The first hours after a breach are spent on a question nobody has a clean answer to: when do we have to tell people?
Minnesota’s answer, in Minn. Stat. § 325E.61, is not a number. It is a standard. And a standard is harder to comply with than a deadline, because you can only be sure you satisfied it in hindsight — usually someone else’s hindsight.
Who has to notify?
Any person or business that conducts business in Minnesota and owns or licenses computerized personal data must notify affected Minnesota residents following a breach of the security of the system.
There are parallel obligations for entities that maintain data they do not own — typically vendors and processors — which generally run to the data owner rather than directly to consumers.
What counts as a breach?
The statute defines “breach of the security of the system” as the “unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information.”
Two limits worth noting:
- Good-faith acquisition by an employee for business purposes is not a breach, provided the information is not used or subject to further unauthorized disclosure.
- “Acquisition” is the operative word. Unauthorized access without acquisition is analyzed differently, and that distinction carries real weight in incident response — though it should never be the basis for a comfortable conclusion reached quickly.
What is “personal information”?
An individual’s name in combination with one or more of:
- Social Security number
- Driver’s license number or Minnesota identification card number
- Financial account number, or credit or debit card number, together with any required security code, access code, or password permitting access to the account
Publicly available information lawfully made available from government records is excluded.
Note what is not on this list. Email addresses and passwords alone, health information standing by itself, and biometric data are not within this definition — which does not mean their exposure is consequence-free. HIPAA, the Gramm-Leach-Bliley Act, the FTC Act, other states’ statutes, and contractual obligations all apply independently, and a multi-state breach is almost always governed by the strictest applicable regime rather than Minnesota’s.
The timing standard
Disclosure must be made “in the most expedient time possible and without unreasonable delay,” consistent with the legitimate needs of law enforcement and with measures necessary to determine the scope of the breach and restore the integrity of the system.
Law enforcement may request a delay where notification would impede a criminal investigation.
There is no fixed day count. In practice, that means:
- Document your timeline contemporaneously. Every day of delay must later be explainable by reference to the investigation, the restoration, or a law enforcement request — not by scheduling, internal debate, or waiting for outside counsel to be retained.
- A delay explained by a documented forensic timeline is defensible. A delay explained by “we were deciding what to do” is not.
- Do not use the standard’s flexibility as permission to be slow. Regulators and plaintiffs read “most expedient time possible” against what a diligent company would have done.
The 48-hour credit bureau rule
This is the one that gets missed. Minn. Stat. § 325E.61, subd. 2:
If a person discovers circumstances requiring notification under this section and section 13.055, subdivision 6, of more than 500 persons at one time, the person shall also notify, within 48 hours, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, as defined by United States Code, title 15, section 1681a, of the timing, distribution, and content of the notices.
Read the threshold precisely: “more than 500,” not “500 or more.” A notification to exactly 500 people does not trigger it. That is a one-person difference on a 48-hour clock, and it is the kind of detail an incident response plan should state in the statute’s own words rather than paraphrase.
Forty-eight hours is a real deadline in a statute otherwise built on a standard, and it runs while the incident response team is still assembling. Put it in the incident response plan by name.
One exemption that decides coverage entirely
Minn. Stat. § 325E.61, subd. 4 is a single sentence, and for a large category of Minnesota businesses it ends the analysis:
This section and section 13.055, subdivision 6, do not apply to any “financial institution” as defined by United States Code, title 15, section 6809(3).
That is the Gramm-Leach-Bliley Act definition, and it is considerably broader than “bank.” Institutions within it are outside § 325E.61 altogether — which does not mean they are unregulated. It means their breach obligations come from the federal financial privacy regime and their regulators instead, and an incident response plan built on this section would be built on the wrong statute.
Check this before anything else. Whether § 325E.61 applies to you at all is a threshold question, not a detail.
Who enforces it, and who cannot
The Attorney General enforces § 325E.61. There is no private right of action.
The statute also provides that waivers of its requirements are void and unenforceable — so a contract term purporting to release these obligations does not.
This puts Minnesota’s breach statute in the same architecture as the Minnesota Consumer Data Privacy Act, Minn. Stat. ch. 325M, which likewise reserves enforcement to the Attorney General. We wrote about that pattern — real rights, government-only enforcement — here.
But do not read “no private right of action” as “no litigation exposure.” Breach class actions in Minnesota proceed on other theories entirely: negligence, breach of contract, breach of implied contract, unjust enrichment, and consumer protection statutes including the private attorney general provision at Minn. Stat. § 8.31, subd. 3a. The absence of a statutory private remedy under § 325E.61 removes one claim, not the case.
What a defensible response looks like
Hours 0–24
- Contain. Isolate affected systems; do not destroy evidence in the process.
- Engage counsel before forensics, so the investigation is structured with privilege in mind from the outset rather than retroactively.
- Preserve logs, images, and artifacts. Retention policies delete the evidence you will need.
- Start the contemporaneous timeline. Every decision, with the time and the reason.
Days 1–7 5. Scope it. Whose data, what fields, how many, and in which states — the state count drives which regimes apply. 6. Determine whether the definition is met under Minnesota law and under every other applicable statute. 7. Notify your cyber insurer. Policies have notice conditions, and panel-counsel requirements are common. 8. Calendar the 48-hour credit bureau obligation if the count approaches 500 — the trigger is more than 500 notified at one time.
Notification 9. Notify without unreasonable delay, in the manner the statute permits. 10. Say something useful. What happened, what data, what you are doing, what the recipient should do. Notices that read as legal throat-clearing generate complaints and regulator attention. 11. Offer credit monitoring where the exposed data warrants it. Not required in every case; frequently expected. 12. Prepare for the follow-on — regulator inquiries, contractual notice obligations to business customers, and litigation.
For individuals whose data was exposed
- Freeze your credit with all three bureaus. It is free, it is the single most effective step, and it blocks new-account fraud in a way monitoring does not.
- Take the offered monitoring. Accepting it does not waive anything.
- Read your statements, and dispute in writing.
- Keep the breach notice. It is evidence of the source if fraud follows.
- Know your credit-report remedies. Unlike § 325E.61, the FCRA does provide a private right of action with fees — see our FCRA piece.
The structural observation
Minnesota’s breach statute is nearly two decades old in concept and shows it: a narrow definition of personal information tied to Social Security numbers and financial accounts, a flexible timing standard, and enforcement lodged entirely with the Attorney General.
The MCDPA, effective in 2025, is the modern layer — broader in what it protects and what it requires, and likewise enforced only by the Attorney General.
For a Minnesota business, the practical consequence is that your breach obligations are rarely defined by Minnesota law alone. They are defined by the strictest statute that reaches any affected person, and by your contracts. Building a response plan around § 325E.61 by itself is building for the easiest case you will face.
Madgett Law, LLC advises Minnesota businesses on breach response, multi-state notification analysis, and the contractual and regulatory exposure that follows — and represents individuals whose information has been misused. If you are in the first days of an incident, the timeline documentation you create now is what defends the decisions later. Send us a message or call 612-470-6529.
Sources: Minn. Stat. § 325E.61 (breach of the security of the system; definition of personal information; notification in the most expedient time possible and without unreasonable delay; law enforcement delay; subd. 2, 48-hour notice to nationwide consumer reporting agencies where more than 500 persons are notified at one time, as defined by 15 U.S.C. § 1681a; subd. 3, waiver prohibited, reaching this section and § 13.055, subd. 6; subd. 4, exemption for any “financial institution” as defined by 15 U.S.C. § 6809(3); Attorney General enforcement); Minn. Stat. ch. 325M (Minnesota Consumer Data Privacy Act); Minn. Stat. § 8.31, subd. 3a (Minnesota Office of the Revisor of Statutes); 15 U.S.C. § 1681 et seq. This article is general legal information about Minnesota law, not legal advice, and reading it does not create an attorney–client relationship. Breach obligations depend on the data involved and the residency of affected individuals, and other federal, state, and contractual requirements frequently apply. No outcome is promised or implied.