🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
US-MN v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing15 sources retrieved model claude-sonnet-5 · 2026-08-05

Minnesota, USA

US-MN schema gdpri-v2 trajectory: not yet assessedhybrid regimeoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 44 claims · 25 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
44Claimsbaseline..claims[]
11Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Minnesota's Consumer Data Privacy Act entered a new enforcement posture this cycle. The Minnesota Attorney General's Office confirmed that the MCDPA's 30-day advance-notice cure period expired on January 31, 2026, and announced on February 5, 2026 that it can now bring enforcement actions against noncompliant controllers without giving prior notice or an opportunity to cure. Since the MCDPA took effect on July 31, 2025, the statute has carried exclusive enforcement authority with the Attorney General and no private right of action; the sunset of the cure period marks the transition from a notice-based posture, in which the Attorney General had to give written notice of noncompliance and thirty days to cure before acting, to a direct-enforcement posture aligned with the standard most other comprehensive state privacy laws have already reached.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A comprehensive, currently in-force consumer privacy statute exists with a clearly identified enforcement authority and confirmed statutory citation (Minn. Stat. ch. 325M).

Primary frameworkMinnesota Consumer Data Privacy Act (MCDPA), Minn. Stat. ch. 325M (2024, effective July 31, 2025)
Traffic-light rationale — GreenA comprehensive, currently in-force consumer privacy statute exists with a clearly identified enforcement authority and confirmed statutory citation (Minn. Stat. ch. 325M).

Sub-modules (5)

Regulator And AuthorityGreen

The AGO is the sole enforcement authority for the MCDPA; the Act is not privately enforceable.

Claims (1):

  • The Minnesota Attorney General's Office is the exclusive enforcement authority for the MCDPA, and the Act is not privately enforceable.

Act And InstrumentsGreen

MCDPA signed May 19, 2024, codified at Minn. Stat. ch. 325M, effective July 31, 2025.

Claims (1):

  • The Minnesota Consumer Data Privacy Act was signed into law on May 19, 2024, codified at Minnesota Statutes chapter 325M, and took effect July 31, 2025.

Material ScopeGreen

Applicability thresholds are volume/revenue-based (100,000 MN residents, or 25%+ revenue from data sales plus 25,000 residents); small businesses per SBA definition are exempt.

Claims (2):

  • The MCDPA applies to entities that control or process the personal data of 100,000 or more Minnesota residents, or that derive over 25% of revenue from selling personal data and process or control personal data of 25,000 or more consumers.
  • Small businesses as defined by the U.S. Small Business Administration are exempt from the MCDPA, and there is no full exemption for HIPAA- or GLBA-covered entities, though targeted exemptions exist for health and financial data processing.

Territorial ScopeAmber

Coverage is triggered by processing volume tied to Minnesota residents rather than the controller's physical location, giving the statute extraterritorial reach over out-of-state online businesses.

Claims (1):

  • MCDPA applicability is triggered by the volume of Minnesota residents' personal data controlled or processed rather than the controller's physical presence in Minnesota, giving the statute extraterritorial reach.

Regulator Registration And FilingAmber

No controller/processor registration or pre-processing filing obligation with the AGO was identified in AGO guidance materials reviewed.

Absence provenance: unavailable. Searched: ag.state.mn.us/Data-Privacy/, ag.state.mn.us/Data-Privacy/Business/Controller/, ag.state.mn.us/Data-Privacy/Business/Processor/.

Claims (1):

  • No provision requiring controllers to register with or file notices to the Minnesota AGO prior to processing personal data was identified in reviewed AGO guidance.
Category narrative83 words

Minnesota's data-protection landscape is anchored by the Minnesota Consumer Data Privacy Act (MCDPA), codified at Minnesota Statutes chapter 325M, which took effect July 31, 2025 and is enforced exclusively by the Minnesota Attorney General's Office (AGO). The statute applies to controllers/processors meeting Minnesota-resident-volume or data-sale-revenue thresholds, without a physical-presence nexus, and layers atop pre-existing sectoral and government-data statutes (e.g., the Minnesota Government Data Practices Act, Minn. Stat. ch. 13, which governs government-held data only and is out of scope for consumer-sector MCDPA obligations).

Sources and claims (6)
  1. ConfirmedMinnesota Attorney General's Office — The Minnesota Attorney General's Office is the exclusive enforcement authority for the MCDPA, and the Act is not privately enforceable.observed
  2. ConfirmedMinnesota Attorney General's Office — The Minnesota Consumer Data Privacy Act was signed into law on May 19, 2024, codified at Minnesota Statutes chapter 325M, and took effect July 31, 2025.observed
  3. ConfirmedMinnesota Attorney General's Office — The MCDPA applies to entities that control or process the personal data of 100,000 or more Minnesota residents, or that derive over 25% of revenue from selling personal data and process or control personal data of 25,000 or more consumers.observed
  4. ProbableInternational Association of Privacy Professionals — Small businesses as defined by the U.S. Small Business Administration are exempt from the MCDPA, and there is no full exemption for HIPAA- or GLBA-covered entities, though targeted exemptions exist for health and financial data processing.observed
  5. ProbableMinnesota Attorney General's Office — MCDPA applicability is triggered by the volume of Minnesota residents' personal data controlled or processed rather than the controller's physical presence in Minnesota, giving the statute extraterritorial reach.observed
  6. UncertainMinnesota Attorney General's Office — No provision requiring controllers to register with or file notices to the Minnesota AGO prior to processing personal data was identified in reviewed AGO guidance.observed

#

Strong sensitive-data consent gate exists, but there is no GDPR Art.6-style enumerated lawful-basis framework, and pseudonymisation/anonymisation safe-harbour detail beyond the de-identified-data carve-out was not independently verified against statutory text.

Primary frameworkMinnesota Consumer Data Privacy Act, Minn. Stat. ch. 325M
Traffic-light rationale — AmberStrong sensitive-data consent gate exists, but there is no GDPR Art.6-style enumerated lawful-basis framework, and pseudonymisation/anonymisation safe-harbour detail beyond the de-identified-data carve-out was not independently verified against statutory text.

Sub-modules (4)

Lawful BasesAmber

Processing is governed by collection-limitation/purpose-limitation duties rather than an enumerated lawful-basis list.

Claims (1):

  • The MCDPA's operative model relies on consent plus collection/purpose-limitation duties (limiting collection to what is necessary and disclosed) rather than an enumerated multi-basis lawful-processing framework analogous to GDPR Article 6.

Special CategoriesGreen

Sensitive data is defined broadly, including genetic and biometric data, health, and immigration status.

Claims (1):

  • MCDPA sensitive data includes race, ethnicity, religion, mental or physical health condition, sexual orientation, and precise geolocation, as well as genetic and biometric data, subject to enhanced consent requirements.

Pseudonymisation And AnonymisationAmber

De-identified data that cannot be linked to individuals, and publicly available data, fall outside the Act's collection/consent restrictions.

Claims (1):

  • The MCDPA does not restrict processing of de-identified data, defined as data that cannot be linked to individual consumers, nor data that is publicly available.
Category narrative60 words

The MCDPA does not adopt a GDPR-style enumerated multi-basis lawful-processing model; instead it relies on collection/purpose-limitation duties plus consent gates for sensitive data. Sensitive data is broadly defined (race, ethnicity, religion, health, sexuality, precise location, genetic and biometric data, citizenship/immigration status) and requires affirmative consumer consent before collection or sale. De-identified and publicly available data fall outside the Act's restrictions.

Sources and claims (4)
  1. ProbableMinnesota Attorney General's Office — The MCDPA's operative model relies on consent plus collection/purpose-limitation duties (limiting collection to what is necessary and disclosed) rather than an enumerated multi-basis lawful-processing framework analogous to GDPR Article 6.observed
  2. ConfirmedMinnesota Attorney General's Office — Controllers must obtain a consumer's affirmative consent before collecting or processing sensitive data, including specific location data or data revealing mental or physical health conditions or citizenship/immigration status.observed
  3. ConfirmedMinnesota Attorney General's Office — MCDPA sensitive data includes race, ethnicity, religion, mental or physical health condition, sexual orientation, and precise geolocation, as well as genetic and biometric data, subject to enhanced consent requirements.observed
  4. ConfirmedMinnesota Attorney General's Office — The MCDPA does not restrict processing of de-identified data, defined as data that cannot be linked to individual consumers, nor data that is publicly available.observed

#

Rights are clearly enumerated by the regulator with a defined statutory response deadline (45 days) and complaint escalation path.

Primary frameworkMinnesota Consumer Data Privacy Act, Minn. Stat. ch. 325M, §325M.14
Traffic-light rationale — GreenRights are clearly enumerated by the regulator with a defined statutory response deadline (45 days) and complaint escalation path.

Sub-modules (5)

Access RightGreen

Consumers may access data held about them and obtain a list of specific third parties their data was sold to.

Claims (1):

  • Minnesota consumers have rights to know what data a company holds about them and to obtain a list of specific third parties to which their data has been sold.

Rectification And ErasureGreen

Consumers may correct inaccurate data and request deletion of personal/sensitive data.

Claims (1):

  • Consumers have the right to request correction of inaccurate data and deletion of their personal and sensitive data held by a business.

Restriction And ObjectionGreen

Consumers may opt out of sale, targeted advertising, and profiling, including profiling feeding automated decisions.

Claims (1):

  • Consumers may opt out of the sale of their personal data, use of their data for targeted advertising, and profiling, including profiling used in automated decision-making.

Data PortabilityGreen

The rights package includes a right to obtain a copy of one's data, per the AGO's own rights summary.

Claims (1):

  • The Act's consumer rights structure includes a right to obtain a copy of one's data in addition to rights to a third-party disclosure list, opt-out, access, correction, and deletion.

Deadlines And Response WindowsGreen

Businesses must respond to rights requests within 45 days; non-response triggers an AGO complaint pathway.

Claims (1):

  • Businesses must respond to consumer rights requests within 45 days, and consumers may file a complaint with the Attorney General's Office if a business fails to respond within that window.
Category narrative70 words

The MCDPA grants Minnesota consumers a materially complete rights package summarized by the AGO as 'LOCKED+': a list of third parties data was sold to, opt-out of sale/targeted-advertising/profiling, a copy of data held, knowledge of what is held, edit/correction rights, deletion rights, plus the right to question profiling and automated decisions. Businesses must respond to rights requests within 45 days, with a consumer complaint route to the AGO for non-response.

Sources and claims (5)
  1. ConfirmedMinnesota Attorney General's Office — Minnesota consumers have rights to know what data a company holds about them and to obtain a list of specific third parties to which their data has been sold.observed
  2. ConfirmedMinnesota Attorney General's Office — Consumers have the right to request correction of inaccurate data and deletion of their personal and sensitive data held by a business.observed
  3. ConfirmedMinnesota Attorney General's Office — Consumers may opt out of the sale of their personal data, use of their data for targeted advertising, and profiling, including profiling used in automated decision-making.observed
  4. ProbableInternational Association of Privacy Professionals — The Act's consumer rights structure includes a right to obtain a copy of one's data in addition to rights to a third-party disclosure list, opt-out, access, correction, and deletion.observed
  5. ConfirmedMinnesota Attorney General's Office — Businesses must respond to consumer rights requests within 45 days, and consumers may file a complaint with the Attorney General's Office if a business fails to respond within that window.observed

#

Core accountability, assessment, processor-contract, and breach-notification duties are well evidenced from AGO guidance; DPO/ROPA specifics rely on pre-enactment secondary analysis and were not independently verified against final statute text.

Primary frameworkMinnesota Consumer Data Privacy Act, Minn. Stat. ch. 325M, §325M.13
Traffic-light rationale — AmberCore accountability, assessment, processor-contract, and breach-notification duties are well evidenced from AGO guidance; DPO/ROPA specifics rely on pre-enactment secondary analysis and were not independently verified against final statute text.

Sub-modules (7)

Accountability And DpiaGreen

Businesses must conduct data protection assessments and maintain data security practices.

Claims (1):

  • Businesses subject to the MCDPA must conduct data protection/privacy assessments and maintain data security practices to protect personal data.

Dpo RequirementsAmber

Pre-enactment IAPP analysis suggested an implied obligation to name a chief privacy officer or equivalent contact; not independently confirmed against final AGO guidance.

Absence provenance: unavailable. Searched: ag.state.mn.us/Data-Privacy/Business/Controller/.

Claims (1):

  • Pre-enactment IAPP commentary on the MCDPA bill identified an implied obligation for covered entities to name a chief privacy officer or other individual with primary responsibility for privacy policies and procedures.

Ropa RequirementsAmber

No standalone records-of-processing obligation distinct from the data protection assessment duty was identified.

Absence provenance: unavailable. Searched: ag.state.mn.us/Data-Privacy/Business/Controller/, ag.state.mn.us/Data-Privacy/Business/Processor/.

Joint Controller ArrangementsGreen

Processor contracts must allocate responsibilities and support controller compliance and assessment obligations.

Claims (1):

  • Processor contracts under the MCDPA must require processors to assist controllers with security of processing, breach notifications, and data protection assessments, and must clearly allocate responsibilities between controller and processor.

Security MeasuresGreen

Processors must implement technical/organizational measures appropriate to processing risk.

Claims (1):

  • Processors must implement appropriate technical and organizational measures to ensure security appropriate to the risk of processing, and allow controller-directed assessments and inspections.

Breach NotificationAmber

Processors must notify controllers of security breaches; Minnesota's general breach-notification statute (Minn. Stat. §325E.61) independently requires notice to affected residents, though full statutory text was not retrieved in this pass.

Claims (2):

  • Processors must provide notification to controllers upon a breach of the security of systems used to protect personal data, as part of MCDPA processor obligations.
  • Minnesota maintains a separate general data-breach-notification statute (Minn. Stat. §325E.61 et seq.) applicable to entities holding Minnesotans' personal information, distinct from MCDPA processor-to-controller notice duties.

Retention And DisposalGreen

Businesses may not retain data beyond what is relevant and reasonably necessary for the disclosed purpose.

Claims (1):

  • Businesses may not retain personal data longer than is relevant and reasonably necessary for the disclosed purpose.
Category narrative64 words

Controllers must run data protection/privacy assessments, limit collection and retention to disclosed necessary purposes, and maintain risk-appropriate security. Processor contracts must impose breach-notification assistance, security cooperation, assessment-support, and audit/inspection rights, with a clear allocation of responsibilities. Evidence of a formal, freestanding ROPA obligation or an independent statutory DPO/chief-privacy-officer mandate (as opposed to a named privacy contact) was not conclusively confirmed against enacted statutory text.

Sources and claims (7)
  1. ConfirmedMinnesota Attorney General's Office — Businesses subject to the MCDPA must conduct data protection/privacy assessments and maintain data security practices to protect personal data.observed
  2. UncertainInternational Association of Privacy Professionals — Pre-enactment IAPP commentary on the MCDPA bill identified an implied obligation for covered entities to name a chief privacy officer or other individual with primary responsibility for privacy policies and procedures.observed
  3. ConfirmedMinnesota Attorney General's Office — Processor contracts under the MCDPA must require processors to assist controllers with security of processing, breach notifications, and data protection assessments, and must clearly allocate responsibilities between controller and processor.observed
  4. ConfirmedMinnesota Attorney General's Office — Processors must implement appropriate technical and organizational measures to ensure security appropriate to the risk of processing, and allow controller-directed assessments and inspections.observed
  5. ConfirmedMinnesota Attorney General's Office — Processors must provide notification to controllers upon a breach of the security of systems used to protect personal data, as part of MCDPA processor obligations.observed
  6. UncertainOneTrust DataGuidance — Minnesota maintains a separate general data-breach-notification statute (Minn. Stat. §325E.61 et seq.) applicable to entities holding Minnesotans' personal information, distinct from MCDPA processor-to-controller notice duties.observed
  7. ConfirmedMinnesota Attorney General's Office — Businesses may not retain personal data longer than is relevant and reasonably necessary for the disclosed purpose.observed

#

This module is structurally inapplicable to a US state consumer-privacy statute; explicit absence confirmed via AGO guidance review rather than an unexamined gap.

Primary frameworkMinnesota Consumer Data Privacy Act, Minn. Stat. ch. 325M
Traffic-light rationale — RedThis module is structurally inapplicable to a US state consumer-privacy statute; explicit absence confirmed via AGO guidance review rather than an unexamined gap.

Sub-modules (6)

Transfer MechanismsRed

No transfer-mechanism regime beyond controller-processor contracts identified.

Claims (1):

  • The MCDPA does not establish an EU-style cross-border transfer regime; it imposes controller-processor contractual requirements and consumer rights but contains no identified adequacy determination, SCC/BCR mechanism, transfer impact assessment requirement, or data-localization mandate.

Adequacy ReceivedRed

Not applicable; no adequacy concept in MCDPA.

Absence provenance: unavailable. Searched: ag.state.mn.us/Data-Privacy/.

Adequacy GrantedRed

Not applicable; no adequacy concept in MCDPA.

Absence provenance: unavailable. Searched: ag.state.mn.us/Data-Privacy/.

Sccs And BcrsRed

No SCC/BCR uptake mechanism identified; not part of MCDPA structure.

Absence provenance: unavailable. Searched: ag.state.mn.us/Data-Privacy/Business/Contracts/.

Transfer Impact AssessmentRed

No TIA requirement identified.

Absence provenance: unavailable. Searched: ag.state.mn.us/Data-Privacy/Business/Controller/.

Data LocalisationRed

No data-localisation mandate identified.

Absence provenance: unavailable. Searched: ag.state.mn.us/Data-Privacy/.

Category narrative48 words

As a US state consumer-privacy statute, the MCDPA does not include an EU/GDPR-style cross-border transfer regime. No adequacy-determination mechanism (received or granted), standard contractual clauses/BCR framework, transfer impact assessment requirement, or data-localisation mandate was identified in AGO guidance; the statute's only cross-entity control is the controller-processor contract requirement.

Sources and claims (1)
  1. ProbableMinnesota Attorney General's Office — The MCDPA does not establish an EU-style cross-border transfer regime; it imposes controller-processor contractual requirements and consumer rights but contains no identified adequacy determination, SCC/BCR mechanism, transfer impact assessment requirement, or data-localization mandate.observed

#

Financial, health, and education overlays are evidenced; several other sectors carry unresolved gaps requiring primary-source verification.

Primary frameworkMinnesota Consumer Data Privacy Act, Minn. Stat. ch. 325M (sectoral overlay with HIPAA, GLBA, COPPA)
Traffic-light rationale — AmberFinancial, health, and education overlays are evidenced; several other sectors carry unresolved gaps requiring primary-source verification.

Sub-modules (7)

Financial Sector OverlayAmber

Targeted exemption for GLBA-covered financial data processing; no full entity-level exemption.

Claims (1):

  • The MCDPA provides no full exemption for GLBA-covered financial institutions but includes targeted exemptions for financial data processing.

Health Sector OverlayAmber

Targeted exemption for HIPAA-covered health data processing; no full entity-level exemption; historical multistate health-breach enforcement precedent exists (Inmediata, 2023, pre-MCDPA).

Claims (2):

  • The MCDPA provides no full exemption for HIPAA-covered entities but includes targeted exemptions for health data processing.
  • In 2023, the Minnesota Attorney General joined a 32-state settlement with health-data clearinghouse Inmediata over a multi-year breach of protected health information affecting approximately 113,000 Minnesota residents, predating MCDPA but illustrating active health-data enforcement posture.

Telecoms And EprivacyRed

No MCDPA-specific ePrivacy/telecoms overlay identified.

Absence provenance: unavailable. Searched: ag.state.mn.us MCDPA business guidance pages.

Employment DataRed

Employment/B2B data exclusion status under MCDPA was not confirmed via retrieved sources.

Absence provenance: unavailable. Searched: ag.state.mn.us MCDPA business/controller guidance.

Credit And ScoringRed

FCRA-adjacent credit-scoring exemption status not confirmed.

Absence provenance: unavailable. Searched: ag.state.mn.us MCDPA guidance.

EducationAmber

Certain education technology providers are subject to MCDPA irrespective of general thresholds.

Claims (1):

  • Certain education technology providers are subject to the MCDPA regardless of the general consumer-volume thresholds applicable to other controllers.

InsuranceRed

No insurance-sector-specific overlay identified.

Absence provenance: unavailable. Searched: ag.state.mn.us MCDPA guidance.

Category narrative56 words

The MCDPA does not fully exempt GLBA-covered financial institutions or HIPAA-covered health entities, instead layering targeted (data-level) exemptions on top of those federal regimes. Certain education-technology providers are subject to the MCDPA regardless of the general volume thresholds. Telecoms/ePrivacy, employment-data, credit/scoring, and insurance-specific overlays were not confirmed via retrievable AGO or T1/T2 sources in this pass.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (4)
  1. ProbableInternational Association of Privacy Professionals — The MCDPA provides no full exemption for GLBA-covered financial institutions but includes targeted exemptions for financial data processing.observed
  2. ProbableInternational Association of Privacy Professionals — The MCDPA provides no full exemption for HIPAA-covered entities but includes targeted exemptions for health data processing.observed
  3. ConfirmedMinnesota Attorney General's Office — In 2023, the Minnesota Attorney General joined a 32-state settlement with health-data clearinghouse Inmediata over a multi-year breach of protected health information affecting approximately 113,000 Minnesota residents, predating MCDPA but illustrating active health-data enforcement posture.observed
  4. ProbableMinnesota Attorney General's Office — Certain education technology providers are subject to the MCDPA regardless of the general consumer-volume thresholds applicable to other controllers.observed

#

Universal opt-out and targeted-advertising opt-out are strongly evidenced; dark patterns and clean-room provisions remain unconfirmed gaps.

Primary frameworkMinnesota Consumer Data Privacy Act, Minn. Stat. ch. 325M
Traffic-light rationale — AmberUniversal opt-out and targeted-advertising opt-out are strongly evidenced; dark patterns and clean-room provisions remain unconfirmed gaps.

Sub-modules (6)

Cookies And TrackersGreen

Universal opt-out mechanisms operate via browser-level signals affecting tracking/targeted-ad collection.

Claims (1):

  • The MCDPA requires businesses to honor universal opt-out mechanisms (browser-based signals) that communicate a consumer's opt-out of targeted advertising and data collection/sale across websites.

Dark PatternsRed

No MCDPA-specific dark-pattern prohibition confirmed via retrieved sources.

Absence provenance: unavailable. Searched: ag.state.mn.us MCDPA consumer/business pages.

Opt Out SignalsGreen

Businesses must honor universal opt-out preference signals.

Claims (1):

  • The MCDPA requires businesses to honor universal opt-out mechanisms (browser-based signals) that communicate a consumer's opt-out of targeted advertising and data collection/sale across websites.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rule identified.

Absence provenance: unavailable. Searched: ag.state.mn.us MCDPA business guidance.

Cross Context AdvertisingGreen

Consumers may opt out of sale and targeted advertising use of their personal data.

Claims (1):

  • Consumers have the right to opt out of the sale of personal data and its use for targeted advertising.

Direct MarketingAmber

Direct-marketing-specific suppression rules beyond the general targeted-advertising opt-out were not separately confirmed.

Claims (1):

  • Consumers have the right to opt out of the sale of personal data and its use for targeted advertising.
Category narrative39 words

The MCDPA mandates honoring browser-based universal opt-out mechanisms (GPC-style signals) for targeted advertising and data-sale opt-out, and grants a direct consumer opt-out right for sale/targeted-advertising/profiling. Dark-pattern-specific prohibitions and clean-room/data-collaboration-room rules were not confirmed via retrieved AGO or T1/T2 sources.

Sources and claims (2)
  1. ConfirmedMinnesota Attorney General's Office — The MCDPA requires businesses to honor universal opt-out mechanisms (browser-based signals) that communicate a consumer's opt-out of targeted advertising and data collection/sale across websites.observed
  2. ConfirmedMinnesota Attorney General's Office — Consumers have the right to opt out of the sale of personal data and its use for targeted advertising.observed

#

Profiling/ADM rights are strongly evidenced and materially significant; biometric/genetic standalone-regime status and state-surveillance carve-outs remain unresolved gaps.

Primary frameworkMinnesota Consumer Data Privacy Act, Minn. Stat. ch. 325M, §325M.14
Traffic-light rationale — AmberProfiling/ADM rights are strongly evidenced and materially significant; biometric/genetic standalone-regime status and state-surveillance carve-outs remain unresolved gaps.

Sub-modules (6)

Profiling RestrictionsGreen

Consumers may opt out of profiling in furtherance of decisions with legal or similarly significant effects.

Claims (1):

  • Minnesota's Attorney General has characterized the MCDPA as providing some of the nation's strongest protections against harmful data profiling and automated decision-making, including a consumer right to opt out of profiling used in furtherance of significant decisions.

Automated Decision Making TransparencyGreen

Consumers may request the reasoning and underlying data behind a profiling/automated decision, including AI-facilitated decisions.

Claims (1):

  • Consumers may request information regarding a profiling or automated decision made about them, including the reasoning behind the decision and the data used to reach it, and may question automated decisions facilitated by artificial intelligence.

Ai Risk AssessmentsAmber

The Act creates rights intended to prevent AI/automated systems from depriving residents of critical goods and services.

Claims (1):

  • The MCDPA creates rights intended to ensure that AI and automated systems cannot deprive Minnesota residents of critical goods and services.

Biometric RegimeAmber

Biometric data is a sensitive-data category requiring consent; a standalone biometric-specific statute status is unconfirmed.

Absence provenance: unavailable. Searched: dataguidance.com Minnesota biometric bill pages (no retrievable content).

Claims (1):

  • Biometric data is classified as sensitive data under the MCDPA and subject to consent requirements before collection; no standalone biometric-specific statute comparable to Illinois' BIPA has been confirmed as currently enacted in Minnesota.

Genetic DataAmber

Genetic data is a sensitive-data category requiring consent; separate government-data-practices genetic provisions (Minn. Stat. §13.386) exist but full text was not retrieved.

Absence provenance: unavailable. Searched: dataguidance.com Minnesota Statutes section 13.386 page (no retrievable content).

Claims (1):

  • Genetic data is classified as sensitive data under the MCDPA requiring consumer consent before collection; Minnesota separately maintains government-data-practices provisions addressing genetic information (Minn. Stat. §13.386), though current text of that provision was not independently retrieved.

State Surveillance CarveoutsRed

No MCDPA government/law-enforcement exemption language was confirmed via retrieved sources.

Absence provenance: unavailable. Searched: ag.state.mn.us MCDPA business/controller guidance.

Category narrative86 words

The AGO has characterized the MCDPA as one of the nation's strongest statutes against harmful profiling and automated decision-making, granting consumers a right to question and obtain the reasoning/data behind profiling decisions and to opt out of profiling in furtherance of legally or similarly significant decisions, including AI-facilitated decisions. Genetic and biometric data are classified as sensitive data requiring consent, but standalone biometric- or genetic-specific statutes (comparable to Illinois' BIPA) and government/law-enforcement surveillance carve-outs were not independently confirmed as currently enacted MCDPA provisions in this pass.

Sources and claims (5)
  1. ConfirmedMinnesota Attorney General's Office — Minnesota's Attorney General has characterized the MCDPA as providing some of the nation's strongest protections against harmful data profiling and automated decision-making, including a consumer right to opt out of profiling used in furtherance of significant decisions.observed
  2. ConfirmedMinnesota Attorney General's Office — Consumers may request information regarding a profiling or automated decision made about them, including the reasoning behind the decision and the data used to reach it, and may question automated decisions facilitated by artificial intelligence.observed
  3. ProbableMinnesota Attorney General's Office — The MCDPA creates rights intended to ensure that AI and automated systems cannot deprive Minnesota residents of critical goods and services.observed
  4. UncertainMinnesota Attorney General's Office — Biometric data is classified as sensitive data under the MCDPA and subject to consent requirements before collection; no standalone biometric-specific statute comparable to Illinois' BIPA has been confirmed as currently enacted in Minnesota.observed
  5. UncertainMinnesota Attorney General's Office — Genetic data is classified as sensitive data under the MCDPA requiring consumer consent before collection; Minnesota separately maintains government-data-practices provisions addressing genetic information (Minn. Stat. §13.386), though current text of that provision was not independently retrieved.observed

#

Children's-data provisions are clearly documented by the regulator with specific age thresholds and guardianship extension.

Primary frameworkMinnesota Consumer Data Privacy Act, Minn. Stat. ch. 325M (with COPPA, 15 U.S.C. §§6501-6506, cross-reference)
Traffic-light rationale — GreenChildren's-data provisions are clearly documented by the regulator with specific age thresholds and guardianship extension.

Sub-modules (5)

Age VerificationAmber

No standalone age-verification mandate identified beyond 'known child'/'known consumer age 13-16' actual-knowledge standards.

Claims (1):

  • Controllers may not process a consumer's personal data for targeted advertising or sell that consumer's personal data without the consumer's consent where the controller knows the consumer is between 13 and 16 years of age.

Minor Profiling BansAmber

Consent (rather than an outright ban) is required for targeted advertising/sale involving consumers known to be 13-16.

Claims (1):

  • Controllers may not process a consumer's personal data for targeted advertising or sell that consumer's personal data without the consumer's consent where the controller knows the consumer is between 13 and 16 years of age.

Education SettingsAmber

Certain education technology providers are covered by the MCDPA regardless of general applicability thresholds.

Claims (1):

  • Certain education technology providers are subject to the MCDPA regardless of the general applicability thresholds, extending coverage into student-data contexts.

Dependent AdultsGreen

Consumers may exercise MCDPA rights on behalf of persons under their guardianship or conservatorship.

Claims (1):

  • The MCDPA allows consumers to exercise their statutory rights on behalf of their children or any person over whom the consumer has guardianship or conservatorship.
Category narrative65 words

The MCDPA requires parental/guardian consent before processing a 'known child's' personal data (with limited exceptions) and COPPA compliance, plus an opt-in consent requirement for targeted advertising or sale of data for consumers known to be 13-16 years old. Certain education technology providers are covered regardless of general thresholds, and the Act permits consumers to exercise rights on behalf of children or persons under their guardianship/conservatorship.

Sources and claims (4)
  1. ConfirmedMinnesota Attorney General's Office — Controllers may not process a consumer's personal data for targeted advertising or sell that consumer's personal data without the consumer's consent where the controller knows the consumer is between 13 and 16 years of age.observed
  2. ConfirmedMinnesota Attorney General's Office — Controllers may not process the personal data concerning a known child without obtaining consent from the child's parent or lawful guardian (with limited exceptions), and must comply with COPPA.observed
  3. ProbableMinnesota Attorney General's Office — Certain education technology providers are subject to the MCDPA regardless of the general applicability thresholds, extending coverage into student-data contexts.observed
  4. ConfirmedMinnesota Attorney General's Office — The MCDPA allows consumers to exercise their statutory rights on behalf of their children or any person over whom the consumer has guardianship or conservatorship.observed

#

Enforcement powers, penalties, and activity are well documented and robust, but the absence of a private right of action and expiration of the cure period both materially shift risk allocation, and no collective-redress mechanism exists.

Primary frameworkMinnesota Consumer Data Privacy Act, Minn. Stat. ch. 325M
Traffic-light rationale — AmberEnforcement powers, penalties, and activity are well documented and robust, but the absence of a private right of action and expiration of the cure period both materially shift risk allocation, and no collective-redress mechanism exists.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

AGO may seek injunctive relief, litigation costs, and civil penalties up to $7,500/violation.

Claims (1):

  • The Minnesota Attorney General may seek injunctive relief, litigation expenses, and civil penalties of up to $7,500 per violation against MCDPA violators.

Enforcement Activity IndexAmber

Hundreds of education letters and dozens of warning letters sent since July 2025; cure period sunset January 31, 2026.

Claims (1):

  • Since the MCDPA took effect, the Attorney General's Office sent hundreds of education letters and dozens of formal warning letters to companies regarding privacy policy, consent, and universal opt-out compliance issues, and the Act's mandatory pre-enforcement cure/notice period expired on January 31, 2026.

Regulator Funding And CapacityGreen

MCDPA funded four new AGO attorneys plus an investigator dedicated to enforcement.

Claims (1):

  • The MCDPA included funding for the Attorney General's Office to hire four new attorneys and an investigator focused primarily on enforcing the Act, placing Minnesota among the most heavily resourced state privacy enforcers per independent industry analysis.

Collective Redress And Class ActionsRed

No collective-redress/class-action mechanism specific to MCDPA identified; enforcement is AGO-exclusive.

Claims (1):

  • No collective-redress or class-action mechanism specific to MCDPA enforcement has been identified; enforcement is vested exclusively in the Attorney General.

Private Right Of ActionRed

The MCDPA contains no private right of action.

Claims (1):

  • The MCDPA contains no private right of action; only the Attorney General may enforce the Act.

Recent Developments 180DAmber

June 2026: Minnesota joined an 18-attorney-general coalition opposing the federal SECURE Data Act on preemption grounds.

Claims (1):

  • In June 2026, Minnesota joined a coalition of 18 attorneys general and agencies opposing the proposed federal SECURE Data Act, with the Minnesota AGO stating the bill would preempt and weaken protections under the state's Consumer Data Privacy Act.
Category narrative112 words

The AGO holds exclusive investigative and enforcement authority, able to seek injunctive relief, litigation expenses, and civil penalties up to $7,500 per violation; the Act carries no private right of action or identified class-action mechanism. A mandatory 30-day cure/notice period sunset on January 31, 2026, after which the AGO may bring enforcement actions without prior warning. The office was funded to add four attorneys and an investigator, and has sent hundreds of education letters and dozens of formal warning letters since the Act took effect. Within the last 180 days, Minnesota joined an 18-state coalition opposing the proposed federal SECURE Data Act, which the AGO says would preempt and weaken MCDPA protections.

Periodic update · new data 2026-09-28

Enforcement & Redress

The Minnesota Consumer Data Privacy Act's cure-period provision, which required the Attorney General to give written notice of noncompliance and thirty days to cure before bringing an enforcement action, expired on January 31, 2026. The Minnesota Attorney General's Office confirmed on February 5, 2026 that it can now bring enforcement actions without providing advance notice, marking the state's transition from a notice-based enforcement posture to a direct-enforcement posture. The MCDPA carries exclusive enforcement authority with the Attorney General and there is no private right of action for Minnesota consumers; this exclusivity was established when the statute took effect on July 31, 2025 and is unchanged by the cure-period sunset. The Attorney General's February 5, 2026 announcement described this shift as strengthening the office's ability to protect consumer data, consistent with the broader pattern among comprehensive state privacy statutes of an initial grace period followed by a harder-edged enforcement phase once the statute has had time to bed in.

Outlook

The expiry of the cure period raises near-term compliance risk for controllers who had relied on the notice-and-cure window as an informal grace period. Whether the Attorney General has brought any concluded, non-warning enforcement action under the MCDPA since the January 31, 2026 expiry has not been confirmed and remains the key open question to watch in this jurisdiction.

1 earlier distinct update(s)
Periodic update · new data 2026-09-22

Enforcement & Redress

Minnesota's enforcement posture under the Consumer Data Privacy Act shifted materially this cycle. The Act's mandatory 30-day cure/warning period, which had required the Attorney General to give controllers an opportunity to remedy violations before facing penalties, sunset on January 31, 2026. The Minnesota Attorney General's Office publicly confirmed this sunset on February 5, 2026, and in doing so noted that hundreds of education letters had been sent to companies during the initial warning period that preceded it.

The MCDPA's underlying enforcement design remains structurally unchanged around this development: the Attorney General holds exclusive enforcement authority over the Act, and there is no private right of action available to individual consumers. Violations are subject to civil penalties of up to $7,500 per violation, recoverable by the Attorney General together with injunctive relief and litigation expenses. What has changed is that these penalties are no longer preceded by a mandatory cure opportunity; controllers now face direct civil-penalty exposure for MCDPA violations without a guaranteed warning window.

This structural shift materially raises compliance risk for any organization doing business in Minnesota and subject to the Act's applicability thresholds, even though no public monetary enforcement action following the cure period's sunset has been confirmed as of this cycle. The Attorney General's confirmed communication about the sunset, combined with the prior education-letter campaign, is understood as a public signal that enforcement is expected to intensify following the transition, though the evidence available this cycle does not establish that any specific enforcement action has in fact been brought.

Outlook

The key question going forward is whether the Minnesota Attorney General brings or settles a post-cure-period enforcement action, which would be the clearest indicator of how the AG intends to exercise its now-unencumbered civil-penalty authority. This has not been established this cycle and is flagged as an open gap for future monitoring rather than assumed either way.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (6)
  1. ConfirmedMinnesota Attorney General's Office — The Minnesota Attorney General may seek injunctive relief, litigation expenses, and civil penalties of up to $7,500 per violation against MCDPA violators.observed
  2. ConfirmedMinnesota Attorney General's Office — Since the MCDPA took effect, the Attorney General's Office sent hundreds of education letters and dozens of formal warning letters to companies regarding privacy policy, consent, and universal opt-out compliance issues, and the Act's mandatory pre-enforcement cure/notice period expired on January 31, 2026.observed
  3. ProbableMinnesota Attorney General's Office — The MCDPA included funding for the Attorney General's Office to hire four new attorneys and an investigator focused primarily on enforcing the Act, placing Minnesota among the most heavily resourced state privacy enforcers per independent industry analysis.observed
  4. ProbableMinnesota Attorney General's Office — No collective-redress or class-action mechanism specific to MCDPA enforcement has been identified; enforcement is vested exclusively in the Attorney General.observed
  5. ConfirmedMinnesota Attorney General's Office — The MCDPA contains no private right of action; only the Attorney General may enforce the Act.observed
  6. ConfirmedMinnesota Attorney General's Office — In June 2026, Minnesota joined a coalition of 18 attorneys general and agencies opposing the proposed federal SECURE Data Act, with the Minnesota AGO stating the bill would preempt and weaken protections under the state's Consumer Data Privacy Act.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metpass
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct73.33
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Minnesota, USA
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 44 claim(s) (44 category placement(s)), 25 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacydata localisation
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redresscollective redress and class actions
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, data_subject_rights, children_and_vulnerable_groups, and enforcement_and_redress rest primarily on T1 Minnesota AGO primary-source pages (ag.state.mn.us/Data-Privacy and Office/Communications releases), giving high confidence. lawful_processing_and_special_data, controller_processor_duties, sectoral_watch, adtech_and_commercial_privacy, and algorithmic_biometric_and_surveillance_governance mix T1 AGO guidance with T2 IAPP bill-stage analysis (some pre-enactment) for granular items (DPO/chief-privacy-officer implication, GLBA/HIPAA targeted-exemption scope), which were not independently re-verified against final statutory text of Minn. Stat. ch. 325M. cross_border_and_adequacy is a confirmed structural gap (state consumer-privacy statutes lack an EU-style transfer regime) rather than an unresearched module. Several sectoral_watch sub-modules (telecoms/eprivacy, employment_data, credit_and_scoring, insurance) and adtech sub-modules (dark_patterns, clean_rooms_and_dcr) and algorithmic sub-modules (biometric_regime, genetic_data, state_surveillance_carveouts) carry explicit absent_field_provenance because no retrievable T1/T2 source confirmed content in this pass; several DataGuidance (T4) pages returned only paywalled stubs with no substantive content and were excluded from claim support.

Unresolved questions (5):

  • Is there an explicit statutory 'chief privacy officer' or DPO-equivalent designation requirement in the enacted Minn. Stat. ch. 325M text, or does the privacy-notice contact-person requirement suffice as the sole equivalent?
  • What is the current enactment/introduction status of standalone Minnesota biometric-privacy and genetic-information-privacy bills referenced in legislative tracking sources, and do they materially supplement the MCDPA's sensitive-data consent gate?
  • Does the MCDPA's 'controller' definition exclude employment/B2B personal data, consistent with most peer state comprehensive privacy statutes, and if so under what specific statutory carve-out?
  • What are the precise notice timelines and thresholds under Minnesota's general breach-notification statute (Minn. Stat. §325E.61 et seq.), which is structurally distinct from MCDPA processor-to-controller breach-notice duties?
  • Are there MCDPA-specific dark-pattern prohibitions, clean-room/data-collaboration-room provisions, or government/law-enforcement exemption carve-outs in the enacted statutory text beyond what AGO consumer-facing guidance summarizes?

Escalate to primary-source review: yes