Minnesota
Minnesota MCDPA Compliance Checklist (Minn. Stat. 325M)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 8 primary sources cited on this page. How we verify our legal content

Complying with the Minnesota Consumer Data Privacy Act (MCDPA), codified at Minn. Stat. ch. 325M, means more than answering consumer requests. A covered controller must build and document a privacy governance program, including a data inventory that few other state laws require, and be ready to recognize universal opt-out signals, obtain opt-in consent for sensitive data, and answer a consumer's questions about an automated profiling decision.
The MCDPA took effect July 31, 2025 for most controllers, with a delayed July 31, 2029 date for postsecondary institutions regulated by the Office of Higher Education. As of 2026, the Minnesota Attorney General enforces the law under Minn. Stat. 325M.20, the 30-day cure period has sunset, and penalties run up to $7,500 per violation.
Jurisdiction scope: This covers Minnesota's Consumer Data Privacy Act (Minn. Stat. ch. 325M). It is general legal information, not legal advice.
Step 1: Determine whether the MCDPA applies to you
Start with the applicability test in Minn. Stat. 325M.12. The MCDPA reaches a controller that conducts business in Minnesota, or produces products or services targeted to Minnesota residents, and that during a calendar year meets one of two thresholds.
The first threshold is controlling or processing the personal data of 100,000 or more consumers, not counting data processed solely to complete a payment transaction. The second is controlling or processing the data of 25,000 or more consumers while deriving over 25 percent of gross revenue from the sale of personal data.
Minnesota also exempts small businesses as defined by the United States Small Business Administration, although an exempt small business still may not sell a consumer's sensitive data without consent. Map your entity and data sets against the act's exemptions, including the GLBA and HIPAA carve-outs, before concluding you are out of scope.
Step 2: Build a data inventory and governance program
This is the MCDPA's signature compliance burden. Under Minn. Stat. 325M.18, a controller must establish, implement, and maintain reasonable administrative, technical, and physical data security practices, and as part of that program must maintain an inventory of the personal data it manages.
The controller must also document and maintain a description of the policies and procedures it has adopted to comply with the act. That documentation must address data minimization and retention practices and include the name and contact information for the controller's chief privacy officer or other individual with primary responsibility for data privacy.
Few other state privacy laws require a documented data inventory of this kind, so a controller cannot simply copy a Virginia-style program. The inventory is also the foundation for satisfying the specific-third-party list right, because you cannot tell a consumer which named recipients got their data unless you have mapped your data flows. Build this first; the rest of the program depends on it.

Step 3: Update your privacy notice
Under the MCDPA, a controller must provide consumers a reasonably accessible, clear, and meaningful privacy notice. The notice should describe the categories of personal data processed, the purposes for processing, the categories of personal data shared with third parties, and the categories of third parties involved.
The notice must also explain how consumers may exercise their rights and appeal a controller's decision, and it must disclose if the controller sells personal data or processes it for targeted advertising or profiling, along with how to opt out. Because Minnesota requires recognition of universal opt-out signals, the notice should explain that the controller honors such signals.
Step 4: Handle sensitive data and universal opt-out
Two consent and signal duties sit at the heart of MCDPA processing. First, a controller must obtain opt-in consent before processing sensitive data, which includes data revealing racial or ethnic origin, religion, a health condition or diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data, precise geolocation, and a known child's data. Consent must be a clear affirmative act; it cannot be buried or inferred from inaction. Build a revocation path too: Minn. Stat. 325M.16 requires a revocation mechanism at least as easy as giving consent, and processing must stop as soon as practicable and no later than 15 days after a revocation request.
Second, the controller must recognize a universal opt-out mechanism, such as the Global Privacy Control, that lets a consumer opt out of sale and targeted advertising through a single browser or device signal. Configure your systems to detect and honor those signals, not just opt-out requests filed one by one.
Step 5: Stand up request handling, the 45-day clock, and appeals
Set up a process for consumers to submit verified rights requests through methods you describe in your privacy notice. The controller generally must respond within 45 days, with one 45-day extension when reasonably necessary and disclosed to the consumer.
You must also offer an appeals process for any refusal. The appeals process must be conspicuous and easy to use, and when an appeal is denied you must give the consumer a method to contact the Minnesota Attorney General. Free responses are generally required up to twice per consumer per year, with reasonable fees allowed only when a request is manifestly unfounded or excessive, not merely because it is a second request within the period.

Step 6: Build a profiling-result answer mechanism
Minnesota is the only state, as of 2026, that requires a controller to answer a consumer's questions about an automated profiling decision, so most off-the-shelf compliance programs will not cover it. If you use profiling in furtherance of decisions that produce legal or similarly significant effects, you need an operational way to respond.
Under Minn. Stat. 325M.14, a consumer may question the result of the profiling. You must be able to inform the consumer of the reason the profiling resulted in the decision and, if feasible, what the consumer might do to secure a different decision in the future. You must also let the consumer review the personal data used, correct it, and have the decision reevaluated if it relied on inaccurate data. Document how your models reach decisions well enough to explain them, because you cannot answer these questions about a model you cannot interpret.
Step 7: Assessments, processor contracts, and enforcement reality
Conduct and document data protection assessments for higher-risk processing, including the sale of personal data, processing for targeted advertising, certain profiling, and the processing of sensitive data. The Attorney General may require a controller to disclose a relevant assessment in connection with an investigation, so keep them retrievable.
Put written contracts in place with every processor. Those contracts must set out processing instructions and require the processor to maintain confidentiality, delete or return data, support the controller's obligations, and submit to audits, consistent with the controller-processor duties in the act.
Finally, budget for the enforcement reality. The Minnesota Attorney General is the sole enforcer under Minn. Stat. 325M.20, civil penalties run up to $7,500 per violation, and there is no private right of action. The 30-day right to cure sunset January 31, 2026, so as of 2026 a cure opportunity is discretionary rather than guaranteed. The safer posture is to be compliant before a complaint arrives, not to rely on fixing problems after the fact.
Related guides
- Minnesota data privacy laws parent hub
- What is the Minnesota MCDPA?
- Minnesota MCDPA consumer rights
- State data privacy law comparison
- What is the CCPA?
More Minnesota Laws
Frequently Asked Questions
Does my business have to comply with the Minnesota MCDPA?
Under Minn. Stat. 325M.12, the MCDPA applies if you conduct business in Minnesota or target its residents and, in a calendar year, control or process the personal data of 100,000 or more consumers, or of 25,000 or more consumers while deriving over 25 percent of gross revenue from selling data. Small businesses as defined by the U.S. Small Business Administration are exempt, though they still need consent to sell sensitive data.
What is the Minnesota data inventory requirement?
Under Minn. Stat. 325M.18, a Minnesota controller must maintain an inventory of the personal data it manages and document its data privacy and security policies and procedures, including data minimization and retention practices and the contact information for its chief privacy officer. This documented data inventory is uncommon among state privacy laws and is the foundation for answering the specific-third-party list right.
When did the Minnesota MCDPA take effect for compliance?
The MCDPA took effect July 31, 2025 for most controllers. Postsecondary institutions regulated by the Office of Higher Education have a delayed compliance date of July 31, 2029. As of 2026, most covered businesses must already be compliant.
Do I need consent to process sensitive data in Minnesota?
Yes. The MCDPA requires opt-in consent before processing sensitive data, which includes data revealing racial or ethnic origin, religion, health conditions, sexual orientation, citizenship or immigration status, genetic or biometric data, precise geolocation, and a known child's data. Consent must be a clear affirmative act and cannot be inferred from inaction or a pre-checked box.
How fast must a Minnesota controller answer a request?
A controller generally must respond to a verified consumer request within 45 days. It may extend once by another 45 days when reasonably necessary, as long as it informs the consumer of the extension and the reason within the first 45 days. Up to two responses in a 12-month period are generally free, and a fee applies only when a request is manifestly unfounded or excessive.
What does Minnesota require for profiling decisions?
If you profile consumers in furtherance of decisions with legal or similarly significant effects, Minn. Stat. 325M.14 requires you to let a consumer question the result, learn the reason for the decision, learn what they might do to change it, and review and correct the data used. You need an operational and documented way to explain your automated decisions, which is unique to Minnesota among states as of 2026.
Do I need data protection assessments under the MCDPA?
Yes, for higher-risk processing. The MCDPA requires controllers to conduct and document data protection assessments for activities such as selling personal data, targeted advertising, certain profiling, and processing sensitive data. The Minnesota Attorney General may require disclosure of a relevant assessment during an investigation, so keep them current and retrievable.
Is there still a cure period under the Minnesota MCDPA, and can consumers sue?
The MCDPA's 30-day right to cure sunset January 31, 2026, so as of 2026 any cure opportunity is at the Minnesota Attorney General's discretion rather than guaranteed. There is also no private right of action: enforcement rests solely with the Attorney General under Minn. Stat. 325M.20, who may seek civil penalties of up to $7,500 per violation. Consumers file complaints with the Attorney General rather than suing directly.
Updates
Added the consent-revocation mechanism duty and its 15-day processing-stop deadline to the sensitive-data step.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected the free-response allowance under Minn. Stat. 325M.14: the MCDPA entitles a consumer to up to two free responses per year, not one, and a fee applies only to manifestly unfounded or excessive requests, not simply to a second request.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Minnesota Statutes, Chapter 325M: CONSUMER DIGITAL AND DATA PRIVACY
§ 325M.16RESPONSIBILITIES OF CONTROLLERSIn forcecited in 4 of our articles
Subdivision 1. Transparency obligations. (a) Controllers must provide consumers with a reasonably accessible, clear, and meaningful privacy notice that includes: (1) the categories of personal data processed by the controller; (2) the purposes for which the categories of personal data are processed; (3) an explanation of the rights contained in section 325M.14 and how and where consumers may exercise those rights, including how a consumer may appeal a controller's action with regard to the consumer's request; (4) the categories of personal data that the controller sells to or shares with third parties, if any; (5) the categories of third parties, if any, with whom the controller sells or shares personal data; (6) the controller's contact information, including an active email address or other online mechanism that the consumer may use to contact the controller; (7) a description of the controller's retention policies for personal data; and (8) the date the privacy notice was last updated.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at revisor.mn.gov
Also relied on in: Minnesota Data Privacy Laws: Consumer Rights Guide (2026), Minnesota Biometric Privacy Laws: Collection, Consent & Penalties (2026), Minnesota MCDPA Consumer Rights (Minn. Stat. 325M.14)
§ 325M.12SCOPE; EXCLUSIONSIn forcecited in 5 of our articles
Subdivision 1. Scope. (a) Sections 325M.10 to 325M.21 apply to legal entities that conduct business in Minnesota or produce products or services that are targeted to residents of Minnesota, and that satisfy one or more of the following thresholds: (1) during a calendar year, controls or processes personal data of 100,000 consumers or more, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or (2) derives over 25 percent of gross revenue from the sale of personal data and processes or controls personal data of 25,000 consumers or more. (b) A controller or processor acting as a technology provider under section 13.32 shall comply with sections 13.32 and 325M.10 to 325M.21, except that when the provisions of section 13.32 conflict with sections 325M.10 to 325M.21, section 13.32 prevails. Subd. 2. Exclusions.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at revisor.mn.gov
Also relied on in: What Is the Minnesota Consumer Data Privacy Act (MCDPA)?, Minnesota Employee Monitoring Laws (2026): Cameras, GPS & Privacy
§ 325M.14CONSUMER PERSONAL DATA RIGHTSIn forcecited in 5 of our articles
Subdivision 1. Consumer rights provided. (a) Except as provided in sections 325M.10 to 325M.21, a controller must comply with a request to exercise the consumer rights provided in this subdivision. (b) A consumer has the right to confirm whether or not a controller is processing personal data concerning the consumer and access the categories of personal data the controller is processing. (c) A consumer has the right to correct inaccurate personal data concerning the consumer, taking into account the nature of the personal data and the purposes of the processing of the personal data. (d) A consumer has the right to delete personal data concerning the consumer. (e) A consumer has the right to obtain personal data concerning the consumer, which the consumer previously provided to the controller, in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at revisor.mn.gov
§ 325M.18DATA PRIVACY POLICIES; DATA PRIVACY AND PROTECTION ASSESSMENTSIn forcecited in 4 of our articles
(a) A controller must document and maintain a description of the policies and procedures the controller has adopted to comply with sections 325M.10 to 325M.21. The description must include, where applicable: (1) the name and contact information for the controller's chief privacy officer or other individual with primary responsibility for directing the policies and procedures implemented to comply with the provisions of sections 325M.10 to 325M.21; and (2) a description of the controller's data privacy policies and procedures which reflect the requirements in section 325M.16, and any policies and procedures designed to: (i) reflect the requirements of sections 325M.10 to 325M.21 in the design of the controller's systems; (ii) identify and provide personal data to a consumer as required by sections 325M.10 to 325M.21; (iii) establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data, including the maintenance of an inventory of the data that must be managed to exercise the responsibilities under this item; (iv) limit the collection of personal data to what…
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at revisor.mn.gov
§ 325M.20ATTORNEY GENERAL ENFORCEMENTIn forcecited in 5 of our articles
(a) In the event that a controller or processor violates sections 325M.10 to 325M.21, the attorney general, prior to filing an enforcement action under paragraph (b), must provide the controller or processor with a warning letter identifying the specific provisions of sections 325M.10 to 325M.21 the attorney general alleges have been or are being violated. If, after 30 days of issuance of the warning letter, the attorney general believes the controller or processor has failed to cure any alleged violation, the attorney general may bring an enforcement action under paragraph (b). This paragraph expires January 31, 2026. (b) The attorney general may bring a civil action against a controller or processor to enforce a provision of sections 325M.10 to 325M.21 in accordance with section 8.31. If the state prevails in an action to enforce sections 325M.10 to 325M.21, the state may, in addition to penalties provided by paragraph (c) or other remedies provided by law, be allowed an amount determined by the court to be the reasonable value of all or part of the state's litigation expenses incurred.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at revisor.mn.gov
Explore the law
This article also draws on these acts and chapters (opening at their first section): Minnesota Statutes, Chapter 325M: CONSUMER DIGITAL AND DATA PRIVACY § 325M.01 (DEFINITIONS)
Related law for further reading — not part of this article’s citations.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Minnesota Statutes Chapter 325M: Consumer Data Privacy Act (Full Chapter)(revisor.mn.gov).gov
- Minn. Stat. 325M.12: Scope; Exclusions (Applicability Thresholds)(revisor.mn.gov).gov
- Minn. Stat. 325M.14: Consumer Personal Data Rights and Profiling(revisor.mn.gov).gov
- Minn. Stat. 325M.14: Controller Response and Appeals(revisor.mn.gov).gov
- Minn. Stat. 325M.18: Controller Duties, Data Inventory, and Security(revisor.mn.gov).gov
- Minn. Stat. 325M.20: Enforcement and Civil Penalties(revisor.mn.gov).gov
- Minnesota Attorney General: MCDPA Business Compliance(ag.state.mn.us).gov
- Minnesota Attorney General: MCDPA Business Enforcement Overview(ag.state.mn.us).gov