ResearchState Privacy Laws › Minnesota
MINNESOTA · STATE RESEARCH PROFILE

Minnesota Consumer Data Privacy Act

MCDPA · Normalized Research Card v2.1

IN FORCELAST VERIFIED · AUG 26 2026

At a glance

ScopeNumerical threshold
Threshold100,000 consumers; or 25,000 consumers plus >25% gross revenue from sale
Sensitive dataHeightened protections apply
Universal opt-outYes / opt-out preference mechanisms form part of the framework
EnforcementMinnesota Attorney General
Private actionNo general private action under MCDPA
PenaltyAttorney General enforcement; consult current §325M.20
EffectiveJuly 31, 2025

Who must comply?

Applicability model: Numerical threshold.

Core threshold: 100,000 consumers; or 25,000 consumers plus >25% gross revenue from sale

Applicability remains subject to statutory entity, data-level and activity-specific exemptions. Employment/B2B treatment and federal-law carve-outs should be read together with the official statute linked below.

Consumer rights

Right / protectionStatus
Access✓ Included / qualified by statute
Correction✓ Included / qualified by statute
Deletion✓ Included / qualified by statute
Portability✓ Included / qualified by statute
Opt-out sale✓ Included / qualified by statute
Opt-out targeted advertising✓ Included / qualified by statute
Profiling rights✓ Included / qualified by statute
Additional transparency rights✓ Included / qualified by statute

Sensitive data & minors

Sensitive-data standard: Heightened protections apply

The framework includes age-sensitive protections and sits alongside Minnesota's separate social-media provisions.

Business obligations

Controller responsibilities, small-business rules, privacy policies, retention transparency and data privacy/protection assessments.

Enforcement

Authority: Minnesota Attorney General

Private right of action: No general private action under MCDPA

Penalty / remedy baseline: Attorney General enforcement; consult current §325M.20

What makes Minnesota different?

Minnesota is unusually useful for AI-era compliance because its framework combines detailed profiling rights, transparency and assessment duties with retention-related disclosures.

Developments to watch

Postsecondary institutions regulated by the Office of Higher Education have a later compliance date of July 31, 2029. Chapter 325M also contains separate social-media provisions.

Editorial rule: future-effective, proposed and pending measures are kept separate from current law.

Primary sources & verification

Last verified: August 26, 2026

Research standard: primary official sources prioritized; official guidance used to explain operational requirements.

← ALL STATE PRIVACY LAWS

← Maryland   Montana →

USDataLaws.com provides independent legal and regulatory research for informational purposes. It does not provide legal advice. Laws, regulations and enforcement positions may change after the stated verification date.