Minnesota has become one of the strongest states in the U.S. for consumer data protection. The Minnesota Consumer Data Privacy Act took effect on 31 July 2025, joining a growing list of comprehensive state privacy statutes across the country.
Unlike several other state laws built on the same framework, the Minnesota Consumer Data Privacy Act introduces unique provisions around profiling, automated decision-making, and sensitive data governance. These additions make it one of the most detailed privacy regulations currently active.
This guide covers every major element of the law, from applicability thresholds and consumer rights to enforcement penalties and practical compliance steps. Whether you are a controller, processor, or privacy professional, this resource explains exactly what the MCDPA requires.
The Minnesota Consumer Data Privacy Act is a comprehensive state-level privacy law that gives Minnesota residents enforceable rights over their personal data. It regulates how businesses collect, process, store, share, and sell personal information belonging to state consumers.
Governor Tim Walz signed the MCDPA into law on 19 May 2024, making Minnesota the nineteenth state to enact a comprehensive consumer privacy statute. The full text is codified under Minnesota Statutes Chapter 325M, sections 325M.10 through 325M.21. It officially took effect on 31 July 2025.
While most state privacy laws follow a framework originating in Washington State, the MCDPA builds on that model with several important additions. These include a specific third-party list right, profiling transparency requirements, and mandatory universal opt-out signal recognition.
According to the Minnesota Attorney General’s Office, the MCDPA is considered among the strongest consumer data privacy laws in the country. It also requires businesses to appoint a privacy officer and maintain detailed data inventories.
| Feature | MCDPA (Minnesota) | CCPA (California) | VCDPA (Virginia) |
|---|---|---|---|
| Third Party List Right | Yes | No | No |
| Profiling Questioning Right | Yes | No | No |
| Universal Opt Out Signal | Required | Required | Optional |
| Privacy Officer Mandate | Yes | No | No |
| Sensitive Data Opt In | Yes | Yes | Yes |
| Private Right of Action | No | Limited | No |
| Cure Period | 30 days (expired Jan 2026) | 30 days | 30 days |
Not every business falls under the MCDPA. The law targets organisations that handle significant volumes of personal data belonging to Minnesota residents or that profit substantially from selling such data.
A business is subject to the MCDPA if it conducts business in Minnesota or deliberately targets products and services toward Minnesota residents. It must also meet one of two processing thresholds defined under the statute.
Education technology providers are also covered under specific provisions, regardless of whether they meet standard thresholds. Small businesses as defined by the U.S. Small Business Administration are exempt from most obligations under the law.
Several categories of organisations are excluded to prevent overlap with existing federal regulations. Understanding the difference between opt-in and opt-out requirements across these frameworks helps clarify where the MCDPA applies and where federal law takes precedence.
The MCDPA grants Minnesota residents a detailed set of enforceable rights. These rights give individuals practical control over how their personal data is collected, used, shared, and retained by businesses.
Consumers have the right to confirm whether a business is processing their personal data. They can also request access to the specific categories and individual pieces of data collected about them.
This right extends beyond a simple yes or no confirmation. Businesses must provide a detailed account of what data they hold, how it was obtained, and the purposes for which it is currently being used.
Minnesota residents can request corrections to inaccurate personal data held by a controller. They can also ask for complete deletion of their personal data, subject to certain legal exceptions such as ongoing contractual obligations.
Controllers must act on verified deletion requests within the legally specified timeframe. Understanding user consent and why it matters is essential for businesses handling these requests, as consent forms the foundation of lawful data processing under the MCDPA.
Consumers can request a copy of their personal data in a portable, readily usable, and machine-readable format. This allows individuals to transfer their information between service providers without losing access to their data.
One of the most distinctive rights under the MCDPA is the right to obtain a list of specific third parties to whom a controller has sold personal data. This goes well beyond the general category disclosures required by most state statutes.
This provision gives consumers significantly more transparency about exactly where their data ends up. No other active state privacy law in the U.S. currently offers this level of specificity for third-party data sale disclosures.
Minnesota residents can opt out of the sale of their personal data, targeted advertising based on their data, and profiling that produces legal or similarly significant effects. These opt-out rights apply across all processing activities.
Businesses that handle do not sell my personal information requests must ensure their opt-out mechanisms are accessible and functional. The MCDPA requires these preferences to be honoured without requiring consumers to create accounts.
The MCDPA contains some of the strongest protections against harmful data profiling in any U.S. state privacy law. These provisions target automated processes that evaluate, predict, or influence personal aspects of an individual’s life.
Profiling refers to any form of automated processing that uses personal data to evaluate, analyse, or predict characteristics about a person. This includes assessments of behaviour, preferences, economic status, health, reliability, location, or work performance.
The definition applies regardless of whether artificial intelligence is involved in the process. Any automated system that makes evaluative judgements about individuals based on personal data falls within the scope of this legal provision.
Consumers can opt out of profiling used to make automated decisions with legal or similarly significant effects. This includes decisions affecting access to housing, insurance, education, employment, healthcare, or financial services.
These protections represent a significant advancement over other state laws, which typically allow consumers to opt out of profiling but do not grant the right to question or challenge individual automated decisions.
The Minnesota Consumer Data Privacy Act defines sensitive data broadly and requires explicit opt-in consent before any collection or processing can take place. This standard is higher than the opt-out model used for non-sensitive personal data.
Sensitive data under the MCDPA includes information revealing racial or ethnic origin, religious beliefs, mental or physical health conditions, sexual orientation, and citizenship status. A detailed breakdown of what constitutes sensitive personal information helps businesses identify which data categories require heightened protection under the law.
Personal data of children under the age of 13 is automatically classified as sensitive under the MCDPA. Controllers must comply with both the MCDPA and the federal Children’s Online Privacy Protection Act when handling data belonging to known children.
For children and teenagers under 16, businesses must obtain verifiable parental or guardian consent before selling personal data or using it for targeted advertising. This provision adds an extra layer of protection beyond the standard opt-in requirements.
Compliance with the MCDPA requires businesses to implement structural changes across their data governance practices. These obligations cover privacy notices, data assessments, consumer request handling, and vendor management arrangements.
Controllers must publish a clear, accessible privacy notice disclosing the categories of personal data collected, the purposes for processing, and the categories of third parties with whom data is shared. The notice must explain consumer rights and provide contact details.
The privacy notice must include an email address or other electronic mechanism for consumers to exercise their rights. It must also disclose retention periods for each data category and identify whether any data is sold or used for targeted advertising.
Controllers must conduct formal data privacy and protection assessments for processing activities that present a heightened risk of harm. These assessments must be documented, regularly reviewed, and made available to the Minnesota Attorney General upon request.
Activities requiring a data protection assessment include processing sensitive data, conducting targeted advertising, selling personal data, and profiling that could result in unfair treatment, financial injury, reputational harm, or intrusion upon a consumer’s private affairs.
Businesses must respond to verified consumer requests within 45 days from the date of receipt. If a request is particularly complex or request volume is high, an extension of up to 45 additional days may be granted with proper notice to the consumer.
Controllers must also establish a clear appeals process for denied requests. If a consumer’s request is refused, the business must explain the reasons for denial and provide instructions for how the consumer can appeal the decision through the proper channel.
The MCDPA requires all covered controllers to recognise and honour universal opt-out signals, such as the Global Privacy Control. When a consumer activates this signal through their browser, it must be treated as a valid opt-out request for targeted advertising and data sales.
This requirement eliminates the need for consumers to individually adjust privacy preferences on every website they visit. It represents a significant step forward in practical privacy protection and aligns with the approach taken by California’s CCPA regulations.
Data processors must adhere to the instructions of the controller and assist with meeting obligations under the law. This includes supporting consumer rights requests, contributing to data protection assessments, and submitting to reasonable audits and inspections.
Vendor contracts must clearly define the scope and purpose of data processing. Processors must notify controllers promptly of any data breach or security incident that could affect personal data they handle on the controller’s behalf under the agreement.
The Minnesota Attorney General holds exclusive enforcement authority under the MCDPA. There is no private right of action, meaning individual consumers cannot file lawsuits against businesses directly for violations of the law.
The Attorney General’s Office can investigate complaints, issue cease and desist orders, impose civil penalties, and seek injunctive relief to halt ongoing noncompliance. The MCDPA included dedicated funding for four new attorneys and an investigator focused on enforcement.
Consumers can report suspected violations through the official PrivacyMN.com portal maintained by the Attorney General’s Office. This centralised reporting system streamlines enforcement and helps prioritise investigations based on complaint patterns and severity levels.
Each individual violation of the MCDPA can result in a civil penalty of up to 7,500 USD. When multiple consumers are affected by the same noncompliant practice, the financial exposure increases rapidly and can reach significant totals for businesses.
For the first six months after the law took effect, the Attorney General was required to provide written notice of alleged violations and grant businesses 30 days to cure the issue. This grace period expired on 31 January 2026.
Since the cure period has ended, businesses face immediate enforcement risk for violations. Organisations that have not yet aligned their practices should review how GDPR compares to CCPA and use those frameworks as a baseline for building a comprehensive privacy programme that also covers the MCDPA requirements.
Getting compliant with the Minnesota Consumer Data Privacy Act requires a structured approach across multiple areas of your business. The following checklist covers the most critical steps that controllers and processors should prioritise.
Even well-intentioned businesses can overlook critical requirements when adapting to the Minnesota Consumer Data Privacy Act. Awareness of these common pitfalls can help you avoid enforcement actions and protect your reputation.
The Minnesota Consumer Data Privacy Act represents a meaningful step forward in U.S. consumer privacy protection. Its unique provisions around profiling transparency, third-party disclosure, and universal opt-out signals set it apart from other state laws. With the cure period now expired, businesses that have not yet achieved full compliance face real enforcement risk. Taking action now protects both your organisation and the consumers who trust you with their personal data.
Managing privacy compliance across multiple state laws can feel overwhelming. Seers provides an AI-powered consent management platform that helps businesses meet MCDPA, GDPR, CCPA, and other regulatory requirements from a single dashboard. Get started today and simplify your compliance journey.
START FREE TODAYThe Minnesota Consumer Data Privacy Act is a comprehensive state privacy law granting Minnesota residents enforceable rights over their personal data. It was signed on 19 May 2024 and took full effect on 31 July 2025. The law regulates how businesses collect, process, store, and sell personal information. It also introduces unique provisions around profiling and automated decision-making not found in other states.
The MCDPA applies to businesses operating in Minnesota or targeting Minnesota residents that meet specific data processing thresholds. A business must either control or process personal data of at least 100,000 Minnesota consumers annually, or derive over 25 per cent of gross revenue from data sales while processing data of at least 25,000 consumers. Education technology providers are also covered.
The MCDPA provides some of the strongest profiling protections in any U.S. state privacy law. Consumers can opt out of profiling used for automated decisions affecting housing, employment, insurance, education, or healthcare. They can request detailed explanations of profiling decisions, review the data used, and ask for re-evaluation when inaccurate data influenced the outcome.
Each individual violation can result in a civil penalty of up to 7,500 USD. The Minnesota Attorney General has exclusive enforcement authority and can investigate complaints, issue cease and desist orders, and seek injunctive relief. There is no private right of action. When a single noncompliant practice affects many consumers, financial exposure escalates rapidly and can become substantial.
Yes, the MCDPA mandates that all covered controllers recognise universal opt-out mechanisms such as the Global Privacy Control. When activated through a web browser, this signal must be treated as a valid opt-out request for targeted advertising and data sales. This eliminates the need for consumers to adjust privacy preferences individually on every website they visit.
Sensitive data includes information revealing racial or ethnic origin, religious beliefs, health conditions, sexual orientation, citizenship or immigration status, biometric and genetic data. Financial account numbers, social security numbers, government identification numbers, and health insurance numbers also qualify. Personal data of children under 13 is automatically classified as sensitive under the MCDPA.
No, the cure period expired on 31 January 2026. During the initial six months, the Attorney General was required to issue written notice and grant 30 days for businesses to correct violations. Since February 2026, the Attorney General can pursue enforcement actions immediately without providing a cure opportunity. All businesses should ensure full compliance now.
Both laws grant consumers rights to access, delete, and opt out of data sales, but the MCDPA includes unique provisions not found in the CCPA. These include a right to obtain a list of specific third parties who received sold data, mandatory privacy officer appointment, and profiling questioning rights. The CCPA offers limited private right of action for data breaches while the MCDPA relies solely on Attorney General enforcement.
The most critical first step is conducting a comprehensive data mapping exercise to identify all personal data flows across your organisation. This includes understanding where data is collected, how it is stored, who it is shared with, and for what purposes. From there, update privacy notices, appoint a privacy officer, implement opt-out mechanisms, and conduct data protection assessments.
Yes, the MCDPA applies to any business targeting products or services toward Minnesota residents, regardless of physical location. If a company meets the data processing thresholds and deliberately directs commercial activities toward Minnesota consumers, it must comply with the law. This extraterritorial reach is consistent with most other comprehensive state privacy statutes currently active.
Rimsha ZafarRimsha is a Senior Content Writer at Seers AI with over 5 years of experience in advanced technologies and AI-driven tools. Her expertise as a research analyst shapes clear, thoughtful insights into responsible data use, trust, and future-facing technologies.