Minnesota's Consumer Data Privacy Act Exempts Small Businesses — and Then Regulates Them Anyway

August 21, 2026 · David J.S. Madgett · Updated October 1, 2026

Most companies size up the Minnesota Consumer Data Privacy Act the way they size up every other state privacy law. Run the applicability thresholds, and if you’re under them, close the file. Minnesota’s thresholds are high — 100,000 consumers, or 25,000 plus a quarter of gross revenue from selling data — so most Minnesota businesses close the file fast.

That’s the wrong place to stop reading, and I tell every business client who asks. The Act’s exclusion list runs 21 clauses, and two of them do something unusual. The small-business exclusion isn’t really an exclusion. It’s a swap, and the obligation it swaps in applies to a business of any size with no consumer-count threshold at all. And there’s no general exclusion for nonprofits. The only nonprofit the list names is an insurance anti-fraud organization.

A Minnesota company comfortably below both thresholds can still be sued by the Attorney General under this statute. Very few of them know it.


Where is the Minnesota Consumer Data Privacy Act actually codified?

At Minn. Stat. §§ 325M.10 to 325M.21. The Act doesn’t have a chapter of its own:

Sections 325M.10 to 325M.21 may be cited as the “Minnesota Consumer Data Privacy Act.”

Minn. Stat. § 325M.10.

This is more than a citation quibble. Chapter 325M now carries three separate enactments: the older internet-service-provider privacy sections at §§ 325M.01–.09, the MCDPA at §§ 325M.10–.21, and the Prohibiting Social Media Manipulation Act beginning at § 325M.30. A cite to “chapter 325M” doesn’t identify a statute anymore. That’s why every point below is tied to a specific section.

And here’s something that doesn’t exist: Minnesota Statutes contain no chapter 325O. The Revisor returns nothing for it. A compliance memo, vendor questionnaire, or multistate chart that cites “Minn. Stat. ch. 325O” is citing an authority that won’t resolve. I’ve learned that when the chapter number is wrong, the substance behind it deserves a second look too.

For how the MCDPA sits next to Minnesota’s breach statute and the Government Data Practices Act, see my comparison of Minnesota’s three privacy regimes. This piece is the deep read on the MCDPA itself.


When did it take effect, and did anyone get extra time?

July 31, 2025 — with one exception: postsecondary institutions regulated by the Office of Higher Education have until July 31, 2029. The effective-date section of the enacting article reads in full:

This article is effective July 31, 2025, except that postsecondary institutions regulated by the Office of Higher Education are not required to comply with this article until July 31, 2029.

Laws 2024, ch. 121, art. 5, § 14.

There’s no other delayed-compliance date in the Act, and no phase-in by company size. Every covered entity that isn’t a postsecondary institution regulated by the Office of Higher Education has been fully subject to the MCDPA for more than a year.


Which companies are covered?

Two gates, and a company has to clear both. Section 325M.12, subd. 1(a), applies the Act:

to legal entities that conduct business in Minnesota or produce products or services that are targeted to residents of Minnesota, and that satisfy one or more of the following thresholds:

(1) during a calendar year, controls or processes personal data of 100,000 consumers or more, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or

(2) derives over 25 percent of gross revenue from the sale of personal data and processes or controls personal data of 25,000 consumers or more.

Three pieces of that text carry the weight.

“Targeted to residents of Minnesota” is a separate hook from doing business here. A company with no Minnesota presence that markets into the state is inside the first gate.

The 100,000 count excludes payment-transaction data. Personal data “controlled or processed solely for the purpose of completing a payment transaction” doesn’t count toward the threshold. For a retailer whose customer volume is mostly card swipes, that exclusion can be the difference between covered and not. Write the math down when you do it, because the burden of establishing an exemption falls on the controller. Section 325M.19(g): “the controller bears the burden of demonstrating that the processing qualifies for the exemption.”

“Consumer” is narrower than “person.” Section 325M.11(g): “‘Consumer’ means a natural person who is a Minnesota resident acting only in an individual or household context. Consumer does not include a natural person acting in a commercial or employment context.” Business contacts and employees aren’t consumers, so they don’t count toward 100,000 — and, as you’ll see below, their data is outside the Act twice over.

One more rule kicks in at the scope stage. A controller or processor acting as a technology provider under Minn. Stat. § 13.32 must comply with both statutes, “except that when the provisions of section 13.32 conflict with sections 325M.10 to 325M.21, section 13.32 prevails.” § 325M.12, subd. 1(b). An education-technology vendor serving Minnesota schools is under the Data Practices Act on top of the MCDPA, and the Data Practices Act wins the conflict.


Is the small-business “exemption” really an exemption?

When a small-business client asks me whether the MCDPA applies, my answer goes: mostly no, and the part that does apply has teeth. This is the provision that trips companies up, and it’s written as a carve-back inside the exclusion list. Section 325M.12, subd. 2(a)(19), excludes:

a small business, as defined by the United States Small Business Administration under Code of Federal Regulations, title 13, part 121, except that a small business identified in this clause is subject to section 325M.17.

And § 325M.17 provides:

(a) A small business, as defined by the United States Small Business Administration under Code of Federal Regulations, title 13, part 121, that conducts business in Minnesota or produces products or services that are targeted to residents of Minnesota, must not sell a consumer’s sensitive data without the consumer’s prior consent.

(b) Penalties and attorney general enforcement procedures under section 325M.20 apply to a small business that violates this section.

Now lay § 325M.17(a) next to § 325M.12, subd. 1(a). The threshold language is gone. Section 325M.17 reaches any small business that conducts business in Minnesota or targets Minnesota residents. No 100,000-consumer floor, no revenue test, no minimum data volume. A four-person Minnesota company that has never held the data of a thousand people is inside § 325M.17 the moment it sells sensitive data without prior consent. And § 325M.17(b) attaches the same Attorney General enforcement and the same civil penalty of up to $7,500 per violation that applies to a company a thousand times its size.

Two definitions decide how much that costs.

“Sale” is broader than a sale. Section 325M.11(u): “‘Sale,’ ‘sell,’ or ‘sold’ means the exchange of personal data for monetary or other valuable consideration by the controller to a third party.” A barter, a data-for-services arrangement, or a co-marketing swap is a sale. The subdivision then excludes six transfers that aren’t sales: disclosure to a processor acting on the controller’s behalf; disclosure to a third party to provide a product or service the consumer requested; disclosure or transfer to an affiliate; disclosure of information the consumer intentionally made public through mass media without restricting the audience; transfer as an asset in a merger, acquisition, bankruptcy, or similar transaction in which the third party assumes control of the assets; and exchanges between the producer of a good or service and the producer’s authorized sales-and-service agents to enable cooperative provisioning.

“Sensitive data” is four categories, and the fourth surprises people. Section 325M.11(v) defines it as personal data revealing racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, sexual orientation, or citizenship or immigration status; the processing of biometric data or genetic information for the purpose of uniquely identifying an individual; the personal data of a known child; or specific geolocation data.

“Specific geolocation data” is defined with a precision most operators have never checked. Section 325M.11(w) reaches information that “directly identifies the geographic coordinates of a consumer or a device linked to a consumer with an accuracy of more than three decimal degrees of latitude and longitude or the equivalent in an alternative geographic coordinate system, or a street address derived from the coordinates.” A small app developer making money on location signal is selling sensitive data. That’s a category that includes a great many businesses that would never call themselves data companies.

A “known child,” in turn, is “a person under circumstances where a controller has actual knowledge of, or willfully disregards, that the person is under 13 years of age.” § 325M.11(o). Willful disregard is enough. A business that sets itself up not to know its users’ ages hasn’t dodged the definition.

So for a small Minnesota business the picture is short. The MCDPA’s compliance machinery — privacy notices, request handling, assessments — doesn’t apply to you. One rule does, it has no size threshold, and the Attorney General enforces it.


Are nonprofits exempt?

Not as a class. Section 325M.12, subd. 2(a), lists 21 exclusions. Government entities as defined by § 13.02, subd. 7a, are excluded. Federally recognized Indian tribes are excluded. State and federally chartered banks and credit unions are excluded, as are insurance companies, insurance producers, and third-party administrators of self-insurance. Small businesses are excluded, subject to § 325M.17.

The only nonprofit named anywhere in the list is clause (20): “a nonprofit organization that is established to detect and prevent fraudulent acts in connection with insurance.”

There’s no clause excluding charitable organizations, foundations, trade associations, membership organizations, or 501(c)(3) entities generally. A Minnesota nonprofit that clears the applicability thresholds in § 325M.12, subd. 1 — a large health-adjacent charity, a statewide membership organization, a major arts institution with a six-figure donor and ticket-buyer file — is a controller with the full set of controller obligations. Plenty of multistate privacy templates assume a nonprofit exemption. This statute doesn’t have one, and the entity leaning on that template is leaning on nothing.


What else is excluded, and is the exclusion entity-level or data-level?

Both, and the difference decides how much work an exclusion saves you. Some clauses in § 325M.12, subd. 2(a), exclude an entity, and the whole organization drops out. Others exclude a category of information, and the organization stays in while only that data drops out.

Entity-level exclusions: government entities (clause 1); federally recognized Indian tribes (clause 2); state or federally chartered banks and credit unions, and affiliates or subsidiaries principally engaged in financial activities under 12 U.S.C. § 1843(k) (clause 16); small businesses, subject to § 325M.17 (clause 19); insurance-fraud-prevention nonprofits (clause 20); air carriers subject to the federal Airline Deregulation Act, but only as to personal data related to prices, routes, or services and only to the extent that Act preempts (clause 21); and insurance companies as defined in § 60A.02, subd. 4, insurance producers under § 60K.31, subd. 6, third-party administrators of self-insurance, and their financial-activities affiliates — with an express carve-back that clause 18 “does not apply to a person that, alone or in combination with another person, establishes and maintains a self-insurance program that does not otherwise engage in the business of entering into policies of insurance.”

Data-level exclusions cover the federal-overlay categories. Protected health information under HIPAA, health records under Minn. Stat. § 144.291, subd. 2, and 42 C.F.R. pt. 2 patient-identifying information (clause 3); human-subjects research information under 45 C.F.R. pt. 46, ICH good clinical practice guidelines, or 21 C.F.R. pts. 50 and 56 (clause 3(iv)); Health Care Quality Improvement Act materials and patient safety work product (clause 3(v)–(vi)); data deidentified under 45 C.F.R. pt. 164 (clause 4); information intermingled indistinguishably with health data held by a covered entity, business associate, health care provider, or 42 C.F.R. pt. 2 program (clause 5); limited data sets, self-regulatory-organization records, and mortgage-originator and nonbank-financial-institution data intermingled with Gramm-Leach-Bliley information (clause 6); public health activities data under 45 C.F.R. pt. 164.512 (clause 7); consumer reporting agency, furnisher, and user activity to the extent it is subject to and compliant with the Fair Credit Reporting Act (clause 8); GLBA data (clause 9); Driver’s Privacy Protection Act data (clause 10); FERPA-regulated data (clause 11); Farm Credit Act data (clause 12); data under the Minnesota Insurance Fair Information Reporting Act, §§ 72A.49–.505 (clause 14); payment-only credit, check, or cash transaction data where no consumer data is retained (clause 15); and chapter 56 lender data intermingled with FCRA information (clause 17).

Two things about that list.

The federal exclusions are conditional. GLBA, DPPA, and Farm Credit data are excluded only “if the collection, processing, sale, or disclosure is in compliance with that law.” The FCRA exclusion applies “only to the extent” the activity is subject to FCRA regulation and the information is not used “except as authorized by the Fair Credit Reporting Act.” Mishandle the data under federal law and you don’t get the state exclusion either. A furnisher that reports outside what the FCRA authorizes loses clause (8) and lands back inside the MCDPA. That’s a live problem for anyone in the credit-reporting chain; see my discussion of what happens when a credit report error will not get fixed.

Employee data is excluded twice. Clause (13) removes data collected “in the course of an individual acting as a job applicant to or an employee, owner, director, officer, medical staff member, or contractor of a business if the data is collected and used solely within the context of the role,” along with emergency contact information used solely for emergency contact purposes and data necessary to administer benefits. That’s on top of the “consumer” definition in § 325M.11(g), which already excludes a person acting in a commercial or employment context. Build the MCDPA program for the customer file, not the HR file. And watch the words “solely within the context of the role,” because that’s where an employer that repurposes employee data for marketing loses the exclusion.


What rights does a Minnesota consumer actually have?

Seven, set out in § 325M.14, subd. 1, paragraphs (b) through (h). Five you’ll recognize from other states’ statutes. Two you might not.

The familiar five: confirm and access the categories of personal data being processed (para. (b)); correct inaccurate personal data (para. (c)); delete personal data (para. (d)); portability — obtain data the consumer previously provided in “a portable and, to the extent technically feasible, readily usable format” that permits transmission to another controller “without hindrance,” where processing is automated (para. (e)); and opt out of processing for targeted advertising, sale, or profiling in furtherance of automated decisions producing legal or similarly significant effects (para. (f)).

The two worth knowing by name:

The right to question a profiling result. Section 325M.14, subd. 1(g):

If a consumer’s personal data is profiled in furtherance of decisions that produce legal effects concerning a consumer or similarly significant effects concerning a consumer, the consumer has the right to question the result of the profiling, to be informed of the reason that the profiling resulted in the decision, and, if feasible, to be informed of what actions the consumer might have taken to secure a different decision and the actions that the consumer might take to secure a different decision in the future. The consumer has the right to review the consumer’s personal data used in the profiling. If the decision is determined to have been based upon inaccurate personal data … the consumer has the right to have the data corrected and the profiling decision reevaluated based upon the corrected data.

That’s not an opt-out. It’s a right to an explanation and, if it’s shown the input data was inaccurate, a right to have the decision made again. “Decisions that produce legal or similarly significant effects” is defined in § 325M.11(i) as controller decisions resulting in “the provision or denial by the controller of financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunities, health care services, or access to essential goods or services.” Any automated underwriting, tenant-screening, or eligibility model touching Minnesota consumers should be built with this paragraph sitting in front of the engineer.

The right to a list of specific third parties. Section 325M.14, subd. 1(h): “A consumer has a right to obtain a list of the specific third parties to which the controller has disclosed the consumer’s personal data. If the controller does not maintain the information in a format specific to the consumer, a list of specific third parties to whom the controller has disclosed any consumers’ personal data may be provided instead.” Specific third parties, not categories. The fallback in the second sentence is real relief, but it produces a document a company may not want to hand over: the full list of everybody it shares data with.

A generic multistate privacy portal won’t satisfy either of these rights. And neither one is the kind of thing you build after a demand letter shows up.


How fast does a controller have to respond?

The Act runs several different clocks, all in § 325M.16 and § 325M.14, and mixing them up is a compliance failure all by itself.

An opt-out request under subd. 1(f) must be honored “as soon as feasibly possible, but no later than 45 days of receipt.” § 325M.14, subd. 4(d).

For any request under subd. 1, the controller must tell the consumer what action it took “without undue delay and in any event within 45 days of receipt,” extendable once by 45 additional days where reasonably necessary — with notice of the extension and its reasons given within the original 45 days. § 325M.14, subd. 4(e).

If the controller takes no action, it has to say so within 45 days, give reasons, and give instructions for appealing. § 325M.14, subd. 4(f).

On appeal, the controller has 45 days to tell the consumer what action it took or didn’t take, with a written explanation, extendable by 60 additional days, again with notice inside the first 45. § 325M.14, subd. 5(c). The appeal response must “clearly and prominently provide the consumer with information about how to file a complaint with the Office of the Attorney General,” and the controller must maintain records of all appeals and its responses for at least 24 months, producible to the Attorney General on written request as part of an investigation. § 325M.14, subd. 5(d).

And the shortest clock in the statute isn’t a request clock at all. When a consumer revokes consent, the controller “shall cease to process the applicable data as soon as practicable, but not later than 15 days after the receipt of the request.” § 325M.16, subd. 2(e). The revocation mechanism must be “at least as easy as the mechanism by which the consent was previously given.”

Responses are free up to twice a year. § 325M.14, subd. 4(g). Where requests are “manifestly unfounded or excessive, in particular because of the repetitive character of the requests,” the controller may charge a reasonable administrative fee or refuse — but “[t]he controller bears the burden of demonstrating the manifestly unfounded or excessive character of the request.”

Two response rules protect the consumer from the response itself. A controller answering an access request must not disclose the consumer’s Social Security number, driver’s license or other government identification number, financial account number, health insurance account or medical identification number, account password or security questions and answers, or biometric data. It must instead say, with sufficient particularity, that it holds that type of information. § 325M.14, subd. 4(i). And a controller is never required to reveal a trade secret. Subd. 4(j).


What must a controller build before any of this happens?

The controller obligations in § 325M.16 aren’t a notice statute with rights bolted on. Several of them are affirmative design mandates.

The privacy notice has eight required contents — categories of personal data processed; the purposes of processing; an explanation of the § 325M.14 rights and how and where to exercise them, including how to appeal; categories of personal data sold or shared with third parties; categories of those third parties; the controller’s contact information “including an active email address or other online mechanism”; a description of retention policies; and the date the notice was last updated. § 325M.16, subd. 1(a). It must be posted “through a conspicuous hyperlink using the word ‘privacy’” on the website home page or the app store or download page, with an in-app link in the settings menu; available “in each language in which the controller provides a product or service”; and “reasonably accessible to and usable by individuals with disabilities.” Subd. 1(c), (d), (g). No separate Minnesota-specific notice is required if the general notice covers everything. Subd. 1(f).

A data inventory is mandatory. Section 325M.16, subd. 2(c), requires reasonable administrative, technical, and physical security practices “including the maintenance of an inventory of the data that must be managed to exercise these responsibilities.” Under this statute the inventory isn’t best practice. It’s in the text.

Data minimization and a retention ceiling are substantive rules. Collection must be “limited to what is adequate, relevant, and reasonably necessary in relation to the purposes for which the data are processed, which must be disclosed to the consumer,” subd. 2(a); processing for purposes not reasonably necessary to or compatible with the disclosed purposes requires consent, subd. 2(b); and a controller “may not retain personal data that is no longer relevant and reasonably necessary in relation to the purposes for which the data were collected and processed,” subd. 2(g).

Sensitive data requires consent, not notice. Subd. 2(d). And “consent” is a defined term with teeth: § 325M.11(f) requires a “freely given, specific, informed, and unambiguous indication,” provides that acceptance of broad terms of use containing data-processing descriptions “along with other, unrelated information does not constitute consent,” provides that “[h]overing over, muting, pausing, or closing a given piece of content does not constitute consent,” and provides that consent obtained by a dark pattern isn’t valid. A “dark pattern” is “a user interface designed or manipulated with the substantial effect of subverting or impairing user autonomy, decision making, or choice.” § 325M.11(j).

Teenagers get an opt-in, not an opt-out. Section 325M.16, subd. 2(f), prohibits processing for targeted advertising or selling personal data without consent “under circumstances where the controller knows that the consumer is between the ages of 13 and 16.” Below 13, the known-child rules and COPPA parental consent apply; a controller in compliance with COPPA “shall be deemed compliant with any obligation to obtain parental consent” under the Act. § 325M.12, subd. 2(b).

Written policies and assessments are paperwork the Attorney General can demand. Section 325M.18(a) requires a documented description of the controller’s compliance policies including “the name and contact information for the controller’s chief privacy officer or other individual with primary responsibility.” Section 325M.18(b) requires a documented data privacy and protection assessment for five categories of processing: targeted advertising; sale of personal data; processing of sensitive data; any processing presenting a heightened risk of harm; and profiling that presents a reasonably foreseeable risk of unfair or deceptive treatment or disparate impact, financial, physical, or reputational injury, offensive intrusion upon solitude or seclusion, or other substantial injury.

The state can get the assessments on demand — “[a]s part of a civil investigative demand, the attorney general may request, in writing, that a controller disclose any data privacy and protection assessment that is relevant to an investigation,” and the controller “must make [it] available.” § 325M.18(f). Two protections come along with that. The assessments are classified as nonpublic data under § 13.02, subd. 9, and disclosure to the Attorney General “does not constitute a waiver of the attorney-client privilege or work product protection.” An assessment prepared for another state’s law “may qualify under this section if the assessments have a similar scope and effect.” § 325M.18(g).

Universal opt-out signals must be honored. Section 325M.14, subd. 3(a), requires controllers to accept an opt-out preference signal for targeted advertising and sale, sent with the consumer’s consent through a platform, technology, or mechanism — expressly including a browser setting, browser extension, or global device setting. § 325M.14, subd. 2(d). The mechanism can’t use a default setting; it must “require the consumer to make an affirmative, freely given, and unambiguous choice.” Subd. 3(a)(2). A controller that recognizes opt-out signals approved under other states’ laws complies. Subd. 3(d). And where a signal conflicts with a consumer’s participation in a loyalty or rewards program, “the controller must comply with the consumer’s opt-out preference signal” — it may then notify the consumer of the conflict and offer a chance to confirm the program, but the signal controls in the meantime. Subd. 3(b).


Who enforces the MCDPA, and is there a private right of action?

The Attorney General, exclusively. There’s no private right of action, and the statute says so in so many words.

Section 325M.20(b) authorizes the Attorney General to bring a civil action under Minn. Stat. § 8.31, and provides that if the state prevails it “may, in addition to penalties provided by paragraph (c) or other remedies provided by law, be allowed an amount determined by the court to be the reasonable value of all or part of the state’s litigation expenses incurred.” Paragraph (c): a violator “is subject to an injunction and liable for a civil penalty of not more than $7,500 for each violation.”

Paragraph (d) shuts the private door, and it names the door it’s shutting:

Nothing in sections 325M.10 to 325M.21 establishes a private right of action, including under section 8.31, subdivision 3a, for a violation of sections 325M.10 to 325M.21 or any other law.

Section 8.31, subd. 3a, is Minnesota’s private attorney general provision, the mechanism that lets an injured person sue for damages, costs, and attorney fees under statutes the Attorney General enforces. Paragraph (d) was written specifically to keep the MCDPA out of it.

And the cure period is over. Section 325M.20(a) required the Attorney General, before suing, to send a warning letter “identifying the specific provisions … the attorney general alleges have been or are being violated,” then wait 30 days for a cure. The paragraph ends: “This paragraph expires January 31, 2026.”

That date has come and gone. For any enforcement action started now, there’s no statutory warning letter, no statutory cure window, and no 30 days to fix what an investigator finds. A company that built its MCDPA risk model around “we will hear from them first” built it on a paragraph that no longer exists.


Can a contract waive any of this?

No. Section 325M.16, subd. 4: “Any provision of a contract or agreement of any kind that purports to waive or limit in any way a consumer’s rights under sections 325M.10 to 325M.21 is contrary to public policy and is void and unenforceable.”

A city or county can’t pile on, either. Section 325M.21(a) provides that the Act “supersede[s] and preempt[s] laws, ordinances, regulations, or the equivalent adopted by any local government regarding the processing of personal data by controllers or processors.” A Minneapolis or St. Paul data ordinance regulating processing by controllers is preempted.

And a controller can’t retaliate. Section 325M.16, subd. 3(b), prohibits discriminating against a consumer for exercising MCDPA rights — including “denying goods or services to the consumer, charging different prices or rates for goods or services, and providing a different level of quality of goods and services” — subject to a bona fide loyalty, rewards, premium features, discounts, or club card program exception. Subdivision 3(a) separately prohibits processing personal data on the basis of actual or perceived race, color, ethnicity, religion, national origin, sex, gender, gender identity, sexual orientation, familial status, lawful source of income, or disability “in a manner that unlawfully discriminates” as to housing, employment, credit, education, or public accommodations.


What doesn’t the MCDPA do?

Four things, and each one is a spot where a reader may assume more protection than the statute gives.

It doesn’t regulate biometrics as such. Biometric data is sensitive data requiring consent when processed “for the purpose of uniquely identifying an individual,” § 325M.11(v)(2), and it’s excluded from access-request disclosure, § 325M.14, subd. 4(i)(6). But there’s no Illinois-style per-scan statutory damages claim, because there’s no private right of action at all. I wrote separately about why Minnesota has no biometric privacy act.

It doesn’t reach government entities. Government entities as defined in § 13.02, subd. 7a, are excluded outright. § 325M.12, subd. 2(a)(1). Government-held data is chapter 13’s territory, and chapter 13, unlike the MCDPA, does give an injured person a damages remedy.

It doesn’t require breach notice. That obligation lives in Minn. Stat. § 325E.61, a separate statute with a much narrower definition of protected information and its own notice standard and 48-hour credit-bureau rule. The MCDPA’s only mention of breach is § 325M.13(b)(2), which requires a processor to help the controller with § 325E.61 notification.

It doesn’t regulate platform design. Content-recommendation and algorithmic-design rules for social platforms sit in a different part of chapter 325M — sections with their own effective dates and, in one case, a statutory-damages claim that doesn’t come into force until 2027. See my treatment of the Social Media Manipulation Act.


Where would I start?

If you’re a small business in Minnesota: figure out whether you sell sensitive data as § 325M.11(u) and (v) define those terms. Remember that “sale” includes exchange for “other valuable consideration” and that “sensitive data” includes street-address-precision location. If you do, get prior consent that satisfies § 325M.11(f), or stop. That’s the entire compliance program § 325M.17 asks of you, and being small doesn’t make it optional.

If you’re a nonprofit above the thresholds: you’re a controller. Read § 325M.12, subd. 2(a), clause by clause and confirm for yourself that nothing there excludes you.

If you’re near the 100,000 line: put the payment-transaction exclusion math in writing, now, while the underlying data still exists. Section 325M.19(g) puts the burden on you.

If you’re covered: the four things that most often don’t exist when I look are the data inventory required by § 325M.16, subd. 2(c); the specific-third-party list contemplated by § 325M.14, subd. 1(h); the profiling explanation required by subd. 1(g); and the 24-month appeal records required by subd. 5(d). All four are cheap to build ahead of time and expensive to reconstruct under a civil investigative demand.

Everyone: the 30-day warning letter expired January 31, 2026. Plan on the state’s first contact being an investigative demand, not a courtesy call.

The MCDPA was written to regulate big data processors, and its thresholds do exactly that. But two provisions slip out from under the thresholds entirely, and they run opposite ways from what you’d expect. Section 325M.17 pushes the Act down, reaching businesses far below the applicability floor with a single prohibition backed by the same $7,500-per-violation penalty. And the missing nonprofit exclusion pushes it sideways, into a kind of organization most compliance planning just assumes is out. You can’t see either one from the threshold provision. Both are in the exclusion list, which is the part of a privacy statute companies read fastest and lawyers read last. I read it last on purpose. Slowly.


Madgett Law, LLC advises Minnesota businesses and nonprofits on MCDPA applicability and compliance — threshold analysis, privacy notices, consumer-request workflows, processor contracting, and data privacy and protection assessments — and represents people whose personal information has been misused. If you’re working out whether the Act reaches your organization, or you’ve received an inquiry from the Attorney General’s office, send us a message or call 612-470-6529.


Sources: Minn. Stat. § 325M.10 (short title; the Act is §§ 325M.10–325M.21); § 325M.11 (definitions relied on: (f) consent; (g) consumer, excluding commercial and employment context; (i) decisions producing legal or similarly significant effects; (j) dark pattern; (o) known child, including willful disregard; (u) sale, including “other valuable consideration” and the six exclusions; (v) sensitive data, four categories; (w) specific geolocation data, three-decimal-degree accuracy and derived street address); § 325M.12 (subd. 1(a) applicability thresholds and the payment-transaction exclusion; subd. 1(b) § 13.32 technology-provider conflict rule; subd. 2(a) the 21 exclusions, including clause (13) employment-context data, clause (19) small business “except that a small business identified in this clause is subject to section 325M.17,” and clause (20) insurance anti-fraud nonprofit; subd. 2(b) COPPA parental-consent safe harbor); § 325M.13(b)(2) (processor assistance with § 325E.61 breach notice); § 325M.14 (subd. 1(b)–(h) consumer rights, including (g) the right to question a profiling result and (h) the list of specific third parties; subd. 2(d) authorized agents and browser-level signals; subd. 3 universal opt-out mechanisms, including (a)(2) no default setting, (b) loyalty-program conflicts, and (d) other-state signal compliance; subd. 4(d)–(j) response deadlines, free-response limit, burden on the controller, withheld identifiers, and trade secrets; subd. 5(c)–(d) appeal deadlines, Attorney General complaint information, and 24-month record retention); § 325M.15 (deidentified and pseudonymous data); § 325M.16 (subd. 1(a) the eight privacy-notice contents and subd. 1(c), (d), (f), (g) accessibility, language, and placement; subd. 2(a)–(g) data minimization, purpose limitation, the data-inventory requirement, sensitive-data consent, the 15-day consent-revocation deadline, the 13-to-16 opt-in, and the retention ceiling; subd. 3 nondiscrimination; subd. 4 waiver void and unenforceable); § 325M.17 (small-business prohibition on selling sensitive data without prior consent, with no volume threshold, and § 325M.20 penalties applied); § 325M.18 (documented policies and the chief privacy officer contact; the five data privacy and protection assessment triggers; (f) civil investigative demand access, nonpublic classification under § 13.02, subd. 9, and no privilege waiver; (g) other-jurisdiction assessments); § 325M.19 ((a)–(e) limitations and permitted processing; (f) proportionality; (g) controller bears the burden of demonstrating an exemption); § 325M.20 ((a) warning letter and 30-day cure, “This paragraph expires January 31, 2026”; (b) Attorney General action under § 8.31 and litigation expenses; (c) injunction and civil penalty of not more than $7,500 per violation; (d) no private right of action, “including under section 8.31, subdivision 3a”); § 325M.21(a) (preemption of local law) — all from the Minnesota Office of the Revisor of Statutes. Effective date: Laws 2024, ch. 121, art. 5, § 14 (“This article is effective July 31, 2025, except that postsecondary institutions regulated by the Office of Higher Education are not required to comply with this article until July 31, 2029.”). Currency: the Revisor’s history line for each of §§ 325M.10–325M.21 shows a single source act, Laws 2024, ch. 121, art. 5, and no amendment banner; Minnesota Statutes contain no chapter 325O.

This article is general legal information about Minnesota law, not legal advice, and reading it does not create an attorney–client relationship. Whether the Minnesota Consumer Data Privacy Act applies to a particular organization depends on its size, its revenue, the data it holds, the industries it operates in, and other laws that may govern the same information independently. No outcome is promised or implied.

Get new guides by email

Plain-English guides to Minnesota law, sent when a new one is written. No schedule, nothing for sale.

Used only to send these guides. Unsubscribe from any email. This is attorney advertising — subscribing does not create an attorney–client relationship.

← All news & articles