EnglishEspañol
Minnesota flag

Minnesota

What Is the Minnesota Consumer Data Privacy Act (MCDPA)?

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 8 primary sources cited on this page. How we verify our legal content

What Is the Minnesota Consumer Data Privacy Act (MCDPA)?

Frequently Asked Questions

What is the Minnesota Consumer Data Privacy Act (MCDPA)?

The MCDPA is Minnesota's comprehensive consumer data privacy law, codified at Minn. Stat. 325M.10 to 325M.21. It was enacted in 2024 as part of omnibus bill HF 4757, signed by Governor Tim Walz, and took effect July 31, 2025 for most controllers. It gives Minnesota residents rights over their personal data and requires covered businesses to be transparent about how they collect, use, and disclose it. Note that Minnesota shares the MCDPA initials with Montana's law, so this guide always means the Minnesota act.

When did the Minnesota MCDPA take effect?

The MCDPA took effect July 31, 2025 for most controllers. Postsecondary institutions regulated by the Office of Higher Education have a delayed compliance date of July 31, 2029. As of 2026, the general effective date has passed, so most covered businesses are fully subject to the law.

Who has to comply with the Minnesota MCDPA?

Under Minn. Stat. 325M.12, the MCDPA covers a controller doing business in Minnesota or targeting Minnesota residents that, in a calendar year, controls or processes the personal data of 100,000 or more consumers, or of 25,000 or more consumers while deriving over 25 percent of gross revenue from selling personal data. Small businesses as defined by the U.S. Small Business Administration are exempt, though they still need consent to sell sensitive data.

What is Minnesota's right to question a profiling result?

Under Minn. Stat. 325M.14, when a consumer is subject to profiling that produces legal or similarly significant effects, the consumer may question the result of the profiling, be informed of the reason it reached that result, learn what actions they might take to secure a different decision in the future, and review and correct the data used. Minnesota was the first state to grant this right; Connecticut adopted a closely modeled version effective July 1, 2026 (Conn. Gen. Stat. 42-518(a)(6), as amended by 2025 Conn. Pub. Act 25-113, Sec. 8), though Connecticut limits the correction-and-reevaluation step to housing decisions while Minnesota's applies to any profiling decision based on inaccurate data.

What is the Minnesota specific third-party list right?

Under Minn. Stat. 325M.14, a Minnesota consumer may obtain a list of the specific third parties to which the controller has disclosed the consumer's personal data. Only if the controller does not maintain that information in a format specific to the consumer may it instead provide a list of the specific third parties to whom it has disclosed any consumers' personal data. This is broader than the category-level disclosure most state laws require, because it identifies named recipients rather than broad groups. Only a handful of states, including Oregon, grant this right.

Does the Minnesota MCDPA require a data inventory?

Yes. Under Minn. Stat. 325M.18, a controller must maintain an inventory of the personal data it manages and document its data privacy and security policies and procedures, including data minimization and retention practices and the contact information for its chief privacy officer. This documented inventory and governance duty is uncommon among U.S. state privacy laws and is often described as a first.

How is the Minnesota MCDPA different from the CCPA?

Key differences: Minnesota lets consumers question the result of an automated profiling decision and request a list of specific named third parties, neither of which California's CCPA provides; Minnesota imposes an affirmative data inventory duty; Minnesota requires opt-in consent for sensitive data while California uses an opt-out right to limit; and California has a limited private right of action for certain breaches while Minnesota has none.

Who enforces the Minnesota MCDPA?

The Minnesota Attorney General has exclusive enforcement authority under Minn. Stat. 325M.20. There is no private right of action. Civil penalties run up to $7,500 per violation. The 30-day right to cure that controllers relied on through 2025 sunset January 31, 2026, so a guaranteed cure window no longer exists as of 2026.

Updates

Corrected the claim that Minnesota is the only state allowing a consumer to question the result of an automated profiling decision, since Connecticut adopted a closely modeled right effective July 1, 2026; clarified that the specific-third-party list fallback is conditional rather than a controller option; and narrowed the citation of the act from all of chapter 325M to Minn. Stat. 325M.10 to 325M.21.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Removed an unsupported claim that nonprofit corporations governed by Chapter 317A also get the delayed July 31, 2029 MCDPA compliance date. The effective-date notes on Minn. Stat. 325M.11, 325M.12, and 325M.20 all state the delayed date applies only to postsecondary institutions regulated by the Office of Higher Education; none mentions nonprofits or Chapter 317A, and the article's own KeyTakeaways/FAQ never repeated the nonprofit claim, consistent with it being an unsupported addition to the opening sentence.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Minnesota Statutes Chapter 325M: Consumer Data Privacy Act (Full Chapter)(revisor.mn.gov).gov
  2. Minn. Stat. 325M.12: Scope; Exclusions (Applicability Thresholds)(revisor.mn.gov).gov
  3. Minn. Stat. 325M.14: Consumer Personal Data Rights(revisor.mn.gov).gov
  4. Minn. Stat. 325M.18: Data Privacy Policies; Data Privacy and Protection Assessments(revisor.mn.gov).gov
  5. Minn. Stat. 325M.20: Enforcement and Civil Penalties(revisor.mn.gov).gov
  6. Minnesota Attorney General: Consumer Data Privacy(ag.state.mn.us).gov
  7. HF 4757 (2024 Regular Session): Omnibus Enacting Measure(revisor.mn.gov).gov
  8. Minnesota Attorney General: MCDPA Business Enforcement Overview(ag.state.mn.us).gov
  9. 2025 Conn. Pub. Act 25-113, Sec. 8 (Substitute SB 1295): Conn. Gen. Stat. 42-518 repealed and substituted, effective July 1, 2026 (profiling-question right)(cga.ct.gov)
  10. Minn. Stat. 325M.10: Citation (Sections 325M.10 to 325M.21 may be cited as the Minnesota Consumer Data Privacy Act)(revisor.mn.gov)
Share: