A comprehensive, currently in-force consumer privacy statute exists with a clearly identified enforcement authority and confirmed statutory citation (Minn. Stat. ch. 325M).
Primary frameworkMinnesota Consumer Data Privacy Act (MCDPA), Minn. Stat. ch. 325M (2024, effective July 31, 2025)
Traffic-light rationale — GreenA comprehensive, currently in-force consumer privacy statute exists with a clearly identified enforcement authority and confirmed statutory citation (Minn. Stat. ch. 325M).
Sub-modules (5)
Regulator And AuthorityGreen
The AGO is the sole enforcement authority for the MCDPA; the Act is not privately enforceable.
Claims (1):
The Minnesota Attorney General's Office is the exclusive enforcement authority for the MCDPA, and the Act is not privately enforceable.
Act And InstrumentsGreen
MCDPA signed May 19, 2024, codified at Minn. Stat. ch. 325M, effective July 31, 2025.
Claims (1):
The Minnesota Consumer Data Privacy Act was signed into law on May 19, 2024, codified at Minnesota Statutes chapter 325M, and took effect July 31, 2025.
Material ScopeGreen
Applicability thresholds are volume/revenue-based (100,000 MN residents, or 25%+ revenue from data sales plus 25,000 residents); small businesses per SBA definition are exempt.
Claims (2):
The MCDPA applies to entities that control or process the personal data of 100,000 or more Minnesota residents, or that derive over 25% of revenue from selling personal data and process or control personal data of 25,000 or more consumers.
Small businesses as defined by the U.S. Small Business Administration are exempt from the MCDPA, and there is no full exemption for HIPAA- or GLBA-covered entities, though targeted exemptions exist for health and financial data processing.
Territorial ScopeAmber
Coverage is triggered by processing volume tied to Minnesota residents rather than the controller's physical location, giving the statute extraterritorial reach over out-of-state online businesses.
Claims (1):
MCDPA applicability is triggered by the volume of Minnesota residents' personal data controlled or processed rather than the controller's physical presence in Minnesota, giving the statute extraterritorial reach.
Regulator Registration And FilingAmber
No controller/processor registration or pre-processing filing obligation with the AGO was identified in AGO guidance materials reviewed.
Absence provenance: not recorded. Searched: ag.state.mn.us/Data-Privacy/, ag.state.mn.us/Data-Privacy/Business/Controller/, ag.state.mn.us/Data-Privacy/Business/Processor/.
Claims (1):
No provision requiring controllers to register with or file notices to the Minnesota AGO prior to processing personal data was identified in reviewed AGO guidance.
Category narrative83 words
Minnesota's data-protection landscape is anchored by the Minnesota Consumer Data Privacy Act (MCDPA), codified at Minnesota Statutes chapter 325M, which took effect July 31, 2025 and is enforced exclusively by the Minnesota Attorney General's Office (AGO). The statute applies to controllers/processors meeting Minnesota-resident-volume or data-sale-revenue thresholds, without a physical-presence nexus, and layers atop pre-existing sectoral and government-data statutes (e.g., the Minnesota Government Data Practices Act, Minn. Stat. ch. 13, which governs government-held data only and is out of scope for consumer-sector MCDPA obligations).
Sources and claims (6)
ConfirmedMinnesota Attorney General's Office — The Minnesota Attorney General's Office is the exclusive enforcement authority for the MCDPA, and the Act is not privately enforceable.observed
ConfirmedMinnesota Attorney General's Office — The Minnesota Consumer Data Privacy Act was signed into law on May 19, 2024, codified at Minnesota Statutes chapter 325M, and took effect July 31, 2025.observed
ConfirmedMinnesota Attorney General's Office — The MCDPA applies to entities that control or process the personal data of 100,000 or more Minnesota residents, or that derive over 25% of revenue from selling personal data and process or control personal data of 25,000 or more consumers.observed
ProbableInternational Association of Privacy Professionals — Small businesses as defined by the U.S. Small Business Administration are exempt from the MCDPA, and there is no full exemption for HIPAA- or GLBA-covered entities, though targeted exemptions exist for health and financial data processing.observed
ProbableMinnesota Attorney General's Office — MCDPA applicability is triggered by the volume of Minnesota residents' personal data controlled or processed rather than the controller's physical presence in Minnesota, giving the statute extraterritorial reach.observed
UncertainMinnesota Attorney General's Office — No provision requiring controllers to register with or file notices to the Minnesota AGO prior to processing personal data was identified in reviewed AGO guidance.observed
Strong sensitive-data consent gate exists, but there is no GDPR Art.6-style enumerated lawful-basis framework, and pseudonymisation/anonymisation safe-harbour detail beyond the de-identified-data carve-out was not independently verified against statutory text.
Primary frameworkMinnesota Consumer Data Privacy Act, Minn. Stat. ch. 325M
Traffic-light rationale — AmberStrong sensitive-data consent gate exists, but there is no GDPR Art.6-style enumerated lawful-basis framework, and pseudonymisation/anonymisation safe-harbour detail beyond the de-identified-data carve-out was not independently verified against statutory text.
Sub-modules (4)
Lawful BasesAmber
Processing is governed by collection-limitation/purpose-limitation duties rather than an enumerated lawful-basis list.
Claims (1):
The MCDPA's operative model relies on consent plus collection/purpose-limitation duties (limiting collection to what is necessary and disclosed) rather than an enumerated multi-basis lawful-processing framework analogous to GDPR Article 6.
Consent ThresholdsGreen
Affirmative consumer consent is required before collecting or selling sensitive data categories.
Claims (1):
Controllers must obtain a consumer's affirmative consent before collecting or processing sensitive data, including specific location data or data revealing mental or physical health conditions or citizenship/immigration status.
Special CategoriesGreen
Sensitive data is defined broadly, including genetic and biometric data, health, and immigration status.
Claims (1):
MCDPA sensitive data includes race, ethnicity, religion, mental or physical health condition, sexual orientation, and precise geolocation, as well as genetic and biometric data, subject to enhanced consent requirements.
Pseudonymisation And AnonymisationAmber
De-identified data that cannot be linked to individuals, and publicly available data, fall outside the Act's collection/consent restrictions.
Claims (1):
The MCDPA does not restrict processing of de-identified data, defined as data that cannot be linked to individual consumers, nor data that is publicly available.
Category narrative60 words
The MCDPA does not adopt a GDPR-style enumerated multi-basis lawful-processing model; instead it relies on collection/purpose-limitation duties plus consent gates for sensitive data. Sensitive data is broadly defined (race, ethnicity, religion, health, sexuality, precise location, genetic and biometric data, citizenship/immigration status) and requires affirmative consumer consent before collection or sale. De-identified and publicly available data fall outside the Act's restrictions.
Sources and claims (4)
ProbableMinnesota Attorney General's Office — The MCDPA's operative model relies on consent plus collection/purpose-limitation duties (limiting collection to what is necessary and disclosed) rather than an enumerated multi-basis lawful-processing framework analogous to GDPR Article 6.observed
ConfirmedMinnesota Attorney General's Office — Controllers must obtain a consumer's affirmative consent before collecting or processing sensitive data, including specific location data or data revealing mental or physical health conditions or citizenship/immigration status.observed
ConfirmedMinnesota Attorney General's Office — MCDPA sensitive data includes race, ethnicity, religion, mental or physical health condition, sexual orientation, and precise geolocation, as well as genetic and biometric data, subject to enhanced consent requirements.observed
ConfirmedMinnesota Attorney General's Office — The MCDPA does not restrict processing of de-identified data, defined as data that cannot be linked to individual consumers, nor data that is publicly available.observed
Traffic-light rationale — GreenRights are clearly enumerated by the regulator with a defined statutory response deadline (45 days) and complaint escalation path.
Sub-modules (5)
Access RightGreen
Consumers may access data held about them and obtain a list of specific third parties their data was sold to.
Claims (1):
Minnesota consumers have rights to know what data a company holds about them and to obtain a list of specific third parties to which their data has been sold.
Rectification And ErasureGreen
Consumers may correct inaccurate data and request deletion of personal/sensitive data.
Claims (1):
Consumers have the right to request correction of inaccurate data and deletion of their personal and sensitive data held by a business.
Restriction And ObjectionGreen
Consumers may opt out of sale, targeted advertising, and profiling, including profiling feeding automated decisions.
Claims (1):
Consumers may opt out of the sale of their personal data, use of their data for targeted advertising, and profiling, including profiling used in automated decision-making.
Data PortabilityGreen
The rights package includes a right to obtain a copy of one's data, per the AGO's own rights summary.
Claims (1):
The Act's consumer rights structure includes a right to obtain a copy of one's data in addition to rights to a third-party disclosure list, opt-out, access, correction, and deletion.
Deadlines And Response WindowsGreen
Businesses must respond to rights requests within 45 days; non-response triggers an AGO complaint pathway.
Claims (1):
Businesses must respond to consumer rights requests within 45 days, and consumers may file a complaint with the Attorney General's Office if a business fails to respond within that window.
Category narrative70 words
The MCDPA grants Minnesota consumers a materially complete rights package summarized by the AGO as 'LOCKED+': a list of third parties data was sold to, opt-out of sale/targeted-advertising/profiling, a copy of data held, knowledge of what is held, edit/correction rights, deletion rights, plus the right to question profiling and automated decisions. Businesses must respond to rights requests within 45 days, with a consumer complaint route to the AGO for non-response.
Sources and claims (5)
ConfirmedMinnesota Attorney General's Office — Minnesota consumers have rights to know what data a company holds about them and to obtain a list of specific third parties to which their data has been sold.observed
ConfirmedMinnesota Attorney General's Office — Consumers have the right to request correction of inaccurate data and deletion of their personal and sensitive data held by a business.observed
ConfirmedMinnesota Attorney General's Office — Consumers may opt out of the sale of their personal data, use of their data for targeted advertising, and profiling, including profiling used in automated decision-making.observed
ProbableInternational Association of Privacy Professionals — The Act's consumer rights structure includes a right to obtain a copy of one's data in addition to rights to a third-party disclosure list, opt-out, access, correction, and deletion.observed
ConfirmedMinnesota Attorney General's Office — Businesses must respond to consumer rights requests within 45 days, and consumers may file a complaint with the Attorney General's Office if a business fails to respond within that window.observed
Core accountability, assessment, processor-contract, and breach-notification duties are well evidenced from AGO guidance; DPO/ROPA specifics rely on pre-enactment secondary analysis and were not independently verified against final statute text.
Traffic-light rationale — AmberCore accountability, assessment, processor-contract, and breach-notification duties are well evidenced from AGO guidance; DPO/ROPA specifics rely on pre-enactment secondary analysis and were not independently verified against final statute text.
Sub-modules (7)
Accountability And DpiaGreen
Businesses must conduct data protection assessments and maintain data security practices.
Claims (1):
Businesses subject to the MCDPA must conduct data protection/privacy assessments and maintain data security practices to protect personal data.
Dpo RequirementsAmber
Pre-enactment IAPP analysis suggested an implied obligation to name a chief privacy officer or equivalent contact; not independently confirmed against final AGO guidance.
Absence provenance: not recorded. Searched: ag.state.mn.us/Data-Privacy/Business/Controller/.
Claims (1):
Pre-enactment IAPP commentary on the MCDPA bill identified an implied obligation for covered entities to name a chief privacy officer or other individual with primary responsibility for privacy policies and procedures.
Ropa RequirementsAmber
No standalone records-of-processing obligation distinct from the data protection assessment duty was identified.
Absence provenance: not recorded. Searched: ag.state.mn.us/Data-Privacy/Business/Controller/, ag.state.mn.us/Data-Privacy/Business/Processor/.
Joint Controller ArrangementsGreen
Processor contracts must allocate responsibilities and support controller compliance and assessment obligations.
Claims (1):
Processor contracts under the MCDPA must require processors to assist controllers with security of processing, breach notifications, and data protection assessments, and must clearly allocate responsibilities between controller and processor.
Security MeasuresGreen
Processors must implement technical/organizational measures appropriate to processing risk.
Claims (1):
Processors must implement appropriate technical and organizational measures to ensure security appropriate to the risk of processing, and allow controller-directed assessments and inspections.
Breach NotificationAmber
Processors must notify controllers of security breaches; Minnesota's general breach-notification statute (Minn. Stat. §325E.61) independently requires notice to affected residents, though full statutory text was not retrieved in this pass.
Claims (2):
Processors must provide notification to controllers upon a breach of the security of systems used to protect personal data, as part of MCDPA processor obligations.
Minnesota maintains a separate general data-breach-notification statute (Minn. Stat. §325E.61 et seq.) applicable to entities holding Minnesotans' personal information, distinct from MCDPA processor-to-controller notice duties.
Retention And DisposalGreen
Businesses may not retain data beyond what is relevant and reasonably necessary for the disclosed purpose.
Claims (1):
Businesses may not retain personal data longer than is relevant and reasonably necessary for the disclosed purpose.
Category narrative64 words
Controllers must run data protection/privacy assessments, limit collection and retention to disclosed necessary purposes, and maintain risk-appropriate security. Processor contracts must impose breach-notification assistance, security cooperation, assessment-support, and audit/inspection rights, with a clear allocation of responsibilities. Evidence of a formal, freestanding ROPA obligation or an independent statutory DPO/chief-privacy-officer mandate (as opposed to a named privacy contact) was not conclusively confirmed against enacted statutory text.
Sources and claims (7)
ConfirmedMinnesota Attorney General's Office — Businesses subject to the MCDPA must conduct data protection/privacy assessments and maintain data security practices to protect personal data.observed
UncertainInternational Association of Privacy Professionals — Pre-enactment IAPP commentary on the MCDPA bill identified an implied obligation for covered entities to name a chief privacy officer or other individual with primary responsibility for privacy policies and procedures.observed
ConfirmedMinnesota Attorney General's Office — Processor contracts under the MCDPA must require processors to assist controllers with security of processing, breach notifications, and data protection assessments, and must clearly allocate responsibilities between controller and processor.observed
ConfirmedMinnesota Attorney General's Office — Processors must implement appropriate technical and organizational measures to ensure security appropriate to the risk of processing, and allow controller-directed assessments and inspections.observed
ConfirmedMinnesota Attorney General's Office — Processors must provide notification to controllers upon a breach of the security of systems used to protect personal data, as part of MCDPA processor obligations.observed
UncertainOneTrust DataGuidance — Minnesota maintains a separate general data-breach-notification statute (Minn. Stat. §325E.61 et seq.) applicable to entities holding Minnesotans' personal information, distinct from MCDPA processor-to-controller notice duties.observed
ConfirmedMinnesota Attorney General's Office — Businesses may not retain personal data longer than is relevant and reasonably necessary for the disclosed purpose.observed
This module is structurally inapplicable to a US state consumer-privacy statute; explicit absence confirmed via AGO guidance review rather than an unexamined gap.
Primary frameworkMinnesota Consumer Data Privacy Act, Minn. Stat. ch. 325M
Traffic-light rationale — RedThis module is structurally inapplicable to a US state consumer-privacy statute; explicit absence confirmed via AGO guidance review rather than an unexamined gap.
Sub-modules (6)
Transfer MechanismsRed
No transfer-mechanism regime beyond controller-processor contracts identified.
Claims (1):
The MCDPA does not establish an EU-style cross-border transfer regime; it imposes controller-processor contractual requirements and consumer rights but contains no identified adequacy determination, SCC/BCR mechanism, transfer impact assessment requirement, or data-localization mandate.
Adequacy ReceivedRed
Not applicable; no adequacy concept in MCDPA.
Absence provenance: not recorded. Searched: ag.state.mn.us/Data-Privacy/.
Adequacy GrantedRed
Not applicable; no adequacy concept in MCDPA.
Absence provenance: not recorded. Searched: ag.state.mn.us/Data-Privacy/.
Sccs And BcrsRed
No SCC/BCR uptake mechanism identified; not part of MCDPA structure.
Absence provenance: not recorded. Searched: ag.state.mn.us/Data-Privacy/Business/Contracts/.
Transfer Impact AssessmentRed
No TIA requirement identified.
Absence provenance: not recorded. Searched: ag.state.mn.us/Data-Privacy/Business/Controller/.
Data LocalisationRed
No data-localisation mandate identified.
Absence provenance: not recorded. Searched: ag.state.mn.us/Data-Privacy/.
Category narrative48 words
As a US state consumer-privacy statute, the MCDPA does not include an EU/GDPR-style cross-border transfer regime. No adequacy-determination mechanism (received or granted), standard contractual clauses/BCR framework, transfer impact assessment requirement, or data-localisation mandate was identified in AGO guidance; the statute's only cross-entity control is the controller-processor contract requirement.
Sources and claims (1)
ProbableMinnesota Attorney General's Office — The MCDPA does not establish an EU-style cross-border transfer regime; it imposes controller-processor contractual requirements and consumer rights but contains no identified adequacy determination, SCC/BCR mechanism, transfer impact assessment requirement, or data-localization mandate.observed
Traffic-light rationale — AmberFinancial, health, and education overlays are evidenced; several other sectors carry unresolved gaps requiring primary-source verification.
Sub-modules (7)
Financial Sector OverlayAmber
Targeted exemption for GLBA-covered financial data processing; no full entity-level exemption.
Claims (1):
The MCDPA provides no full exemption for GLBA-covered financial institutions but includes targeted exemptions for financial data processing.
Health Sector OverlayAmber
Targeted exemption for HIPAA-covered health data processing; no full entity-level exemption; historical multistate health-breach enforcement precedent exists (Inmediata, 2023, pre-MCDPA).
Claims (2):
The MCDPA provides no full exemption for HIPAA-covered entities but includes targeted exemptions for health data processing.
In 2023, the Minnesota Attorney General joined a 32-state settlement with health-data clearinghouse Inmediata over a multi-year breach of protected health information affecting approximately 113,000 Minnesota residents, predating MCDPA but illustrating active health-data enforcement posture.
Telecoms And EprivacyRed
No MCDPA-specific ePrivacy/telecoms overlay identified.
Absence provenance: not recorded. Searched: ag.state.mn.us MCDPA business guidance pages.
Employment DataRed
Employment/B2B data exclusion status under MCDPA was not confirmed via retrieved sources.
Absence provenance: not recorded. Searched: ag.state.mn.us MCDPA business/controller guidance.
Credit And ScoringRed
FCRA-adjacent credit-scoring exemption status not confirmed.
Absence provenance: not recorded. Searched: ag.state.mn.us MCDPA guidance.
EducationAmber
Certain education technology providers are subject to MCDPA irrespective of general thresholds.
Claims (1):
Certain education technology providers are subject to the MCDPA regardless of the general consumer-volume thresholds applicable to other controllers.
InsuranceRed
No insurance-sector-specific overlay identified.
Absence provenance: not recorded. Searched: ag.state.mn.us MCDPA guidance.
Category narrative56 words
The MCDPA does not fully exempt GLBA-covered financial institutions or HIPAA-covered health entities, instead layering targeted (data-level) exemptions on top of those federal regimes. Certain education-technology providers are subject to the MCDPA regardless of the general volume thresholds. Telecoms/ePrivacy, employment-data, credit/scoring, and insurance-specific overlays were not confirmed via retrievable AGO or T1/T2 sources in this pass.
Sources and claims (4)
ProbableInternational Association of Privacy Professionals — The MCDPA provides no full exemption for GLBA-covered financial institutions but includes targeted exemptions for financial data processing.observed
ConfirmedMinnesota Attorney General's Office — In 2023, the Minnesota Attorney General joined a 32-state settlement with health-data clearinghouse Inmediata over a multi-year breach of protected health information affecting approximately 113,000 Minnesota residents, predating MCDPA but illustrating active health-data enforcement posture.observed
ProbableMinnesota Attorney General's Office — Certain education technology providers are subject to the MCDPA regardless of the general consumer-volume thresholds applicable to other controllers.observed
Traffic-light rationale — AmberUniversal opt-out and targeted-advertising opt-out are strongly evidenced; dark patterns and clean-room provisions remain unconfirmed gaps.
Sub-modules (6)
Cookies And TrackersGreen
Universal opt-out mechanisms operate via browser-level signals affecting tracking/targeted-ad collection.
Claims (1):
The MCDPA requires businesses to honor universal opt-out mechanisms (browser-based signals) that communicate a consumer's opt-out of targeted advertising and data collection/sale across websites.
Dark PatternsRed
No MCDPA-specific dark-pattern prohibition confirmed via retrieved sources.
Absence provenance: not recorded. Searched: ag.state.mn.us MCDPA consumer/business pages.
Opt Out SignalsGreen
Businesses must honor universal opt-out preference signals.
Claims (1):
The MCDPA requires businesses to honor universal opt-out mechanisms (browser-based signals) that communicate a consumer's opt-out of targeted advertising and data collection/sale across websites.
Clean Rooms And DcrRed
No clean-room/data-collaboration-room rule identified.
Absence provenance: not recorded. Searched: ag.state.mn.us MCDPA business guidance.
Cross Context AdvertisingGreen
Consumers may opt out of sale and targeted advertising use of their personal data.
Claims (1):
Consumers have the right to opt out of the sale of personal data and its use for targeted advertising.
Direct MarketingAmber
Direct-marketing-specific suppression rules beyond the general targeted-advertising opt-out were not separately confirmed.
Claims (1):
Consumers have the right to opt out of the sale of personal data and its use for targeted advertising.
Category narrative39 words
The MCDPA mandates honoring browser-based universal opt-out mechanisms (GPC-style signals) for targeted advertising and data-sale opt-out, and grants a direct consumer opt-out right for sale/targeted-advertising/profiling. Dark-pattern-specific prohibitions and clean-room/data-collaboration-room rules were not confirmed via retrieved AGO or T1/T2 sources.
Sources and claims (2)
ConfirmedMinnesota Attorney General's Office — The MCDPA requires businesses to honor universal opt-out mechanisms (browser-based signals) that communicate a consumer's opt-out of targeted advertising and data collection/sale across websites.observed
ConfirmedMinnesota Attorney General's Office — Consumers have the right to opt out of the sale of personal data and its use for targeted advertising.observed
Profiling/ADM rights are strongly evidenced and materially significant; biometric/genetic standalone-regime status and state-surveillance carve-outs remain unresolved gaps.
Traffic-light rationale — AmberProfiling/ADM rights are strongly evidenced and materially significant; biometric/genetic standalone-regime status and state-surveillance carve-outs remain unresolved gaps.
Sub-modules (6)
Profiling RestrictionsGreen
Consumers may opt out of profiling in furtherance of decisions with legal or similarly significant effects.
Claims (1):
Minnesota's Attorney General has characterized the MCDPA as providing some of the nation's strongest protections against harmful data profiling and automated decision-making, including a consumer right to opt out of profiling used in furtherance of significant decisions.
Automated Decision Making TransparencyGreen
Consumers may request the reasoning and underlying data behind a profiling/automated decision, including AI-facilitated decisions.
Claims (1):
Consumers may request information regarding a profiling or automated decision made about them, including the reasoning behind the decision and the data used to reach it, and may question automated decisions facilitated by artificial intelligence.
Ai Risk AssessmentsAmber
The Act creates rights intended to prevent AI/automated systems from depriving residents of critical goods and services.
Claims (1):
The MCDPA creates rights intended to ensure that AI and automated systems cannot deprive Minnesota residents of critical goods and services.
Biometric RegimeAmber
Biometric data is a sensitive-data category requiring consent; a standalone biometric-specific statute status is unconfirmed.
Absence provenance: not recorded. Searched: dataguidance.com Minnesota biometric bill pages (no retrievable content).
Claims (1):
Biometric data is classified as sensitive data under the MCDPA and subject to consent requirements before collection; no standalone biometric-specific statute comparable to Illinois' BIPA has been confirmed as currently enacted in Minnesota.
Genetic DataAmber
Genetic data is a sensitive-data category requiring consent; separate government-data-practices genetic provisions (Minn. Stat. §13.386) exist but full text was not retrieved.
Absence provenance: not recorded. Searched: dataguidance.com Minnesota Statutes section 13.386 page (no retrievable content).
Claims (1):
Genetic data is classified as sensitive data under the MCDPA requiring consumer consent before collection; Minnesota separately maintains government-data-practices provisions addressing genetic information (Minn. Stat. §13.386), though current text of that provision was not independently retrieved.
State Surveillance CarveoutsRed
No MCDPA government/law-enforcement exemption language was confirmed via retrieved sources.
Absence provenance: not recorded. Searched: ag.state.mn.us MCDPA business/controller guidance.
Category narrative86 words
The AGO has characterized the MCDPA as one of the nation's strongest statutes against harmful profiling and automated decision-making, granting consumers a right to question and obtain the reasoning/data behind profiling decisions and to opt out of profiling in furtherance of legally or similarly significant decisions, including AI-facilitated decisions. Genetic and biometric data are classified as sensitive data requiring consent, but standalone biometric- or genetic-specific statutes (comparable to Illinois' BIPA) and government/law-enforcement surveillance carve-outs were not independently confirmed as currently enacted MCDPA provisions in this pass.
Sources and claims (5)
ConfirmedMinnesota Attorney General's Office — Minnesota's Attorney General has characterized the MCDPA as providing some of the nation's strongest protections against harmful data profiling and automated decision-making, including a consumer right to opt out of profiling used in furtherance of significant decisions.observed
ConfirmedMinnesota Attorney General's Office — Consumers may request information regarding a profiling or automated decision made about them, including the reasoning behind the decision and the data used to reach it, and may question automated decisions facilitated by artificial intelligence.observed
ProbableMinnesota Attorney General's Office — The MCDPA creates rights intended to ensure that AI and automated systems cannot deprive Minnesota residents of critical goods and services.observed
UncertainMinnesota Attorney General's Office — Biometric data is classified as sensitive data under the MCDPA and subject to consent requirements before collection; no standalone biometric-specific statute comparable to Illinois' BIPA has been confirmed as currently enacted in Minnesota.observed
UncertainMinnesota Attorney General's Office — Genetic data is classified as sensitive data under the MCDPA requiring consumer consent before collection; Minnesota separately maintains government-data-practices provisions addressing genetic information (Minn. Stat. §13.386), though current text of that provision was not independently retrieved.observed
Traffic-light rationale — GreenChildren's-data provisions are clearly documented by the regulator with specific age thresholds and guardianship extension.
Sub-modules (5)
Age VerificationAmber
No standalone age-verification mandate identified beyond 'known child'/'known consumer age 13-16' actual-knowledge standards.
Claims (1):
Controllers may not process a consumer's personal data for targeted advertising or sell that consumer's personal data without the consumer's consent where the controller knows the consumer is between 13 and 16 years of age.
Parental ConsentGreen
Parental/guardian consent required before processing a known child's data, with COPPA compliance required.
Claims (1):
Controllers may not process the personal data concerning a known child without obtaining consent from the child's parent or lawful guardian (with limited exceptions), and must comply with COPPA.
Minor Profiling BansAmber
Consent (rather than an outright ban) is required for targeted advertising/sale involving consumers known to be 13-16.
Claims (1):
Controllers may not process a consumer's personal data for targeted advertising or sell that consumer's personal data without the consumer's consent where the controller knows the consumer is between 13 and 16 years of age.
Education SettingsAmber
Certain education technology providers are covered by the MCDPA regardless of general applicability thresholds.
Claims (1):
Certain education technology providers are subject to the MCDPA regardless of the general applicability thresholds, extending coverage into student-data contexts.
Dependent AdultsGreen
Consumers may exercise MCDPA rights on behalf of persons under their guardianship or conservatorship.
Claims (1):
The MCDPA allows consumers to exercise their statutory rights on behalf of their children or any person over whom the consumer has guardianship or conservatorship.
Category narrative65 words
The MCDPA requires parental/guardian consent before processing a 'known child's' personal data (with limited exceptions) and COPPA compliance, plus an opt-in consent requirement for targeted advertising or sale of data for consumers known to be 13-16 years old. Certain education technology providers are covered regardless of general thresholds, and the Act permits consumers to exercise rights on behalf of children or persons under their guardianship/conservatorship.
Sources and claims (4)
ConfirmedMinnesota Attorney General's Office — Controllers may not process a consumer's personal data for targeted advertising or sell that consumer's personal data without the consumer's consent where the controller knows the consumer is between 13 and 16 years of age.observed
ConfirmedMinnesota Attorney General's Office — Controllers may not process the personal data concerning a known child without obtaining consent from the child's parent or lawful guardian (with limited exceptions), and must comply with COPPA.observed
ProbableMinnesota Attorney General's Office — Certain education technology providers are subject to the MCDPA regardless of the general applicability thresholds, extending coverage into student-data contexts.observed
ConfirmedMinnesota Attorney General's Office — The MCDPA allows consumers to exercise their statutory rights on behalf of their children or any person over whom the consumer has guardianship or conservatorship.observed
Enforcement powers, penalties, and activity are well documented and robust, but the absence of a private right of action and expiration of the cure period both materially shift risk allocation, and no collective-redress mechanism exists.
Primary frameworkMinnesota Consumer Data Privacy Act, Minn. Stat. ch. 325M
Traffic-light rationale — AmberEnforcement powers, penalties, and activity are well documented and robust, but the absence of a private right of action and expiration of the cure period both materially shift risk allocation, and no collective-redress mechanism exists.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
AGO may seek injunctive relief, litigation costs, and civil penalties up to $7,500/violation.
Claims (1):
The Minnesota Attorney General may seek injunctive relief, litigation expenses, and civil penalties of up to $7,500 per violation against MCDPA violators.
Enforcement Activity IndexAmber
Hundreds of education letters and dozens of warning letters sent since July 2025; cure period sunset January 31, 2026.
Claims (1):
Since the MCDPA took effect, the Attorney General's Office sent hundreds of education letters and dozens of formal warning letters to companies regarding privacy policy, consent, and universal opt-out compliance issues, and the Act's mandatory pre-enforcement cure/notice period expired on January 31, 2026.
Regulator Funding And CapacityGreen
MCDPA funded four new AGO attorneys plus an investigator dedicated to enforcement.
Claims (1):
The MCDPA included funding for the Attorney General's Office to hire four new attorneys and an investigator focused primarily on enforcing the Act, placing Minnesota among the most heavily resourced state privacy enforcers per independent industry analysis.
Collective Redress And Class ActionsRed
No collective-redress/class-action mechanism specific to MCDPA identified; enforcement is AGO-exclusive.
Claims (1):
No collective-redress or class-action mechanism specific to MCDPA enforcement has been identified; enforcement is vested exclusively in the Attorney General.
Private Right Of ActionRed
The MCDPA contains no private right of action.
Claims (1):
The MCDPA contains no private right of action; only the Attorney General may enforce the Act.
Recent Developments 180DAmber
June 2026: Minnesota joined an 18-attorney-general coalition opposing the federal SECURE Data Act on preemption grounds.
Claims (1):
In June 2026, Minnesota joined a coalition of 18 attorneys general and agencies opposing the proposed federal SECURE Data Act, with the Minnesota AGO stating the bill would preempt and weaken protections under the state's Consumer Data Privacy Act.
Category narrative112 words
The AGO holds exclusive investigative and enforcement authority, able to seek injunctive relief, litigation expenses, and civil penalties up to $7,500 per violation; the Act carries no private right of action or identified class-action mechanism. A mandatory 30-day cure/notice period sunset on January 31, 2026, after which the AGO may bring enforcement actions without prior warning. The office was funded to add four attorneys and an investigator, and has sent hundreds of education letters and dozens of formal warning letters since the Act took effect. Within the last 180 days, Minnesota joined an 18-state coalition opposing the proposed federal SECURE Data Act, which the AGO says would preempt and weaken MCDPA protections.
Sources and claims (6)
ConfirmedMinnesota Attorney General's Office — The Minnesota Attorney General may seek injunctive relief, litigation expenses, and civil penalties of up to $7,500 per violation against MCDPA violators.observed
ConfirmedMinnesota Attorney General's Office — Since the MCDPA took effect, the Attorney General's Office sent hundreds of education letters and dozens of formal warning letters to companies regarding privacy policy, consent, and universal opt-out compliance issues, and the Act's mandatory pre-enforcement cure/notice period expired on January 31, 2026.observed
ProbableMinnesota Attorney General's Office — The MCDPA included funding for the Attorney General's Office to hire four new attorneys and an investigator focused primarily on enforcing the Act, placing Minnesota among the most heavily resourced state privacy enforcers per independent industry analysis.observed
ProbableMinnesota Attorney General's Office — No collective-redress or class-action mechanism specific to MCDPA enforcement has been identified; enforcement is vested exclusively in the Attorney General.observed
ConfirmedMinnesota Attorney General's Office — The MCDPA contains no private right of action; only the Attorney General may enforce the Act.observed
ConfirmedMinnesota Attorney General's Office — In June 2026, Minnesota joined a coalition of 18 attorneys general and agencies opposing the proposed federal SECURE Data Act, with the Minnesota AGO stating the bill would preempt and weaken protections under the state's Consumer Data Privacy Act.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for United States – Minnesota
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 44 claim(s), 15 source(s) in the cumulative register.
GDPR article map
Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).
regulator_and_framework, data_subject_rights, children_and_vulnerable_groups, and enforcement_and_redress rest primarily on T1 Minnesota AGO primary-source pages (ag.state.mn.us/Data-Privacy and Office/Communications releases), giving high confidence. lawful_processing_and_special_data, controller_processor_duties, sectoral_watch, adtech_and_commercial_privacy, and algorithmic_biometric_and_surveillance_governance mix T1 AGO guidance with T2 IAPP bill-stage analysis (some pre-enactment) for granular items (DPO/chief-privacy-officer implication, GLBA/HIPAA targeted-exemption scope), which were not independently re-verified against final statutory text of Minn. Stat. ch. 325M. cross_border_and_adequacy is a confirmed structural gap (state consumer-privacy statutes lack an EU-style transfer regime) rather than an unresearched module. Several sectoral_watch sub-modules (telecoms/eprivacy, employment_data, credit_and_scoring, insurance) and adtech sub-modules (dark_patterns, clean_rooms_and_dcr) and algorithmic sub-modules (biometric_regime, genetic_data, state_surveillance_carveouts) carry explicit absent_field_provenance because no retrievable T1/T2 source confirmed content in this pass; several DataGuidance (T4) pages returned only paywalled stubs with no substantive content and were excluded from claim support.
Unresolved questions (5):
Is there an explicit statutory 'chief privacy officer' or DPO-equivalent designation requirement in the enacted Minn. Stat. ch. 325M text, or does the privacy-notice contact-person requirement suffice as the sole equivalent?
What is the current enactment/introduction status of standalone Minnesota biometric-privacy and genetic-information-privacy bills referenced in legislative tracking sources, and do they materially supplement the MCDPA's sensitive-data consent gate?
Does the MCDPA's 'controller' definition exclude employment/B2B personal data, consistent with most peer state comprehensive privacy statutes, and if so under what specific statutory carve-out?
What are the precise notice timelines and thresholds under Minnesota's general breach-notification statute (Minn. Stat. §325E.61 et seq.), which is structurally distinct from MCDPA processor-to-controller breach-notice duties?
Are there MCDPA-specific dark-pattern prohibitions, clean-room/data-collaboration-room provisions, or government/law-enforcement exemption carve-outs in the enacted statutory text beyond what AGO consumer-facing guidance summarizes?