Three Minnesota Privacy Laws Apply to Your Company. The One Nobody Plans For Is the Only One With a Private Right of Action.

July 17, 2026 · David J.S. Madgett · Updated August 30, 2026

Ask a Minnesota company what its privacy obligations are and you will hear one statute named: the breach notification law. It sits in the incident response plan, it sits in the vendor contracts, and it is the one the board has heard of.

It is also the narrowest of the three Minnesota regimes that may apply, and the only one of the three that no private plaintiff can use against you.

The other two are the Minnesota Consumer Data Privacy Act, which protects a category of information roughly ten times broader, and the Minnesota Government Data Practices Act — chapter 13 — which most private companies are certain does not apply to them, and which, if they contract with any Minnesota government entity, does.


The breach statute is the narrowest thing you own

Start with the trigger, because it is acquisition, not access. “Breach of the security of the system” means “unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by the person or business.” Minn. Stat. § 325E.61, subd. 1(d). Good-faith acquisition by an employee or agent for the business’s purposes is not a breach, “provided that the personal information is not used or subject to further unauthorized disclosure.”

The protected category is three data elements long. “Personal information” means a first name or first initial and last name in combination with any one or more of: Social Security number; driver’s license number or Minnesota identification card number; or “account number or credit or debit card number, in combination with any required security code, access code, or password that would permit access to an individual’s financial account” — each only “when the data element is not secured by encryption or another method of technology that makes electronic data unreadable or unusable.” Subd. 1(e). Publicly available government-record information is excluded. Subd. 1(f).

Email addresses, passwords standing alone, health information, biometric data, precise location — none of that is inside the definition. Whatever your incident actually exposed, that list is what the statute cares about.

The timing rule is a standard, not a deadline. Disclosure must be made “in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement … or with any measures necessary to determine the scope of the breach, identify the individuals affected, and restore the reasonable integrity of the data system.” Subd. 1(a). There is exactly one hard number in the section, and it is short: where notification of “more than 500 persons at one time” is required, the person must “also notify, within 48 hours, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis.” Subd. 2.

Enforcement belongs to the Attorney General alone: “The attorney general shall enforce this section … under section 8.31.” Subd. 6. Waivers are “contrary to public policy and … void and unenforceable.” Subd. 3.

Then there is the exemption almost everyone misses. Subdivision 4 provides that the section does not apply to any “financial institution” as defined by 15 U.S.C. § 6809(3) — the Gramm-Leach-Bliley definition, which sweeps considerably wider than “bank.” I have seen companies build a whole notification program without ever reading subdivision 4, and the analysis was backward from the first page.

We wrote about the mechanics of complying with this statute here. This piece is about what sits on either side of it.


The MCDPA reaches fewer companies and far more data

Chapter 325M is no longer one act. It now carries three: the older internet-privacy sections (§§ 325M.01–.09), the Minnesota Consumer Data Privacy Act (§§ 325M.10–.21), and the Prohibiting Social Media Manipulation Act (§§ 325M.30–.34, with a new § 325M.40 added in 2026). A citation to “chapter 325M” without a section number now tells the reader nothing.

The MCDPA took effect July 31, 2025, with postsecondary institutions regulated by the Office of Higher Education not required to comply until July 31, 2029. (Laws 2024, ch. 121, art. 5, § 14.)

Sections 325M.10 to 325M.21 apply to legal entities that conduct business in Minnesota or produce products or services targeted to Minnesota residents and that either (1) “during a calendar year, control[] or process[] personal data of 100,000 consumers or more, excluding personal data controlled or processed solely for the purpose of completing a payment transaction,” or (2) “derive[] over 25 percent of gross revenue from the sale of personal data and process[] or control[] personal data of 25,000 consumers or more.” § 325M.12, subd. 1(a).

“Personal data” is defined by linkability rather than by enumeration:

“Personal data” means any information that is linked or reasonably linkable to an identified or identifiable natural person. Personal data does not include deidentified data or publicly available information.

§ 325M.11(p). That is not a list of three data elements. That is nearly everything your systems hold.

“Consumer,” on the other hand, is narrower than people assume. It means “a natural person who is a Minnesota resident acting only in an individual or household context,” and it “does not include a natural person acting in a commercial or employment context.” § 325M.11(g). Employee data sits outside the MCDPA entirely. One clause removes the whole HR file from the statute, and it is the clause I most often find missing from a company’s compliance memo.

Two of the consumer rights in § 325M.14 are unusual enough to know by name. A consumer has “a right to obtain a list of the specific third parties to which the controller has disclosed the consumer’s personal data,” subd. 1(h). And where personal data is profiled in furtherance of decisions producing legal or similarly significant effects, the consumer “has the right to question the result of the profiling, to be informed of the reason that the profiling resulted in the decision, and, if feasible, to be informed of what actions the consumer might have taken to secure a different decision.” Subd. 1(g). The consumer may also require correction and reevaluation where the decision rested on inaccurate data.

On enforcement, the Attorney General may bring a civil action under § 8.31, and a violator “is subject to an injunction and liable for a civil penalty of not more than $7,500 for each violation.” § 325M.20(b)–(c). The 30-day cure letter is gone. Section 325M.20(a) required the Attorney General to send a warning letter identifying the alleged violations and to wait 30 days before suing, and the subdivision ends with a sentence worth reading twice: “This paragraph expires January 31, 2026.” As of that date, the warning-letter step left the statute.

There is no private right of action, and the Legislature said so expressly: “Nothing in sections 325M.10 to 325M.21 establishes a private right of action, including under section 8.31, subdivision 3a.” § 325M.20(d). That is a deliberate closing of the door to Minnesota’s private attorney general statute.


Chapter 13 follows the contract, not the privacy policy

Here is the sentence that catches private companies. Minn. Stat. § 13.05, subd. 11(a):

If a government entity enters into a contract with a private person to perform any of its functions, all of the data created, collected, received, stored, used, maintained, or disseminated by the private person in performing those functions is subject to the requirements of this chapter and the private person must comply with those requirements as if it were a government entity. All contracts entered into by a government entity must include a notice that the requirements of this subdivision apply to the contract. Failure to include the notice in the contract does not invalidate the application of this subdivision. The remedies in section 13.08 apply to the private person under this subdivision.

Read the last two sentences twice. The obligation does not depend on the contract saying so, and the remedies run against the private contractor directly.

Those remedies are why this regime matters far more than its obscurity suggests. Section 13.08, subd. 1, makes a violator “liable to a person … who suffers any damage as a result of the violation,” who may sue “to cover any damages sustained, plus costs and reasonable attorney fees.” And: “In the case of a willful violation, the government entity shall, in addition, be liable to exemplary damages of not less than $1,000, nor more than $15,000 for each violation.” Subdivision 2 authorizes an injunction; subdivision 4 permits an action to compel compliance with costs and fees.

One drafting wrinkle deserves naming rather than papering over. Section 13.08, subd. 1, speaks of liability of “a responsible authority or government entity,” and the exemplary-damages sentence names “the government entity.” The bridge to a private contractor is the last sentence of § 13.05, subd. 11(a) — “[t]he remedies in section 13.08 apply to the private person under this subdivision.” How far that sentence carries the exemplary-damages provision is a question I would expect any competent defendant to raise, and I would want it briefed before anyone budgets the exposure.

Set that against the other two regimes. Section 325E.61 gives the Attorney General exclusive enforcement. The MCDPA expressly forecloses a private right of action. Chapter 13 hands a private plaintiff actual damages, attorney fees, and per-violation exemplary damages with a statutory floor.

The definitions and the trigger differ again. Chapter 13 never classifies data by “personal information” or “personal data.” It classifies by its own scheme — public, private, confidential, nonpublic, protected nonpublic — and the obligations attach to the classification rather than to a breach. For breach notification specifically, § 13.055 requires a government entity to disclose a breach of private or confidential data, prepare an investigation report, and, under subd. 1(a), treats “data maintained by a person under a contract with the government entity that provides for the acquisition of or access to the data” as data maintained by the government entity.

Chapter 13 can also override the MCDPA. Section 325M.12, subd. 1(b), provides that a controller or processor acting as a technology provider under § 13.32 must comply with both, “except that when the provisions of section 13.32 conflict with sections 325M.10 to 325M.21, section 13.32 prevails.” An edtech vendor serving Minnesota schools is inside all three regimes simultaneously, with chapter 13 sitting on top.


Three regimes side by side

§ 325E.61 MCDPA, §§ 325M.10–.21 Chapter 13
Who is covered Any person or business conducting business in Minnesota that owns or licenses computerized personal data; GLBA “financial institutions” exempt, subd. 4 Entities meeting a 100,000-consumer or 25%-revenue/25,000-consumer threshold, § 325M.12, subd. 1 Government entities — and any private person under contract to perform a government function, § 13.05, subd. 11
What is protected Name + SSN, driver’s license/state ID, or financial account number with access credential, subd. 1(e) “[A]ny information that is linked or reasonably linkable to an identified or identifiable natural person,” § 325M.11(p) Government data, by statutory classification
Excluded Encrypted data; public government-record information Employment and commercial context — “consumer” excludes them, § 325M.11(g) Data outside the government function performed
Trigger Unauthorized acquisition, subd. 1(d) Processing personal data at all Collection, use, or dissemination — plus breach under § 13.055
Deadline “[M]ost expedient time possible and without unreasonable delay”; 48 hours to nationwide CRAs if more than 500 persons, subd. 2 45 days to inform a consumer of action on a request, extendable once by 45 days; 45 days on an appeal, extendable by 60, § 325M.14, subds. 4(e), 5(c) Notice “in the most expedient time possible and without unreasonable delay,” § 13.055, subd. 2
Enforcer Attorney General only, subd. 6 Attorney General only; $7,500 per violation, § 325M.20 Any damaged person, § 13.08
Private right of action None Expressly none, § 325M.20(d) Yes — damages, costs, attorney fees; $1,000–$15,000 exemplary for a willful violation

What I tell clients to do

If you contract with any Minnesota government entity — city, county, school district, state agency — start here. Assume chapter 13 applies to the data you touch in performing that contract, because § 13.05, subd. 11(a) puts the notice requirement on the government entity and then says its absence “does not invalidate the application of this subdivision.” Identify the boundary between contract data and your own data, in writing, before performance begins; the chapter attaches to data created or received “in performing those functions,” so the scope of the function defines the scope of the obligation. Designate a human being to handle data requests, because a contractor performing a government function will receive requests it was never built to answer, and § 13.08, subd. 4, makes failure to respond independently actionable. Then price the exposure honestly: actual damages plus fees plus $1,000 to $15,000 per willful violation is a different risk profile from an Attorney General inquiry, and it should not be sitting in a footnote.

If you are above the MCDPA thresholds, recheck the count first — the 100,000-consumer threshold excludes personal data processed “solely for the purpose of completing a payment transaction,” which moves some retailers below the line and is worth documenting either way. Do not build employee data into the program, because “consumer” excludes the employment context; build it for the customer file. Note the date: the Attorney General’s 30-day warning-letter step expired January 31, 2026. And build the two Minnesota-specific rights — the list of specific third parties, and the profiling explanation — by hand, because they do not appear in every state statute and a generic multi-state privacy portal will not satisfy them.

For everyone else, two things. Stop treating § 325E.61 as the perimeter; it is the floor, it is narrow, and a multi-state incident is almost always governed by a stricter statute somewhere else. And calendar the 48 hours the moment the affected count approaches 500. Individuals whose data was exposed should still start with a credit freeze and a police report — see our identity theft steps.


Why the oldest statute is the dangerous one

These three statutes were written in three different decades to solve three different problems, and it shows on every page.

Section 325E.61 is a 2005-era statute that assumes the harm is financial account fraud, defines protected data as the three fields a thief would need for it, and gives the state a policing role. Chapter 325M’s consumer-privacy article is a 2024 statute that assumes the harm is the commercial use of personal information itself, defines protected data by linkability, and gives consumers rights against companies large enough to be worth regulating. Chapter 13 is a 1970s-era statute about the state’s power over its citizens’ records, and it swept private contractors in because the state kept outsourcing the functions that generate those records.

Only the oldest of the three lets an individual into court. Nobody designed it that way. It is what happens when a government-accountability statute acquires a privatization provision, and when two later privacy statutes are written to be enforced by a public official whose office has finite capacity.

The consequence for a Minnesota company is uncomfortable, and I state it plainly to every client who asks: the statute creating the most exposure is the one least likely to appear in your privacy program, and it applies because of a contract your operations team signed, not because of anything your privacy team did. Go read that contract this week.


Madgett Law, LLC advises Minnesota businesses on breach response, Data Practices Act obligations arising from government contracts, and MCDPA compliance — and represents individuals whose information has been misused. If you are in the first days of an incident, or have just discovered that a government contract carries chapter 13 obligations, send us a message or call 612-470-6529.


Sources: Minn. Stat. § 325E.61 (subd. 1(a) notice standard; subd. 1(d) definition of breach and good-faith acquisition; subd. 1(e)–(f) definition and exclusions of “personal information”; subd. 2, 48-hour notice to nationwide consumer reporting agencies where more than 500 persons are notified at one time; subd. 3, waiver void; subd. 4, exemption for “financial institution” as defined by 15 U.S.C. § 6809(3); subd. 6, Attorney General enforcement under § 8.31); Minn. Stat. §§ 325M.10 (citation and effective-date note, Laws 2024, ch. 121, art. 5, § 14), 325M.11(g) and (p) (definitions of “consumer” and “personal data”), 325M.12, subd. 1 (scope thresholds and the § 13.32 technology-provider rule), 325M.14, subds. 1, 4, and 5 (consumer rights; controller response and appeal deadlines), and 325M.20 (Attorney General enforcement; expiration of the warning-letter paragraph on January 31, 2026; $7,500 civil penalty; no private right of action); Minn. Stat. § 13.05, subd. 11 (privatization), § 13.055 (disclosure of breach in security; subd. 1(a) treatment of data maintained by a contractor; subd. 2 notice standard), and § 13.08 (civil remedies — damages, costs, attorney fees, and exemplary damages of not less than $1,000 nor more than $15,000 for a willful violation) — all from the Minnesota Office of the Revisor of Statutes, 2025 Minnesota Statutes.

Currency: Revisor Table 2 (Statutes Changed) shows no amendment to § 325E.61, § 13.05, § 13.055, § 13.08, or §§ 325M.10–.21 in the 2025 or 2026 legislative sessions. Chapter 13 was amended extensively elsewhere in 2026, and chapter 325M’s social media article was amended and expanded — § 325M.33 amended and § 325M.40 added by Laws 2026, ch. 111 (H.F. No. 4138) — so a chapter-level citation to either chapter should be checked against the current text.

This article is general legal information about Minnesota law, not legal advice, and reading it does not create an attorney–client relationship. Which regime applies to a given organization depends on its size, its contracts, the data it holds, and the residency of the individuals involved, and federal and other states’ laws frequently apply independently. No outcome is promised or implied.

Get new guides by email

Plain-English guides to Minnesota law, sent when a new one is written. No schedule, nothing for sale.

Used only to send these guides. Unsubscribe from any email. This is attorney advertising — subscribing does not create an attorney–client relationship.

← All news & articles