Montana
MCDPA Consumer Rights: Montana Privacy Rights (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 7 primary sources cited on this page. How we verify our legal content

The Montana Consumer Data Privacy Act (MCDPA), at Mont. Code Ann. 30-14-2808, gives Montana residents five core data rights: to confirm and access their personal data, to correct inaccuracies, to delete data, to obtain a portable copy, and to opt out of targeted advertising, the sale of personal data, and certain profiling. Businesses covered by the law must respond to a verified request within 45 days, with one 45-day extension available when reasonably necessary. As of 2026, these rights are backed by tougher enforcement: SB 297 eliminated the cure period that once shielded businesses effective October 1, 2025, ahead of its originally scheduled April 2026 sunset.
Two features make Montana's rights framework stronger than a basic opt-out model. Since January 1, 2025, controllers must honor a universal opt-out signal such as the Global Privacy Control, so a single browser setting can carry a consumer's choice across covered sites. And after SB 297, the law applies heightened protections when a controller offers an online service, product, or feature to a consumer it actually knows or willfully disregards is a minor under 18, requiring consent before that minor's data is used for targeted advertising, sale, or profiling.
Jurisdiction scope: This covers the Montana Consumer Data Privacy Act (Mont. Code Ann. Title 30, Chapter 14, Part 28). It is general legal information, not legal advice.
The five consumer rights under the MCDPA
The heart of the MCDPA is the rights list in Mont. Code Ann. 30-14-2808. A Montana consumer may submit a request to a controller to exercise any of five rights. First is the right to confirm whether a controller is processing the consumer's personal data and to access that data. Second is the right to correct inaccuracies, taking into account the nature of the data and the purposes of processing. Third is the right to delete personal data about the consumer.
Fourth is the right to data portability: the consumer may obtain a copy of the personal data the consumer previously provided to the controller "in a portable and, to the extent technically feasible, readily usable format" that allows the data to be transmitted to another controller without hindrance. Fifth is the right to opt out of processing for purposes of targeted advertising, the sale of personal data, and profiling in furtherance of automated decisions that produce legal or similarly significant effects.
These rights belong to "consumers," defined as Montana residents acting in an individual or household context. The MCDPA excludes people acting in a commercial or employment capacity, so an employee asking about workplace records or a business contact asking about a vendor relationship is not exercising a consumer right under this statute. That scope mirrors the Virginia-model privacy laws and contrasts with California, which extended its rights to employees and business contacts.
The access and portability rights in practice
The access right lets a consumer find out what a business holds. A controller that receives a verified access request must confirm whether it is processing the consumer's personal data and provide access to that data. In practice this means a business needs to be able to locate a consumer's data across its systems, which is why data mapping is a foundational compliance task rather than a nice-to-have.
Portability goes a step further by requiring the data to come back in a usable form. The statutory phrase "to the extent technically feasible, readily usable format" sets the standard: the format should let the consumer move the data to another service. The portability right is limited to data the consumer "previously provided," so it does not necessarily reach inferences or derived data a controller generated on its own. A controller may also decline to provide portable data where doing so would require it to reveal a trade secret.
Both rights are subject to verification. A controller is not required to comply with a request if it cannot authenticate the request using commercially reasonable efforts, although it must notify the consumer and may request additional information reasonably necessary to authenticate the request. This guards against someone impersonating a consumer to extract another person's data, a real risk that privacy regulators take seriously.
Correction and deletion
The correction right allows a consumer to fix inaccurate personal data, "taking into account the nature of the personal data and the purposes of the processing." This is more limited than it might sound. It addresses factual inaccuracies in the data a controller holds; it does not give a consumer the power to rewrite legitimate records or to dispute a controller's lawful conclusions. The reasonableness qualifier gives controllers room to weigh how the data is used.
The deletion right is broad on its face: a consumer may request that a controller delete personal data about the consumer. Unlike the portability right, deletion reaches data the controller obtained from sources other than the consumer, not just data the consumer provided. That makes deletion one of the more operationally demanding rights, because a controller must be able to find and remove data it acquired from third parties or generated internally.
Deletion is not absolute. The MCDPA's processing rules and exemptions let a controller retain data where another legal obligation requires it, where the data is needed to complete a transaction the consumer requested, to detect security incidents, to comply with the law, or for similar enumerated purposes. A controller that denies a deletion request in reliance on an exemption should be able to point to the specific basis, because the burden of justifying an exemption generally rests on the controller.

The opt-out rights and the universal opt-out signal
The opt-out right under Mont. Code Ann. 30-14-2808 covers three distinct activities: targeted advertising, the sale of personal data, and profiling in furtherance of automated decisions that produce legal or similarly significant effects. "Sale" under the MCDPA is defined broadly to include the exchange of personal data for monetary or other valuable consideration, which can sweep in data-sharing arrangements that a business might not have labeled a sale.
A controller that sells personal data to third parties or processes personal data for targeted advertising must clearly and conspicuously disclose that processing in its privacy notice and provide access to a clear and conspicuous method outside the privacy notice for a consumer to opt out, such as a link labeled "your opt-out rights" or "your privacy rights" (Mont. Code Ann. 30-14-2812(4)). Mont. Code Ann. 30-14-2809(3)(a) separately requires a clear and conspicuous link on the controller's website to a page where a consumer, or the consumer's authorized agent, can opt out of targeted advertising or the sale of personal data. Since January 1, 2025, Mont. Code Ann. 30-14-2809(3)(b) has also required a controller to let a consumer opt out of targeted advertising or sale through an opt-out preference signal sent with the consumer's consent, such as the Global Privacy Control. This is the feature that turns the opt-out from a per-site chore into a one-time setting.
The universal opt-out requirement is significant because it shifts effort from the consumer to the business. A Montanan can configure a browser or platform-level signal once, and every covered controller must treat that signal as a valid opt-out for sales and targeted advertising. A controller may not require a consumer to create a new account in order to exercise consumer rights, although it may require the consumer to use an existing account (Mont. Code Ann. 30-14-2812(11)(b)). Where processing rests on consent, the controller must also provide a revocation mechanism at least as easy to use as the one by which consent was given, and must stop processing within 45 days of the revocation request (Mont. Code Ann. 30-14-2812(1)(c)).
The 45-day response window and extension
Timing is governed by Mont. Code Ann. 30-14-2808. A controller must respond to a consumer's request "without undue delay, but not later than 45 days after receipt of the request." The clock starts when the controller receives the request, which is why intake processes matter; a request that sits in a generic inbox still counts against the deadline.
The controller "may extend the response period by 45 additional days when reasonably necessary, considering the complexity and number of the consumer's requests." To use the extension, the controller must inform the consumer of the extension within the initial 45-day period and explain the reason for it. The extension is not automatic and is meant for genuinely complex or high-volume situations, not routine convenience. The table below lays out the deadlines.
| Action | Deadline | Authority |
|---|---|---|
| Respond to a consumer request | 45 days from receipt | Mont. Code Ann. 30-14-2808 |
| Extension of response period | One additional 45 days | Mont. Code Ann. 30-14-2808 |
| Respond to an appeal | 60 days from receipt | Mont. Code Ann. 30-14-2808 |
If a controller declines to act on a request, it must inform the consumer without undue delay and within 45 days of the reasons for not taking action and instructions for how to appeal. Information provided in response to a request must generally be furnished free of charge once per consumer during any 12-month period, although a controller may charge a reasonable fee or decline to act on requests that are manifestly unfounded, excessive, or repetitive.

The right to appeal
The MCDPA builds in a second look. Under Mont. Code Ann. 30-14-2808, a controller must establish a process for a consumer to appeal the controller's refusal to act on a request within a reasonable period after the consumer receives the refusal. The appeal process must be conspicuously available and similar to the process for submitting the original request.
Within 60 days after receipt of an appeal, the controller must inform the consumer in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decision. This written-explanation requirement gives the consumer a record of the controller's reasoning, which can matter if the dispute escalates.
If the appeal is denied, the controller must provide the consumer with an online mechanism, if available, or another method through which the consumer may contact the Montana Attorney General to submit a complaint. The appeal route does not create a private lawsuit; instead, it channels unresolved disputes to the Attorney General, who is the sole enforcer of the MCDPA. Consumers cannot sue a business directly under the statute.
Sensitive data and the opt-in default
For sensitive data, the MCDPA flips the default. Under Mont. Code Ann. 30-14-2812, a controller may not process sensitive data without first obtaining the consumer's consent. "Consent" means a clear affirmative act signifying a freely given, specific, informed, and unambiguous agreement, and it cannot be obtained through deceptive design or so-called dark patterns. This opt-in standard is materially stronger than the opt-out that governs ordinary processing.
Sensitive data is defined to include personal data revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis, sex life, sexual orientation, citizenship or immigration status, genetic or biometric data processed for the purpose of uniquely identifying an individual, personal data collected from a known child, and precise geolocation data. Because the consequences of mishandling these categories are serious, controllers should identify sensitive data in their inventory and confirm a lawful consent basis before processing it.
The known-child category links the sensitive-data rule to federal law. Data of a child under 13 is processed in accordance with the Children's Online Privacy Protection Act, so COPPA-compliant consent satisfies the MCDPA for that age group. For older minors, Montana's strengthened minor protections apply instead, which the next section addresses.
Strengthened protections for minors
SB 297 made Montana one of the more protective states for the data of teenagers, not just young children. Under Mont. Code Ann. 30-14-2811(2), a controller that offers an online service, product, or feature to a consumer it actually knows or willfully disregards is a minor, defined at Mont. Code Ann. 30-14-2802 as a consumer under 18 years of age, may not process that minor's personal data for targeted advertising, the sale of personal data, or profiling in furtherance of decisions producing legal or similarly significant effects without consent. The controller also may not collect a minor's precise geolocation data unless it is reasonably necessary to provide the online service, and it must apply data minimization so that a minor's data is not kept longer than reasonably necessary to provide that service. Consent comes from the minor, or from a parent or legal guardian if the minor is a child under 13. Mont. Code Ann. 30-14-2811(4) exempts a service or application used by and under the direction of an educational entity, such as a learning management system or a student engagement program, from the processing and engagement-design restrictions.
These rules reach further than COPPA, which generally governs children under 13. By extending consent requirements and processing limits to minors under 18 whom an online service actually knows or willfully disregards it is serving, Montana treats teenagers as a protected class. The companion provisions at Mont. Code Ann. 30-14-2818 and 30-14-2819 allocate responsibility by role and require data protection assessments for processing that presents a heightened risk of harm to minors, so a teen-facing service carries documentation duties on top of the consent rules.
For consumers and parents, the practical upshot is meaningful control over how a minor's data is used. An online service that actually knows, or willfully disregards, that a user is under 18 cannot quietly enroll that user in behavioral advertising, sell the user's data, or run profiling that drives significant decisions without obtaining consent. As of 2026, these are among the most demanding obligations in the MCDPA, and they sit alongside the same access, correction, deletion, and portability rights that apply to all consumers.
Related guides
- Montana Data Privacy Laws hub
- What is the MCDPA?
- MCDPA Compliance Checklist
- US State Privacy Laws Comparison
- What is the CCPA?
More Montana Laws
Frequently Asked Questions
What rights do Montana consumers have under the MCDPA?
Under Mont. Code Ann. 30-14-2808, consumers can confirm and access their personal data, correct inaccuracies, delete data, obtain a portable copy of data they provided, and opt out of targeted advertising, the sale of personal data, and certain profiling.
How long does a business have to respond to my MCDPA request?
A controller must respond without undue delay and no later than 45 days after receiving the request. It may extend the period by one additional 45 days when reasonably necessary, but it must notify you of the extension within the first 45 days.
Can I opt out of data sales with one signal?
Yes. Since January 1, 2025, Mont. Code Ann. 30-14-2809(3)(b) has required controllers that process data for targeted advertising or sale to let you opt out through an opt-out preference signal such as the Global Privacy Control, so a single browser setting can carry your opt-out across covered sites.
What can I do if a business denies my request?
You can appeal. The controller must respond to an appeal within 60 days with a written explanation. If the appeal is denied, the controller must give you a way to submit a complaint to the Montana Attorney General.
Does the MCDPA cover sensitive data differently?
Yes. Under Mont. Code Ann. 30-14-2812, a controller must obtain your consent before processing sensitive data, which is an opt-in rule. Sensitive data includes health, biometric, precise geolocation, and similar categories.
What extra protections apply to minors?
When an online service, product, or feature is offered to a consumer the controller actually knows or willfully disregards is under 18, Mont. Code Ann. 30-14-2811(2) restricts targeted advertising, sale, and profiling without consent, limits precise geolocation collection, and requires data minimization. Services used under the direction of an educational entity are exempt from parts of that rule. These rules took effect October 1, 2025.
Can I sue a business for violating my MCDPA rights?
No. The MCDPA has no private right of action. The Montana Attorney General is the sole enforcer, and you can submit a complaint for the office to review and decide whether to act.
Is there a fee to make an MCDPA request?
Generally no. A controller must provide information free of charge once per consumer during any 12-month period, though it may charge a reasonable fee or decline to act on requests that are manifestly unfounded, excessive, or repetitive.
Updates
Corrected the opt-out section to cite the actual authorities: the universal opt-out preference signal duty (Mont. Code Ann. 30-14-2809(3)(b)), the outside-the-privacy-notice opt-out method (30-14-2812(4)), and the new-account rule (30-14-2812(11)(b)); also narrowed the minors rules to the online services they actually govern (30-14-2811).
Corrected the cure period end date to October 1, 2025, when SB 297 eliminated it, and restored the statutory automated-decisions qualifier to the profiling opt-out description.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Montana Code Annotated, Title 30
§ 30-14-2808Consumer Personal Data -- Opt-Out -- Compliance -- AppealsIn forcecited in 6 of our articles
30-14-2808. Consumer personal data -- opt-out -- compliance -- appeals. (1) A consumer must have the right to: (a) confirm whether a controller is processing the consumer's personal data and access the consumer's personal data, unless such confirmation or access would require the controller to reveal a trade secret; (b) correct inaccuracies in the consumer's personal data, considering the nature of the personal data and the purposes of the processing of the consumer's personal data; (c) delete personal data about the consumer; (d) obtain a copy of the consumer's personal data previously provided by the consumer to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the personal data to another controller without hindrance when the processing is carried out by automated means, provided the controller is not required to reveal any trade secret; and (e) opt out of the processing of the consumer's personal data for the purposes of: (i) targeted advertising; (ii) the sale of the consumer's personal data, except as provided in 30-14-2812(2); or (iii) profiling in furtherance of automated decisions that…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at mca.legmt.gov
Also relied on in: What Is the MCDPA? Montana Data Privacy Law (2026), How to Request Your Personal Data: US Privacy Rights by State, Montana Data Privacy Laws: MCDPA Consumer Rights Guide (2026)
§ 30-14-2812Data Processing By Controller -- LimitationsIn forcecited in 4 of our articles
30-14-2812. Data processing by controller -- limitations. (1) A controller shall: (a) limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which the personal data is processed, as disclosed to the consumer; (b) establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data appropriate to the volume and nature of the personal data at issue; and (c) provide an effective mechanism for a consumer to revoke the consumer's consent under this section that is at least as easy as the mechanism by which the consumer provided the consumer's consent and, on revocation of the consent, cease to process the personal data as soon as practicable, but not later than 45 days after the receipt of the request.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at mca.legmt.gov
Also relied on in: MCDPA Compliance Checklist: Montana Privacy (2026), Montana Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 30-14-2811Duties Of Controllers -- Duty Of Care -- Rebuttable PresumptionIn forcecited in 3 of our articles
30-14-2811. Duties of controllers -- duty of care -- rebuttable presumption. (1) (a) A controller that offers an online service, product, or feature to a consumer whom the controller actually knows or willfully disregards is a minor shall use reasonable care to avoid a heightened risk of harm to minors caused by the online service, product, or feature. (b) In an enforcement action brought by the attorney general pursuant to 30-14-2817, there is a rebuttable presumption that a controller used reasonable care as required under this section if the controller complied with this section.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at mca.legmt.gov
§ 30-14-2802DefinitionsIn forcecited in 4 of our articles
30-14-2802. Definitions. As used in this part, unless the context clearly indicates otherwise, the following definitions apply: (1) "Adult" means an individual who is 18 years of age or older. (2) "Affiliate" means a legal entity that shares common branding with another legal entity or controls, is controlled by, or is under common control with another legal entity. (3) "Authenticate" means to use reasonable methods to determine that a request to exercise any of the rights afforded under 30-14-2808(1)(a) through (1)(e) is being made by, or on behalf of, the consumer who is entitled to exercise these consumer rights with respect to the personal data at issue. (4) (a) "Biometric data" means data generated by automatic measurements of an individual's biological characteristics, such as a fingerprint, a voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that are used to identify a specific individual.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at mca.legmt.gov
Also relied on in: Montana Employee Monitoring Laws: Workplace Surveillance and Social Media (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Mont. Code Ann. 30-14-2808, Consumer personal data, opt-out, appeals(mca.legmt.gov).gov
- Mont. Code Ann. 30-14-2812, Data processing limitations(mca.legmt.gov).gov
- Mont. Code Ann. 30-14-2811, Duties of controllers, minors(mca.legmt.gov).gov
- Mont. Code Ann. 30-14-2802, Definitions(mca.legmt.gov).gov
- Mont. Code Ann. 30-14-2801 et seq., Montana Consumer Data Privacy Act(mca.legmt.gov).gov
- Montana DOJ Office of Consumer Protection, Montana Consumer Data Privacy(dojmt.gov).gov
- Montana Legislature, SB 297 (2025 session)(bills.legmt.gov).gov
- Global Privacy Control technical specification(globalprivacycontrol.org)
- Mont. Code Ann. 30-14-2809, Authorized agent, opt-out methods and opt-out preference signal(mca.legmt.gov)