Minnesota Privacy Law
Minnesota Consumer Data Privacy Act
Overview
The Minnesota Consumer Data Privacy Act (MCDPA) was signed into law on May 24, 2024, and became effective on July 31, 2025. Minnesota's law is one of the more consumer-protective state privacy laws, combining standard access, deletion, correction, portability, sale opt-out, targeted-advertising opt-out, and profiling opt-out rights with several duties that are less common in the Virginia-model statutes.
The MCDPA gives Minnesota consumers a right to question certain consequential profiling decisions, review the personal data used in the profiling, and have a profiling decision reevaluated if inaccurate data drove the result. It also gives consumers a right to obtain a list of the specific third parties to which the controller disclosed their personal data, unless the controller does not maintain consumer-specific recipient records. Controllers must honor universal opt-out preference signals for sales and targeted advertising, and they must publish privacy notices that include retention-policy disclosures and a last-updated date.
The law applies to entities conducting business in Minnesota or targeting Minnesota consumers that control or process personal data of 100,000 or more Minnesota consumers, or control or process personal data of 25,000 or more Minnesota consumers while deriving more than 25% of gross revenue from the sale of personal data. The Minnesota Attorney General enforces the MCDPA, penalties can reach $7,500 per violation, and the initial mandatory warning-letter cure period expired on January 31, 2026. As of June 3, 2026, businesses should treat Minnesota as an active no-current-mandatory-cure state.
Minnesota Data Privacy Law: 2026 MCDPA Compliance Focus
For the keyword "Minnesota data privacy law," the practical 2026 answer is that the MCDPA is no longer a future deadline. The law has been effective since July 31, 2025, the initial mandatory cure window expired January 31, 2026, and the Minnesota Attorney General can seek injunctions and civil penalties up to $7,500 per violation.
Minnesota is not just another 100,000-consumer threshold law. Its distinct compliance burden is the combination of universal opt-out signal recognition, a right to a list of specific third-party recipients, detailed privacy-notice retention disclosures, and unusually explicit profiling transparency rights.
Source check: Last verified June 3, 2026 against Minnesota Statutes Chapter 325M, especially § 325M.14 consumer rights and universal opt-out mechanisms, § 325M.16 controller responsibilities, § 325M.18 data privacy and protection assessments, and § 325M.20 Attorney General enforcement (date_retrieved: 2026-06-03).
- Effective date: July 31, 2025 for most covered controllers; postsecondary institutions regulated by the Office of Higher Education have a delayed compliance date of July 31, 2029.
- Applicability: 100,000 Minnesota consumers, or 25,000 Minnesota consumers plus more than 25% of gross revenue from personal-data sales.
- Enforcement posture: no current mandatory cure period after January 31, 2026; AG enforcement only; no private right of action.
- High-risk processing: data privacy and protection assessments are required for targeted advertising, sale of personal data, sensitive-data processing, and profiling that presents a reasonably foreseeable risk of unfair or deceptive treatment, financial/physical/reputational injury, intrusion, or other substantial injury.
Applicability Thresholds
Conditions are joined by OR — meeting ANY one triggers applicability.
Consumer Rights
Key Changes in 2025-2026
- MCDPA is now active statewide after its July 31, 2025 effective date
- The mandatory 30-day warning-letter cure period expired January 31, 2026; the AG can now proceed directly under Minnesota Statutes § 325M.20(b)
- Universal opt-out preference signal support is active for data sales and targeted advertising
- Controllers must include retention-policy disclosures and the privacy notice last-updated date in their notices
- Profiling rights are broader than most states: consumers can question certain consequential profiling decisions and seek reevaluation when inaccurate data drove the result
Enforcement Details
Sensitive Data Categories
Consent model: opt-in
Universal Opt-Out / GPC Requirements
Businesses must recognize and honor universal opt-out preference signals such as Global Privacy Control (GPC) for opt-outs from personal data sales and targeted advertising. Minnesota Statutes § 325M.14 requires the mechanism to be consumer-friendly, non-default, and reasonably able to determine Minnesota residency; recognizing opt-out signals approved by other state laws satisfies the Minnesota requirement.
Effective: July 31, 2025
Minor / Child Protections
The MCDPA treats personal data of known children under 13 as sensitive data requiring parental consent under COPPA-aligned rules. For consumers the controller knows are between 13 and 16, the law bars targeted advertising or sale of personal data without consent.
Compliance Checklist
- 1Determine applicability based on Minnesota consumer data processing volumes and revenue thresholds
- 2Implement and test universal opt-out signal recognition for data sales and targeted advertising
- 3Update privacy notices with all MCDPA-required disclosures including algorithmic decision-making
- 4Implement consumer rights request mechanisms with 45-day response period
- 5Obtain opt-in consent for processing sensitive personal data
- 6Conduct data protection assessments for high-risk processing activities
- 7Review data minimization practices to ensure compliance with MCDPA requirements
- 8Remove any compliance plan that assumes a guaranteed cure period is still available after January 31, 2026
Termly builds and maintains a Minnesota-ready privacy policy, a consent banner that recognizes universal opt-out signals like GPC, opt-in consent capture for sensitive data, and a workflow for the access, deletion and correction requests MCDPA grants.