EnglishEspañol
Michigan flag

Michigan

Michigan Data Privacy Laws: Consumer Rights & Protections (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 24 primary sources cited on this page. How we verify our legal content

Michigan Data Privacy Laws: Consumer Rights & Protections (2026)

Frequently Asked Questions

Does Michigan have a comprehensive data privacy law?

No. As of May 2026, Michigan does not have a comprehensive consumer data privacy law. The state relies on targeted statutes including the Identity Theft Protection Act, the Social Security Number Privacy Act, the Insurance Data Security Act, and the Consumer Protection Act. Senate Bill 359, the Personal Data Privacy Act, was introduced in June 2025 and remains in the Senate Committee of the Whole. It has not passed either chamber. Until SB 359 or a successor bill is enacted, Michigan residents rely on these state laws plus federal protections such as HIPAA, COPPA, and GLBA.

What are the penalties for failing to report a data breach in Michigan?

Under the Identity Theft Protection Act (MCL 445.72), a person or agency that knowingly fails to provide required breach notification faces civil fines of up to $250 per failure. Total civil-fine liability from a single breach is capped at $750,000. Separate penalties may apply under the Michigan Consumer Protection Act if the failure involves deceptive trade practices. Insurance licensees face separate reporting obligations: under MCL 500.559 they must notify DIFS within 10 business days of a cybersecurity event, but only when Michigan is the licensee's state of domicile or home state and the event is reasonably likely to cause material harm, or when 250 or more Michigan residents' nonpublic information is involved.

Can my employer access my personal social media accounts in Michigan?

No. Michigan's Internet Privacy Protection Act (Act 478 of 2012) prohibits employers from requesting or requiring employees or job applicants to share login credentials for personal internet accounts. Employers may monitor activity on employer-owned devices and networks, view publicly available information, and investigate specific credible reports of work-related misconduct involving personal accounts. The act does not create a duty for employers to search or monitor personal internet account activity.

How quickly must a company notify me of a data breach in Michigan?

Michigan law requires notification 'without unreasonable delay' but does not set a specific number of days for most businesses. The standard is that the entity must act with the care an ordinarily prudent person would exercise under similar circumstances. Insurance licensees can face a stricter standard: MCL 500.559 requires DIFS notification no later than 10 business days after determining a cybersecurity event occurred, but only when Michigan is the licensee's state of domicile or home state and the event is reasonably likely to cause material harm, or when 250 or more Michigan residents' nonpublic information is involved. Proposed amendments in SB 360-364 would require notification to the Attorney General for breaches affecting more than 100 Michigan residents.

Has Michigan passed the Personal Data Privacy Act?

No. As of May 2026, Senate Bill 359, the Personal Data Privacy Act, has not passed. The Michigan Senate Finance, Insurance, and Consumer Protection Committee reported it favorably on June 11, 2025, and referred it to the Committee of the Whole, where it remained pending. The bill has not been voted on by the full Senate. Michigan has passed SB 359 twice in a prior form in the Senate but it has never advanced through the House. Monitor legislature.mi.gov for updates.

What does the TAKE IT DOWN Act mean for Michigan residents?

The federal TAKE IT DOWN Act (Pub. L. 119-12, signed May 19, 2025) makes it a federal crime to publish nonconsensual intimate images. Beginning May 19, 2026, covered online platforms must maintain a system allowing individuals to report NCII and must remove reported content and known identical copies within 48 hours. The FTC enforces the platform obligations. Michigan AG Nessel has been active on this issue, joining a 36-state coalition demanding xAI address Grok's generation of such content.

Does Michigan have a law protecting insurance customer data?

Yes. The Michigan Insurance Data Security Act (MCL 500.550 to 500.565), effective January 20, 2021, requires insurance licensees to develop and maintain a comprehensive written information security program and, under MCL 500.559, to notify DIFS within 10 business days of a cybersecurity event when Michigan is the licensee's state of domicile or home state and material harm is reasonably likely, or when 250 or more Michigan residents' nonpublic information is involved. The law applies to insurers, producers, adjusters, and other licensed insurance entities, and Michigan-domiciled insurers must also submit an annual compliance certification by February 15 under MCL 500.555(9). Smaller licensees with fewer than 25 employees, including independent contractors, are exempt from the WISP requirement under MCL 500.565. A licensee that grows to 25 or more employees has 180 days to comply.

What should I do if my data is breached in Michigan?

If you receive a breach notification, immediately place fraud alerts with all three major credit bureaus (Equifax, Experian, TransUnion), review your credit reports for unauthorized accounts or activity, consider placing a credit freeze, change passwords for any affected accounts, and monitor financial statements closely. You can also file a complaint with the Michigan Attorney General's Consumer Protection Division at michigan.gov/ag. For health-information breaches, file a complaint with the HHS Office for Civil Rights.

Updates

Corrected the Michigan Insurance Data Security Act reporting citation to MCL 500.559 and added the statutory conditions that trigger the 10-business-day DIFS notice, limited the annual February 15 compliance certification to Michigan-domiciled insurers under MCL 500.555(9), and added the FCRA and Gramm-Leach-Bliley exemption to the Social Security number privacy policy requirement under MCL 445.84(3).

Corrected the Insurance Data Security Act's small-licensee exemption (it applies solely based on employee count under MCL 500.565, not a revenue/asset test), added the 1,000-resident threshold for consumer-reporting-agency breach notification under MCL 445.72, added credit/debit card numbers to the personal-information definition under MCL 445.63, and updated the Kids Code Act's now-lapsed July 1, 2026 effective date and pending-House status.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

May 2026 refresh: Corrected SB 359 legislative status (bill remains in Senate Committee of the Whole, has NOT passed the Senate; prior version incorrectly stated it had passed the Senate). Added Michigan Insurance Data Security Act (MCL 500.550 to 500.565, effective Jan 20, 2021) as a new section. Added Michigan Kids Code Act (SB 758, passed Senate, pending House, effective July 1, 2026 if enacted). Added TAKE IT DOWN Act (Pub. L. 119-12) platform obligations effective May 19, 2026. Updated Roku enforcement section to reflect April 2026 federal court ruling narrowing case to COPPA claims only. Added xAI/Grok multistate AG coalition detail (Jan 26, 2026). Added MCL 15.243 FOIA Section 13 privacy exemption. Updated FAQ to 8 questions. Expanded SourcesList to 25 sources.

Reviewed and approved by an editor

Sources and References

  1. Michigan Identity Theft Protection Act - Act 452 of 2004 (Full Text)(legislature.mi.gov).gov
  2. MCL 445.72 - Breach Notification Requirements(legislature.mi.gov).gov
  3. MCL 445.72a - Data Destruction Requirements(legislature.mi.gov).gov
  4. MCL 445.63 - Personal Information Definitions(legislature.mi.gov).gov
  5. Michigan Social Security Number Privacy Act - Act 454 of 2004(legislature.mi.gov).gov
  6. Michigan Insurance Data Security Act - MCL 500.550 to 500.565(michigan.gov).gov
  7. Michigan Consumer Protection Act - Act 331 of 1976(legislature.mi.gov).gov
  8. Senate Bill 359 - Personal Data Privacy Act (2025)(legislature.mi.gov).gov
  9. SB 359 - Senate Fiscal Agency Analysis (Version G)(legislature.mi.gov).gov
  10. Senate Bills 360-364 - ITPA Amendments (2025)(legislature.mi.gov).gov
  11. SB 360-364 - Senate Fiscal Agency Analysis (Version G)(legislature.mi.gov).gov
  12. Michigan Internet Privacy Protection Act - Act 478 of 2012(legislature.mi.gov).gov
  13. Senate Bill 758 - Michigan Kids Code Act (2025)(legislature.mi.gov).gov
  14. Michigan Student Online Personal Protection Act - Act 368 of 2016(legislature.mi.gov).gov
  15. MCL 380.1136 - Protection of Pupil Privacy(legislature.mi.gov).gov
  16. Preservation of Personal Privacy Act - Act 378 of 1988(legislature.mi.gov).gov
  17. MCL 15.243 - Michigan FOIA Privacy Exemption (Section 13)(legislature.mi.gov).gov
  18. Michigan DHHS - HIPAA Information(michigan.gov).gov
  19. TAKE IT DOWN Act - Text of Pub. L. 119-12(congress.gov).gov
  20. FTC - TAKE IT DOWN Act Platform Enforcement (May 2026)(consumer.ftc.gov).gov
  21. AG Nessel - Roku Lawsuit for Children Privacy Violations (April 2025)(michigan.gov).gov
  22. Michigan Federal Court Narrows Roku Suit to COPPA Claims (April 2026)(troutmanprivacy.com)
  23. AG Nessel - Munson Healthcare Data Breach Alert (January 2026)(michigan.gov).gov
  24. AG Nessel - Demands Action from xAI over Grok NCII (January 2026)(michigan.gov).gov
  25. Michigan Department of Education - Pupil Privacy(michigan.gov).gov
  26. MCL 500.559 - Notification of cybersecurity event to the DIFS Director (Insurance Data Security Act)(legislature.mi.gov)
  27. MCL 500.555 - Comprehensive written information security program; annual certification of compliance(legislature.mi.gov)
  28. MCL 445.84 - Social Security Number Privacy Act; required privacy policy and FCRA/GLBA exemption(legislature.mi.gov)
Share: