EnglishEspañol
Minnesota flag

Minnesota

Minnesota MCDPA Consumer Rights (Minn. Stat. 325M.14)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 7 primary sources cited on this page. How we verify our legal content

Minnesota MCDPA Consumer Rights (Minn. Stat. 325M.14)

Frequently Asked Questions

What rights do Minnesota residents have under the MCDPA?

Under Minn. Stat. 325M.14, Minnesota residents have the rights to confirm whether a controller is processing their personal data and access the categories of that data, correct inaccuracies, delete data, and obtain a portable copy of data they provided. They may also opt out of targeted advertising, the sale of personal data, and profiling for significant decisions. Minnesota adds two distinctive rights: obtaining a list of the specific third parties that received their data, and questioning the result of a profiling decision.

What is Minnesota's right to question a profiling decision?

When a consumer is subject to profiling that produces legal or similarly significant effects, Minn. Stat. 325M.14 lets the consumer question the result, be informed of the reason it reached that result, learn what actions might secure a different decision in the future, and review and correct the data used. The decision can be reevaluated if it relied on inaccurate data. Connecticut is the only other state with a comparable right, effective July 1, 2026, and its version is narrower: it does not cover what actions might have secured a different decision, and it limits correction and reevaluation to housing decisions.

Can I get a list of the companies that received my data in Minnesota?

Yes. Under Minn. Stat. 325M.14, a Minnesota consumer may obtain a list of the specific third parties to which the controller disclosed the consumer's personal data, or at the controller's option any personal data. This names the actual recipients rather than just broad categories, which is more transparent than what most state laws require. Only a few states, such as Oregon, offer this.

How long does a Minnesota controller have to respond?

A controller generally must respond to a verified MCDPA request within 45 days. It may extend that period once by an additional 45 days when reasonably necessary, as long as it tells the consumer about the extension and the reason within the first 45 days. Information must generally be provided free up to twice per year, though a reasonable fee may apply when a request is manifestly unfounded or excessive.

Can I opt out of targeted ads and data sales in Minnesota?

Yes. Under Minn. Stat. 325M.14, Minnesota consumers may opt out of targeted advertising, the sale of personal data, and profiling for significant decisions. The MCDPA also requires controllers to recognize a universal opt-out mechanism, such as the Global Privacy Control, so a single browser or device signal can communicate an opt-out of sale and targeted advertising across controllers.

Do controllers need my consent to process sensitive data in Minnesota?

Yes. The MCDPA requires opt-in consent before a controller may process sensitive data, which includes data revealing racial or ethnic origin, religion, health conditions, sexual orientation, citizenship or immigration status, genetic or biometric data, precise geolocation, and a known child's data. Unlike California's opt-out model, Minnesota requires affirmative permission first.

What can I do if a Minnesota controller ignores my request?

The MCDPA requires controllers to offer an appeal process for refusals. You submit an appeal much as you submitted the original request, and the controller must respond in writing with its reasoning. If the appeal is denied, the controller must give you a way to contact the Minnesota Attorney General. There is no private right of action, so the Attorney General, not a private lawsuit, is the enforcement path.

Is there still a cure period under the Minnesota MCDPA?

Not as a guarantee. The MCDPA included a 30-day right to cure that let controllers fix a violation before the Attorney General brought an action, but that provision sunset January 31, 2026. As of 2026, any cure opportunity is at the Attorney General's discretion rather than a built-in right.

Updates

Corrected the Minnesota access right to reach the categories of personal data rather than the data itself, updated the profiling-challenge right to note that Connecticut added a narrower version effective July 1, 2026 while Minnesota's remains the broadest, and fixed the MCDPA's codification to Minn. Stat. secs. 325M.10 to 325M.21.

Added the 15-day consent-revocation right and the specific appeal-response timeline under the Minnesota Consumer Data Privacy Act.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Corrected the free-response allowance under Minn. Stat. 325M.14: the MCDPA entitles a consumer to up to two free responses per year, not one, and a fee applies only to manifestly unfounded or excessive requests, not simply to a second request.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Minn. Stat. 325M.14: Consumer Personal Data Rights(revisor.mn.gov).gov
  2. Minn. Stat. 325M.14: Controller Response and Appeals(revisor.mn.gov).gov
  3. Minnesota Statutes Chapter 325M: Consumer Data Privacy Act (Full Chapter)(revisor.mn.gov).gov
  4. Minn. Stat. 325M.16: Controller Duties and Sensitive Data Consent(revisor.mn.gov).gov
  5. Minn. Stat. 325M.20: Enforcement and Civil Penalties(revisor.mn.gov).gov
  6. Minnesota Attorney General: Consumer Data Privacy(ag.state.mn.us).gov
  7. Minnesota Attorney General: MCDPA Business Enforcement Overview(ag.state.mn.us).gov
  8. Minn. Stat. ch. 325M - Minnesota Consumer Data Privacy Act at secs. 325M.10 to 325M.21(revisor.mn.gov)
  9. Connecticut Public Act 25-113 (Substitute S.B. 1295), Sec. 8, amending Conn. Gen. Stat. Sec. 42-518 effective July 1, 2026(cga.ct.gov)
Share: