Author: Rimsha Zafar
July 23, 2025

Minnesota Consumer Data Privacy Act: Overview of Rights and Obligations

Minnesota has become one of the strongest states in the U.S. for consumer data protection. The Minnesota Consumer Data Privacy Act took effect on 31 July 2025, joining a growing list of comprehensive state privacy statutes across the country.

 

Unlike several other state laws built on the same framework, the Minnesota Consumer Data Privacy Act introduces unique provisions around profiling, automated decision-making, and sensitive data governance. These additions make it one of the most detailed privacy regulations currently active.

 

This guide covers every major element of the law, from applicability thresholds and consumer rights to enforcement penalties and practical compliance steps. Whether you are a controller, processor, or privacy professional, this resource explains exactly what the MCDPA requires.

What Is the Minnesota Consumer Data Privacy Act

The Minnesota Consumer Data Privacy Act is a comprehensive state-level privacy law that gives Minnesota residents enforceable rights over their personal data. It regulates how businesses collect, process, store, share, and sell personal information belonging to state consumers.

Legislative Background and Effective Date

Governor Tim Walz signed the MCDPA into law on 19 May 2024, making Minnesota the nineteenth state to enact a comprehensive consumer privacy statute. The full text is codified under Minnesota Statutes Chapter 325M, sections 325M.10 through 325M.21. It officially took effect on 31 July 2025.

How MCDPA Differs from Other State Privacy Laws

While most state privacy laws follow a framework originating in Washington State, the MCDPA builds on that model with several important additions. These include a specific third-party list right, profiling transparency requirements, and mandatory universal opt-out signal recognition.

 

According to the Minnesota Attorney General’s Office, the MCDPA is considered among the strongest consumer data privacy laws in the country. It also requires businesses to appoint a privacy officer and maintain detailed data inventories.

Comparison of Key State Privacy Law Features

Privacy Comparison Table
Feature MCDPA (Minnesota) CCPA (California) VCDPA (Virginia)
Third Party List Right Yes No No
Profiling Questioning Right Yes No No
Universal Opt Out Signal Required Required Optional
Privacy Officer Mandate Yes No No
Sensitive Data Opt In Yes Yes Yes
Private Right of Action No Limited No
Cure Period 30 days (expired Jan 2026) 30 days 30 days

Who Must Comply with the MCDPA

Not every business falls under the MCDPA. The law targets organisations that handle significant volumes of personal data belonging to Minnesota residents or that profit substantially from selling such data.

 

Applicability Thresholds

A business is subject to the MCDPA if it conducts business in Minnesota or deliberately targets products and services toward Minnesota residents. It must also meet one of two processing thresholds defined under the statute.

 

  • Controls or processes personal data of at least 100,000 Minnesota consumers during a calendar year.
  • Derives over 25 per cent of gross revenue from the sale of personal data and processes data of at least 25,000 Minnesota consumers.

 

Education technology providers are also covered under specific provisions, regardless of whether they meet standard thresholds. Small businesses as defined by the U.S. Small Business Administration are exempt from most obligations under the law.

Entities Exempt from the MCDPA

Several categories of organisations are excluded to prevent overlap with existing federal regulations. Understanding the difference between opt-in and opt-out requirements across these frameworks helps clarify where the MCDPA applies and where federal law takes precedence.

 

  • State and local government agencies
  • Tribal nations operating under separate sovereignty
  • Financial institutions already regulated under the Gramm-Leach-Bliley Act
  • Entities covered by the Health Insurance Portability and Accountability Act
  • Higher education institutions, which are exempt until 2029
  • Nonprofits, though not all types receive blanket exemptions

Consumer Rights Under the Minnesota Consumer Data Privacy Act

The MCDPA grants Minnesota residents a detailed set of enforceable rights. These rights give individuals practical control over how their personal data is collected, used, shared, and retained by businesses.

Right to Know and Access Personal Data

Consumers have the right to confirm whether a business is processing their personal data. They can also request access to the specific categories and individual pieces of data collected about them.

 

This right extends beyond a simple yes or no confirmation. Businesses must provide a detailed account of what data they hold, how it was obtained, and the purposes for which it is currently being used.

Right to Correction and Deletion

Minnesota residents can request corrections to inaccurate personal data held by a controller. They can also ask for complete deletion of their personal data, subject to certain legal exceptions such as ongoing contractual obligations.

 

Controllers must act on verified deletion requests within the legally specified timeframe. Understanding user consent and why it matters is essential for businesses handling these requests, as consent forms the foundation of lawful data processing under the MCDPA.

Right to Data Portability

Consumers can request a copy of their personal data in a portable, readily usable, and machine-readable format. This allows individuals to transfer their information between service providers without losing access to their data.

Right to a List of Third Parties

One of the most distinctive rights under the MCDPA is the right to obtain a list of specific third parties to whom a controller has sold personal data. This goes well beyond the general category disclosures required by most state statutes.

 

This provision gives consumers significantly more transparency about exactly where their data ends up. No other active state privacy law in the U.S. currently offers this level of specificity for third-party data sale disclosures.

Right to Opt Out of Targeted Advertising, Sales, and Profiling

Minnesota residents can opt out of the sale of their personal data, targeted advertising based on their data, and profiling that produces legal or similarly significant effects. These opt-out rights apply across all processing activities.

Businesses that handle do not sell my personal information requests must ensure their opt-out mechanisms are accessible and functional. The MCDPA requires these preferences to be honoured without requiring consumers to create accounts.

Profiling and Automated Decision Making Under the MCDPA

The MCDPA contains some of the strongest protections against harmful data profiling in any U.S. state privacy law. These provisions target automated processes that evaluate, predict, or influence personal aspects of an individual’s life.

What Counts as Profiling Under the Law

Profiling refers to any form of automated processing that uses personal data to evaluate, analyse, or predict characteristics about a person. This includes assessments of behaviour, preferences, economic status, health, reliability, location, or work performance.

 

The definition applies regardless of whether artificial intelligence is involved in the process. Any automated system that makes evaluative judgements about individuals based on personal data falls within the scope of this legal provision.

Consumer Rights Related to Profiling

Consumers can opt out of profiling used to make automated decisions with legal or similarly significant effects. This includes decisions affecting access to housing, insurance, education, employment, healthcare, or financial services.

 

  • Request a detailed explanation of how the profiling decision was made.
  • Review the personal data that was used in the profiling process.
  • Request a re-evaluation of any decision made using inaccurate or outdated data.
  • Opt out of profiling entirely for decisions producing significant effects.

 

These protections represent a significant advancement over other state laws, which typically allow consumers to opt out of profiling but do not grant the right to question or challenge individual automated decisions.

Children's Data Under the MCDPA

The Minnesota Consumer Data Privacy Act defines sensitive data broadly and requires explicit opt-in consent before any collection or processing can take place. This standard is higher than the opt-out model used for non-sensitive personal data.

What Qualifies as Sensitive Data

Sensitive data under the MCDPA includes information revealing racial or ethnic origin, religious beliefs, mental or physical health conditions, sexual orientation, and citizenship status. A detailed breakdown of what constitutes sensitive personal information helps businesses identify which data categories require heightened protection under the law.

 

  • Biometric data used for uniquely identifying an individual
  • Genetic data and health-related information
  • Precise geolocation data
  • Social security numbers and government-issued identification numbers
  • Financial account numbers and account passwords
  • Health insurance account numbers

Sensitive Data Categories and Protections

Personal data of children under the age of 13 is automatically classified as sensitive under the MCDPA. Controllers must comply with both the MCDPA and the federal Children’s Online Privacy Protection Act when handling data belonging to known children. 

 

For children and teenagers under 16, businesses must obtain verifiable parental or guardian consent before selling personal data or using it for targeted advertising. This provision adds an extra layer of protection beyond the standard opt-in requirements.

Business Obligations Under the Minnesota Consumer Data Privacy Act

Compliance with the MCDPA requires businesses to implement structural changes across their data governance practices. These obligations cover privacy notices, data assessments, consumer request handling, and vendor management arrangements.

Privacy Notice Requirements

Controllers must publish a clear, accessible privacy notice disclosing the categories of personal data collected, the purposes for processing, and the categories of third parties with whom data is shared. The notice must explain consumer rights and provide contact details.

 

The privacy notice must include an email address or other electronic mechanism for consumers to exercise their rights. It must also disclose retention periods for each data category and identify whether any data is sold or used for targeted advertising.

Data Protection Assessments

Controllers must conduct formal data privacy and protection assessments for processing activities that present a heightened risk of harm. These assessments must be documented, regularly reviewed, and made available to the Minnesota Attorney General upon request.

 

Activities requiring a data protection assessment include processing sensitive data, conducting targeted advertising, selling personal data, and profiling that could result in unfair treatment, financial injury, reputational harm, or intrusion upon a consumer’s private affairs.

Responding to Consumer Requests

Businesses must respond to verified consumer requests within 45 days from the date of receipt. If a request is particularly complex or request volume is high, an extension of up to 45 additional days may be granted with proper notice to the consumer.

 

Controllers must also establish a clear appeals process for denied requests. If a consumer’s request is refused, the business must explain the reasons for denial and provide instructions for how the consumer can appeal the decision through the proper channel.

Universal Opt Out Mechanism

The MCDPA requires all covered controllers to recognise and honour universal opt-out signals, such as the Global Privacy Control. When a consumer activates this signal through their browser, it must be treated as a valid opt-out request for targeted advertising and data sales.

 

This requirement eliminates the need for consumers to individually adjust privacy preferences on every website they visit. It represents a significant step forward in practical privacy protection and aligns with the approach taken by California’s CCPA regulations.

Processor and Vendor Obligations

Data processors must adhere to the instructions of the controller and assist with meeting obligations under the law. This includes supporting consumer rights requests, contributing to data protection assessments, and submitting to reasonable audits and inspections.

 

Vendor contracts must clearly define the scope and purpose of data processing. Processors must notify controllers promptly of any data breach or security incident that could affect personal data they handle on the controller’s behalf under the agreement.

Enforcement, Penalties, and the Cure Period

The Minnesota Attorney General holds exclusive enforcement authority under the MCDPA. There is no private right of action, meaning individual consumers cannot file lawsuits against businesses directly for violations of the law.

Role of the Minnesota Attorney General

The Attorney General’s Office can investigate complaints, issue cease and desist orders, impose civil penalties, and seek injunctive relief to halt ongoing noncompliance. The MCDPA included dedicated funding for four new attorneys and an investigator focused on enforcement.

 

Consumers can report suspected violations through the official PrivacyMN.com portal maintained by the Attorney General’s Office. This centralised reporting system streamlines enforcement and helps prioritise investigations based on complaint patterns and severity levels.

Civil Penalties and Financial Risk

Each individual violation of the MCDPA can result in a civil penalty of up to 7,500 USD. When multiple consumers are affected by the same noncompliant practice, the financial exposure increases rapidly and can reach significant totals for businesses.

 

  • Repeated violations of the same provision
  • Systematic failure to respond to consumer rights requests
  • Insufficient data protection documentation and assessments
  • Noncompliant privacy notices or missing contact mechanisms

The 30 Day Cure Period

For the first six months after the law took effect, the Attorney General was required to provide written notice of alleged violations and grant businesses 30 days to cure the issue. This grace period expired on 31 January 2026.

 

Since the cure period has ended, businesses face immediate enforcement risk for violations. Organisations that have not yet aligned their practices should review how GDPR compares to CCPA and use those frameworks as a baseline for building a comprehensive privacy programme that also covers the MCDPA requirements.

Practical Compliance Checklist for the MCDPA

Getting compliant with the Minnesota Consumer Data Privacy Act requires a structured approach across multiple areas of your business. The following checklist covers the most critical steps that controllers and processors should prioritise.

 

 

  • Conduct a full data mapping exercise to identify where personal data is collected, stored, processed, and shared across all systems.
  • Appoint a designated privacy officer responsible for overseeing MCDPA compliance and serving as primary contact for consumer requests.
  • Update your privacy notice to include all required disclosures, including data categories, processing purposes, third-party sharing, and retention periods.
  • Implement opt-out mechanisms for targeted advertising, data sales, and profiling, including support for universal opt-out signals like Global Privacy Control.
  • Establish documented procedures for responding to consumer access, correction, deletion, and portability requests within the 45-day statutory timeframe.
  • Conduct data protection assessments for all high-risk processing activities, including those involving sensitive data, profiling, and targeted advertising.
  • Review and update all processor and vendor contracts to ensure they include MCDPA-compliant terms around data handling, breach notification, and audit rights.
  • Train all relevant staff, particularly those in marketing, customer service, and IT, on the new requirements and consumer rights under the law.
  • Set up an appeals process for denied consumer requests, including clear communication about the reasons for denial and next steps available.
  • Establish a system for tracking and documenting all consumer requests and responses, as this documentation may be requested by the Attorney General.

Common Mistakes Businesses Make with MCDPA Compliance

Even well-intentioned businesses can overlook critical requirements when adapting to the Minnesota Consumer Data Privacy Act. Awareness of these common pitfalls can help you avoid enforcement actions and protect your reputation.

 

  • Treating the MCDPA as identical to the CCPA or VCDPA and failing to address Minnesota-specific requirements like third-party list rights and profiling provisions.
  • Neglecting to implement universal opt-out signal recognition, which is mandatory under the MCDPA and not optional as it is under some other state laws.
  • Using dark patterns or confusing interfaces that make it difficult for consumers to exercise their opt-out or deletion rights effectively.
  • Failing to conduct data protection assessments for processing activities that involve sensitive data or profiling of Minnesota consumers.
  • Not appointing a privacy officer or failing to include proper contact information and electronic mechanisms in the privacy notice.
  • Ignoring the special requirements for children’s data, which requires opt-in consent from parents or guardians for individuals under age 16.

Wrapping Up

The Minnesota Consumer Data Privacy Act represents a meaningful step forward in U.S. consumer privacy protection. Its unique provisions around profiling transparency, third-party disclosure, and universal opt-out signals set it apart from other state laws. With the cure period now expired, businesses that have not yet achieved full compliance face real enforcement risk. Taking action now protects both your organisation and the consumers who trust you with their personal data.

Stay MCDPA Compliant with Seers AI

Managing privacy compliance across multiple state laws can feel overwhelming. Seers provides an AI-powered consent management platform that helps businesses meet MCDPA, GDPR, CCPA, and other regulatory requirements from a single dashboard. Get started today and simplify your compliance journey.

START FREE TODAY

Frequently Asked Questions (FAQs)

What is the Minnesota Consumer Data Privacy Act and when did it take effect?

The Minnesota Consumer Data Privacy Act is a comprehensive state privacy law granting Minnesota residents enforceable rights over their personal data. It was signed on 19 May 2024 and took full effect on 31 July 2025. The law regulates how businesses collect, process, store, and sell personal information. It also introduces unique provisions around profiling and automated decision-making not found in other states.

Which businesses are required to comply with the MCDPA?

The MCDPA applies to businesses operating in Minnesota or targeting Minnesota residents that meet specific data processing thresholds. A business must either control or process personal data of at least 100,000 Minnesota consumers annually, or derive over 25 per cent of gross revenue from data sales while processing data of at least 25,000 consumers. Education technology providers are also covered.

How does the MCDPA handle profiling and artificial intelligence?

The MCDPA provides some of the strongest profiling protections in any U.S. state privacy law. Consumers can opt out of profiling used for automated decisions affecting housing, employment, insurance, education, or healthcare. They can request detailed explanations of profiling decisions, review the data used, and ask for re-evaluation when inaccurate data influenced the outcome.

What are the penalties for violating the Minnesota Consumer Data Privacy Act?

Each individual violation can result in a civil penalty of up to 7,500 USD. The Minnesota Attorney General has exclusive enforcement authority and can investigate complaints, issue cease and desist orders, and seek injunctive relief. There is no private right of action. When a single noncompliant practice affects many consumers, financial exposure escalates rapidly and can become substantial.

Does the MCDPA require businesses to recognise universal opt-out signals?

Yes, the MCDPA mandates that all covered controllers recognise universal opt-out mechanisms such as the Global Privacy Control. When activated through a web browser, this signal must be treated as a valid opt-out request for targeted advertising and data sales. This eliminates the need for consumers to adjust privacy preferences individually on every website they visit.

What types of data are classified as sensitive under the MCDPA?

Sensitive data includes information revealing racial or ethnic origin, religious beliefs, health conditions, sexual orientation, citizenship or immigration status, biometric and genetic data. Financial account numbers, social security numbers, government identification numbers, and health insurance numbers also qualify. Personal data of children under 13 is automatically classified as sensitive under the MCDPA.

Is the MCDPA cure period still active for businesses?

No, the cure period expired on 31 January 2026. During the initial six months, the Attorney General was required to issue written notice and grant 30 days for businesses to correct violations. Since February 2026, the Attorney General can pursue enforcement actions immediately without providing a cure opportunity. All businesses should ensure full compliance now.

How does the MCDPA compare to the California Consumer Privacy Act?

Both laws grant consumers rights to access, delete, and opt out of data sales, but the MCDPA includes unique provisions not found in the CCPA. These include a right to obtain a list of specific third parties who received sold data, mandatory privacy officer appointment, and profiling questioning rights. The CCPA offers limited private right of action for data breaches while the MCDPA relies solely on Attorney General enforcement.

What should businesses do first to prepare for MCDPA compliance?

The most critical first step is conducting a comprehensive data mapping exercise to identify all personal data flows across your organisation. This includes understanding where data is collected, how it is stored, who it is shared with, and for what purposes. From there, update privacy notices, appoint a privacy officer, implement opt-out mechanisms, and conduct data protection assessments.

Does the MCDPA apply to businesses located outside Minnesota?

Yes, the MCDPA applies to any business targeting products or services toward Minnesota residents, regardless of physical location. If a company meets the data processing thresholds and deliberately directs commercial activities toward Minnesota consumers, it must comply with the law. This extraterritorial reach is consistent with most other comprehensive state privacy statutes currently active. 

 

Rimsha Zafar

Rimsha is a Senior Content Writer at Seers AI with over 5 years of experience in advanced technologies and AI-driven tools. Her expertise as a research analyst shapes clear, thoughtful insights into responsible data use, trust, and future-facing technologies.

ORCIDResearchGateGoogle ScholarLinkedIn