Michigan
Michigan Data Privacy Laws: Consumer Rights & Protections (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 24 primary sources cited on this page. How we verify our legal content

Michigan has no comprehensive consumer data privacy law. The Identity Theft Protection Act (MCL 445.61 to 445.79c) requires breach notification, the Social Security Number Privacy Act (MCL 445.81 to 445.85) restricts SSN use, and the Insurance Data Security Act (MCL 500.550 to 500.565) applies to insurance licensees.
Michigan protects personal information through a patchwork of targeted statutes rather than a single comprehensive privacy law. The Identity Theft Protection Act governs data breach notification. The Social Security Number Privacy Act limits how businesses handle SSNs. The Insurance Data Security Act imposes cybersecurity mandates on every insurance licensee in the state. Several additional sector-specific laws cover student records, employee internet accounts, and library borrowing records.
The legislative landscape is moving. Senate Bill 359 would create Michigan's first comprehensive consumer data privacy framework with access, correction, deletion, and opt-out rights, but the bill remained in the Senate Committee of the Whole as of June 2025 and has not passed either chamber. Senate Bills 360 through 364, which would modernize the breach-notification law and require AG notification for large breaches, passed the Senate in August 2025 and sit in the House Committee on Government Operations.
Layered over all state law are several federal statutes, including HIPAA, GLBA, COPPA, FCRA, and the newly effective TAKE IT DOWN Act, that together provide baseline privacy protections for Michigan residents regardless of what the state legislature does next.
This guide covers every major Michigan data privacy law currently in effect, the pending legislation moving through the legislature, your rights as a Michigan consumer, and what businesses operating in Michigan must do to comply.
Michigan Identity Theft Protection Act
The Identity Theft Protection Act, enacted as Act 452 of 2004 and codified at MCL 445.61 through 445.79c, is Michigan's primary data breach notification law. It sets the baseline for how businesses and government agencies must handle security breaches involving personal information.

What Triggers a Breach Notification
Under MCL 445.72, any person or agency that owns or licenses data in a database must notify affected Michigan residents when a security breach occurs. Notification is required when a resident's unencrypted and unredacted personal information was accessed and acquired by an unauthorized person, or when encrypted personal information was accessed by someone with unauthorized access to the encryption key.
The law defines a "security breach" as the unauthorized access and acquisition of data that compromises the security or confidentiality of personal information maintained as part of a database regarding multiple individuals.
What Counts as Personal Information
The ITPA defines "personal information" under MCL 445.63 as a person's first name or first initial and last name linked to one or more of the following:
- Social Security number
- Driver license number or state personal identification card number
- Demand deposit or other financial account number, or credit card or debit card number, combined with a security code, access code, or password that permits access to the account
The definition currently covers computerized personal information. Proposed amendments in SB 360-364 would expand this to personal information in any medium and would add passport numbers and individually identifiable health-care records as protected categories.
Notice Requirements
Businesses and agencies must provide breach notification "without unreasonable delay." The law does not set a specific number of days; the standard is the care an ordinarily prudent person would exercise under similar circumstances. After notifying affected individuals, entities must also notify each nationwide consumer reporting agency of the breach without unreasonable delay, including the number of notices sent, if the breach required notice to more than 1,000 Michigan residents. Breaches requiring notice to 1,000 or fewer residents are exempt from this consumer-reporting-agency notification duty.
One exception applies. If a person or agency determines that the breach has not caused and is not likely to cause substantial loss or injury to, or result in identity theft with respect to, one or more Michigan residents, notification is not required.
Penalties for Noncompliance
A person or agency that knowingly fails to provide required breach notification faces civil fines of up to $250 per failure to notify. Total civil-fine liability from a single security breach is capped at $750,000. These fines are enforced by the Michigan Attorney General.
Data Destruction Requirements
MCL 445.72a requires any person or agency that maintains a database containing personal information to destroy that data when it is removed from the database and is not being retained elsewhere for a lawful purpose. "Destroy" means shredding, erasing, or otherwise modifying the data so it cannot be read, deciphered, or reconstructed through generally available means. A knowing violation is a misdemeanor punishable by a fine of up to $250 per violation. Entities that comply with equivalent federal data-disposal requirements are considered in compliance with this provision.
Proposed ITPA Amendments: SB 360-364
The Michigan Senate introduced Senate Bills 360 through 364 in 2025 to modernize the Identity Theft Protection Act. The Senate passed all five bills on August 26, 2025, and they were referred to the House Committee on Government Operations, where they remain pending as of May 2026.
The bills would require private and state entities with access to Michigan residents' personal information to maintain written security procedures, including assignment of a security coordinator. For breaches affecting more than 100 Michigan residents, entities would be required to notify the Attorney General in addition to affected individuals. The expanded personal-information definition would add passport numbers and health-care records. SB 361 through 364 are all tie-barred to SB 360, meaning all five bills must pass together.
Social Security Number Privacy Act
The Social Security Number Privacy Act, enacted as Act 454 of 2004 and codified at MCL 445.81 through 445.85, specifically protects SSN privacy in Michigan.
Prohibited Actions
No person may intentionally:
- Publicly display all or more than four sequential digits of a Social Security number
- Use all or more than four sequential digits of an SSN as a primary account number for an individual
- Visibly print all or more than four sequential digits of an SSN on any identification badge, card, membership card, permit, or license
Required Privacy Policies
Since January 1, 2006, a person who obtains one or more Social Security numbers in the ordinary course of business must create a written privacy policy that ensures SSN confidentiality, prohibits unlawful disclosure, limits access to SSN-containing documents, and describes proper disposal methods.
This requirement does not apply across the board. MCL 445.84(3) exempts a person who possesses Social Security numbers in the ordinary course of business and in compliance with the federal Fair Credit Reporting Act (15 USC 1681 to 1681v) or subtitle A of title V of the Gramm-Leach-Bliley Act (15 USC 6801 to 6809). That carve-out covers banks, insurers, and consumer reporting agencies already regulated under those federal frameworks.
Public Records Exemption
All or more than four sequential digits of an SSN contained in a public record are exempt from disclosure under Michigan's Freedom of Information Act (MCL 15.231 et seq.). Michigan FOIA Section 13(1)(a), codified at MCL 15.243, provides a broader privacy exemption for any information of a personal nature where public disclosure would constitute a clearly unwarranted invasion of privacy.
Penalties
A person who violates the SSN Privacy Act with knowledge that their conduct violates the law is guilty of a misdemeanor punishable by imprisonment for up to 93 days, a fine of up to $1,000, or both.
Michigan Insurance Data Security Act
Michigan enacted the Insurance Data Security Act, codified at MCL 500.550 through 500.565 as Chapter 5A of the Insurance Code of 1956 (Act 218), on December 28, 2018. The law took effect January 20, 2021. It is modeled on the 2017 NAIC Insurance Data Security Model Law and applies to every insurance licensee in Michigan.

Who It Covers
The act applies to all persons licensed under the Michigan Insurance Code, including insurers, producers, adjusters, third-party administrators, and any other licensed insurance entity doing business in Michigan.
Information Security Program Requirements
Each licensee must develop, implement, and maintain a comprehensive written information security program (WISP) based on the licensee's own risk assessment. The WISP must:
- Identify reasonably foreseeable internal and external threats to nonpublic information
- Assess the likelihood and potential damage from those threats
- Assess the sufficiency of existing safeguards
- Establish and maintain safeguards to control identified risks
The annual compliance certification is narrower than the security-program duty. MCL 500.555(9) requires each insurer domiciled in Michigan to submit a written statement to the Department of Insurance and Financial Services (DIFS) by February 15 of each year certifying compliance with that section. Licensees that are not Michigan-domiciled insurers, such as producers, adjusters, and third-party administrators, do not file that certification.
Cybersecurity Event Reporting
When a licensee determines that a cybersecurity event involving nonpublic information has occurred, MCL 500.559(1) requires notice to the DIFS Director as promptly as possible, but no later than 10 business days after the determination, when either of two conditions is met:
- Michigan is the licensee's state of domicile (for an insurer) or home state (for an insurance producer), and the cybersecurity event has a reasonable likelihood of materially harming a consumer residing in Michigan or any material part of the licensee's normal operations
- The licensee reasonably believes the nonpublic information involved is that of 250 or more consumers residing in Michigan, and the event either requires notice to a government body, self-regulatory agency, or other supervisory body under state or federal law, or has a reasonable likelihood of causing that same material harm
A licensee that meets neither condition does not owe the 10-business-day DIFS report for that event, though other duties under the act and the ITPA can still apply. Where the duty is triggered, the 10-day deadline is stricter than the general breach-notification standard under the ITPA, which uses "without unreasonable delay."
Licensees must also notify affected individuals and, in certain circumstances, other regulators in states where affected individuals reside.
Exemptions
Licensees with fewer than 25 employees, including independent contractors, are exempt from the WISP requirement under MCL 500.565. A licensee that grows to 25 or more employees has 180 days to comply. Licensees subject to and in compliance with HIPAA are also exempt from this chapter, except for the notification requirements in sections 559 and 561.
Michigan Consumer Protection Act
The Michigan Consumer Protection Act (MCPA), Act 331 of 1976, codified at MCL 445.901 through 445.922, serves as a general enforcement tool for data privacy violations. While not a standalone privacy statute, its broad prohibition against unfair, unconscionable, or deceptive trade practices gives the Attorney General authority to pursue companies that mishandle personal data.
MCL 445.903 includes specific privacy protections. The law prohibits requiring a consumer to disclose their SSN as a condition of selling or leasing goods or providing services, except in specified circumstances. The Attorney General has used the MCPA alongside federal statutes in enforcement actions against technology companies.
Consumers may bring private lawsuits under the MCPA to recover actual damages or $250, whichever is greater, plus reasonable attorney fees. The Attorney General may seek injunctive relief, civil fines, and restitution.
The Proposed Personal Data Privacy Act (SB 359)

The most significant pending data privacy legislation in Michigan is Senate Bill 359, introduced June 5, 2025, and referred to the Senate Committee on Finance, Insurance, and Consumer Protection. The committee reported it favorably on June 11, 2025, and referred it to the Committee of the Whole, where it remained as of June 2025. The bill has not passed either chamber.
SB 359 is a reintroduction of Senate Bill 659 from the 2023-2024 session, which passed the Senate but did not advance through the House. Both chambers would need to pass the bill and the Governor would need to sign it before it becomes law.
Who It Would Cover
SB 359 would apply to entities that conduct business in Michigan or produce products or services targeted to Michigan residents, and that during a calendar year either control or process personal data of 100,000 or more consumers, or control or process personal data of 25,000 or more consumers and derive any revenue from the sale of personal data.
Consumer Rights Under SB 359
If enacted, the bill would grant Michigan residents the following rights over their personal data:
- Right to confirm whether a business is processing their personal data
- Right to access their personal data held by a business
- Right to correct inaccuracies in their personal data
- Right to delete their personal data
- Right to obtain a portable copy of their data
- Right to opt out of processing for targeted advertising
- Right to opt out of the sale of personal data
- Right to opt out of profiling that produces legal or similarly significant effects
The bill would also require businesses to honor opt-out preference signals, such as Global Privacy Control, when sent with a consumer's consent.
Consent Requirements
Collectors would need to obtain consent from consumers before processing their personal data and provide a privacy notice explaining the purpose of that processing.
Data Broker Registry
The bill would create a public registry for data brokers, defined as entities that knowingly collect and sell or license personal data about consumers with whom they have no direct relationship. Data brokers would be required to register annually with the Attorney General beginning February 1, 2026 (a date that has now passed; any final enacted version would likely push this deadline forward).
Enforcement
SB 359 would be enforced exclusively by the Michigan Attorney General. There would be no private right of action.
Internet Privacy Protection Act
Michigan's Internet Privacy Protection Act, enacted as Act 478 of 2012, protects employees and job applicants from being required to share their personal social media and internet account credentials.
The law prohibits employers from requesting or requiring an employee or job applicant to grant access to, allow observation of, or disclose login information for personal internet accounts. Employers retain the right to monitor activity on employer-owned devices and networks, view publicly available information, and investigate specific credible reports of work-related misconduct involving personal accounts.
Michigan Kids Code Act (Pending)
The Michigan Senate passed Senate Bill 758, the Kids Code Act, on April 29, 2026, and the bill moved to the House for consideration. As passed by the Senate, the bill specified a July 1, 2026 effective date, but that date has now passed with the bill still pending in a House committee and no further action taken. If SB 758 is enacted later, its effective date would need to be revised.
SB 758 is tie-barred to Senate Bill 759 and would apply to covered online service providers with more than $25 million in annual revenue or more than 50,000 Michigan users. Covered entities would be prohibited from using addictive design features such as infinite scroll, autoplay videos, or gamification to encourage excessive use by minors. The bill would also restrict collection of biometric data from minors, prohibit the use of dark patterns to manipulate children, and require age verification where the provider has actual knowledge a user is under 13. Targeted advertising to minors would be prohibited.
As of August 2026, SB 758 remains pending in the House Communications and Technology Committee, where it was referred on April 29, 2026. It has not been enacted.
Student Data Privacy Protections
Michigan has enacted specific protections for student data that supplement federal requirements under FERPA.

Student Online Personal Protection Act
The Student Online Personal Protection Act, Act 368 of 2016, regulates operators of websites, online services, and applications used for K-12 school purposes. It covers personally identifiable student information including educational records, contact information, discipline records, test results, special education data, and grades.
Protection of Pupil Privacy Act
MCL 380.1136 prohibits school districts, intermediate school districts, public school academies, educational management organizations, and authorizing bodies from selling or providing personally identifiable information from pupil education records to for-profit business entities.
State FERPA Compliance
Michigan enacted Public Act 88 of 2000, which requires public bodies to exempt from disclosure any information that would prevent them from complying with FERPA. The Michigan Department of Education and the Center for Educational Performance and Information maintain strict data governance frameworks to protect student records.
Preservation of Personal Privacy Act
The Preservation of Personal Privacy Act, Act 378 of 1988, codified at MCL 445.1711 through 445.1715, protects the privacy of records related to the purchase, rental, or borrowing of books, written materials, sound recordings, and video recordings.
This law prohibits disclosure of customer identification tied to these materials, with exceptions for collecting payment on overdue accounts (after written notice), activities incident to the ordinary course of business, and marketing purposes when written notice is provided. A person who violates this act may be liable in a civil action for actual damages.
Federal Laws That Apply in Michigan
Because Michigan lacks a comprehensive state privacy law, several federal statutes provide important baseline protections for Michigan residents.

HIPAA
The Health Insurance Portability and Accountability Act protects health information held by covered entities including healthcare providers, health plans, and healthcare clearinghouses. The Michigan Department of Health and Human Services implements HIPAA at the state level. Michigan supplements HIPAA with additional state-level protections for behavioral health and substance use disorder treatment records, which require separate consent for disclosure beyond treatment, payment, and coordination of care purposes.
TAKE IT DOWN Act (Effective May 19, 2026)
The TAKE IT DOWN Act, Pub. L. 119-12, was signed into law on May 19, 2025. Its criminal prohibition on publishing nonconsensual intimate images (NCII) took effect immediately. Platform takedown obligations became effective May 19, 2026: covered online platforms must implement a system allowing individuals to request removal of NCII, and must remove reported content and known identical copies within 48 hours. The Federal Trade Commission has authority to enforce these platform obligations. Michigan AG Nessel, along with 35 other attorneys general, had sent a January 26, 2026 letter to xAI demanding it disable Grok's ability to produce nonconsensual intimate images and child sexual abuse material, citing the pending federal obligations.
COPPA
The Children's Online Privacy Protection Act restricts collection of personal information from children under 13 by websites and online services. Michigan's AG has actively invoked COPPA in enforcement, including the ongoing Roku lawsuit (discussed below).
Gramm-Leach-Bliley Act
The GLB Act requires financial institutions to explain their information-sharing practices and protect sensitive data. Michigan-based banks, credit unions, insurance companies, and other financial services providers must comply with GLB's privacy and safeguard requirements.
FCRA and FACTA
The Fair Credit Reporting Act and its amendment, FACTA, regulate the collection and use of consumer report information. The FTC enforces FCRA against consumer reporting agencies and users of consumer reports operating in Michigan.
APRA (Did Not Pass)
The American Privacy Rights Act was introduced as a bicameral federal draft in 2024. It did not pass into law. As of May 2026, no successor federal comprehensive privacy bill has been enacted.
Recent Enforcement Actions
Roku Lawsuit: Non-COPPA Claims Dismissed (April 2026)
Attorney General Dana Nessel filed suit against Roku, Inc. in the U.S. District Court for the Eastern District of Michigan in April 2025, alleging the streaming platform violated COPPA and the Michigan Consumer Protection Act by collecting children's personal information without required parental consent. In April 2026, the federal court narrowed the case substantially. The court dismissed all non-COPPA claims, including VPPA and state consumer protection claims, for lack of standing, finding the Attorney General did not have a sufficient quasi-sovereign interest to support parens patriae standing on those claims. The COPPA claims survived because COPPA includes an express parens patriae provision authorizing state enforcement.
Healthcare Data Breach Alerts (2025-2026)
AG Nessel has issued multiple consumer alerts regarding major breaches affecting Michigan residents, including incidents involving McLaren Health Care, Change Healthcare, Ascension Healthcare, AT&T, and Munson Healthcare in Traverse City.
xAI Multistate Coalition (January 2026)
On January 26, 2026, AG Nessel joined 35 other attorneys general in demanding action from xAI over Grok's generation of nonconsensual intimate images and child sexual abuse material. The letter demanded xAI immediately disable that capability, remove existing content, and report illegal content to authorities.
How to File a Data Privacy Complaint in Michigan
If you believe your data privacy rights have been violated in Michigan, you have several options.
Contact the Michigan Attorney General's Consumer Protection Division. You can file a complaint online through the Michigan Attorney General's website or by calling the Consumer Protection hotline. For insurance-related data security incidents, complaints may also be directed to the Department of Insurance and Financial Services.
For data breaches, affected individuals should place fraud alerts with the three major credit bureaus, review credit reports for unauthorized activity, and consider placing a credit freeze on their accounts.
For HIPAA violations involving health information, file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights.
For violations involving student records, contact the U.S. Department of Education's Student Privacy Policy Office.
What Michigan Businesses Must Do Now
Even without a comprehensive privacy law, Michigan businesses have clear obligations under existing statutes.

Mandatory Requirements Under Current Law
- Breach notification: Notify affected Michigan residents without unreasonable delay after discovering a security breach involving their personal information (MCL 445.72)
- SSN protection: Never publicly display SSNs, and maintain a written privacy policy if you collect them unless you possess them in compliance with the FCRA or the Gramm-Leach-Bliley Act (MCL 445.81 to 445.85)
- Data destruction: Destroy personal information through shredding, erasure, or modification when removing it from databases (MCL 445.72a)
- Employee privacy: Never request or require employees or applicants to share personal social media or internet account credentials (Act 478 of 2012)
- Insurance licensees: Maintain a written information security program, and notify DIFS within 10 business days of a cybersecurity event when the MCL 500.559(1) triggers are met (Michigan domicile or home state plus likely material harm, or 250 or more Michigan residents affected). Michigan-domiciled insurers also file an annual compliance certification by February 15 (MCL 500.550 to 500.565)
- Student data: If you operate educational technology for K-12 purposes, comply with the Student Online Personal Protection Act (Act 368 of 2016)
- TAKE IT DOWN Act platforms: If you operate a covered online platform, implement a NCII takedown-request system and remove reported content within 48 hours (effective May 19, 2026)
Preparing for Comprehensive Privacy Law
With SB 359 still pending in the Senate and SB 360-364 awaiting House action, Michigan businesses should begin preparing now by:
- Auditing what personal data they collect, process, and store
- Reviewing privacy notices and consent mechanisms
- Implementing data access and deletion request workflows
- Evaluating whether they qualify as a data broker under SB 359's definition
- Training staff on data privacy requirements
- Consulting with legal counsel about compliance timelines if SB 359 passes
This article is for informational purposes only and does not constitute legal advice. It covers Michigan data privacy law as of May 2026. Data privacy laws change frequently and enforcement interpretations evolve over time. Consult a licensed attorney in Michigan for advice about your specific situation.
More Michigan Laws
Frequently Asked Questions
Does Michigan have a comprehensive data privacy law?
No. As of May 2026, Michigan does not have a comprehensive consumer data privacy law. The state relies on targeted statutes including the Identity Theft Protection Act, the Social Security Number Privacy Act, the Insurance Data Security Act, and the Consumer Protection Act. Senate Bill 359, the Personal Data Privacy Act, was introduced in June 2025 and remains in the Senate Committee of the Whole. It has not passed either chamber. Until SB 359 or a successor bill is enacted, Michigan residents rely on these state laws plus federal protections such as HIPAA, COPPA, and GLBA.
What are the penalties for failing to report a data breach in Michigan?
Under the Identity Theft Protection Act (MCL 445.72), a person or agency that knowingly fails to provide required breach notification faces civil fines of up to $250 per failure. Total civil-fine liability from a single breach is capped at $750,000. Separate penalties may apply under the Michigan Consumer Protection Act if the failure involves deceptive trade practices. Insurance licensees face separate reporting obligations: under MCL 500.559 they must notify DIFS within 10 business days of a cybersecurity event, but only when Michigan is the licensee's state of domicile or home state and the event is reasonably likely to cause material harm, or when 250 or more Michigan residents' nonpublic information is involved.
Can my employer access my personal social media accounts in Michigan?
No. Michigan's Internet Privacy Protection Act (Act 478 of 2012) prohibits employers from requesting or requiring employees or job applicants to share login credentials for personal internet accounts. Employers may monitor activity on employer-owned devices and networks, view publicly available information, and investigate specific credible reports of work-related misconduct involving personal accounts. The act does not create a duty for employers to search or monitor personal internet account activity.
How quickly must a company notify me of a data breach in Michigan?
Michigan law requires notification 'without unreasonable delay' but does not set a specific number of days for most businesses. The standard is that the entity must act with the care an ordinarily prudent person would exercise under similar circumstances. Insurance licensees can face a stricter standard: MCL 500.559 requires DIFS notification no later than 10 business days after determining a cybersecurity event occurred, but only when Michigan is the licensee's state of domicile or home state and the event is reasonably likely to cause material harm, or when 250 or more Michigan residents' nonpublic information is involved. Proposed amendments in SB 360-364 would require notification to the Attorney General for breaches affecting more than 100 Michigan residents.
Has Michigan passed the Personal Data Privacy Act?
No. As of May 2026, Senate Bill 359, the Personal Data Privacy Act, has not passed. The Michigan Senate Finance, Insurance, and Consumer Protection Committee reported it favorably on June 11, 2025, and referred it to the Committee of the Whole, where it remained pending. The bill has not been voted on by the full Senate. Michigan has passed SB 359 twice in a prior form in the Senate but it has never advanced through the House. Monitor legislature.mi.gov for updates.
What does the TAKE IT DOWN Act mean for Michigan residents?
The federal TAKE IT DOWN Act (Pub. L. 119-12, signed May 19, 2025) makes it a federal crime to publish nonconsensual intimate images. Beginning May 19, 2026, covered online platforms must maintain a system allowing individuals to report NCII and must remove reported content and known identical copies within 48 hours. The FTC enforces the platform obligations. Michigan AG Nessel has been active on this issue, joining a 36-state coalition demanding xAI address Grok's generation of such content.
Does Michigan have a law protecting insurance customer data?
Yes. The Michigan Insurance Data Security Act (MCL 500.550 to 500.565), effective January 20, 2021, requires insurance licensees to develop and maintain a comprehensive written information security program and, under MCL 500.559, to notify DIFS within 10 business days of a cybersecurity event when Michigan is the licensee's state of domicile or home state and material harm is reasonably likely, or when 250 or more Michigan residents' nonpublic information is involved. The law applies to insurers, producers, adjusters, and other licensed insurance entities, and Michigan-domiciled insurers must also submit an annual compliance certification by February 15 under MCL 500.555(9). Smaller licensees with fewer than 25 employees, including independent contractors, are exempt from the WISP requirement under MCL 500.565. A licensee that grows to 25 or more employees has 180 days to comply.
What should I do if my data is breached in Michigan?
If you receive a breach notification, immediately place fraud alerts with all three major credit bureaus (Equifax, Experian, TransUnion), review your credit reports for unauthorized accounts or activity, consider placing a credit freeze, change passwords for any affected accounts, and monitor financial statements closely. You can also file a complaint with the Michigan Attorney General's Consumer Protection Division at michigan.gov/ag. For health-information breaches, file a complaint with the HHS Office for Civil Rights.
Updates
Corrected the Michigan Insurance Data Security Act reporting citation to MCL 500.559 and added the statutory conditions that trigger the 10-business-day DIFS notice, limited the annual February 15 compliance certification to Michigan-domiciled insurers under MCL 500.555(9), and added the FCRA and Gramm-Leach-Bliley exemption to the Social Security number privacy policy requirement under MCL 445.84(3).
Corrected the Insurance Data Security Act's small-licensee exemption (it applies solely based on employee count under MCL 500.565, not a revenue/asset test), added the 1,000-resident threshold for consumer-reporting-agency breach notification under MCL 445.72, added credit/debit card numbers to the personal-information definition under MCL 445.63, and updated the Kids Code Act's now-lapsed July 1, 2026 effective date and pending-House status.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
May 2026 refresh: Corrected SB 359 legislative status (bill remains in Senate Committee of the Whole, has NOT passed the Senate; prior version incorrectly stated it had passed the Senate). Added Michigan Insurance Data Security Act (MCL 500.550 to 500.565, effective Jan 20, 2021) as a new section. Added Michigan Kids Code Act (SB 758, passed Senate, pending House, effective July 1, 2026 if enacted). Added TAKE IT DOWN Act (Pub. L. 119-12) platform obligations effective May 19, 2026. Updated Roku enforcement section to reflect April 2026 federal court ruling narrowing case to COPPA claims only. Added xAI/Grok multistate AG coalition detail (Jan 26, 2026). Added MCL 15.243 FOIA Section 13 privacy exemption. Updated FAQ to 8 questions. Expanded SourcesList to 25 sources.
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Michigan Compiled Laws
§ 445.72Notice of security breach; requirementsIn forcecited in 7 of our articles
(1) Unless the person or agency determines that the security breach has not or is not likely to cause substantial loss or injury to, or result in identity theft with respect to, 1 or more residents of this state, a person or agency that owns or licenses data that are included in a database that discovers a security breach, or receives notice of a security breach under subsection (2), shall provide a notice of the security breach to each resident of this state who meets 1 or more of the following: (a) That resident's unencrypted and unredacted personal information was accessed and acquired by an unauthorized person. (b) That resident's personal information was accessed and acquired in encrypted form by a person with unauthorized access to the encryption key.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at legislature.mi.gov
Cited in 8 court opinions in our collectionLatest citing opinion in our collection: 2025
In the courts (editorial summary, independently checked):Federal courts differ on private enforcement. In re Target Corp. Customer Data Security Breach Litigation (2014) read subsection (15) to imply consumers may sue through Michigan's consumer protection act. Angus v. Flagstar Bank, FSB (2025) held that a 445.72 violation cannot support an MCPA claim.
Opinions citing this section in our collection:
- In re Target Corp. Customer Data Security Breach Litigation (District Court, D. Minnesota 2014, 66 F. Supp. 3d 1154)✓Hackers took card and personal data of roughly 110 million Target shoppers; on a motion to dismiss the court read the subsection preserving other civil remedies as implying consumers may enforce the section 445.72 notice duty through other Michigan laws.
- In re Equifax, Inc. (District Court, N.D. Georgia 2019, 362 F. Supp. 3d 1295)✓Hackers took the personal data of nearly 150 million people from Equifax; following Target, the court declined to dismiss the section 445.72 claim for lack of a private right of action, relying on the subsection preserving other civil remedies.
- Negron v. Ascension Health (District Court, E.D. Missouri 2025)“…XVI. Michigan Identity Theft Protection Act, Mich. Comp. Laws § 445.72 XVII. Michigan Consumer Protection A…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Michigan Data Breach Notification Laws: Reporting Rules & Timelines (2026), Michigan Biometric Privacy Laws: Collection, Consent & Penalties (2026), Michigan Identity Theft Laws: Penalties and Victim Resources
§ 15.231Short title; public policyIn forcecited in 6 of our articles
(1) This act shall be known and may be cited as the "freedom of information act". (2) It is the public policy of this state that all persons, except those persons incarcerated in state or local correctional facilities, are entitled to full and complete information regarding the affairs of government and the official acts of those who represent them as public officials and public employees, consistent with this act. The people shall be informed so that they may fully participate in the democratic process.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at legislature.mi.gov
Cited in 386 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Booth Newspapers, Inc v. University of Michigan Board of Regents (Michigan Supreme Court 1993, 444 Mich. 211)“…SA 4.1800(11) et seq., or the Freedom of Information Act, MCL 15.231 et seq.; MSA 4.1801(1) et seq. We…”
- Herald Co. v. City of Bay City (Michigan Supreme Court 2000, 463 Mich. 111)“…that they may fully participate in the democratic process. [MCL 15.231(2); MSA 4.1801(1)(2) (emphasis added).]…”
- Coblentz v. City of Novi (Michigan Supreme Court 2006, 475 Mich. 558)“…m disclosure under the Freedom of Information Act (FOIA), MCL 15.231 et seq. We address also whether it was…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Michigan Laws on Recording Police: Your Rights and Legal Limits (2026), Public Records Laws by State: FOIA Guide for All 50 States (2026), Michigan Freedom of Information Act: 5 Business Days, Fees, and How to Appeal
§ 15.243Exemptions from disclosure; public body as school district, intermediate school district, or public school academy; withholding of information required by law or in possession of executive officeIn forcecited in 5 of our articles
(1) A public body may exempt from disclosure as a public record under this act any of the following: (a) Information of a personal nature if public disclosure of the information would constitute a clearly unwarranted invasion of an individual's privacy. (b) Investigating records compiled for law enforcement purposes, but only to the extent that disclosure as a public record would do any of the following: (i) Interfere with law enforcement proceedings. (ii) Deprive a person of the right to a fair trial or impartial administrative adjudication. (iii) Constitute an unwarranted invasion of personal privacy. (iv) Disclose the identity of a confidential source, or if the record is compiled by a law enforcement agency in the course of a criminal investigation, disclose confidential information furnished only by a confidential source. (v) Disclose law enforcement investigative techniques or procedures. (vi) Endanger the life or physical safety of law enforcement personnel. (vii) Disclose the identity of a party who, as described in subdivision (cc), proceeds anonymously in a civil action in which the party alleges that the party was the victim of sexual misconduct.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at legislature.mi.gov
Cited in 203 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Booth Newspapers, Inc v. University of Michigan Board of Regents (Michigan Supreme Court 1993, 444 Mich. 211)“…nces in which public records may be exempt from disclosure. MCL 15.243; MSA 4.1801(13). These exemptions must…”
- Herald Co. v. City of Bay City (Michigan Supreme Court 2000, 463 Mich. 111)“…a clearly unwarranted invasion of an individual's privacy. [MCL 15.243(1); MSA 4.1801(13)(1).] The trial cou…”
- Coblentz v. City of Novi (Michigan Supreme Court 2006, 475 Mich. 558)“…ems were not exempt because defendant failed to comply with MCL 15.243(1)(f)(iii). Finally, the Court of Appea…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Michigan Police Bodycam Laws: Retention & Public Records, How to Get a Police Report in Michigan (2026 Guide), Police Reports by State: How to Get a Copy, What They Cost, and What's Public
§ 380.1136Protection of pupil privacyIn forcecited in 2 of our articles
(1) Subject to subsection (7), to protect pupil privacy, the superintendent of public instruction shall ensure that the department complies with all of the following and the state budget director shall ensure that CEPI complies with all of the following: (a) The department or CEPI shall not sell any information that is part of a pupil's education records. (b) By April 21, 2017, the department and CEPI each shall post on its website a notice of the information it collects for a pupil's education records. The notice must include at least an inventory of all pupil data elements collected by the department or CEPI and a description of each pupil data element. (c) At least 30 days before initiating the collection of any pupil data elements in addition to those already disclosed in the inventory under subdivision (b), the department or CEPI shall post on its website a notice of the additional pupil data elements it is proposing to collect and an explanation of the reasons for the proposal.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at legislature.mi.gov
§ 445.1711DefinitionsIn forcecited in 2 of our articles
As used in this act: (a) "Customer" means an individual who purchases, rents, or borrows a book, other written material, a sound recording, or a video recording. (b) "Employee" means an individual who works for an employer in exchange for wages or other remuneration. (c) "Employer" means a person that has 1 or more employees. (d) "Ordinary course of business" means activities related to the sale, rental, or lending of, or advertising in, materials described in section 2. (e) "Written" includes any electronic means using the Internet or otherwise authorized under the uniform electronic transactions act, 2000 PA 305, MCL 450.831 to 450.849.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at legislature.mi.gov
Cited in 13 court opinions in our collectionLatest citing opinion in our collection: 2023
Opinions citing this section in our collection:
- in Re Certified Question (Deacon v. Pandora) (Michigan Supreme Court 2016, 499 Mich. 477)“…ted the preservation of personal privacy act (PPPA), MCL 445.1711 et seq. (also commonly known as the vid…”
- People of Michigan v. Miquall Molic Abram (Michigan Supreme Court 2015)“…a for violation of the Michigan Video Rental Privacy Act, MCL 445.1711 et seq., by adequately alleging that Pa…”
- Deacon v. Pandora Media, Inc. (Michigan Supreme Court 2015, 498 Mich. 882)“…ora for violation of the Michigan Video Rental Privacy Act, MCL 445.1711 et seq., by adequately alleging that…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 445.61Short titleIn forcecited in 7 of our articles
This act shall be known and may be cited as the "identity theft protection act".
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at legislature.mi.gov
Cited in 4 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Michigan Federation of Teachers & School Related Personnel v. University of Michigan (Michigan Supreme Court 2008, 481 Mich. 657)“…ure enacted 2004 PA 452, the Identity Theft Protection Act, MCL 445.61 et seq., whose title states, among othe…”
- Deidre Goldsmith v. Faith Hope & Love Outreach Center Inc (Michigan Court of Appeals 2026)“…ing identity theft under the Identity Theft Protection Act, MCL 445.61 et seq., forfeiture of property under M…”
- Keffer Development Services, LLC v. Hartford Casualty Insurance Company (District Court, W.D. Pennsylvania 2026)“…ations Act; (4) the Michigan Identity Theft Protection Act (MCL 445.61 et seq.); and (5) Ohio data security l…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 445.63DefinitionsIn forcecited in 7 of our articles
As used in this act: (a) "Agency" means a department, board, commission, office, agency, authority, or other unit of state government of this state. The term includes an institution of higher education of this state. The term does not include a circuit, probate, district, or municipal court. (b) "Breach of the security of a database" or "security breach" means the unauthorized access and acquisition of data that compromises the security or confidentiality of personal information maintained by a person or agency as part of a database of personal information regarding multiple individuals. These terms do not include unauthorized access to data by an employee or other individual if the access meets all of the following: (i) The employee or other individual acted in good faith in accessing the data. (ii) The access was related to the activities of the agency or person. (iii) The employee or other individual did not misuse any personal information or disclose any personal information to an unauthorized person. (c) "Child or spousal support" means support for a child or spouse, paid or provided pursuant to state or federal law under a court order or judgment.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at legislature.mi.gov
Cited in 5 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- People v. Perry (Michigan Court of Appeals 2016, 317 Mich. App. 589)“…license or state personal identification card number . . .” MCL 445.63(q). Circumstantial evidence and reasona…”
- Michigan Federation of Teachers & School Related Personnel v. University of Michigan (Michigan Supreme Court 2008, 481 Mich. 657)“…very type of information sought by plaintiff in this case. MCL 445.63(o). See also, e.g., Identity Theft and…”
- Deidre Goldsmith v. Faith Hope & Love Outreach Center Inc (Michigan Court of Appeals 2026)“…d for the purpose of identifying a specific person . . . .” MCL 445.63(q). Defendants argue that the…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 445.72aDestruction of data containing personal information required; violation as misdemeanor; fine; compliance; "destroy" definedIn forcecited in 4 of our articles
(1) Subject to subsection (3), a person or agency that maintains a database that includes personal information regarding multiple individuals shall destroy any data that contain personal information concerning an individual when that data is removed from the database and the person or agency is not retaining the data elsewhere for another purpose not prohibited by state or federal law. This subsection does not prohibit a person or agency from retaining data that contain personal information for purposes of an investigation, audit, or internal review. (2) A person who knowingly violates this section is guilty of a misdemeanor punishable by a fine of not more than $250.00 for each violation. This subsection does not affect the availability of any civil remedy for a violation of state or federal law. (3) A person or agency is considered to be in compliance with this section if the person or agency is subject to federal law concerning the disposal of records containing personal identifying information and the person or agency is in compliance with that federal law.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at legislature.mi.gov
§ 445.81Short titleIn forcecited in 2 of our articles
This act shall be known and may be cited as the "social security number privacy act".
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at legislature.mi.gov
Cited in 3 court opinions in our collectionLatest citing opinion in our collection: 2019
Opinions citing this section in our collection:
- Adam Nyman v. Thomson Reuters Holdings Inc (Michigan Court of Appeals 2019)“…olations of the Social Security Number Privacy Act (SSNPA), MCL 445.81 et seq., plaintiffs 1 appeal as of righ…”
- Dow Chemical Employees' Credit Union v. Brenda Geiling (Michigan Court of Appeals 2018)“…aling, and violated the Social Security Number Privacy Act, MCL 445.81 et seq., by disseminating unredacted ve…”
- Jerry Stacy v. HRB Tax Group, Inc. (Court of Appeals for the Sixth Circuit 2013, 516 F. App'x 588)“…actment of the Social Security Number Privacy Act (SSNPA), Mich. Comp. Laws Ann. § 445.81 et seq. (West 2013).1 1…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 445.901Short titleIn forcecited in 4 of our articles
This act shall be known and may be cited as the "Michigan consumer protection act".
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at legislature.mi.gov
Cited in 287 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Attorney General v. Powerpick Player's Club of Michigan, LLC (Michigan Court of Appeals 2010, 287 Mich. App. 13)“…tions violated the Michigan Consumer Protection Act (MCPA), MCL 445.901 et seq. A Contrary to the ruli…”
- Liss v. Lewiston-Richards, Inc (Michigan Supreme Court 2007, 478 Mich. 203)“…f action under the Michigan Consumer Protection Act (MCPA), MCL 445.901 et seq. As the basis of their claim,…”
- Woodman v. KERA, LLC (Michigan Court of Appeals 2008, 280 Mich. App. 125)“…and violation of Michigan's Consumer Protection Act (MCPA), MCL 445.901 et seq. Plaintiff alleged that defend…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Michigan AI Laws and Regulation (2026)
§ 445.903Unfair, unconscionable, or deceptive methods, acts, or practices in conduct of trade or commerce; rules; applicability of subsection (1)(hh)In forcecited in 6 of our articles
(1) Unfair, unconscionable, or deceptive methods, acts, or practices in the conduct of trade or commerce are unlawful and are defined as follows: (a) Causing a probability of confusion or misunderstanding as to the source, sponsorship, approval, or certification of goods or services. (b) Using deceptive representations or deceptive designations of geographic origin in connection with goods or services. (c) Representing that goods or services have sponsorship, approval, characteristics, ingredients, uses, benefits, or quantities that they do not have or that a person has sponsorship, approval, status, affiliation, or connection that he or she does not have. (d) Representing that goods are new if they are deteriorated, altered, reconditioned, used, or secondhand. (e) Representing that goods or services are of a particular standard, quality, or grade, or that goods are of a particular style or model, if they are of another. (f) Disparaging the goods, services, business, or reputation of another by false or misleading representation of fact. (g) Advertising or representing goods or services with intent not to dispose of those goods or services as advertised or represented.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at legislature.mi.gov
Cited in 210 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Smith v. Globe Life Insurance (Michigan Supreme Court 1999, 460 Mich. 446)“…its reading of the terms “specifically authorized.” Under MCL 445.903; MSA 19.418(3), the MCPA protects consu…”
- Gorman v. American Honda Motor Co. (Michigan Court of Appeals 2013, 302 Mich. App. 113)“…acts, or practices in the conduct of trade or commerce[.]” MCL 445.903(1). The act defines “trade or commerce”…”
- Dell v. Citizens Insurance Company of America (Michigan Court of Appeals 2015, 312 Mich. App. 734)“…e or commerce as set forth in the [MCPA] . . . . See, e.g., MCL 445.903(1)(a), (c), (e), (n), (s), (x)…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 500.550Private cause of action not created; exclusive standardsIn forcecited in 2 of our articles
This chapter does not create or imply a private cause of action for violation of its provisions and does not curtail a private cause of action that would otherwise exist in the absence of this chapter. Notwithstanding any other provision of law, this chapter establishes the exclusive standards, for this state, applicable to licensees for data security, the investigation of a cybersecurity event, and notification to the director.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at legislature.mi.gov
§ 500.565Exemption for certain licensees; timeline for implementation and complianceIn force
(1) A licensee that has fewer than 25 employees, including any independent contractors, is exempt from section 555. (2) A licensee subject to and in compliance with the health insurance portability and accountability act of 1996, Public Law 104�191, and with regulations promulgated under that act, is not required to comply with this chapter except for the requirements under sections 559 and 561. (3) An employee, agent, representative, or designee of a licensee, who is also a licensee, is exempt from section 555 and does not need to develop its own information security program to the extent that the employee, agent, representative, or designee is covered by the information security program of the other licensee. (4) If a licensee ceases to qualify for the exception under subsection (1), the licensee has 180 days to comply with this chapter. (5) This chapter takes effect on January 20, 2021. A licensee shall implement section 555 by January 20, 2022. However, a licensee has until January 20, 2023 to implement section 555(6).
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at legislature.mi.gov
Explore the law
The laws cited above reference these related sections in their own text:
- Michigan Compiled Laws § 750.145c — Definitions; child sexually abusive activity or material; penalties; possession of child sexually abusive material; expert testimony; defenses; acts of commercial film or photographic print processor; report to law enforcement agency by computer technician; reasonable availability of evidence to defendant; applicability and uniformity of section; enactment or enforcement of ordinance, rule, or regulation prohibited view in our statute record · read at the official source
- Michigan Compiled Laws § 750.520b — Criminal sexual conduct in the first degree; circumstances; felony; consecutive terms view in our statute record · read at the official source
- Michigan Compiled Laws § 750.520c — Criminal sexual conduct in the second degree; felony view in our statute record · read at the official source
- Michigan Compiled Laws § 750.520d — Criminal sexual conduct in the third degree; felony view in our statute record · read at the official source
- Michigan Compiled Laws § 750.520e — Criminal sexual conduct in the fourth degree; misdemeanor view in our statute record · read at the official source
- Michigan Compiled Laws § 750.520g — Assault with intent to commit criminal sexual conduct; felony view in our statute record · read at the official source
Related law for further reading — not part of this article’s citations.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Michigan Identity Theft Protection Act - Act 452 of 2004 (Full Text)(legislature.mi.gov).gov
- MCL 445.72 - Breach Notification Requirements(legislature.mi.gov).gov
- MCL 445.72a - Data Destruction Requirements(legislature.mi.gov).gov
- MCL 445.63 - Personal Information Definitions(legislature.mi.gov).gov
- Michigan Social Security Number Privacy Act - Act 454 of 2004(legislature.mi.gov).gov
- Michigan Insurance Data Security Act - MCL 500.550 to 500.565(michigan.gov).gov
- Michigan Consumer Protection Act - Act 331 of 1976(legislature.mi.gov).gov
- Senate Bill 359 - Personal Data Privacy Act (2025)(legislature.mi.gov).gov
- SB 359 - Senate Fiscal Agency Analysis (Version G)(legislature.mi.gov).gov
- Senate Bills 360-364 - ITPA Amendments (2025)(legislature.mi.gov).gov
- SB 360-364 - Senate Fiscal Agency Analysis (Version G)(legislature.mi.gov).gov
- Michigan Internet Privacy Protection Act - Act 478 of 2012(legislature.mi.gov).gov
- Senate Bill 758 - Michigan Kids Code Act (2025)(legislature.mi.gov).gov
- Michigan Student Online Personal Protection Act - Act 368 of 2016(legislature.mi.gov).gov
- MCL 380.1136 - Protection of Pupil Privacy(legislature.mi.gov).gov
- Preservation of Personal Privacy Act - Act 378 of 1988(legislature.mi.gov).gov
- MCL 15.243 - Michigan FOIA Privacy Exemption (Section 13)(legislature.mi.gov).gov
- Michigan DHHS - HIPAA Information(michigan.gov).gov
- TAKE IT DOWN Act - Text of Pub. L. 119-12(congress.gov).gov
- FTC - TAKE IT DOWN Act Platform Enforcement (May 2026)(consumer.ftc.gov).gov
- AG Nessel - Roku Lawsuit for Children Privacy Violations (April 2025)(michigan.gov).gov
- Michigan Federal Court Narrows Roku Suit to COPPA Claims (April 2026)(troutmanprivacy.com)
- AG Nessel - Munson Healthcare Data Breach Alert (January 2026)(michigan.gov).gov
- AG Nessel - Demands Action from xAI over Grok NCII (January 2026)(michigan.gov).gov
- Michigan Department of Education - Pupil Privacy(michigan.gov).gov
- MCL 500.559 - Notification of cybersecurity event to the DIFS Director (Insurance Data Security Act)(legislature.mi.gov)
- MCL 500.555 - Comprehensive written information security program; annual certification of compliance(legislature.mi.gov)
- MCL 445.84 - Social Security Number Privacy Act; required privacy policy and FCRA/GLBA exemption(legislature.mi.gov)