Michigan
Michigan Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 10 primary sources cited on this page. How we verify our legal content

Michigan's Identity Theft Protection Act requires any business or agency holding Michigan residents' personal data to notify affected individuals after a breach of unencrypted information under MCL 445.72. Notice must be sent without unreasonable delay; no fixed day deadline exists under current law.
When a Michigan business discovers that hackers accessed its customer database, the clock starts ticking. The Identity Theft Protection Act sets out exactly what must happen next, who must be told, and what the consequences are for staying silent. Whether you are a business owner trying to comply or a resident who received a breach notice, understanding these rules is essential.
This guide covers Michigan's current data breach notification requirements under MCL 445.72, the penalties for noncompliance, safe harbor provisions, and pending legislation that could significantly tighten the rules. For broader context on privacy protections in the state, see the parent guide to Michigan Data Privacy Laws.
What Law Governs Data Breach Notification in Michigan
Michigan's data breach notification obligations come from the Identity Theft Protection Act, enacted as Act 452 of 2004 and effective March 1, 2005. The notification duty was not part of that original act. MCL 445.72 was added two years later by 2006 PA 566, effective July 2, 2007, and MCL 445.72(16) applies it to any breach discovered or notified on or after July 2, 2006. The section was last amended by 2010 PA 315, effective April 1, 2011. Key definitions sit in MCL 445.63.
The law applies to any person or agency that owns or licenses data included in a database containing personal information of Michigan residents. "Person" is defined broadly to include individuals, partnerships, corporations, limited liability companies, associations, and other legal entities. "Agency" covers state government departments, boards, commissions, and public universities.

What Triggers a Notification Obligation
A breach notification is required when there is unauthorized access and acquisition of data that compromises the security or confidentiality of personal information maintained in a database. Under MCL 445.63, a "security breach" means the unauthorized access and acquisition of data that compromises the security or confidentiality of personal information.
Personal Information That Triggers Notification
The law protects a Michigan resident's first name or first initial combined with last name, linked to one or more of the following unencrypted data elements:
- Social Security number
- Driver's license number or state personal identification card number
- Financial account number, credit card number, or debit card number in combination with any required security code, access code, or password that would permit access to the account
If a breach involves only a name without any of these linked data elements, notification is not required under this statute.
When Notification Is Not Required
An entity can skip notification if it determines that the breach "has not or is not likely to cause substantial loss or injury to, or result in identity theft with respect to" Michigan residents. The entity must exercise the care that "an ordinarily prudent person or agency in like position would exercise under similar circumstances" when making this determination.

The Encryption Safe Harbor
Michigan provides a clear encryption safe harbor. If the compromised data was encrypted or redacted, and the encryption key was not also accessed or acquired, no notification is required.
Under MCL 445.63, "encrypted" means data transformed through an algorithmic process into a form with a low probability of assigning meaning without a confidential process or key. "Redacted" means altering data so that no more than four digits of a driver's license, state ID, or account number are accessible, or no more than five digits of a Social Security number.
However, if an unauthorized person gains access to both the encrypted data and the encryption key, the safe harbor does not apply, and notification is required.
The Good-Faith Employee Exception
Not every unauthorized access counts as a breach. Under MCL 445.63, a security breach does not include access by an employee or other individual when all three conditions are met:
- The employee acted in good faith
- The access was related to the activities of the agency or person
- The employee did not misuse or disclose any personal information to an unauthorized person
This exception recognizes that employees sometimes access records outside their normal scope while performing legitimate work functions. As long as the access was well-intentioned, job-related, and no information was misused or shared, it falls outside the breach definition.
Notification Timeline and Methods
How Quickly Must Notice Be Sent
Michigan requires notification "without unreasonable delay." Unlike many newer state laws, Michigan does not currently set a specific number of days. The law does allow two exceptions to the timing requirement:
- Scope determination. A delay is permitted if necessary to determine the scope of the breach and restore the integrity of the database.
- Law enforcement request. Notice may be delayed at the request of a law enforcement agency investigating the breach.
Acceptable Notification Methods
MCL 445.72 allows several methods:
- Written notice by postal mail to the affected resident's last known address
- Electronic notice if the resident previously consented to electronic communications or has an existing business relationship with the entity
- Telephone notice via a live representative, with a follow-up written notice
- Substitute notice when the entity demonstrates that the cost of direct notification would exceed $250,000 or that notice would have to be provided to more than 500,000 Michigan residents (MCL 445.72(5)(d)). Substitute notice requires all three: email notification (when addresses are available), conspicuous posting on the entity's website, and notification to major statewide media.
What the Notice Must Include
Michigan law requires breach notifications to contain:
- A description of the security breach in general terms
- The type of personal information compromised
- What remedial measures the entity has taken to prevent further breaches
- A telephone number where affected individuals can get more information
- A reminder to remain vigilant for signs of fraud and identity theft
Consumer Reporting Agency Notification
For breaches affecting more than 1,000 Michigan residents, the entity must also notify each nationwide consumer reporting agency without unreasonable delay, unless the entity is subject to the Gramm-Leach-Bliley Act (15 U.S.C. 6801 through 6809), which MCL 445.72(8)(b) exempts from this duty. The notice must include the number of affected residents and the timing of the notification to those residents.
Third-Party Data Holders
An entity that maintains a database containing personal information that it does not own or license must notify the owner or licensor of the data after discovering a breach. The data owner then assumes responsibility for notifying affected individuals.
This provision is particularly relevant for cloud service providers, data processors, and IT vendors that store personal information on behalf of other businesses.

Penalties and Enforcement
Civil Fines
Under MCL 445.72, a person that knowingly fails to provide required breach notification may face civil fines of up to $250 per failure to notify. The aggregate liability from a single breach event is capped at $750,000.
The Michigan Attorney General or a county prosecuting attorney may bring an action to recover these civil fines.
Criminal Penalties
Filing a fraudulent or false breach notification with intent to defraud is a misdemeanor under the Identity Theft Protection Act:
- First offense: Up to 93 days imprisonment or a fine up to $250 per violation, or both
- Second offense: Up to 93 days imprisonment or a fine up to $500 per violation, or both
- Third or subsequent offense: Up to 93 days imprisonment or a fine up to $750 per violation, or both
No Private Right of Action
Michigan's breach notification statute does not create a private right of action. Individual consumers cannot sue a company directly for failing to provide breach notification. However, the statute explicitly states that it does not eliminate other remedies available under existing law. Affected individuals may still pursue claims under common law theories such as negligence if they can demonstrate actual damages.
Why the Consumer Protection Act Does Not Reach Notification Failures
The Michigan Consumer Protection Act makes it an unfair trade practice to violate "section 11 of the identity theft protection act, 2004 PA 452, MCL 445.71" (MCL 445.903(1)(jj)). That cross-reference points to MCL 445.71, which prohibits denying credit or public utility service to identity theft victims and sending unsolicited pre-approved credit checks and cards. It does not point to MCL 445.72, the breach notification section, and no other subdivision of MCL 445.903 covers breach notification.
A failure to notify is therefore enforced through the Identity Theft Protection Act's own civil fines, not as a Consumer Protection Act claim. MCL 445.72(15) preserves the availability of other civil remedies for violations of state or federal law, but it does not create a Consumer Protection Act cause of action for failing to send breach notice.
Data Destruction Requirements
Michigan also imposes obligations for securely disposing of personal information. Under MCL 445.72a, any entity that maintains a database of personal information must destroy that data when it is removed from the database, unless retention serves another lawful purpose.
"Destroy" means shredding, erasing, or otherwise modifying the data to make it unreadable or indecipherable. Violations of the destruction requirement carry misdemeanor penalties of up to $250 per violation.
Compliance Safe Harbors
Michigan recognizes two important compliance safe harbors:
- Financial institutions that comply with Federal Interagency Guidance on Response Programs for Unauthorized Access to Customer Information are deemed in compliance with Michigan's notification requirements.
- HIPAA-covered entities that comply with federal health data breach notification rules under the HITECH Act satisfy Michigan's requirements.

Pending Legislation: SB 360 Would Overhaul Michigan Breach Rules
Senate Bill 360, part of a five-bill package (SB 360-364), passed the Michigan Senate on August 26, 2025, by a vote of 19-15. It has been referred to the House Committee on Government Operations. If enacted, it would represent the most significant update to Michigan's breach notification framework since those requirements were added in 2006.
45-Day Notification Deadline
SB 360 would keep the current "without unreasonable delay" standard but add a hard outer limit of 45 days after the entity determines a breach occurred; notice would still have to go out sooner where a shorter delay is reasonable.
Attorney General Notification
Breaches affecting 100 or more Michigan residents would require written notice to the Attorney General no later than the date notice is provided to individuals. Current law does not require AG notification.
Expanded Personal Information Definition
The bill would add biometric data (fingerprints, voiceprints, retina or iris images, and genetic information used for identity authentication) to the categories of personal information that trigger notification obligations.
Mandatory Identity Theft Services
When a breach involves Social Security numbers or taxpayer identification numbers, the entity would be required to offer identity theft prevention and mitigation services at no cost for at least 24 months.
Cybersecurity Program Requirements
A new Section 11a would require entities handling personal information to implement and maintain reasonable security procedures, including:
- Appointing a security coordinator
- Identifying and assessing reasonably foreseeable risks
- Implementing safeguards aligned with the NIST Cybersecurity Framework 2.0 or equivalent industry standards
- Contractually requiring service providers to maintain similar safeguards
Enhanced Penalties
SB 360 would add civil fines of up to $2,000 for failing to maintain required security procedures or failing to investigate a potential breach, and would create a new misdemeanor for scam solicitations that mimic breach notices, carrying fines of $1,000/$2,000/$3,000 for first, second, and third offenses (the existing $250/$500/$750 fraudulent-notice fines are unchanged), in addition to the existing $250-per-notification-failure penalties.
As of August 2026, SB 360 remains pending in the House Committee on Government Operations, with no further action recorded since its August 2025 referral. A previous version of the bill (SB 888 in the 2023-2024 session) passed the Senate but stalled in the House.
Employer Obligations After a Breach
Michigan does not have a separate employer-specific breach notification statute. However, employers that maintain databases of employee personal information (Social Security numbers, direct deposit details, driver's license numbers) are subject to the same notification requirements under MCL 445.72 as any other data holder.
Employers should take these steps after discovering a breach affecting employee data:
- Assess the scope of the breach and what personal information was accessed
- Determine notification obligations based on whether the data was encrypted and whether harm is likely
- Notify affected employees without unreasonable delay using one of the approved methods
- Report to consumer reporting agencies if more than 1,000 employees are affected
- Document the investigation and remedial actions taken
- Review and strengthen security measures to prevent future incidents
This article provides general legal information about Michigan data breach notification laws. It is not legal advice. Data breach notification requirements are subject to change through legislation and regulatory guidance. Consult a qualified Michigan attorney for advice about your specific situation.
More Michigan Laws
Frequently Asked Questions
How quickly must a Michigan business notify customers after a data breach?
Under current law (MCL 445.72), Michigan businesses must notify affected residents 'without unreasonable delay.' There is no specific day deadline. Delays are permitted only to determine the scope of the breach or at the request of law enforcement. If SB 360 passes, a firm 45-day outer limit would apply on top of the unreasonable-delay standard.
Does Michigan require businesses to notify the Attorney General about data breaches?
No, current Michigan law does not require notification to the Attorney General. The only mandatory notification beyond affected individuals is to nationwide consumer reporting agencies when a breach affects more than 1,000 Michigan residents. SB 360, pending in the House, would require AG notification for breaches affecting 100 or more residents.
What are the penalties for failing to report a data breach in Michigan?
A person that knowingly fails to provide required breach notification faces civil fines of up to $250 per failure to notify, with aggregate liability capped at $750,000 per breach event. The Michigan Attorney General or a county prosecuting attorney can bring enforcement actions. Filing a false breach notification is a misdemeanor carrying up to 93 days imprisonment.
Does Michigan's breach notification law apply to encrypted data?
No, if the compromised data was properly encrypted and the encryption key was not also accessed or acquired, notification is not required. This encryption safe harbor is one of the most important compliance tools available to Michigan businesses. It provides a strong incentive to encrypt all stored personal information.
Can individuals sue a company for failing to notify them of a data breach in Michigan?
Michigan's Identity Theft Protection Act does not create a private right of action for breach notification failures. Only the Attorney General and county prosecuting attorneys can bring enforcement actions under the statute. However, individuals may pursue claims under other legal theories, such as negligence, if they can demonstrate actual damages from the failure to notify.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected two statutory points: the breach notification duty in MCL 445.72 was added by 2006 PA 566 (applying to breaches on or after July 2, 2006), not by the 2004 Identity Theft Protection Act, and the Michigan Consumer Protection Act's unfair-trade-practice hook reaches MCL 445.71 conduct only, so a failure to notify is not an MCPA violation.
Corrected the substitute-notice triggers to the two the statute authorizes, clarified SB 360 adds a 45-day outer limit on top of the unreasonable-delay standard, and added the GLBA exemption from consumer reporting agency notification.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Michigan Compiled Laws
§ 445.72Notice of security breach; requirementsIn forcecited in 7 of our articles
(1) Unless the person or agency determines that the security breach has not or is not likely to cause substantial loss or injury to, or result in identity theft with respect to, 1 or more residents of this state, a person or agency that owns or licenses data that are included in a database that discovers a security breach, or receives notice of a security breach under subsection (2), shall provide a notice of the security breach to each resident of this state who meets 1 or more of the following: (a) That resident's unencrypted and unredacted personal information was accessed and acquired by an unauthorized person. (b) That resident's personal information was accessed and acquired in encrypted form by a person with unauthorized access to the encryption key.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at legislature.mi.gov
Cited in 8 court opinions in our collectionLatest citing opinion in our collection: 2025
In the courts (editorial summary, independently checked):Federal courts differ on private enforcement. In re Target Corp. Customer Data Security Breach Litigation (2014) read subsection (15) to imply consumers may sue through Michigan's consumer protection act. Angus v. Flagstar Bank, FSB (2025) held that a 445.72 violation cannot support an MCPA claim.
Opinions citing this section in our collection:
- In re Target Corp. Customer Data Security Breach Litigation (District Court, D. Minnesota 2014, 66 F. Supp. 3d 1154)✓Hackers took card and personal data of roughly 110 million Target shoppers; on a motion to dismiss the court read the subsection preserving other civil remedies as implying consumers may enforce the section 445.72 notice duty through other Michigan laws.
- In re Equifax, Inc. (District Court, N.D. Georgia 2019, 362 F. Supp. 3d 1295)✓Hackers took the personal data of nearly 150 million people from Equifax; following Target, the court declined to dismiss the section 445.72 claim for lack of a private right of action, relying on the subsection preserving other civil remedies.
- Negron v. Ascension Health (District Court, E.D. Missouri 2025)“…XVI. Michigan Identity Theft Protection Act, Mich. Comp. Laws § 445.72 XVII. Michigan Consumer Protection A…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Michigan Data Privacy Laws: Consumer Rights & Protections (2026), Michigan Biometric Privacy Laws: Collection, Consent & Penalties (2026), Michigan Identity Theft Laws: Penalties and Victim Resources
§ 445.63DefinitionsIn forcecited in 7 of our articles
As used in this act: (a) "Agency" means a department, board, commission, office, agency, authority, or other unit of state government of this state. The term includes an institution of higher education of this state. The term does not include a circuit, probate, district, or municipal court. (b) "Breach of the security of a database" or "security breach" means the unauthorized access and acquisition of data that compromises the security or confidentiality of personal information maintained by a person or agency as part of a database of personal information regarding multiple individuals. These terms do not include unauthorized access to data by an employee or other individual if the access meets all of the following: (i) The employee or other individual acted in good faith in accessing the data. (ii) The access was related to the activities of the agency or person. (iii) The employee or other individual did not misuse any personal information or disclose any personal information to an unauthorized person. (c) "Child or spousal support" means support for a child or spouse, paid or provided pursuant to state or federal law under a court order or judgment.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at legislature.mi.gov
Cited in 5 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- People v. Perry (Michigan Court of Appeals 2016, 317 Mich. App. 589)“…license or state personal identification card number . . .” MCL 445.63(q). Circumstantial evidence and reasona…”
- Michigan Federation of Teachers & School Related Personnel v. University of Michigan (Michigan Supreme Court 2008, 481 Mich. 657)“…very type of information sought by plaintiff in this case. MCL 445.63(o). See also, e.g., Identity Theft and…”
- Deidre Goldsmith v. Faith Hope & Love Outreach Center Inc (Michigan Court of Appeals 2026)“…d for the purpose of identifying a specific person . . . .” MCL 445.63(q). Defendants argue that the…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 445.72aDestruction of data containing personal information required; violation as misdemeanor; fine; compliance; "destroy" definedIn forcecited in 4 of our articles
(1) Subject to subsection (3), a person or agency that maintains a database that includes personal information regarding multiple individuals shall destroy any data that contain personal information concerning an individual when that data is removed from the database and the person or agency is not retaining the data elsewhere for another purpose not prohibited by state or federal law. This subsection does not prohibit a person or agency from retaining data that contain personal information for purposes of an investigation, audit, or internal review. (2) A person who knowingly violates this section is guilty of a misdemeanor punishable by a fine of not more than $250.00 for each violation. This subsection does not affect the availability of any civil remedy for a violation of state or federal law. (3) A person or agency is considered to be in compliance with this section if the person or agency is subject to federal law concerning the disposal of records containing personal identifying information and the person or agency is in compliance with that federal law.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at legislature.mi.gov
§ 445.61Short titleIn forcecited in 7 of our articles
This act shall be known and may be cited as the "identity theft protection act".
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at legislature.mi.gov
Cited in 4 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Michigan Federation of Teachers & School Related Personnel v. University of Michigan (Michigan Supreme Court 2008, 481 Mich. 657)“…ure enacted 2004 PA 452, the Identity Theft Protection Act, MCL 445.61 et seq., whose title states, among othe…”
- Deidre Goldsmith v. Faith Hope & Love Outreach Center Inc (Michigan Court of Appeals 2026)“…ing identity theft under the Identity Theft Protection Act, MCL 445.61 et seq., forfeiture of property under M…”
- Keffer Development Services, LLC v. Hartford Casualty Insurance Company (District Court, W.D. Pennsylvania 2026)“…ations Act; (4) the Michigan Identity Theft Protection Act (MCL 445.61 et seq.); and (5) Ohio data security l…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 445.903Unfair, unconscionable, or deceptive methods, acts, or practices in conduct of trade or commerce; rules; applicability of subsection (1)(hh)In forcecited in 6 of our articles
(1) Unfair, unconscionable, or deceptive methods, acts, or practices in the conduct of trade or commerce are unlawful and are defined as follows: (a) Causing a probability of confusion or misunderstanding as to the source, sponsorship, approval, or certification of goods or services. (b) Using deceptive representations or deceptive designations of geographic origin in connection with goods or services. (c) Representing that goods or services have sponsorship, approval, characteristics, ingredients, uses, benefits, or quantities that they do not have or that a person has sponsorship, approval, status, affiliation, or connection that he or she does not have. (d) Representing that goods are new if they are deteriorated, altered, reconditioned, used, or secondhand. (e) Representing that goods or services are of a particular standard, quality, or grade, or that goods are of a particular style or model, if they are of another. (f) Disparaging the goods, services, business, or reputation of another by false or misleading representation of fact. (g) Advertising or representing goods or services with intent not to dispose of those goods or services as advertised or represented.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at legislature.mi.gov
Cited in 210 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Smith v. Globe Life Insurance (Michigan Supreme Court 1999, 460 Mich. 446)“…its reading of the terms “specifically authorized.” Under MCL 445.903; MSA 19.418(3), the MCPA protects consu…”
- Gorman v. American Honda Motor Co. (Michigan Court of Appeals 2013, 302 Mich. App. 113)“…acts, or practices in the conduct of trade or commerce[.]” MCL 445.903(1). The act defines “trade or commerce”…”
- Dell v. Citizens Insurance Company of America (Michigan Court of Appeals 2015, 312 Mich. App. 734)“…e or commerce as set forth in the [MCPA] . . . . See, e.g., MCL 445.903(1)(a), (c), (e), (n), (s), (x)…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
United States Code Title 15
§ 6801Protection of nonpublic personal informationIn forcecited in 4 of our articles
It is the policy of the Congress that each financial institution has an affirmative and continuing obligation to respect the privacy of its customers and to protect the security and confidentiality of those customers’ nonpublic personal information. In furtherance of the policy in subsection (a), each agency or authority described in section 6805(a) of this title, other than the Bureau of Consumer Financial Protection, shall establish appropriate standards for the financial institutions subject to their jurisdiction relating to administrative, technical, and physical safeguards— to insure the security and confidentiality of customer records and information; to protect against any anticipated threats or hazards to the security or integrity of such records; and to protect against unauthorized access to or use of such records or information which could result in substantial harm or inconvenience to any customer.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 250 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Individual Reference Services Group, Inc. v. Federal Trade Commission (District Court, District of Columbia 2001, 145 F. Supp. 2d 6)“…o. 106-102, 113 Stat. 1338 (1999) (codified as amended at 15 U.S.C.A. § 6801 'et seq. (2000)) (the “GL…”
- In re Equifax, Inc. (District Court, N.D. Georgia 2019, 371 F. Supp. 3d 1150)“…p. , 799 F.3d 236 , 247 (3d Cir. 2015). See 15 U.S.C. § 6801 (b). See 16 C.F.R. § 314.4…”
- Leland Stevens v. Interactive Financial Advisors (Court of Appeals for the Seventh Circuit 2016, 830 F.3d 735)“…clients to a non- affiliated third party like Stevens. See 15 U.S.C. § 6801; 17 C.F.R. § 248.10. This prevented Ste…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Georgia Data Privacy Laws: Breach Notification & Consumer Rights (2026), Oklahoma Data Privacy Laws: OKCDPA, Breach Notification & Consumer Rights (2026), New Hampshire Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Identity Theft Protection Act (Act 452 of 2004)(legislature.mi.gov).gov
- MCL 445.72 - Security Breach Notification Requirements(legislature.mi.gov).gov
- MCL 445.63 - Identity Theft Protection Act Definitions(legislature.mi.gov).gov
- MCL 445.72a - Data Destruction Requirements(legislature.mi.gov).gov
- Michigan Consumer Protection Act (MCL 445.903)(legislature.mi.gov).gov
- Senate Bill 360 of 2025 - Identity Theft Protection Act Amendments(legislature.mi.gov).gov
- SB 360 Engrossed Bill Text(legislature.mi.gov).gov
- Michigan Attorney General - Consumer Protection(michigan.gov).gov
- NIST Cybersecurity Framework 2.0(nist.gov).gov
- Federal Interagency Guidance on Response Programs(federalregister.gov).gov
- MCL 445.71 - Prohibited Conduct in Trade or Commerce (Identity Theft Protection Act sec. 11)(legislature.mi.gov)