Minnesota
Minnesota MCDPA Consumer Rights (Minn. Stat. 325M.14)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 7 primary sources cited on this page. How we verify our legal content

The Minnesota Consumer Data Privacy Act (MCDPA), codified at Minn. Stat. secs. 325M.10 to 325M.21 with the consumer rights set out in Minn. Stat. 325M.14, gives Minnesota residents the rights to confirm processing and access the categories of personal data held about them, correct, delete, and port their personal data, plus the right to opt out of targeted advertising, the sale of their data, and profiling. Two rights go further than almost any other state: the right to obtain a list of the specific third parties that received their data, and the broadest version in the country of the right to question the result of an automated profiling decision.
A controller generally must respond to a consumer rights request within 45 days, and consumers may appeal a refusal. As of 2026, the Minnesota Attorney General enforces these rights under Minn. Stat. 325M.20, with civil penalties up to $7,500 per violation and no private right of action.
Jurisdiction scope: This covers Minnesota's Consumer Data Privacy Act (Minn. Stat. secs. 325M.10 to 325M.21). It is general legal information, not legal advice.
The core MCDPA consumer rights
Minnesota consumers hold a familiar set of core rights under Minn. Stat. 325M.14, though one of them is drawn more narrowly than in most comprehensive state privacy laws. The first is the right to confirm whether or not a controller is processing personal data concerning the consumer and to access the categories of personal data the controller is processing. That reaches the categories rather than the data itself, which is narrower than a state such as Connecticut, whose law lets a consumer access the personal data itself.
The second is the right to correct inaccuracies in the consumer's personal data, taking into account the nature of the data and the purposes of processing. The third is the right to delete personal data concerning the consumer.
The fourth is the right to data portability: to obtain a copy of the personal data the consumer previously provided, in a portable and, to the extent technically feasible, readily usable format that lets the consumer transmit the data to another controller without hindrance. These four rights form the backbone of a Minnesota data request, but the MCDPA adds rights that most states do not.
The right to a list of specific third parties
One of the two features that set Minnesota apart is the ability to learn exactly which third parties received a consumer's data. Under Minn. Stat. 325M.14, a Minnesota consumer may obtain a list of the specific third parties to which the controller has disclosed the consumer's personal data.
At the controller's option, the controller may instead provide a list of the specific third parties to which it has disclosed any personal data. Either way, the disclosure identifies named recipients rather than broad groups.
This goes well beyond the more common model. Most state privacy laws let a consumer learn only the categories of third parties, such as "advertising networks" or "service providers." Minnesota, like Oregon, requires named entities. For consumers, that is a far more meaningful window into where their data actually traveled. For controllers, it is one of the harder rights to satisfy, because it requires tracking disclosures at the recipient level.

The right to question a profiling result: the broadest in the country
The MCDPA's headline right is the most far-reaching version of its kind in any state privacy law, and only one other state, Connecticut, grants anything comparable. It applies when a consumer is subject to profiling in furtherance of decisions that produce legal effects concerning the consumer or similarly significant effects, such as decisions about credit, housing, insurance, education, or employment.
In that situation, Minn. Stat. 325M.14 gives the consumer the right to question the result of the profiling. The consumer also has the right to be informed of the reason that the profiling resulted in the decision, including, if feasible, the type of data used and how it was relevant.
Minnesota goes further still. The consumer has the right, if feasible, to be informed of what actions the consumer might have taken to secure a different decision, and what actions the consumer might take to secure a different decision in the future. And the consumer has the right to review the personal data used in the profiling, to correct that data, and to have the decision reevaluated if it was based on inaccurate data.
Most state laws stop at letting a consumer opt out of profiling before it happens. Minnesota lets a consumer who has already been profiled challenge the outcome itself and demand the reasoning. Connecticut became the second state to do so: Public Act 25-113 rewrote Conn. Gen. Stat. sec. 42-518 effective July 1, 2026 to give consumers the right, if feasible, to question the result of profiling, be informed of the reason it produced the decision, and review the data used. Connecticut's version stops short of Minnesota's in two ways: it does not require telling the consumer what actions might have produced a different decision, and it limits correction and reevaluation to profiling decisions concerning housing. Minnesota's remains the broadest profiling-challenge right in the country and the practical centerpiece of the MCDPA.
The opt-out rights and universal opt-out mechanism
Beyond access-style rights, Minnesota consumers may opt out of three specific processing activities under Minn. Stat. 325M.14: targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects.
To make these opt-outs usable at scale, the MCDPA requires controllers to recognize a universal opt-out mechanism, sometimes called an opt-out preference signal, such as the Global Privacy Control. A consumer who configures a browser or device signal can communicate an opt-out of sale and targeted advertising without filing a separate request with every controller. This requirement applies as part of the act's obligations that took effect with the law.
Processing sensitive data carries a higher bar. Sensitive data, which includes data revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data, precise geolocation, and the personal data of a known child, may not be processed without the consumer's opt-in consent. A controller cannot simply offer an opt-out for sensitive data; it must obtain affirmative permission first. Consent also stays revocable: under Minn. Stat. 325M.16, once you revoke consent the controller must stop processing your data as soon as practicable, and no later than 15 days after receiving the request.

How to exercise your rights and the 45-day clock
A Minnesota consumer exercises these rights by submitting a request to the controller through a method the controller designates, which the controller must describe in its privacy notice. A controller may need to verify the consumer's identity before acting.
The controller generally must respond within 45 days of receiving the request. When reasonably necessary, the controller may extend that period once by an additional 45 days, as long as it informs the consumer of the extension and the reason for it within the first 45 days. Information must generally be provided free of charge up to twice per consumer per year, though a controller may charge a reasonable fee, or refuse to act, when a request is manifestly unfounded or excessive.
If a controller declines to act on a request, it must inform the consumer without undue delay and explain the reason. The consumer then has the right to appeal.
Appeals and getting the Attorney General involved
The MCDPA gives consumers an appeal path when a controller refuses to act. A controller must establish a process for a consumer to appeal the controller's refusal to take action on a request, and that process must be conspicuously available and similar to the process for submitting the original request.
Within 45 days of receiving an appeal (extendable by 60 additional days where reasonably necessary, per Minn. Stat. 325M.14 subd. 5(c)), the controller must respond in writing, explaining the action taken or not taken and the reasons. If the controller denies the appeal, it must provide the consumer with a method to contact the Minnesota Attorney General to submit a complaint.
That referral matters because the Attorney General is the sole enforcer of the MCDPA under Minn. Stat. 325M.20. There is no private right of action, so a consumer cannot personally sue a controller for an MCDPA violation. Civil penalties of up to $7,500 per violation are available to the state. The 30-day right to cure that controllers relied on through 2025 sunset January 31, 2026, so a controller can no longer count on a guaranteed grace period.
Related guides
- Minnesota data privacy laws parent hub
- What is the Minnesota MCDPA?
- Minnesota MCDPA compliance checklist
- State data privacy law comparison
- What is the CCPA?
More Minnesota Laws
Frequently Asked Questions
What rights do Minnesota residents have under the MCDPA?
Under Minn. Stat. 325M.14, Minnesota residents have the rights to confirm whether a controller is processing their personal data and access the categories of that data, correct inaccuracies, delete data, and obtain a portable copy of data they provided. They may also opt out of targeted advertising, the sale of personal data, and profiling for significant decisions. Minnesota adds two distinctive rights: obtaining a list of the specific third parties that received their data, and questioning the result of a profiling decision.
What is Minnesota's right to question a profiling decision?
When a consumer is subject to profiling that produces legal or similarly significant effects, Minn. Stat. 325M.14 lets the consumer question the result, be informed of the reason it reached that result, learn what actions might secure a different decision in the future, and review and correct the data used. The decision can be reevaluated if it relied on inaccurate data. Connecticut is the only other state with a comparable right, effective July 1, 2026, and its version is narrower: it does not cover what actions might have secured a different decision, and it limits correction and reevaluation to housing decisions.
Can I get a list of the companies that received my data in Minnesota?
Yes. Under Minn. Stat. 325M.14, a Minnesota consumer may obtain a list of the specific third parties to which the controller disclosed the consumer's personal data, or at the controller's option any personal data. This names the actual recipients rather than just broad categories, which is more transparent than what most state laws require. Only a few states, such as Oregon, offer this.
How long does a Minnesota controller have to respond?
A controller generally must respond to a verified MCDPA request within 45 days. It may extend that period once by an additional 45 days when reasonably necessary, as long as it tells the consumer about the extension and the reason within the first 45 days. Information must generally be provided free up to twice per year, though a reasonable fee may apply when a request is manifestly unfounded or excessive.
Can I opt out of targeted ads and data sales in Minnesota?
Yes. Under Minn. Stat. 325M.14, Minnesota consumers may opt out of targeted advertising, the sale of personal data, and profiling for significant decisions. The MCDPA also requires controllers to recognize a universal opt-out mechanism, such as the Global Privacy Control, so a single browser or device signal can communicate an opt-out of sale and targeted advertising across controllers.
Do controllers need my consent to process sensitive data in Minnesota?
Yes. The MCDPA requires opt-in consent before a controller may process sensitive data, which includes data revealing racial or ethnic origin, religion, health conditions, sexual orientation, citizenship or immigration status, genetic or biometric data, precise geolocation, and a known child's data. Unlike California's opt-out model, Minnesota requires affirmative permission first.
What can I do if a Minnesota controller ignores my request?
The MCDPA requires controllers to offer an appeal process for refusals. You submit an appeal much as you submitted the original request, and the controller must respond in writing with its reasoning. If the appeal is denied, the controller must give you a way to contact the Minnesota Attorney General. There is no private right of action, so the Attorney General, not a private lawsuit, is the enforcement path.
Is there still a cure period under the Minnesota MCDPA?
Not as a guarantee. The MCDPA included a 30-day right to cure that let controllers fix a violation before the Attorney General brought an action, but that provision sunset January 31, 2026. As of 2026, any cure opportunity is at the Attorney General's discretion rather than a built-in right.
Updates
Corrected the Minnesota access right to reach the categories of personal data rather than the data itself, updated the profiling-challenge right to note that Connecticut added a narrower version effective July 1, 2026 while Minnesota's remains the broadest, and fixed the MCDPA's codification to Minn. Stat. secs. 325M.10 to 325M.21.
Added the 15-day consent-revocation right and the specific appeal-response timeline under the Minnesota Consumer Data Privacy Act.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected the free-response allowance under Minn. Stat. 325M.14: the MCDPA entitles a consumer to up to two free responses per year, not one, and a fee applies only to manifestly unfounded or excessive requests, not simply to a second request.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Minnesota Statutes, Chapter 325M: CONSUMER DIGITAL AND DATA PRIVACY
§ 325M.14CONSUMER PERSONAL DATA RIGHTSIn forcecited in 5 of our articles
Subdivision 1. Consumer rights provided. (a) Except as provided in sections 325M.10 to 325M.21, a controller must comply with a request to exercise the consumer rights provided in this subdivision. (b) A consumer has the right to confirm whether or not a controller is processing personal data concerning the consumer and access the categories of personal data the controller is processing. (c) A consumer has the right to correct inaccurate personal data concerning the consumer, taking into account the nature of the personal data and the purposes of the processing of the personal data. (d) A consumer has the right to delete personal data concerning the consumer. (e) A consumer has the right to obtain personal data concerning the consumer, which the consumer previously provided to the controller, in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at revisor.mn.gov
Also relied on in: Minnesota MCDPA Compliance Checklist (Minn. Stat. 325M), Minnesota Data Privacy Laws: Consumer Rights Guide (2026), Minnesota Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 325M.16RESPONSIBILITIES OF CONTROLLERSIn forcecited in 4 of our articles
Subdivision 1. Transparency obligations. (a) Controllers must provide consumers with a reasonably accessible, clear, and meaningful privacy notice that includes: (1) the categories of personal data processed by the controller; (2) the purposes for which the categories of personal data are processed; (3) an explanation of the rights contained in section 325M.14 and how and where consumers may exercise those rights, including how a consumer may appeal a controller's action with regard to the consumer's request; (4) the categories of personal data that the controller sells to or shares with third parties, if any; (5) the categories of third parties, if any, with whom the controller sells or shares personal data; (6) the controller's contact information, including an active email address or other online mechanism that the consumer may use to contact the controller; (7) a description of the controller's retention policies for personal data; and (8) the date the privacy notice was last updated.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at revisor.mn.gov
§ 325M.20ATTORNEY GENERAL ENFORCEMENTIn forcecited in 5 of our articles
(a) In the event that a controller or processor violates sections 325M.10 to 325M.21, the attorney general, prior to filing an enforcement action under paragraph (b), must provide the controller or processor with a warning letter identifying the specific provisions of sections 325M.10 to 325M.21 the attorney general alleges have been or are being violated. If, after 30 days of issuance of the warning letter, the attorney general believes the controller or processor has failed to cure any alleged violation, the attorney general may bring an enforcement action under paragraph (b). This paragraph expires January 31, 2026. (b) The attorney general may bring a civil action against a controller or processor to enforce a provision of sections 325M.10 to 325M.21 in accordance with section 8.31. If the state prevails in an action to enforce sections 325M.10 to 325M.21, the state may, in addition to penalties provided by paragraph (c) or other remedies provided by law, be allowed an amount determined by the court to be the reasonable value of all or part of the state's litigation expenses incurred.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at revisor.mn.gov
Also relied on in: What Is the Minnesota Consumer Data Privacy Act (MCDPA)?
Explore the law
This article also draws on these acts and chapters (opening at their first section): Minnesota Statutes, Chapter 325M: CONSUMER DIGITAL AND DATA PRIVACY § 325M.01 (DEFINITIONS)
Related law for further reading — not part of this article’s citations.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Minn. Stat. 325M.14: Consumer Personal Data Rights(revisor.mn.gov).gov
- Minn. Stat. 325M.14: Controller Response and Appeals(revisor.mn.gov).gov
- Minnesota Statutes Chapter 325M: Consumer Data Privacy Act (Full Chapter)(revisor.mn.gov).gov
- Minn. Stat. 325M.16: Controller Duties and Sensitive Data Consent(revisor.mn.gov).gov
- Minn. Stat. 325M.20: Enforcement and Civil Penalties(revisor.mn.gov).gov
- Minnesota Attorney General: Consumer Data Privacy(ag.state.mn.us).gov
- Minnesota Attorney General: MCDPA Business Enforcement Overview(ag.state.mn.us).gov
- Minn. Stat. ch. 325M - Minnesota Consumer Data Privacy Act at secs. 325M.10 to 325M.21(revisor.mn.gov)
- Connecticut Public Act 25-113 (Substitute S.B. 1295), Sec. 8, amending Conn. Gen. Stat. Sec. 42-518 effective July 1, 2026(cga.ct.gov)