Montana
MCDPA Compliance Checklist: Montana Privacy (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 8 primary sources cited on this page. How we verify our legal content

Complying with the Montana Consumer Data Privacy Act (MCDPA), Mont. Code Ann. 30-14-2801 et seq., starts with one question: do you control or process the personal data of 25,000 Montana consumers, or 15,000 if more than 25 percent of your gross revenue comes from selling personal data? As of 2026 those are the lowest coverage thresholds of any state privacy law, so far smaller businesses are now in scope than were a year earlier. If you are covered, the law requires a privacy notice, opt-in consent for sensitive data, recognition of a universal opt-out signal, data protection assessments, processor contracts, and heightened safeguards for minors.
There is no longer a safety net. The 60-day cure period that once let a business fix an alleged violation before any enforcement action was originally set to sunset April 1, 2026, but SB 297 cut it short, eliminating the cure mechanism effective October 1, 2025. As of that date the Montana Attorney General can sue without sending a warning letter, and civil penalties reach up to $7,500 per violation under Mont. Code Ann. 30-14-2820. Compliance now needs to be in place before a complaint arrives, not assembled afterward.
Jurisdiction scope: This covers the Montana Consumer Data Privacy Act (Mont. Code Ann. Title 30, Chapter 14, Part 28). It is general legal information, not legal advice.
Step 1: Run the applicability test at the low thresholds
The first compliance step is deciding whether the MCDPA applies to you at all, and after SB 297 that question catches more businesses than it used to. Under Mont. Code Ann. 30-14-2803, the law applies to a person that conducts business in Montana, or that produces products or services targeted at Montana residents, and that during a calendar year controls or processes the personal data of either 25,000 or more Montana consumers, or 15,000 or more Montana consumers while deriving more than 25 percent of gross revenue from the sale of personal data.
Those counts do not gate the entire law. Mont. Code Ann. 30-14-2803(1) expressly excludes 30-14-2811, 30-14-2818, and 30-14-2819 from the threshold test, and 30-14-2803(2) applies those three minor-protection sections to any person that conducts business in Montana or delivers commercial products or services intentionally targeted to Montana residents, with no consumer count at all. A business below the thresholds still owes the minor-specific duties described in Steps 6 and 8.
Count Montana consumers, not your total user base. A business with a large national footprint but few Montana customers may fall below the line for the threshold-gated portions of the law, while a Montana-focused business can be covered with a comparatively small number of users. The primary 25,000 count excludes personal data processed solely to complete a payment transaction, but that carve-out is narrow and does not cover the customer data you keep afterward. The table below compares Montana's triggers to other major state laws.
| Law | Primary trigger | Notes |
|---|---|---|
| Montana MCDPA | 25,000 consumers | 15,000 if over 25% revenue from selling data |
| California CCPA | $25M revenue, 100,000 consumers, or 50% revenue from sale | Revenue-based trigger |
| Virginia VCDPA | 100,000 consumers | 25,000 if over 50% revenue from sale |
| Texas TDPSA | No numeric threshold | Excludes small businesses per SBA definition |
Document your analysis. Because the thresholds are now so low, businesses that previously concluded they were exempt should re-run the test against the 25,000 and 15,000 figures that took effect October 1, 2025. A dated written determination is useful if the Attorney General later asks how you reached your conclusion.
Step 2: Check the exemptions before you build
Even above the thresholds, a business may be wholly or partly exempt. Under Mont. Code Ann. 30-14-2804, exempt entities include state and local government bodies, narrowly scoped nonprofit organizations, institutions of higher education, national securities associations, banks and credit unions; the statute contains no exemption for federally recognized tribes and no entity-level exemption for air carriers. Data-level exemptions cover protected health information under HIPAA, consumer report data under the Fair Credit Reporting Act, education records under FERPA, and similar categories already regulated by federal law. Air carriers belong to this data-level list rather than the entity list: Mont. Code Ann. 30-14-2804(2)(p) exempts only personal data handled in relation to price, route, or service, and only to the extent this part is preempted by the Airline Deregulation Act, 49 U.S.C. 41713, so an airline's other Montana consumer data stays covered.
SB 297 reworked the financial-sector and nonprofit treatment, so old assumptions may no longer hold as of 2026. The broad entity-level exemption for financial institutions under the Gramm-Leach-Bliley Act was reshaped, with specific exemptions retained for banks, credit unions, and certain insurers, while the data-level GLBA exemption for regulated data remains. The nonprofit exemption was narrowed in scope. Confirm your status against the current statutory text rather than a pre-SB 297 summary.
Mixed-status businesses are common. A company may handle some exempt data, such as HIPAA-protected records, alongside non-exempt consumer data that the MCDPA covers. The exemptions apply to the specific entity or data type, so the covered portions of your operation still need full compliance. Map which data sits inside and outside the exemptions so you can apply MCDPA controls precisely where they are required.
Step 3: Publish a compliant privacy notice
The MCDPA requires a controller to provide consumers with a reasonably accessible, clear, and meaningful privacy notice. The notice must describe the categories of personal data the controller processes, the purposes for processing, how consumers may exercise their rights and appeal a decision, the categories of personal data the controller shares with third parties, and the categories of third parties with whom it shares data.
If the controller sells personal data or processes it for targeted advertising, the notice must disclose that and explain how a consumer may opt out. SB 297 enhanced these notice requirements, so a privacy policy drafted for the original 2024 version of the law should be reviewed against the amended standard. The notice should also explain that consumers can submit a complaint to the Montana Attorney General if an appeal is denied.
Keep the notice current. The MCDPA contemplates that consumers be informed of material changes to a controller's privacy practices, so a process for updating the notice and, where appropriate, notifying consumers of material changes belongs in your compliance program. Treat the privacy notice as a living document tied to your actual data practices, not a one-time legal artifact.

Step 4: Build opt-out and universal opt-out handling
Covered controllers must give consumers a clear and conspicuous way to opt out of targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects, as set out in Mont. Code Ann. 30-14-2808, with the universal opt-out mechanism requirement at 30-14-2809. The opt-out cannot be hidden behind an account requirement, and it cannot be more burdensome than the corresponding opt-in. A practical setup includes a visible link and a request intake that routes to the right system.
The harder technical requirement is the universal opt-out mechanism. Since January 1, 2025, a controller that processes personal data for targeted advertising or sale must recognize an opt-out preference signal, such as the Global Privacy Control, that communicates a consumer's choice. That means your web properties need to detect the signal and apply the opt-out automatically, without requiring the consumer to do anything else on your site. Test this end to end, because a signal that is received but not acted on is a violation waiting to be found.
Treat opt-out logging as part of the build. You should be able to show that a given opt-out, whether submitted directly or via a preference signal, was received and honored. Records of opt-out handling help demonstrate compliance now that there is no cure period to fall back on.
Step 5: Require opt-in consent for sensitive data
Sensitive data carries an opt-in rule under Mont. Code Ann. 30-14-2812: a controller may not process sensitive data without first obtaining the consumer's consent. Consent must be a clear affirmative act that is freely given, specific, informed, and unambiguous, and it cannot be extracted through dark patterns or deceptive interface design. Pre-checked boxes and bundled consent do not meet the standard.
Sensitive data includes personal data revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis, sex life, sexual orientation, citizenship or immigration status, genetic or biometric data used to identify a person, personal data of a known child, and precise geolocation. The first compliance task here is identification: inventory your data and flag which fields fall into these categories, because you cannot apply an opt-in gate to data you have not located.
For a known child under 13, processing must follow the federal Children's Online Privacy Protection Act, and COPPA-compliant consent satisfies the MCDPA for that group. For older minors, the strengthened minor protections in the next section apply. Build the consent flow so that sensitive-data processing simply does not start until valid consent is captured and recorded.
Step 6: Conduct data protection assessments
The MCDPA requires controllers to conduct and document data protection assessments for processing activities that present a heightened risk of harm to consumers, under Mont. Code Ann. 30-14-2814. Covered activities include processing for targeted advertising, the sale of personal data, certain profiling, and the processing of sensitive data. The assessment must weigh the benefits of the processing against the potential risks to consumers, taking into account safeguards that mitigate those risks.
SB 297 increased the stakes by expanding the Attorney General's authority to require production of these assessments. An assessment is no longer just internal hygiene; the Attorney General may demand it during an investigation, and it must be made available in a way that does not waive attorney-client privilege or work-product protection. That means your assessments need to actually exist, be reasonably current, and be retrievable on request.
The companion provisions at Mont. Code Ann. 30-14-2818 and 30-14-2819, which apply without regard to the Step 1 thresholds, add a minor-specific assessment duty for processing that presents a heightened risk of harm to minors, and 30-14-2819 requires retaining those assessments for at least three years. A teen-facing service therefore carries documentation obligations on top of its consent obligations. Build a repeatable assessment template and run it whenever you launch a new high-risk processing activity rather than treating it as a one-time exercise.

Step 7: Put processor contracts and data security in place
When a controller engages a processor to handle personal data on its behalf, the MCDPA requires a binding contract that governs the processing. The contract must set out the processing instructions, the nature and purpose of processing, the type of data and duration, and obligations on the processor to maintain confidentiality, delete or return data at the end of the engagement, assist the controller with its obligations, and submit to reasonable audits. Review and paper your vendor relationships so each processor is under a compliant contract.
Controllers also owe a baseline data-security duty. The MCDPA requires controllers to establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal data at issue. There is no single prescribed standard, so the obligation scales with risk: more sensitive or higher-volume data calls for stronger safeguards.
Data minimization underlies both duties. The MCDPA limits collection to what is adequate, relevant, and reasonably necessary for the disclosed purposes, and bars processing for incompatible new purposes without consent. Keeping less data reduces both your security exposure and the scope of consumer requests you must service.
Step 8: Apply heightened safeguards for minors
SB 297 made minors a focal point of Montana compliance, and these duties are not gated by the applicability thresholds in Step 1: under Mont. Code Ann. 30-14-2803(2) they reach any business that conducts business in Montana or intentionally targets Montana residents, whatever its consumer count. Under Mont. Code Ann. 30-14-2811, for a consumer the controller knows is a minor, defined as an individual under 18, the controller may not process personal data for targeted advertising, the sale of personal data, or profiling without consent. The controller may not collect precise geolocation data unless reasonably necessary, and it must apply data minimization so a minor's data is not retained longer than reasonably necessary to provide the requested service.
These obligations reach further than COPPA, which generally governs children under 13, because Montana extends consent and processing limits to all known minors under 18. If your service is likely to be used by teenagers, build age-aware logic so that, once a user is known to be a minor, the targeted-advertising, sale, and profiling pathways are blocked absent consent. Pair that logic with the minor-specific data protection assessment required by Mont. Code Ann. 30-14-2819.
Document the controls. Because the Attorney General can require assessments and there is no cure period, a teen-facing business should be able to show what age signals it uses, what processing it restricts, and how it captures any consent. This is among the most demanding parts of the MCDPA as of 2026.
The bottom line: no cure period, real penalties
The single most important compliance fact for 2026 is that the safety net is gone, and it went earlier than the law's own original schedule anticipated. The MCDPA originally included a 60-day right to cure that was set to sunset 18 months after the effective date, on April 1, 2026, but SB 297 removed the cure mechanism early, effective October 1, 2025. The result should be stated plainly: as of October 1, 2025, there is no mandatory cure period, and the Montana Attorney General may bring an enforcement action without first sending a warning letter or allowing a business to fix the violation. (The current text of the penalty section, Mont. Code Ann. 30-14-2820(2), still references "the 30-day period described in 30-14-2817(3)," but that cross-reference is a holdover from the pre-SB 297 numbering; the current 30-14-2817(3) covers civil investigative demands, not a waiting period, so it does not restore a cure window.)
Enforcement runs through the Montana Unfair Trade Practices and Consumer Protection Act, with civil penalties up to $7,500 per violation under Mont. Code Ann. 30-14-2820, plus injunctive relief and the recovery of investigation and enforcement costs. SB 297 also expanded the Attorney General's investigative powers, including civil investigative demands and the authority to require production of data protection assessments. There is no private right of action, so enforcement is centralized in the Attorney General's office.
Because there is no longer a grace period, the practical advice is to close gaps before a complaint lands. Keep your applicability analysis, privacy notice, consent records, opt-out logs, processor contracts, and data protection assessments current and retrievable. A business that can demonstrate a working compliance program is in a far stronger position now that a first violation can lead directly to penalties.
Related guides
- Montana Data Privacy Laws hub
- What is the MCDPA?
- MCDPA Consumer Rights
- US State Privacy Laws Comparison
- What is the CCPA?
More Montana Laws
Frequently Asked Questions
How do I know if the MCDPA applies to my business?
As of 2026 most of the MCDPA applies if you conduct business in Montana or target Montana residents and control or process the personal data of 25,000 or more Montana consumers, or 15,000 or more if you derive over 25 percent of gross revenue from selling personal data (Mont. Code Ann. 30-14-2803(1)). Three minor-protection sections, 30-14-2811, 30-14-2818 and 30-14-2819, are carved out of those counts: under 30-14-2803(2) they apply to any business that targets Montana residents, regardless of size.
Why are Montana's thresholds a compliance concern in 2026?
SB 297 lowered the thresholds from 50,000 to 25,000 consumers, and from 25,000 to 15,000 for data sellers, effective October 1, 2025. They are now the lowest of any state privacy law, so businesses that were previously exempt should re-run the applicability test.
Do I still get a chance to fix a violation before enforcement?
No. The 60-day cure period was originally scheduled to sunset April 1, 2026, but SB 297 eliminated it early, effective October 1, 2025. The Montana Attorney General can now bring an enforcement action without sending a warning letter or allowing a cure, so there is no safety net.
What goes in an MCDPA privacy notice?
The notice must describe the categories of data processed, the purposes, how consumers exercise their rights and appeal, the categories of data shared, and the categories of third parties. If you sell data or use it for targeted advertising, you must disclose that and explain how to opt out.
What is the universal opt-out requirement?
Since January 1, 2025, controllers that process data for targeted advertising or sale must recognize an opt-out preference signal such as the Global Privacy Control and apply the opt-out automatically, without requiring the consumer to take further steps on your site.
When do I need a data protection assessment?
You must conduct and document assessments for higher-risk processing, including targeted advertising, sale, certain profiling, and sensitive data (Mont. Code Ann. 30-14-2814). After SB 297 the Attorney General can require these assessments during an investigation.
What are the penalties under the MCDPA?
Civil penalties run up to $7,500 per violation under Mont. Code Ann. 30-14-2820, enforced by the Attorney General through the Unfair Trade Practices Act, along with injunctive relief and recovery of enforcement costs. There is no private right of action.
What extra steps apply if my service reaches minors?
For consumers you know are under 18, you cannot process data for targeted advertising, sale, or profiling without consent, cannot collect precise geolocation unless reasonably necessary, and must minimize data (Mont. Code Ann. 30-14-2811). A minor-specific data protection assessment is also required.
Updates
Clarified that Montana's 25,000 and 15,000 consumer thresholds do not gate the MCDPA's minor-protection sections, and corrected the air-carrier exemption from an entity-level exemption to the narrow price, route, or service data carve-out at Mont. Code Ann. 30-14-2804(2)(p).
Removed an exemption for federally recognized tribes that does not exist in Mont. Code Ann. 30-14-2804, corrected the exemptions citation, and added the universal opt-out and assessment-retention pinpoint cites.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected the MCDPA cure-period end date: SB 297 eliminated it effective October 1, 2025 (not April 1, 2026, which was only the original law's now-superseded sunset date), and noted that the current penalty statute's residual "30-day period" cross-reference no longer describes an operative waiting period.
Governing law re-checked for recent changes
Corrected the MCDPA civil-penalty citation: the $7,500-per-violation figure is set by Mont. Code Ann. 30-14-2820 (the MCDPA-specific penalty provision), not 30-14-142 (a general Unfair Trade Practices Act section capping fines at $10,000).
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Montana Code Annotated, Title 30
§ 30-14-2812Data Processing By Controller -- LimitationsIn forcecited in 4 of our articles
30-14-2812. Data processing by controller -- limitations. (1) A controller shall: (a) limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which the personal data is processed, as disclosed to the consumer; (b) establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data appropriate to the volume and nature of the personal data at issue; and (c) provide an effective mechanism for a consumer to revoke the consumer's consent under this section that is at least as easy as the mechanism by which the consumer provided the consumer's consent and, on revocation of the consent, cease to process the personal data as soon as practicable, but not later than 45 days after the receipt of the request.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at mca.legmt.gov
Also relied on in: MCDPA Consumer Rights: Montana Privacy Rights (2026), What Is the MCDPA? Montana Data Privacy Law (2026), Montana Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 30-14-2803ApplicabilityIn forcecited in 3 of our articles
30-14-2803. Applicability. (1) The provisions of this part, excluding 30-14-2811, 30-14-2818, and 30-14-2819, apply to persons that conduct business in this state or persons that produce products or services that are targeted to residents of this state and: (a) control or process the personal data of not less than 25,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or (b) control or process the personal data of not less than 15,000 consumers and derive more than 25% of gross revenue from the sale of personal data. (2) Sections 30-14-2811, 30-14-2818, and 30-14-2819 apply to persons that conduct business in this state or deliver commercial products or services that are intentionally targeted to residents of this state.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at mca.legmt.gov
Also relied on in: Montana Data Privacy Laws: MCDPA Consumer Rights Guide (2026)
§ 30-14-2808Consumer Personal Data -- Opt-Out -- Compliance -- AppealsIn forcecited in 6 of our articles
30-14-2808. Consumer personal data -- opt-out -- compliance -- appeals. (1) A consumer must have the right to: (a) confirm whether a controller is processing the consumer's personal data and access the consumer's personal data, unless such confirmation or access would require the controller to reveal a trade secret; (b) correct inaccuracies in the consumer's personal data, considering the nature of the personal data and the purposes of the processing of the consumer's personal data; (c) delete personal data about the consumer; (d) obtain a copy of the consumer's personal data previously provided by the consumer to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the personal data to another controller without hindrance when the processing is carried out by automated means, provided the controller is not required to reveal any trade secret; and (e) opt out of the processing of the consumer's personal data for the purposes of: (i) targeted advertising; (ii) the sale of the consumer's personal data, except as provided in 30-14-2812(2); or (iii) profiling in furtherance of automated decisions that…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at mca.legmt.gov
Also relied on in: How to Request Your Personal Data: US Privacy Rights by State
§ 30-14-2811Duties Of Controllers -- Duty Of Care -- Rebuttable PresumptionIn forcecited in 3 of our articles
30-14-2811. Duties of controllers -- duty of care -- rebuttable presumption. (1) (a) A controller that offers an online service, product, or feature to a consumer whom the controller actually knows or willfully disregards is a minor shall use reasonable care to avoid a heightened risk of harm to minors caused by the online service, product, or feature. (b) In an enforcement action brought by the attorney general pursuant to 30-14-2817, there is a rebuttable presumption that a controller used reasonable care as required under this section if the controller complied with this section.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at mca.legmt.gov
§ 30-14-2814Data Protection AssessmentIn forcecited in 2 of our articles
30-14-2814. Data protection assessment. (1) A controller shall conduct and document a data protection assessment for each of the controller's processing activities that presents a heightened risk of harm to a consumer. For the purposes of this section, processing that presents a heightened risk of harm to a consumer includes: (a) the processing of personal data for the purposes of targeted advertising; (b) the sale of personal data; (c) the processing of personal data for the purposes of profiling in which the profiling presents a reasonably foreseeable risk of: (i) unfair or deceptive treatment of or unlawful disparate impact on consumers; (ii) financial, physical, or reputational injury to consumers; (iii) a physical or other form of intrusion on the solitude or seclusion or the private affairs or concerns of consumers in which the intrusion would be offensive to a reasonable person; or (iv) other substantial injury to consumers; and (d) the processing of sensitive data.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at mca.legmt.gov
§ 30-14-2820Civil Penalty InjunctionIn forcecited in 2 of our articles
30-14-2820. Civil penalty injunction. (1) A violation of this part is a violation of Title 30, chapter 14, parts 1 and 2. (2) A person who violates the provisions of this part following the 30-day period described in 30-14-2817(3) is liable for a civil penalty in an amount not to exceed $7,500 for each violation. (3) The attorney general may bring an action in the name of this state to: (a) recover a civil penalty under this section; (b) restrain or enjoin the person from violating this part; or (c) recover the civil penalty and seek injunctive relief. (4) The attorney general may recover reasonable attorney fees and other reasonable expenses incurred in investigating and bringing an action under this section. (5) The attorney general shall deposit a civil penalty collected under this section in a special revenue account to the credit of the department pursuant to 30-14-143.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at mca.legmt.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Mont. Code Ann. 30-14-2803, Applicability(mca.legmt.gov).gov
- Mont. Code Ann. 30-14-2808, Consumer personal data, opt-out, appeals(mca.legmt.gov).gov
- Mont. Code Ann. 30-14-2811, Duties of controllers, minors(mca.legmt.gov).gov
- Mont. Code Ann. 30-14-2812, Data processing limitations(mca.legmt.gov).gov
- Mont. Code Ann. 30-14-2814, Data protection assessment(mca.legmt.gov).gov
- Mont. Code Ann. 30-14-2820, Civil penalty injunction(mca.legmt.gov).gov
- Montana DOJ Office of Consumer Protection, Montana Consumer Data Privacy(dojmt.gov).gov
- Montana Legislature, SB 297 (2025 session)(bills.legmt.gov).gov
- Global Privacy Control technical specification(globalprivacycontrol.org)
- Mont. Code Ann. 30-14-2804, Exemptions(mca.legmt.gov)