🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-MN · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 15 sources retrieved model claude-sonnet-5 ·

United States – Minnesota

US-MN schema gdpri-v2 trajectory: not recordedhybrid regimeoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 44 claims · 15 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
44Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A comprehensive, currently in-force consumer privacy statute exists with a clearly identified enforcement authority and confirmed statutory citation (Minn. Stat. ch. 325M).

Primary frameworkMinnesota Consumer Data Privacy Act (MCDPA), Minn. Stat. ch. 325M (2024, effective July 31, 2025)
Traffic-light rationale — GreenA comprehensive, currently in-force consumer privacy statute exists with a clearly identified enforcement authority and confirmed statutory citation (Minn. Stat. ch. 325M).

Sub-modules (5)

Regulator And AuthorityGreen

The AGO is the sole enforcement authority for the MCDPA; the Act is not privately enforceable.

Claims (1):

  • The Minnesota Attorney General's Office is the exclusive enforcement authority for the MCDPA, and the Act is not privately enforceable.

Act And InstrumentsGreen

MCDPA signed May 19, 2024, codified at Minn. Stat. ch. 325M, effective July 31, 2025.

Claims (1):

  • The Minnesota Consumer Data Privacy Act was signed into law on May 19, 2024, codified at Minnesota Statutes chapter 325M, and took effect July 31, 2025.

Material ScopeGreen

Applicability thresholds are volume/revenue-based (100,000 MN residents, or 25%+ revenue from data sales plus 25,000 residents); small businesses per SBA definition are exempt.

Claims (2):

  • The MCDPA applies to entities that control or process the personal data of 100,000 or more Minnesota residents, or that derive over 25% of revenue from selling personal data and process or control personal data of 25,000 or more consumers.
  • Small businesses as defined by the U.S. Small Business Administration are exempt from the MCDPA, and there is no full exemption for HIPAA- or GLBA-covered entities, though targeted exemptions exist for health and financial data processing.

Territorial ScopeAmber

Coverage is triggered by processing volume tied to Minnesota residents rather than the controller's physical location, giving the statute extraterritorial reach over out-of-state online businesses.

Claims (1):

  • MCDPA applicability is triggered by the volume of Minnesota residents' personal data controlled or processed rather than the controller's physical presence in Minnesota, giving the statute extraterritorial reach.

Regulator Registration And FilingAmber

No controller/processor registration or pre-processing filing obligation with the AGO was identified in AGO guidance materials reviewed.

Absence provenance: not recorded. Searched: ag.state.mn.us/Data-Privacy/, ag.state.mn.us/Data-Privacy/Business/Controller/, ag.state.mn.us/Data-Privacy/Business/Processor/.

Claims (1):

  • No provision requiring controllers to register with or file notices to the Minnesota AGO prior to processing personal data was identified in reviewed AGO guidance.
Category narrative83 words

Minnesota's data-protection landscape is anchored by the Minnesota Consumer Data Privacy Act (MCDPA), codified at Minnesota Statutes chapter 325M, which took effect July 31, 2025 and is enforced exclusively by the Minnesota Attorney General's Office (AGO). The statute applies to controllers/processors meeting Minnesota-resident-volume or data-sale-revenue thresholds, without a physical-presence nexus, and layers atop pre-existing sectoral and government-data statutes (e.g., the Minnesota Government Data Practices Act, Minn. Stat. ch. 13, which governs government-held data only and is out of scope for consumer-sector MCDPA obligations).

Sources and claims (6)
  1. ConfirmedMinnesota Attorney General's OfficeThe Minnesota Attorney General's Office is the exclusive enforcement authority for the MCDPA, and the Act is not privately enforceable.observed
  2. ConfirmedMinnesota Attorney General's OfficeThe Minnesota Consumer Data Privacy Act was signed into law on May 19, 2024, codified at Minnesota Statutes chapter 325M, and took effect July 31, 2025.observed
  3. ConfirmedMinnesota Attorney General's OfficeThe MCDPA applies to entities that control or process the personal data of 100,000 or more Minnesota residents, or that derive over 25% of revenue from selling personal data and process or control personal data of 25,000 or more consumers.observed
  4. ProbableInternational Association of Privacy ProfessionalsSmall businesses as defined by the U.S. Small Business Administration are exempt from the MCDPA, and there is no full exemption for HIPAA- or GLBA-covered entities, though targeted exemptions exist for health and financial data processing.observed
  5. ProbableMinnesota Attorney General's OfficeMCDPA applicability is triggered by the volume of Minnesota residents' personal data controlled or processed rather than the controller's physical presence in Minnesota, giving the statute extraterritorial reach.observed
  6. UncertainMinnesota Attorney General's OfficeNo provision requiring controllers to register with or file notices to the Minnesota AGO prior to processing personal data was identified in reviewed AGO guidance.observed

#

Strong sensitive-data consent gate exists, but there is no GDPR Art.6-style enumerated lawful-basis framework, and pseudonymisation/anonymisation safe-harbour detail beyond the de-identified-data carve-out was not independently verified against statutory text.

Primary frameworkMinnesota Consumer Data Privacy Act, Minn. Stat. ch. 325M
Traffic-light rationale — AmberStrong sensitive-data consent gate exists, but there is no GDPR Art.6-style enumerated lawful-basis framework, and pseudonymisation/anonymisation safe-harbour detail beyond the de-identified-data carve-out was not independently verified against statutory text.

Sub-modules (4)

Lawful BasesAmber

Processing is governed by collection-limitation/purpose-limitation duties rather than an enumerated lawful-basis list.

Claims (1):

  • The MCDPA's operative model relies on consent plus collection/purpose-limitation duties (limiting collection to what is necessary and disclosed) rather than an enumerated multi-basis lawful-processing framework analogous to GDPR Article 6.

Special CategoriesGreen

Sensitive data is defined broadly, including genetic and biometric data, health, and immigration status.

Claims (1):

  • MCDPA sensitive data includes race, ethnicity, religion, mental or physical health condition, sexual orientation, and precise geolocation, as well as genetic and biometric data, subject to enhanced consent requirements.

Pseudonymisation And AnonymisationAmber

De-identified data that cannot be linked to individuals, and publicly available data, fall outside the Act's collection/consent restrictions.

Claims (1):

  • The MCDPA does not restrict processing of de-identified data, defined as data that cannot be linked to individual consumers, nor data that is publicly available.
Category narrative60 words

The MCDPA does not adopt a GDPR-style enumerated multi-basis lawful-processing model; instead it relies on collection/purpose-limitation duties plus consent gates for sensitive data. Sensitive data is broadly defined (race, ethnicity, religion, health, sexuality, precise location, genetic and biometric data, citizenship/immigration status) and requires affirmative consumer consent before collection or sale. De-identified and publicly available data fall outside the Act's restrictions.

Sources and claims (4)
  1. ProbableMinnesota Attorney General's OfficeThe MCDPA's operative model relies on consent plus collection/purpose-limitation duties (limiting collection to what is necessary and disclosed) rather than an enumerated multi-basis lawful-processing framework analogous to GDPR Article 6.observed
  2. ConfirmedMinnesota Attorney General's OfficeControllers must obtain a consumer's affirmative consent before collecting or processing sensitive data, including specific location data or data revealing mental or physical health conditions or citizenship/immigration status.observed
  3. ConfirmedMinnesota Attorney General's OfficeMCDPA sensitive data includes race, ethnicity, religion, mental or physical health condition, sexual orientation, and precise geolocation, as well as genetic and biometric data, subject to enhanced consent requirements.observed
  4. ConfirmedMinnesota Attorney General's OfficeThe MCDPA does not restrict processing of de-identified data, defined as data that cannot be linked to individual consumers, nor data that is publicly available.observed

#

Rights are clearly enumerated by the regulator with a defined statutory response deadline (45 days) and complaint escalation path.

Primary frameworkMinnesota Consumer Data Privacy Act, Minn. Stat. ch. 325M, §325M.14
Traffic-light rationale — GreenRights are clearly enumerated by the regulator with a defined statutory response deadline (45 days) and complaint escalation path.

Sub-modules (5)

Access RightGreen

Consumers may access data held about them and obtain a list of specific third parties their data was sold to.

Claims (1):

  • Minnesota consumers have rights to know what data a company holds about them and to obtain a list of specific third parties to which their data has been sold.

Rectification And ErasureGreen

Consumers may correct inaccurate data and request deletion of personal/sensitive data.

Claims (1):

  • Consumers have the right to request correction of inaccurate data and deletion of their personal and sensitive data held by a business.

Restriction And ObjectionGreen

Consumers may opt out of sale, targeted advertising, and profiling, including profiling feeding automated decisions.

Claims (1):

  • Consumers may opt out of the sale of their personal data, use of their data for targeted advertising, and profiling, including profiling used in automated decision-making.

Data PortabilityGreen

The rights package includes a right to obtain a copy of one's data, per the AGO's own rights summary.

Claims (1):

  • The Act's consumer rights structure includes a right to obtain a copy of one's data in addition to rights to a third-party disclosure list, opt-out, access, correction, and deletion.

Deadlines And Response WindowsGreen

Businesses must respond to rights requests within 45 days; non-response triggers an AGO complaint pathway.

Claims (1):

  • Businesses must respond to consumer rights requests within 45 days, and consumers may file a complaint with the Attorney General's Office if a business fails to respond within that window.
Category narrative70 words

The MCDPA grants Minnesota consumers a materially complete rights package summarized by the AGO as 'LOCKED+': a list of third parties data was sold to, opt-out of sale/targeted-advertising/profiling, a copy of data held, knowledge of what is held, edit/correction rights, deletion rights, plus the right to question profiling and automated decisions. Businesses must respond to rights requests within 45 days, with a consumer complaint route to the AGO for non-response.

Sources and claims (5)
  1. ConfirmedMinnesota Attorney General's OfficeMinnesota consumers have rights to know what data a company holds about them and to obtain a list of specific third parties to which their data has been sold.observed
  2. ConfirmedMinnesota Attorney General's OfficeConsumers have the right to request correction of inaccurate data and deletion of their personal and sensitive data held by a business.observed
  3. ConfirmedMinnesota Attorney General's OfficeConsumers may opt out of the sale of their personal data, use of their data for targeted advertising, and profiling, including profiling used in automated decision-making.observed
  4. ProbableInternational Association of Privacy ProfessionalsThe Act's consumer rights structure includes a right to obtain a copy of one's data in addition to rights to a third-party disclosure list, opt-out, access, correction, and deletion.observed
  5. ConfirmedMinnesota Attorney General's OfficeBusinesses must respond to consumer rights requests within 45 days, and consumers may file a complaint with the Attorney General's Office if a business fails to respond within that window.observed

#

Core accountability, assessment, processor-contract, and breach-notification duties are well evidenced from AGO guidance; DPO/ROPA specifics rely on pre-enactment secondary analysis and were not independently verified against final statute text.

Primary frameworkMinnesota Consumer Data Privacy Act, Minn. Stat. ch. 325M, §325M.13
Traffic-light rationale — AmberCore accountability, assessment, processor-contract, and breach-notification duties are well evidenced from AGO guidance; DPO/ROPA specifics rely on pre-enactment secondary analysis and were not independently verified against final statute text.

Sub-modules (7)

Accountability And DpiaGreen

Businesses must conduct data protection assessments and maintain data security practices.

Claims (1):

  • Businesses subject to the MCDPA must conduct data protection/privacy assessments and maintain data security practices to protect personal data.

Dpo RequirementsAmber

Pre-enactment IAPP analysis suggested an implied obligation to name a chief privacy officer or equivalent contact; not independently confirmed against final AGO guidance.

Absence provenance: not recorded. Searched: ag.state.mn.us/Data-Privacy/Business/Controller/.

Claims (1):

  • Pre-enactment IAPP commentary on the MCDPA bill identified an implied obligation for covered entities to name a chief privacy officer or other individual with primary responsibility for privacy policies and procedures.

Ropa RequirementsAmber

No standalone records-of-processing obligation distinct from the data protection assessment duty was identified.

Absence provenance: not recorded. Searched: ag.state.mn.us/Data-Privacy/Business/Controller/, ag.state.mn.us/Data-Privacy/Business/Processor/.

Joint Controller ArrangementsGreen

Processor contracts must allocate responsibilities and support controller compliance and assessment obligations.

Claims (1):

  • Processor contracts under the MCDPA must require processors to assist controllers with security of processing, breach notifications, and data protection assessments, and must clearly allocate responsibilities between controller and processor.

Security MeasuresGreen

Processors must implement technical/organizational measures appropriate to processing risk.

Claims (1):

  • Processors must implement appropriate technical and organizational measures to ensure security appropriate to the risk of processing, and allow controller-directed assessments and inspections.

Breach NotificationAmber

Processors must notify controllers of security breaches; Minnesota's general breach-notification statute (Minn. Stat. §325E.61) independently requires notice to affected residents, though full statutory text was not retrieved in this pass.

Claims (2):

  • Processors must provide notification to controllers upon a breach of the security of systems used to protect personal data, as part of MCDPA processor obligations.
  • Minnesota maintains a separate general data-breach-notification statute (Minn. Stat. §325E.61 et seq.) applicable to entities holding Minnesotans' personal information, distinct from MCDPA processor-to-controller notice duties.

Retention And DisposalGreen

Businesses may not retain data beyond what is relevant and reasonably necessary for the disclosed purpose.

Claims (1):

  • Businesses may not retain personal data longer than is relevant and reasonably necessary for the disclosed purpose.
Category narrative64 words

Controllers must run data protection/privacy assessments, limit collection and retention to disclosed necessary purposes, and maintain risk-appropriate security. Processor contracts must impose breach-notification assistance, security cooperation, assessment-support, and audit/inspection rights, with a clear allocation of responsibilities. Evidence of a formal, freestanding ROPA obligation or an independent statutory DPO/chief-privacy-officer mandate (as opposed to a named privacy contact) was not conclusively confirmed against enacted statutory text.

Sources and claims (7)
  1. ConfirmedMinnesota Attorney General's OfficeBusinesses subject to the MCDPA must conduct data protection/privacy assessments and maintain data security practices to protect personal data.observed
  2. UncertainInternational Association of Privacy ProfessionalsPre-enactment IAPP commentary on the MCDPA bill identified an implied obligation for covered entities to name a chief privacy officer or other individual with primary responsibility for privacy policies and procedures.observed
  3. ConfirmedMinnesota Attorney General's OfficeProcessor contracts under the MCDPA must require processors to assist controllers with security of processing, breach notifications, and data protection assessments, and must clearly allocate responsibilities between controller and processor.observed
  4. ConfirmedMinnesota Attorney General's OfficeProcessors must implement appropriate technical and organizational measures to ensure security appropriate to the risk of processing, and allow controller-directed assessments and inspections.observed
  5. ConfirmedMinnesota Attorney General's OfficeProcessors must provide notification to controllers upon a breach of the security of systems used to protect personal data, as part of MCDPA processor obligations.observed
  6. UncertainOneTrust DataGuidanceMinnesota maintains a separate general data-breach-notification statute (Minn. Stat. §325E.61 et seq.) applicable to entities holding Minnesotans' personal information, distinct from MCDPA processor-to-controller notice duties.observed
  7. ConfirmedMinnesota Attorney General's OfficeBusinesses may not retain personal data longer than is relevant and reasonably necessary for the disclosed purpose.observed

#

This module is structurally inapplicable to a US state consumer-privacy statute; explicit absence confirmed via AGO guidance review rather than an unexamined gap.

Primary frameworkMinnesota Consumer Data Privacy Act, Minn. Stat. ch. 325M
Traffic-light rationale — RedThis module is structurally inapplicable to a US state consumer-privacy statute; explicit absence confirmed via AGO guidance review rather than an unexamined gap.

Sub-modules (6)

Transfer MechanismsRed

No transfer-mechanism regime beyond controller-processor contracts identified.

Claims (1):

  • The MCDPA does not establish an EU-style cross-border transfer regime; it imposes controller-processor contractual requirements and consumer rights but contains no identified adequacy determination, SCC/BCR mechanism, transfer impact assessment requirement, or data-localization mandate.

Adequacy ReceivedRed

Not applicable; no adequacy concept in MCDPA.

Absence provenance: not recorded. Searched: ag.state.mn.us/Data-Privacy/.

Adequacy GrantedRed

Not applicable; no adequacy concept in MCDPA.

Absence provenance: not recorded. Searched: ag.state.mn.us/Data-Privacy/.

Sccs And BcrsRed

No SCC/BCR uptake mechanism identified; not part of MCDPA structure.

Absence provenance: not recorded. Searched: ag.state.mn.us/Data-Privacy/Business/Contracts/.

Transfer Impact AssessmentRed

No TIA requirement identified.

Absence provenance: not recorded. Searched: ag.state.mn.us/Data-Privacy/Business/Controller/.

Data LocalisationRed

No data-localisation mandate identified.

Absence provenance: not recorded. Searched: ag.state.mn.us/Data-Privacy/.

Category narrative48 words

As a US state consumer-privacy statute, the MCDPA does not include an EU/GDPR-style cross-border transfer regime. No adequacy-determination mechanism (received or granted), standard contractual clauses/BCR framework, transfer impact assessment requirement, or data-localisation mandate was identified in AGO guidance; the statute's only cross-entity control is the controller-processor contract requirement.

Sources and claims (1)
  1. ProbableMinnesota Attorney General's OfficeThe MCDPA does not establish an EU-style cross-border transfer regime; it imposes controller-processor contractual requirements and consumer rights but contains no identified adequacy determination, SCC/BCR mechanism, transfer impact assessment requirement, or data-localization mandate.observed

#

Financial, health, and education overlays are evidenced; several other sectors carry unresolved gaps requiring primary-source verification.

Primary frameworkMinnesota Consumer Data Privacy Act, Minn. Stat. ch. 325M (sectoral overlay with HIPAA, GLBA, COPPA)
Traffic-light rationale — AmberFinancial, health, and education overlays are evidenced; several other sectors carry unresolved gaps requiring primary-source verification.

Sub-modules (7)

Financial Sector OverlayAmber

Targeted exemption for GLBA-covered financial data processing; no full entity-level exemption.

Claims (1):

  • The MCDPA provides no full exemption for GLBA-covered financial institutions but includes targeted exemptions for financial data processing.

Health Sector OverlayAmber

Targeted exemption for HIPAA-covered health data processing; no full entity-level exemption; historical multistate health-breach enforcement precedent exists (Inmediata, 2023, pre-MCDPA).

Claims (2):

  • The MCDPA provides no full exemption for HIPAA-covered entities but includes targeted exemptions for health data processing.
  • In 2023, the Minnesota Attorney General joined a 32-state settlement with health-data clearinghouse Inmediata over a multi-year breach of protected health information affecting approximately 113,000 Minnesota residents, predating MCDPA but illustrating active health-data enforcement posture.

Telecoms And EprivacyRed

No MCDPA-specific ePrivacy/telecoms overlay identified.

Absence provenance: not recorded. Searched: ag.state.mn.us MCDPA business guidance pages.

Employment DataRed

Employment/B2B data exclusion status under MCDPA was not confirmed via retrieved sources.

Absence provenance: not recorded. Searched: ag.state.mn.us MCDPA business/controller guidance.

Credit And ScoringRed

FCRA-adjacent credit-scoring exemption status not confirmed.

Absence provenance: not recorded. Searched: ag.state.mn.us MCDPA guidance.

EducationAmber

Certain education technology providers are subject to MCDPA irrespective of general thresholds.

Claims (1):

  • Certain education technology providers are subject to the MCDPA regardless of the general consumer-volume thresholds applicable to other controllers.

InsuranceRed

No insurance-sector-specific overlay identified.

Absence provenance: not recorded. Searched: ag.state.mn.us MCDPA guidance.

Category narrative56 words

The MCDPA does not fully exempt GLBA-covered financial institutions or HIPAA-covered health entities, instead layering targeted (data-level) exemptions on top of those federal regimes. Certain education-technology providers are subject to the MCDPA regardless of the general volume thresholds. Telecoms/ePrivacy, employment-data, credit/scoring, and insurance-specific overlays were not confirmed via retrievable AGO or T1/T2 sources in this pass.

Sources and claims (4)
  1. ProbableInternational Association of Privacy ProfessionalsThe MCDPA provides no full exemption for GLBA-covered financial institutions but includes targeted exemptions for financial data processing.observed
  2. ProbableInternational Association of Privacy ProfessionalsThe MCDPA provides no full exemption for HIPAA-covered entities but includes targeted exemptions for health data processing.observed
  3. ConfirmedMinnesota Attorney General's OfficeIn 2023, the Minnesota Attorney General joined a 32-state settlement with health-data clearinghouse Inmediata over a multi-year breach of protected health information affecting approximately 113,000 Minnesota residents, predating MCDPA but illustrating active health-data enforcement posture.observed
  4. ProbableMinnesota Attorney General's OfficeCertain education technology providers are subject to the MCDPA regardless of the general consumer-volume thresholds applicable to other controllers.observed

#

Universal opt-out and targeted-advertising opt-out are strongly evidenced; dark patterns and clean-room provisions remain unconfirmed gaps.

Primary frameworkMinnesota Consumer Data Privacy Act, Minn. Stat. ch. 325M
Traffic-light rationale — AmberUniversal opt-out and targeted-advertising opt-out are strongly evidenced; dark patterns and clean-room provisions remain unconfirmed gaps.

Sub-modules (6)

Cookies And TrackersGreen

Universal opt-out mechanisms operate via browser-level signals affecting tracking/targeted-ad collection.

Claims (1):

  • The MCDPA requires businesses to honor universal opt-out mechanisms (browser-based signals) that communicate a consumer's opt-out of targeted advertising and data collection/sale across websites.

Dark PatternsRed

No MCDPA-specific dark-pattern prohibition confirmed via retrieved sources.

Absence provenance: not recorded. Searched: ag.state.mn.us MCDPA consumer/business pages.

Opt Out SignalsGreen

Businesses must honor universal opt-out preference signals.

Claims (1):

  • The MCDPA requires businesses to honor universal opt-out mechanisms (browser-based signals) that communicate a consumer's opt-out of targeted advertising and data collection/sale across websites.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rule identified.

Absence provenance: not recorded. Searched: ag.state.mn.us MCDPA business guidance.

Cross Context AdvertisingGreen

Consumers may opt out of sale and targeted advertising use of their personal data.

Claims (1):

  • Consumers have the right to opt out of the sale of personal data and its use for targeted advertising.

Direct MarketingAmber

Direct-marketing-specific suppression rules beyond the general targeted-advertising opt-out were not separately confirmed.

Claims (1):

  • Consumers have the right to opt out of the sale of personal data and its use for targeted advertising.
Category narrative39 words

The MCDPA mandates honoring browser-based universal opt-out mechanisms (GPC-style signals) for targeted advertising and data-sale opt-out, and grants a direct consumer opt-out right for sale/targeted-advertising/profiling. Dark-pattern-specific prohibitions and clean-room/data-collaboration-room rules were not confirmed via retrieved AGO or T1/T2 sources.

Sources and claims (2)
  1. ConfirmedMinnesota Attorney General's OfficeThe MCDPA requires businesses to honor universal opt-out mechanisms (browser-based signals) that communicate a consumer's opt-out of targeted advertising and data collection/sale across websites.observed
  2. ConfirmedMinnesota Attorney General's OfficeConsumers have the right to opt out of the sale of personal data and its use for targeted advertising.observed

#

Profiling/ADM rights are strongly evidenced and materially significant; biometric/genetic standalone-regime status and state-surveillance carve-outs remain unresolved gaps.

Primary frameworkMinnesota Consumer Data Privacy Act, Minn. Stat. ch. 325M, §325M.14
Traffic-light rationale — AmberProfiling/ADM rights are strongly evidenced and materially significant; biometric/genetic standalone-regime status and state-surveillance carve-outs remain unresolved gaps.

Sub-modules (6)

Profiling RestrictionsGreen

Consumers may opt out of profiling in furtherance of decisions with legal or similarly significant effects.

Claims (1):

  • Minnesota's Attorney General has characterized the MCDPA as providing some of the nation's strongest protections against harmful data profiling and automated decision-making, including a consumer right to opt out of profiling used in furtherance of significant decisions.

Automated Decision Making TransparencyGreen

Consumers may request the reasoning and underlying data behind a profiling/automated decision, including AI-facilitated decisions.

Claims (1):

  • Consumers may request information regarding a profiling or automated decision made about them, including the reasoning behind the decision and the data used to reach it, and may question automated decisions facilitated by artificial intelligence.

Ai Risk AssessmentsAmber

The Act creates rights intended to prevent AI/automated systems from depriving residents of critical goods and services.

Claims (1):

  • The MCDPA creates rights intended to ensure that AI and automated systems cannot deprive Minnesota residents of critical goods and services.

Biometric RegimeAmber

Biometric data is a sensitive-data category requiring consent; a standalone biometric-specific statute status is unconfirmed.

Absence provenance: not recorded. Searched: dataguidance.com Minnesota biometric bill pages (no retrievable content).

Claims (1):

  • Biometric data is classified as sensitive data under the MCDPA and subject to consent requirements before collection; no standalone biometric-specific statute comparable to Illinois' BIPA has been confirmed as currently enacted in Minnesota.

Genetic DataAmber

Genetic data is a sensitive-data category requiring consent; separate government-data-practices genetic provisions (Minn. Stat. §13.386) exist but full text was not retrieved.

Absence provenance: not recorded. Searched: dataguidance.com Minnesota Statutes section 13.386 page (no retrievable content).

Claims (1):

  • Genetic data is classified as sensitive data under the MCDPA requiring consumer consent before collection; Minnesota separately maintains government-data-practices provisions addressing genetic information (Minn. Stat. §13.386), though current text of that provision was not independently retrieved.

State Surveillance CarveoutsRed

No MCDPA government/law-enforcement exemption language was confirmed via retrieved sources.

Absence provenance: not recorded. Searched: ag.state.mn.us MCDPA business/controller guidance.

Category narrative86 words

The AGO has characterized the MCDPA as one of the nation's strongest statutes against harmful profiling and automated decision-making, granting consumers a right to question and obtain the reasoning/data behind profiling decisions and to opt out of profiling in furtherance of legally or similarly significant decisions, including AI-facilitated decisions. Genetic and biometric data are classified as sensitive data requiring consent, but standalone biometric- or genetic-specific statutes (comparable to Illinois' BIPA) and government/law-enforcement surveillance carve-outs were not independently confirmed as currently enacted MCDPA provisions in this pass.

Sources and claims (5)
  1. ConfirmedMinnesota Attorney General's OfficeMinnesota's Attorney General has characterized the MCDPA as providing some of the nation's strongest protections against harmful data profiling and automated decision-making, including a consumer right to opt out of profiling used in furtherance of significant decisions.observed
  2. ConfirmedMinnesota Attorney General's OfficeConsumers may request information regarding a profiling or automated decision made about them, including the reasoning behind the decision and the data used to reach it, and may question automated decisions facilitated by artificial intelligence.observed
  3. ProbableMinnesota Attorney General's OfficeThe MCDPA creates rights intended to ensure that AI and automated systems cannot deprive Minnesota residents of critical goods and services.observed
  4. UncertainMinnesota Attorney General's OfficeBiometric data is classified as sensitive data under the MCDPA and subject to consent requirements before collection; no standalone biometric-specific statute comparable to Illinois' BIPA has been confirmed as currently enacted in Minnesota.observed
  5. UncertainMinnesota Attorney General's OfficeGenetic data is classified as sensitive data under the MCDPA requiring consumer consent before collection; Minnesota separately maintains government-data-practices provisions addressing genetic information (Minn. Stat. §13.386), though current text of that provision was not independently retrieved.observed

#

Children's-data provisions are clearly documented by the regulator with specific age thresholds and guardianship extension.

Primary frameworkMinnesota Consumer Data Privacy Act, Minn. Stat. ch. 325M (with COPPA, 15 U.S.C. §§6501-6506, cross-reference)
Traffic-light rationale — GreenChildren's-data provisions are clearly documented by the regulator with specific age thresholds and guardianship extension.

Sub-modules (5)

Age VerificationAmber

No standalone age-verification mandate identified beyond 'known child'/'known consumer age 13-16' actual-knowledge standards.

Claims (1):

  • Controllers may not process a consumer's personal data for targeted advertising or sell that consumer's personal data without the consumer's consent where the controller knows the consumer is between 13 and 16 years of age.

Minor Profiling BansAmber

Consent (rather than an outright ban) is required for targeted advertising/sale involving consumers known to be 13-16.

Claims (1):

  • Controllers may not process a consumer's personal data for targeted advertising or sell that consumer's personal data without the consumer's consent where the controller knows the consumer is between 13 and 16 years of age.

Education SettingsAmber

Certain education technology providers are covered by the MCDPA regardless of general applicability thresholds.

Claims (1):

  • Certain education technology providers are subject to the MCDPA regardless of the general applicability thresholds, extending coverage into student-data contexts.

Dependent AdultsGreen

Consumers may exercise MCDPA rights on behalf of persons under their guardianship or conservatorship.

Claims (1):

  • The MCDPA allows consumers to exercise their statutory rights on behalf of their children or any person over whom the consumer has guardianship or conservatorship.
Category narrative65 words

The MCDPA requires parental/guardian consent before processing a 'known child's' personal data (with limited exceptions) and COPPA compliance, plus an opt-in consent requirement for targeted advertising or sale of data for consumers known to be 13-16 years old. Certain education technology providers are covered regardless of general thresholds, and the Act permits consumers to exercise rights on behalf of children or persons under their guardianship/conservatorship.

Sources and claims (4)
  1. ConfirmedMinnesota Attorney General's OfficeControllers may not process a consumer's personal data for targeted advertising or sell that consumer's personal data without the consumer's consent where the controller knows the consumer is between 13 and 16 years of age.observed
  2. ConfirmedMinnesota Attorney General's OfficeControllers may not process the personal data concerning a known child without obtaining consent from the child's parent or lawful guardian (with limited exceptions), and must comply with COPPA.observed
  3. ProbableMinnesota Attorney General's OfficeCertain education technology providers are subject to the MCDPA regardless of the general applicability thresholds, extending coverage into student-data contexts.observed
  4. ConfirmedMinnesota Attorney General's OfficeThe MCDPA allows consumers to exercise their statutory rights on behalf of their children or any person over whom the consumer has guardianship or conservatorship.observed

#

Enforcement powers, penalties, and activity are well documented and robust, but the absence of a private right of action and expiration of the cure period both materially shift risk allocation, and no collective-redress mechanism exists.

Primary frameworkMinnesota Consumer Data Privacy Act, Minn. Stat. ch. 325M
Traffic-light rationale — AmberEnforcement powers, penalties, and activity are well documented and robust, but the absence of a private right of action and expiration of the cure period both materially shift risk allocation, and no collective-redress mechanism exists.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

AGO may seek injunctive relief, litigation costs, and civil penalties up to $7,500/violation.

Claims (1):

  • The Minnesota Attorney General may seek injunctive relief, litigation expenses, and civil penalties of up to $7,500 per violation against MCDPA violators.

Enforcement Activity IndexAmber

Hundreds of education letters and dozens of warning letters sent since July 2025; cure period sunset January 31, 2026.

Claims (1):

  • Since the MCDPA took effect, the Attorney General's Office sent hundreds of education letters and dozens of formal warning letters to companies regarding privacy policy, consent, and universal opt-out compliance issues, and the Act's mandatory pre-enforcement cure/notice period expired on January 31, 2026.

Regulator Funding And CapacityGreen

MCDPA funded four new AGO attorneys plus an investigator dedicated to enforcement.

Claims (1):

  • The MCDPA included funding for the Attorney General's Office to hire four new attorneys and an investigator focused primarily on enforcing the Act, placing Minnesota among the most heavily resourced state privacy enforcers per independent industry analysis.

Collective Redress And Class ActionsRed

No collective-redress/class-action mechanism specific to MCDPA identified; enforcement is AGO-exclusive.

Claims (1):

  • No collective-redress or class-action mechanism specific to MCDPA enforcement has been identified; enforcement is vested exclusively in the Attorney General.

Private Right Of ActionRed

The MCDPA contains no private right of action.

Claims (1):

  • The MCDPA contains no private right of action; only the Attorney General may enforce the Act.

Recent Developments 180DAmber

June 2026: Minnesota joined an 18-attorney-general coalition opposing the federal SECURE Data Act on preemption grounds.

Claims (1):

  • In June 2026, Minnesota joined a coalition of 18 attorneys general and agencies opposing the proposed federal SECURE Data Act, with the Minnesota AGO stating the bill would preempt and weaken protections under the state's Consumer Data Privacy Act.
Category narrative112 words

The AGO holds exclusive investigative and enforcement authority, able to seek injunctive relief, litigation expenses, and civil penalties up to $7,500 per violation; the Act carries no private right of action or identified class-action mechanism. A mandatory 30-day cure/notice period sunset on January 31, 2026, after which the AGO may bring enforcement actions without prior warning. The office was funded to add four attorneys and an investigator, and has sent hundreds of education letters and dozens of formal warning letters since the Act took effect. Within the last 180 days, Minnesota joined an 18-state coalition opposing the proposed federal SECURE Data Act, which the AGO says would preempt and weaken MCDPA protections.

Sources and claims (6)
  1. ConfirmedMinnesota Attorney General's OfficeThe Minnesota Attorney General may seek injunctive relief, litigation expenses, and civil penalties of up to $7,500 per violation against MCDPA violators.observed
  2. ConfirmedMinnesota Attorney General's OfficeSince the MCDPA took effect, the Attorney General's Office sent hundreds of education letters and dozens of formal warning letters to companies regarding privacy policy, consent, and universal opt-out compliance issues, and the Act's mandatory pre-enforcement cure/notice period expired on January 31, 2026.observed
  3. ProbableMinnesota Attorney General's OfficeThe MCDPA included funding for the Attorney General's Office to hire four new attorneys and an investigator focused primarily on enforcing the Act, placing Minnesota among the most heavily resourced state privacy enforcers per independent industry analysis.observed
  4. ProbableMinnesota Attorney General's OfficeNo collective-redress or class-action mechanism specific to MCDPA enforcement has been identified; enforcement is vested exclusively in the Attorney General.observed
  5. ConfirmedMinnesota Attorney General's OfficeThe MCDPA contains no private right of action; only the Attorney General may enforce the Act.observed
  6. ConfirmedMinnesota Attorney General's OfficeIn June 2026, Minnesota joined a coalition of 18 attorneys general and agencies opposing the proposed federal SECURE Data Act, with the Minnesota AGO stating the bill would preempt and weaken protections under the state's Consumer Data Privacy Act.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Minnesota
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 44 claim(s), 15 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacydata localisation
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redresscollective redress and class actions
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, data_subject_rights, children_and_vulnerable_groups, and enforcement_and_redress rest primarily on T1 Minnesota AGO primary-source pages (ag.state.mn.us/Data-Privacy and Office/Communications releases), giving high confidence. lawful_processing_and_special_data, controller_processor_duties, sectoral_watch, adtech_and_commercial_privacy, and algorithmic_biometric_and_surveillance_governance mix T1 AGO guidance with T2 IAPP bill-stage analysis (some pre-enactment) for granular items (DPO/chief-privacy-officer implication, GLBA/HIPAA targeted-exemption scope), which were not independently re-verified against final statutory text of Minn. Stat. ch. 325M. cross_border_and_adequacy is a confirmed structural gap (state consumer-privacy statutes lack an EU-style transfer regime) rather than an unresearched module. Several sectoral_watch sub-modules (telecoms/eprivacy, employment_data, credit_and_scoring, insurance) and adtech sub-modules (dark_patterns, clean_rooms_and_dcr) and algorithmic sub-modules (biometric_regime, genetic_data, state_surveillance_carveouts) carry explicit absent_field_provenance because no retrievable T1/T2 source confirmed content in this pass; several DataGuidance (T4) pages returned only paywalled stubs with no substantive content and were excluded from claim support.

Unresolved questions (5):

  • Is there an explicit statutory 'chief privacy officer' or DPO-equivalent designation requirement in the enacted Minn. Stat. ch. 325M text, or does the privacy-notice contact-person requirement suffice as the sole equivalent?
  • What is the current enactment/introduction status of standalone Minnesota biometric-privacy and genetic-information-privacy bills referenced in legislative tracking sources, and do they materially supplement the MCDPA's sensitive-data consent gate?
  • Does the MCDPA's 'controller' definition exclude employment/B2B personal data, consistent with most peer state comprehensive privacy statutes, and if so under what specific statutory carve-out?
  • What are the precise notice timelines and thresholds under Minnesota's general breach-notification statute (Minn. Stat. §325E.61 et seq.), which is structurally distinct from MCDPA processor-to-controller breach-notice duties?
  • Are there MCDPA-specific dark-pattern prohibitions, clean-room/data-collaboration-room provisions, or government/law-enforcement exemption carve-outs in the enacted statutory text beyond what AGO consumer-facing guidance summarizes?

Escalate to primary-source review: yes