EnglishEspañol
Minnesota flag

Minnesota

Minnesota Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 5 primary sources cited on this page. How we verify our legal content

Minnesota Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must a business notify Minnesota residents of a data breach?

Minnesota requires notification "in the most expedient time possible and without unreasonable delay." Unlike many states, Minnesota does not set a specific day count. The timeline depends on the circumstances, including the time needed to investigate the breach and restore system integrity. Law enforcement may also request a delay if notification would impede a criminal investigation.

Does Minnesota require businesses to notify the Attorney General after a data breach?

No. Minnesota's general breach notification statute (Minn. Stat. 325E.61) does not require businesses to notify the Attorney General. However, when a breach affects more than 500 people, the business must notify the major consumer reporting agencies (Equifax, Experian, and TransUnion) within 48 hours. The Attorney General retains enforcement authority and may investigate breaches independently.

Does encryption protect businesses from Minnesota's breach notification requirements?

Yes. Minnesota provides an encryption safe harbor. If the compromised personal information was encrypted or otherwise made unreadable, and the encryption key was not also acquired during the breach, notification is not required. If the unauthorized person obtained both the encrypted data and the decryption key, full notification obligations apply.

Does Minnesota's breach notification law cover biometric data?

No. Minnesota's breach notification statute (Minn. Stat. 325E.61) does not include biometric data in its definition of personal information. A breach exposing fingerprints, facial geometry, or voiceprints does not trigger notification under this law. The MCDPA classifies biometric data as sensitive personal data requiring consent before processing, but it does not extend the breach notification trigger to biometric data.

What are the penalties for violating Minnesota's breach notification law?

The Minnesota Attorney General enforces the breach notification law and can pursue enforcement actions under state consumer protection statutes. The statute itself gives individuals no express right to sue for notification failures, though whether Minn. Stat. 8.31's private attorney general provision could support such a suit remains unsettled. The AG can seek injunctive relief and civil penalties of up to $25,000 per violation. Any contractual waiver of notification requirements is void and unenforceable as contrary to public policy.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the description of what Minnesota's breach notification law excludes from 'personal information': Minn. Stat. 325E.61 excludes only publicly available information lawfully made available from federal, state, or local government records, not data from publicly available sources generally.

Corrected the consumer reporting agency thresholds to the statutory more-than-500 and more-than-1,000 triggers, clarified the unsettled private-enforcement question under Minn. Stat. 8.31, and fixed two citation precision issues.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Corrected a miscited statute for the MCDPA processor breach-assistance duty. Minn. Stat. 325O.04 does not exist; the correct citation, confirmed against the live text at the Minnesota Office of the Revisor of Statutes, is Minn. Stat. 325M.13(b)(2), which is part of the MCDPA (chapter 325M) and contains the exact quoted language.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Minn. Stat. 325E.61(revisor.mn.gov).gov
  2. Minn. Stat. 325E.64(revisor.mn.gov).gov
  3. Minn. Stat. 13.055(revisor.mn.gov).gov
  4. Minnesota Consumer Data Privacy Act (HF 2309)(revisor.mn.gov).gov
  5. Minnesota Attorney General(ag.state.mn.us).gov
Share: