13.32 and 325M.10 to 325M.21, except that when the provisions of section 13.32 conflict with sections 325M.10 to 325M.21, section 13.32 prevails. Subd. 2. Exclusions.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at revisor.mn.gov
Also relied on in: Minnesota Employee Monitoring Laws (2026): Cameras, GPS & Privacy
§ 325M.18DATA PRIVACY POLICIES; DATA PRIVACY AND PROTECTION ASSESSMENTSIn forcecited in 4 of our articles
(a) A controller must document and maintain a description of the policies and procedures the controller has adopted to comply with sections 325M.10 to 325M.21. The description must include, where applicable: (1) the name and contact information for the controller's chief privacy officer or other individual with primary responsibility for directing the policies and procedures implemented to comply with the provisions of sections 325M.10 to 325M.21; and (2) a description of the controller's data privacy policies and procedures which reflect the requirements in section 325M.16, and any policies and procedures designed to: (i) reflect the requirements of sections 325M.10 to 325M.21 in the design of the controller's systems; (ii) identify and provide personal data to a consumer as required by sections 325M.10 to 325M.21; (iii) establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data, including the maintenance of an inventory of the data that must be managed to exercise the responsibilities under this item; (iv) limit the collection of personal data to what…
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at revisor.mn.gov
§ 325M.20ATTORNEY GENERAL ENFORCEMENTIn forcecited in 5 of our articles
(a) In the event that a controller or processor violates sections 325M.10 to 325M.21, the attorney general, prior to filing an enforcement action under paragraph (b), must provide the controller or processor with a warning letter identifying the specific provisions of sections 325M.10 to 325M.21 the attorney general alleges have been or are being violated. If, after 30 days of issuance of the warning letter, the attorney general believes the controller or processor has failed to cure any alleged violation, the attorney general may bring an enforcement action under paragraph (b). This paragraph expires January 31, 2026. (b) The attorney general may bring a civil action against a controller or processor to enforce a provision of sections 325M.10 to 325M.21 in accordance with section 8.31. If the state prevails in an action to enforce sections 325M.10 to 325M.21, the state may, in addition to penalties provided by paragraph (c) or other remedies provided by law, be allowed an amount determined by the court to be the reasonable value of all or part of the state's litigation expenses incurred.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at revisor.mn.gov
Also relied on in: Minnesota MCDPA Consumer Rights (Minn. Stat. 325M.14)
Explore the law
This article also draws on these acts and chapters (opening at their first section): Minnesota Statutes, Chapter 325M: CONSUMER DIGITAL AND DATA PRIVACY § 325M.01 (DEFINITIONS)
Related law for further reading — not part of this article’s citations.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Minnesota Statutes Chapter 325M: Consumer Data Privacy Act (Full Chapter)(revisor.mn.gov).gov
- Minn. Stat. 325M.12: Scope; Exclusions (Applicability Thresholds)(revisor.mn.gov).gov
- Minn. Stat. 325M.14: Consumer Personal Data Rights(revisor.mn.gov).gov
- Minn. Stat. 325M.18: Data Privacy Policies; Data Privacy and Protection Assessments(revisor.mn.gov).gov
- Minn. Stat. 325M.20: Enforcement and Civil Penalties(revisor.mn.gov).gov
- Minnesota Attorney General: Consumer Data Privacy(ag.state.mn.us).gov
- HF 4757 (2024 Regular Session): Omnibus Enacting Measure(revisor.mn.gov).gov
- Minnesota Attorney General: MCDPA Business Enforcement Overview(ag.state.mn.us).gov
- 2025 Conn. Pub. Act 25-113, Sec. 8 (Substitute SB 1295): Conn. Gen. Stat. 42-518 repealed and substituted, effective July 1, 2026 (profiling-question right)(cga.ct.gov)
- Minn. Stat. 325M.10: Citation (Sections 325M.10 to 325M.21 may be cited as the Minnesota Consumer Data Privacy Act)(revisor.mn.gov)