On January 31, 2026, a sentence in the Minnesota Statutes expired on schedule, and almost nobody noticed.
The sentence is the last one in Minn. Stat. § 325M.20(a). Here is the paragraph it ends:
(a) In the event that a controller or processor violates sections 325M.10 to 325M.21, the attorney general, prior to filing an enforcement action under paragraph (b), must provide the controller or processor with a warning letter identifying the specific provisions of sections 325M.10 to 325M.21 the attorney general alleges have been or are being violated. If, after 30 days of issuance of the warning letter, the attorney general believes the controller or processor has failed to cure any alleged violation, the attorney general may bring an enforcement action under paragraph (b). This paragraph expires January 31, 2026.
The bolding is mine. The words are the Legislature’s.
That was the Minnesota Consumer Data Privacy Act’s right to cure, and it is gone — 217 days gone as of this writing. What operates in its place is § 325M.20(b) and (c): a civil action brought under Minn. Stat. § 8.31, an injunction, “a civil penalty of not more than $7,500 for each violation,” and, if the state prevails, “the reasonable value of all or part of the state’s litigation expenses incurred.” No letter. No thirty days. No opportunity to fix it first.
Every client alert written in 2024 and 2025 that told Minnesota businesses they had a cure period is now wrong, and the ones sitting in a compliance binder are worse than wrong, because somebody is relying on them. If your file contains a 2024 memo on the MCDPA, the operative paragraph in it has expired.
The Attorney General’s Office announced the change itself. In a February 5, 2026 communication headed “Minnesota Consumer Data Privacy Act takes full effect,” the office reported that in the statute’s first six months it had sent “hundreds of education letters” to companies, received “more than 200 complaints regarding the MCDPA,” and sent “dozens of warning letters to companies that identified problems with privacy policies, procedures for honoring consumer data rights, consent mechanisms for collecting sensitive data, and responses to universal opt-out signals.” Then it said the quiet part in its own subheadline: “AGO can now bring enforcement actions without providing 30-day notice.”
Dozens of companies got a letter and a chance to fix it. That door closed in January.
Two disclosures, and the second one is not the usual one
The first is ordinary. My firm sells the work described in this essay — threshold determinations, assessments, vendor contract terms, response protocols. I have an obvious commercial interest in Minnesota businesses concluding they need a lawyer for this. Discount accordingly and check the sections yourself; every one of them is linked at the bottom.
The second is not ordinary and I am not going to bury it in a footer. I am a candidate for Minnesota Attorney General in 2026. This essay describes the enforcement powers of that office — the $7,500-per-violation authority, the civil investigative demand, the litigation-expense award. A reader who learned that somewhere else, after reading this, would be right to feel handled.
So: I am not going to tell you what I would do with any of it. There is no prediction in this piece about how that office will or should exercise its discretion, no proposal, and nothing about the current officeholder except the office’s own published account of what it has already done. What follows is a description of statutes that are in force today, quoted from the Revisor’s text, and they say what they say regardless of who reads them out loud.
Subdivision 1, paragraph (g) is the strongest automated-decision right in the country
Here is the thing about the MCDPA that Minnesota business lawyers have largely not priced in. It is not the deletion right, and it is not the universal opt-out signal. It is Minn. Stat. § 325M.14, subd. 1(g):
(g) If a consumer’s personal data is profiled in furtherance of decisions that produce legal effects concerning a consumer or similarly significant effects concerning a consumer, the consumer has the right to question the result of the profiling, to be informed of the reason that the profiling resulted in the decision, and, if feasible, to be informed of what actions the consumer might have taken to secure a different decision and the actions that the consumer might take to secure a different decision in the future. The consumer has the right to review the consumer’s personal data used in the profiling. If the decision is determined to have been based upon inaccurate personal data, taking into account the nature of the personal data and the purposes of the processing of the personal data, the consumer has the right to have the data corrected and the profiling decision reevaluated based upon the corrected data.
Read it as an operations requirement rather than as a right, because that is what it becomes the day a consumer sends the form. On request, a controller must be able to state the reason this decision came out the way it did — not the general logic of the system, “the reason that the profiling resulted in the decision.” It must, if feasible, supply a counterfactual: what this person could have done differently. It must show the person the input data. And if the inputs were wrong, it must correct them and run the decision again.
Explainability, counterfactual explanation, and re-adjudication, in one paragraph, in a state privacy statute, in force since July 31, 2025.
The definitions are what make this bite. “Profiling,” under § 325M.11(s), means “any form of automated processing of personal data to evaluate, analyze, or predict personal aspects related to an identified or identifiable natural person’s economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.” Any form. A logistic-regression scoring model somebody wrote in 2009 is profiling. So is a spreadsheet with weights in it. The statute is indifferent to whether the vendor’s marketing says “AI.” And § 325M.11(i) defines the decisions that trigger the right — the provision or denial of “financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunities, health care services, or access to essential goods or services.”
Four operational facts follow, and each one costs money:
The clock is 45 days. Section 325M.14, subd. 4(e), requires the controller to inform the consumer of any action taken on a subdivision 1 request “without undue delay and in any event within 45 days of receipt,” extendable once by 45 more where reasonably necessary — but the extension itself must be communicated within the original 45 days, “together with the reasons for the delay.”
No browser signal handles this. Subdivision 2(d) lets a consumer designate an authorized agent — the mechanism behind global opt-out signals — but only “to exercise the consumer’s right to opt out of the processing of the consumer’s personal data for purposes of targeted advertising and sale under subdivision 1, paragraph (f).” Paragraph (g) is not in that list. Profiling questions arrive one at a time from individual people, and a human has to work each one.
There is a mandatory appeal, and it has a retention rule attached. Under subd. 5(a) a controller “must establish an internal process whereby a consumer may appeal a refusal to take action.” Under subd. 5(d), the controller must give written reasons, must “clearly and prominently provide the consumer with information about how to file a complaint with the Office of the Attorney General,” and “must maintain records of all appeals and the controller’s responses for at least 24 months and shall, upon written request by the attorney general as part of an investigation, compile and provide a copy of the records to the attorney general.” A business that mishandles these is building the state’s file for it.
The trade-secret escape is narrower than vendors say. Subdivision 4(j) provides that “a controller is not required to reveal any trade secret.” That excuses revealing a trade secret. It does not excuse the duty to state the reason the profiling resulted in the decision. Those are different things, and a vendor that conflates them is describing its own convenience.
And the state is not leaving consumers to figure this out. The Attorney General’s Office published template forms at privacymn.com for consumers to use in asserting these rights. Whatever else is true, the volume side of this is being handled for the requester.
Who is inside it
Section 325M.12, subd. 1(a), applies the Act to “legal entities that conduct business in Minnesota or produce products or services that are targeted to residents of Minnesota,” that also cross one of two thresholds: controlling or processing personal data of 100,000 consumers or more in a calendar year, excluding data handled “solely for the purpose of completing a payment transaction”; or deriving over 25 percent of gross revenue from selling personal data while processing or controlling data of 25,000 consumers or more.
Note what is absent. There is no revenue-only threshold. A Minnesota company with half a billion dollars in revenue and forty thousand customers is outside the Act’s main obligations; a company with 100,001 customers and three million dollars in revenue is inside them. Size in dollars is the wrong question, and it is the first question most executives ask.
Small businesses as defined by the SBA size standards are excluded from most of the Act by § 325M.12, subd. 2(a)(19) — but not from § 325M.17, which prohibits a small business from selling “a consumer’s sensitive data without the consumer’s prior consent” and expressly applies the § 325M.20 penalties and enforcement procedures to a violation. There is no such thing as being entirely outside this statute.
The Legislature wrote the commercial argument, and put it in paragraph (f)
Section 325M.18 is the sleeper. It requires a controller to “conduct and document a data privacy and protection assessment” for five categories of processing, and the fifth is the one that matters here — profiling, “where the profiling presents a reasonably foreseeable risk of”:
(i) unfair or deceptive treatment of, or disparate impact on, consumers;
(ii) financial, physical, or reputational injury to consumers;
(iii) a physical or other intrusion upon the solitude or seclusion, or the private affairs or concerns, of consumers, where the intrusion would be offensive to a reasonable person; or
(iv) other substantial injury to consumers.
Minnesota’s privacy statute puts disparate impact into the trigger for a mandatory, documented assessment. A business running a model that scores people has to sit down and write out whether that model presents a reasonably foreseeable risk of disparate impact — and then keep the writing.
Sit with what that means. The statute compels the creation of a document whose entire subject is your own legal exposure, and § 325M.18(d) tells you how to write it: the assessment “must identify and weigh the benefits that may flow directly and indirectly from the processing to the controller, consumer, other stakeholders, and the public against the potential risks to the rights of the consumer associated with the processing, as mitigated by safeguards that can be employed by the controller to reduce the potential risks.” That is a risk memo. In any other context a lawyer would tell you never to write it down.
The Legislature saw the problem. Section 325M.18(f):
(f) As part of a civil investigative demand, the attorney general may request, in writing, that a controller disclose any data privacy and protection assessment that is relevant to an investigation conducted by the attorney general. The controller must make a data privacy and protection assessment available to the attorney general upon a request made under this paragraph. The attorney general may evaluate the data privacy and protection assessments for compliance with sections 325M.10 to 325M.21. Data privacy and protection assessments are classified as nonpublic data, as defined by section 13.02, subdivision 9. The disclosure of a data privacy and protection assessment pursuant to a request from the attorney general under this paragraph does not constitute a waiver of the attorney-client privilege or work product protection with respect to the assessment and any information contained in the assessment.
Two protections are in there, and they are worth separating.
The first is a classification. In the Attorney General’s hands the assessment is “nonpublic data” under Minn. Stat. § 13.02, subd. 9, which defines the term as “data not on individuals made by statute or federal law applicable to the data: (a) not accessible to the public; and (b) accessible to the subject, if any, of the data.” That is a public-access rule. It means a competitor, a reporter, or a plaintiff’s lawyer cannot obtain your assessment out of the state’s files with a data practices request.
The second is the non-waiver sentence, and it is the one that decides where this work should sit. Handing your assessment to the Attorney General under paragraph (f) “does not constitute a waiver of the attorney-client privilege or work product protection with respect to the assessment and any information contained in the assessment.” Ordinarily, voluntary production of a privileged document to a government investigator is the classic waiver fact pattern. The Legislature took that consequence off the table for this one production.
Which produces the commercial argument I did not have to invent, because the statute made it: the same assessment written by a consultant has no privilege for paragraph (f) to preserve. A consulting deliverable is a business record. It is produced to the AG, and what the AG reads is exactly what it was written to be — the company’s own analysis of the risk that its model treats people unfairly. On that production, paragraph (f) preserves something a consultancy has nothing to preserve.
What paragraph (f) does not do
Now the part a lawyer overstating this in public gets wrong, and I would rather be the one to say it.
Paragraph (f) does not create a privilege. It preserves one. Non-waiver language presupposes that something privileged existed before the production, and the antecedent question — is this statutorily mandated assessment attorney-client privileged or work product in the first place? — is not answered anywhere in § 325M.18. A document created because a statute requires every covered business to create it, on a schedule, as part of routine compliance, is precisely the document an opposing party argues was made for a business purpose rather than in anticipation of litigation. That argument is available and it is not frivolous. Whether the assessment is privileged turns on who directed it, why, what it was for, and how the company treated it — the ordinary analysis, unchanged.
It does not let you refuse to produce. The second sentence is mandatory: “The controller must make a data privacy and protection assessment available to the attorney general upon a request made under this paragraph.” Privilege survives the production. It does not excuse the production. Anyone selling you a privileged assessment as a way to keep the Attorney General from reading it has read the paragraph backwards.
Its non-waiver is keyed to one recipient and one request. The sentence protects “disclosure of a data privacy and protection assessment pursuant to a request from the attorney general under this paragraph.” It says nothing about production to a federal agency, to another state’s attorney general, or to a private litigant. Whether counsel’s assessment is protected from a private litigant is decided by ordinary privilege and work-product law, not by paragraph (f). Selective-waiver doctrine is unfriendly territory generally, and paragraph (f) does not extend past its own terms.
And it is thirteen months old. I have found no Minnesota decision construing paragraph (f), and I would not represent to a client that one exists. Its plain language is clear enough as to what it does. How courts handle the antecedent privilege question for a compelled compliance document is genuinely open.
The honest version of the sales pitch is therefore narrower than the version you will hear, and it is still good: the statute orders you to write down your own risk, and it removes the single largest disincentive to having counsel do it. Take the removed disincentive. Do not pretend it is a shield.
One more thing lives in § 325M.18 and it is worth a sentence. Paragraph (g) provides that assessments “conducted by a controller for the purpose of compliance with other laws or regulations may qualify under this section if the assessments have a similar scope and effect,” and paragraph (h) provides that “[a] single data protection assessment may address multiple sets of comparable processing operations that include similar activities.” Scope the work once for the strictest applicable regime and it carries. Scope it six times and you have paid for it six times.
The disparate-impact trigger raises a question this essay does not answer
Section 325M.18(b)(5)(i) puts “unfair or deceptive treatment of, or disparate impact on, consumers” into a Minnesota statute as the trigger for a mandatory written assessment. Separately, § 325M.16, subd. 3(a), prohibits a controller from processing personal data on the basis of protected characteristics “in a manner that unlawfully discriminates” as to housing, employment, credit, education, or public accommodations.
What relationship those provisions bear to the Minnesota Human Rights Act, Minn. Stat. ch. 363A — whether an assessment conducted under § 325M.18 becomes evidence in a chapter 363A case, and what “unlawfully discriminates” in § 325M.16 borrows from chapter 363A — is a real question and I have not researched it. I am flagging it rather than guessing at it. If your model makes employment or credit decisions about Minnesotans, that unanswered question is a reason to have this conversation with a lawyer and not a vendor.
Colorado went backward, Europe moved the goalposts, and Minnesota did neither
If you have a Colorado deck from 2024 or 2025, throw it out. The Colorado AI Act that everyone in this field spent two years writing about — high-risk AI systems, algorithmic discrimination, a duty of reasonable care — no longer exists in that form. SB 24-205, approved May 17, 2024, keyed its duties to February 1, 2026. SB 25B-004, approved August 28, 2025, moved them to June 30, 2026. The Act was then challenged in federal court in X.AI LLC v. Weiser, No. 1:26-cv-01515 (D. Colo.), filed April 9, 2026 — I have read the docket and not the orders, so that is all I will say about it. And on May 14, 2026, SB 26-189 repealed and reenacted the whole of part 17 of article 1 of title 6 under a new heading — automated decision-making technology in consequential decisions — effective January 1, 2027 and applicable only to consequential decisions made on or after that date.
The citation survived. The statute behind it did not. The high-risk-system and algorithmic-discrimination vocabulary is out; the new text is built on automated decision-making technology, covered ADMT, and consequential decisions. Colorado also retained a 60-day notice-and-cure procedure that does not itself sunset until January 1, 2030 — though it is a discretionary opportunity the enforcing authority may extend, not an entitlement a defendant can demand.
Line the two states up and you get a comparison that surprised me when I ran it. A Minnesota business has less grace under Minnesota’s privacy statute today than a Colorado business will have under Colorado’s AI statute for its first three years. And on the narrow question of what an individual can demand about a single automated decision, Minnesota’s § 325M.14, subd. 1(g) — in force since July 2025 — is stronger than what Colorado’s replacement will provide in 2027, which offers human review only to the extent commercially reasonable and expressly does not require correcting opinions, predictions, or scores. Minnesota did not pass an AI act. Minnesota passed a privacy act with an automated-decision provision in it, and that provision is doing more work than the AI act everybody watched.
Europe reaches a Minnesota company through a single clause, and it has nothing to do with having a European office. Regulation (EU) 2024/1689, article 2(1), applies the AI Act to:
(c) providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union;
No establishment. No marketing into the Union. No contract with an EU entity. The trigger is that the output gets used there. A Minneapolis company whose résumé-ranking model scores applicants for a Dublin subsidiary is a deployer under 2(1)(c).
The dates moved six weeks ago and most published checklists have not caught up. Regulation (EU) 2026/1744, of 8 July 2026, in force 27 July 2026, rewrote article 113. The high-risk obligations that people had penciled in for 2026 and 2027 now apply from 2 December 2027 for Annex III systems — employment, credit, education, essential services — and 2 August 2028 for Annex I product systems. What is in force is the general application date of 2 August 2026, which carries the article 50 transparency duties: telling people they are interacting with an AI system, marking synthetic output as machine-detectable, and disclosing deep fakes. Those have been binding for a month, and a US company with EU-facing output is inside them now while it waits for a high-risk deadline that moved away from it.
The ethics layer is one opinion, one FAQ, and a silence
For lawyers rather than their clients, three things and no more.
ABA Formal Opinion 512, July 29, 2024. Persuasive in Minnesota, not binding — it construes the Model Rules, and Minnesota lawyers answer to the Minnesota Rules of Professional Conduct. Two lines from it earn their keep. On consent under Rule 1.6: “To obtain informed consent when using a GAI tool, merely adding general, boiler-plate provisions to engagement letters purporting to authorize the lawyer to use GAI is not sufficient.” A great many Minnesota engagement letters acquired exactly that clause in 2024. And on Rule 8.4(c): “Even an unintentional misstatement to a court can involve a misrepresentation under Rule 8.4(c).” There is no good-faith-hallucination defense. I have written elsewhere in this section about what the opinion does to an hourly bill and will not repeat it.
The District of Minnesota answered the disclosure question in writing, and the answer is no. Its GenAI FAQ, dated October 1, 2025: “The District of Minnesota does not currently require disclosure of AI use in court filings. Litigants should be aware, however, of AI-use disclosure requirements in other jurisdictions.” The same document places the burden where it belongs — “pursuant to Fed. R. Civ. P. 11 and 26(g), you are ultimately responsible for the accuracy and sufficiency of the resulting work product” — and asks for something more demanding than most firms are doing: “Confirm that GenAI-provided legal research and citations are valid references to existing caselaw, statutes, or regulations that have not been superseded or overruled, and that cited excerpts are not taken out of context.” That is a citator pass, not an existence check. It is also an FAQ and not a standing order; its force comes from Rule 11, which it says out loud. And it does not displace any individual judge’s practice pointers, which still have to be read case by case.
Minnesota’s regulator has said nothing. I checked the Lawyers Professional Responsibility Board two ways myself: its published list of Board opinions runs 1 through 26 and none of them addresses artificial intelligence, and a site search for “artificial intelligence” returns “Sorry, but nothing matched your search terms.” So Minnesota lawyers are working from the general rules — 1.1, 1.4, 1.5, 1.6, 3.1, 3.3, 5.1, 5.3, 8.4 — and from persuasive out-of-state authority. That is a gap, and lawyers guessing about it should know they are guessing.
The contract is where this is decided
The other essays in this arc are about what you can prove regarding a model’s behavior and its provenance as a file. Both end in the same place: the risk is real, it is unallocated, and almost no vendor agreement allocates it. Here is the allocation, with the Minnesota hooks attached.
Per-decision explainability. You owe the consumer “the reason that the profiling resulted in the decision.” If your vendor will not produce per-decision explanations, you cannot comply — and § 325M.13(f) forecloses the obvious workaround: “In no event shall any contract relieve a controller or a processor from the liabilities imposed on a controller or processor by virtue of the controller’s or processor’s roles in the processing relationship under sections 325M.10 to 325M.21.” You cannot contract out of the liability. Contract in the capability: explanations on demand within an SLA shorter than 45 days, the input features actually used, a re-scoring facility for corrected data, and a real remedy if the vendor cannot deliver.
Assessment cooperation, which the statute already gives you. Section 325M.13(b)(2) obligates the processor to “provide information to the controller necessary to enable the controller to conduct and document any data privacy and protection assessments required by section 325M.18.” Quote that section in the negotiation. Then put it in the contract with a deadline, because a statutory duty owed to you with no contractual clock attached is a duty you will be litigating about in month eleven.
Training data and IP in the outputs. Here is the honest state of it: across every jurisdiction surveyed for this piece — Minnesota, Colorado, and the European Union — no statute gives a deployer an indemnity for third-party IP claims arising from a model’s outputs. That allocation is purely contractual, and vendors fight hardest over the distinction between indemnifying the model and indemnifying what the model produces. Draft for outputs, separately capped or uncapped, carved out of the general liability cap, with defense control and settlement consent allocated, and with a model-change notice covenant plus a right to suspend use.
Your own data, in four questions. Is client or customer data used to train, fine-tune, or improve the vendor’s models? What is retained, where, and for how long — remembering that § 325M.16, subd. 2(g), bars you from retaining personal data that is no longer relevant and reasonably necessary, and your vendor’s default retention is not a defense. What happens on termination, with a deletion certification and a deadline? And which sub-processors, in which countries, under what flow-down?
One thing you do not need to negotiate: § 325M.16, subd. 4, voids “[a]ny provision of a contract or agreement of any kind that purports to waive or limit in any way a consumer’s rights” under the Act. Terms-of-service boilerplate does not reach MCDPA rights, in either direction.
What the work actually consists of
Strip out the consulting vocabulary and an AI governance engagement in Minnesota is six documents, each anchored to a subdivision rather than to a framework.
A written applicability determination. One page per jurisdiction, with the citation and the trigger fact, because the triggers are not intuitively related to each other: Minnesota counts consumers (§ 325M.12, subd. 1(a)); the EU counts where the output is used (art. 2(1)(c)); Colorado, from 2027, will count doing business in the state plus one covered individual, with no size floor. Several of the regimes a Minnesota company is likely to touch have no revenue threshold at all. We are too small for this is not an answer until somebody has read the applicability sections.
A system inventory that catches the old models. Section 325M.16, subd. 2(c), already requires “the maintenance of an inventory of the data” as part of a controller’s security practices — that is a statutory inventory duty in force in Minnesota today, independent of anything AI-specific. Build it against § 325M.11(s)’s functional definition of profiling, so it catches the scoring spreadsheet and not just the thing procurement bought last year.
The § 325M.18 assessments, scoped once for the strictest applicable regime and reused under paragraph (g).
The profiling response protocol, with templates, the subd. 5 appeal process, and the 24-month retention rule built into the records system rather than into a policy document nobody opens.
The vendor contract terms described above, in the master agreement, before signature — which is the only point at which any of them are cheap.
A written AI use policy with a named human in it. Section 325M.18(a) requires the controller to document and maintain a description of its compliance policies and procedures, and that description must include, where applicable, “the name and contact information for the controller’s chief privacy officer or other individual with primary responsibility for directing the policies and procedures implemented to comply with the provisions of sections 325M.10 to 325M.21.” The statute contemplates a person, not a committee.
What a lawyer should refuse to sell is a certification that any of this makes the client compliant. It does not. It reduces risk, it creates a record, and it preserves defenses, and anyone promising more than that is selling something the statutes do not contain.
One adjacent item, because it comes up in every one of these conversations and gets answered wrong. Minnesota’s criminal deep fake statute, Minn. Stat. § 617.262, has no private right of action — it is a criminal statute and nothing else. The civil cause of action is a separate section, Minn. Stat. § 604.32, and it is considerably better than people expect: general and special damages, disgorgement of “any profit made from the dissemination,” “a civil penalty awarded to the plaintiff of an amount up to $100,000,” and attorney fees. That is a different subject with different facts, and I have written about the remedies side of it for a client-facing audience.
The strongest case against this essay
Here is the argument I would make against everything above, and it is not weak.
The MCDPA has no private right of action. Section 325M.20(d) forecloses it in terms, “including under section 8.31, subdivision 3a.” So the entire enforcement risk is concentrated in one office with a finite number of privacy attorneys and a large docket of everything else. The office’s own February 2026 account describes education letters, warning letters, and complaint intake — the posture of a regulator building a compliance culture, not one filing test cases. A business that reads the risk as low over the next twenty-four months is not being irrational.
There is more. The words “if feasible” in subd. 1(g) are doing real work, and nobody knows yet how much. The trade-secret provision in subd. 4(j) will be litigated, and a company with a genuinely proprietary model will have arguments. And no Minnesota decision construing this statute has surfaced, which cuts both ways — it also means the aggressive reading is untested.
I concede all of it, and the concession does not move me, for one reason. The $7,500 exposure is per violation, and the operative capability under subd. 1(g) — per-decision explanation, counterfactual, re-scoring on corrected data — cannot be assembled in the forty-five days after the first request arrives. It has to be negotiated into a vendor contract that may have three years left on it. The cost of being wrong about enforcement timing is not a fine; it is discovering in month eleven of a signed agreement that your vendor has no obligation to tell you why it said no to somebody.
What would prove me wrong
The Attorney General brings no MCDPA enforcement action in the next two years. If September 2028 arrives with no case filed under sections 325M.10 to 325M.21, the expired cure period changed less than this essay says it did, and I will have overweighted a statutory sunset against an office’s actual enforcement posture. Watch the litigation the office files, not the statute.
A court reads § 325M.18(f) narrowly and the privilege point collapses. The most likely path is a holding that a statutorily compelled compliance assessment is a business record made in the ordinary course, so no privilege attached and there was nothing for paragraph (f) to preserve. If that happens, the difference between counsel’s assessment and a consultant’s shrinks to the difference in quality of the analysis, which is a real difference and a much smaller one than I have claimed here.
Subdivision 1(g) turns out to mean less than it says. If “if feasible” is read to excuse the counterfactual whenever a model is complex, and “the reason that the profiling resulted in the decision” is satisfied by a generic description of the system’s logic, then Minnesota’s automated-decision right is a notice requirement wearing a heavier coat, and my claim that it is the strongest in the country is wrong.
Federal preemption arrives and moots the state layer. If Congress or a court preempts the automated-decision provisions of the state privacy statutes, the analysis above becomes historical. I am not predicting that and I would not advise a client to wait for it — advising a client to wait is advising a client to be out of compliance with an in-force statute on a bet nobody can handicap — but if it happens, I was building on sand.
I have stated my two interests above and they both point the same direction: I sell this work, and I am running for the office that enforces it. The statutes are linked below. Read them and decide whether I have described them accurately, which is the only question that matters here.
Sources
Every Minnesota statute below was retrieved by curl from the Office of the Revisor of Statutes with a browser user-agent and read as raw text, not through a summarizer. The Revisor currently publishes the 2025 edition; each MCDPA section carries the Revisor’s note that it was added by Laws 2024, chapter 121, article 5, and is effective July 31, 2025, except that postsecondary institutions regulated by the Office of Higher Education are not required to comply until July 31, 2029.
- Minn. Stat. § 325M.10 — the short-title provision, which makes sections 325M.10 to 325M.21 citable as the Minnesota Consumer Data Privacy Act. The MCDPA is that section range, not all of chapter 325M, which also contains an older internet-privacy block and the social-media provisions
- Minn. Stat. § 325M.11 — paragraph (s), the functional definition of “profiling”; paragraph (i), “Decisions that produce legal or similarly significant effects concerning the consumer”
- Minn. Stat. § 325M.12 — subd. 1(a)(1)–(2), the 100,000-consumer and 25%-revenue/25,000-consumer thresholds; subd. 2(a)(19), the SBA small-business exclusion
- Minn. Stat. § 325M.13 — paragraph (b)(1)–(2), processor duties to assist with § 325M.14 requests and to supply information for § 325M.18 assessments; paragraph (f), no contract relieves either party of its liabilities
- Minn. Stat. § 325M.14 — subd. 1(f) profiling opt-out; subd. 1(g), quoted in full, the right to question a profiling result, to the reason for it, to a counterfactual “if feasible,” to review the input data, and to re-evaluation on corrected data; subd. 2(d), the authorized-agent mechanism limited to paragraph (f); subd. 4(d)–(e) 45-day clocks and the extension rule; subd. 4(j) trade secret; subd. 5(a) and (d), mandatory appeal, written reasons, AG-complaint information, and 24-month record retention producible to the attorney general
- Minn. Stat. § 325M.16 — subd. 1(b), profiling disclosure and out-of-notice opt-out method; subd. 2(c), the data-inventory requirement; subd. 2(g), the retention prohibition; subd. 3(a), the anti-discrimination provision; subd. 4, waiver of consumer rights is void
- Minn. Stat. § 325M.17 — small businesses may not sell sensitive data without prior consent, and § 325M.20’s penalties apply to a violation
- Minn. Stat. § 325M.18 — paragraph (a), documented policies and a named responsible individual; paragraph (b)(5), quoted in part, mandatory assessments for profiling presenting a reasonably foreseeable risk of “unfair or deceptive treatment of, or disparate impact on, consumers”; paragraph (d), the weighing standard; paragraph (f), quoted in full, the civil-investigative-demand production duty, the nonpublic-data classification, and the non-waiver of attorney-client privilege and work product; paragraphs (g)–(h), reciprocity and consolidation
- Minn. Stat. § 325M.20 — paragraph (a), quoted in full, the warning-letter-and-30-day-cure requirement and its self-executing expiration on January 31, 2026; paragraph (b), civil action under § 8.31 and litigation expenses; paragraph (c), injunction and “a civil penalty of not more than $7,500 for each violation”; paragraph (d), no private right of action
- Minn. Stat. § 13.02 — subd. 9, the definition of “nonpublic data” incorporated by § 325M.18(f)
- Minn. Stat. § 604.32 — subd. 3, the civil remedies for nonconsensual dissemination of a deep fake: general and special damages, disgorgement of profit, “a civil penalty awarded to the plaintiff of an amount up to $100,000,” and fees. Minn. Stat. § 617.262 is the criminal counterpart and contains no civil cause of action
- Office of the Minnesota Attorney General, Minnesota Consumer Data Privacy Act takes full effect (Feb. 5, 2026) — the subheadline “AGO can now bring enforcement actions without providing 30-day notice”; “hundreds of education letters”; “more than 200 complaints regarding the MCDPA” in the first six months; “dozens of warning letters”; the office’s description of the notice period sunsetting January 31, 2026; and the consumer template forms at privacymn.com
- Regulation (EU) 2024/1689, consolidated text as amended through 27 July 2026 — article 2(1)(c), quoted verbatim, the third-country trigger where “the output produced by the AI system is used in the Union”; article 113 as replaced by Regulation (EU) 2026/1744 of 8 July 2026 (OJ L 1744, 24.7.2026), showing Annex III high-risk obligations applying from 2 December 2027, Annex I from 2 August 2028, and articles 102–110 from 27 July 2026, against a general application date of 2 August 2026; article 50, the transparency obligations in force since that general date
- U.S. District Court, District of Minnesota, GenAI FAQ (Oct. 1, 2025) — “The District of Minnesota does not currently require disclosure of AI use in court filings”; the Rule 11 and 26(g) responsibility statement; and the practice pointer to confirm that cited authority has “not been superseded or overruled.” Text extracted from the court’s own PDF; the extraction renders one glyph in place of the “f” in fi/fl ligatures and I restored it, changing nothing else
- ABA Standing Committee on Ethics and Professional Responsibility, Formal Opinion 512, Generative Artificial Intelligence Tools (July 29, 2024) — the boiler-plate engagement-letter holding under Rule 1.6 and the Rule 8.4(c) unintentional-misstatement holding. americanbar.org refuses automated clients; I read the ABA’s own PDF through an Internet Archive capture of that exact URL. ABA formal opinions are persuasive in Minnesota, not binding
- Lawyers Professional Responsibility Board, Board Opinions and the site search for artificial intelligence — Opinions 1 through 26, none addressing artificial intelligence; the search returns “Sorry, but nothing matched your search terms”
- Colorado General Assembly, SB 24-205, SB 25B-004, and SB 26-189 — the original February 1, 2026 duty date, the delay to June 30, 2026, and the May 14, 2026 repeal-and-reenactment of part 17 of article 1 of title 6 as an automated-decision-making-technology framework, effective January 1, 2027. Nothing from Colorado is quoted in this essay: the signed act’s PDF text layer has corrupted intra-word spacing, and I will not put a normalized extraction inside quotation marks. Colorado propositions here are stated in my own words and should be checked against the printed session law
- X.AI LLC v. Weiser, No. 1:26-cv-01515 (D. Colo.), filed April 9, 2026 — docket facts only. I have not read any order in that case and nothing here characterizes one
- Companion essays in this section: The Gap Between Intended and Proven, Executable Code You Are Calling a Model, The Layer That Does Not Relocate, What You Owe the Client You Automated, and The Discovery of Your Prompts. On the client-facing side: AI-Assisted Identity Theft: What the Data Shows and Minnesota Voice and Likeness Cloning Remedies
General information about Minnesota and European law for a professional audience, current as of September 5, 2026 — not legal advice, and reading it creates no attorney–client relationship. The stated falsifiers are the author’s, and no outcome is promised or implied. Two interests are disclosed in the text and bear repeating: this firm sells the services described, and the author is a candidate for Minnesota Attorney General in 2026. Nothing here predicts or proposes how that office would exercise its enforcement discretion. Minnesota state-court rules on artificial intelligence are outside this essay’s scope and are not addressed; the Minnesota Human Rights Act question raised by § 325M.18(b)(5)(i) is identified and expressly left open. No client information appears in this article. Questions about anything here: Send us a message or 612-470-6529.