🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-MT · run data-protection-2026-08-06 v13-gdpri-1.0.0
content: ai_generated 10 sources retrieved model claude-sonnet-5 ·

United States – Montana

US-MT schema gdpri-v2 trajectory: not recordedhybrid regimeoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 38 claims · 10 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
38Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core omnibus instrument is in force with a clear regulator and settled scope; only the registration/filing sub-module is unpopulated.

Primary frameworkMontana Consumer Data Privacy Act (Title 30, ch. 14, part 28, MCA), as amended by SB 297 (2025)
Traffic-light rationale — GreenCore omnibus instrument is in force with a clear regulator and settled scope; only the registration/filing sub-module is unpopulated.

Sub-modules (5)

Regulator And AuthorityGreen

The Montana Attorney General has exclusive statutory authority to enforce the MTCDPA.

Claims (1):

  • The Montana Attorney General has exclusive authority to enforce the provisions of the Montana Consumer Data Privacy Act.

Act And InstrumentsGreen

MTCDPA entered into force October 1, 2024; SB 297 amendments entered into force October 1, 2025.

Claims (2):

  • The Montana Consumer Data Privacy Act came into effect on October 1, 2024, after being signed by the Governor of Montana in May 2023.
  • Senate Bill 297 revises portions of the Montana Consumer Data Privacy Act and is effective October 1, 2025.

Material ScopeGreen

Personal data is any information linked or reasonably linkable to an identified/identifiable individual, excluding de-identified and publicly available data.

Claims (1):

  • "Personal data" means any information that is linked or reasonably linkable to an identified or identifiable individual and does not include de-identified data or publicly available information.

Territorial ScopeGreen

Applies to persons conducting business in Montana or targeting Montana residents that meet consumer-volume/revenue thresholds.

Claims (1):

  • The Act applies to those that conduct business in Montana or deliver commercial products/services intentionally targeted at Montana residents and that control or process the personal data of not less than 25,000 consumers (formerly 50,000), or of 25,000 consumers deriving more than 25% of revenue from data sales.

Regulator Registration And FilingRed

No controller/processor registration or filing obligation with the Montana AG was identified in the MTCDPA or SB 297 text summarized by available sources.

Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act controller registration filing requirement, Montana Attorney General data privacy registration.

Category narrative102 words

Montana's comprehensive consumer privacy regime is the Montana Consumer Data Privacy Act (MTCDPA), enacted 2023 and effective October 1, 2024, amended by SB 297 effective October 1, 2025. Enforcement runs exclusively through the Montana Attorney General's Office of Consumer Protection; there is no dedicated privacy agency. Material scope covers 'personal data' linked/reasonably linkable to identifiable individuals, excluding de-identified and publicly available data. Territorial scope reaches any person conducting business in Montana or targeting products/services at Montana residents, subject to consumer-volume thresholds (25,000 consumers post-SB297, previously 50,000, or 25,000 with 25%+ revenue from data sales). No controller registration or filing regime was identified.

Sources and claims (5)
  1. ConfirmedDataGuidanceThe Montana Attorney General has exclusive authority to enforce the provisions of the Montana Consumer Data Privacy Act.observed
  2. ConfirmedDataGuidanceThe Montana Consumer Data Privacy Act came into effect on October 1, 2024, after being signed by the Governor of Montana in May 2023.observed
  3. ConfirmedMontana Department of Justice, Office of Consumer ProtectionSenate Bill 297 revises portions of the Montana Consumer Data Privacy Act and is effective October 1, 2025.observed
  4. ConfirmedMontana Department of Justice, Office of Consumer Protection"Personal data" means any information that is linked or reasonably linkable to an identified or identifiable individual and does not include de-identified data or publicly available information.observed
  5. ConfirmedMontana Department of Justice, Office of Consumer ProtectionThe Act applies to those that conduct business in Montana or deliver commercial products/services intentionally targeted at Montana residents and that control or process the personal data of not less than 25,000 consumers (formerly 50,000), or of 25,000 consumers deriving more than 25% of revenue from data sales.observed

#

Consent and sensitive-data protections exist but the regime lacks a GDPR Art 6-equivalent enumerated lawful-basis structure.

Primary frameworkMontana Consumer Data Privacy Act (Title 30, ch. 14, part 28, MCA), as amended by SB 297 (2025)
Traffic-light rationale — AmberConsent and sensitive-data protections exist but the regime lacks a GDPR Art 6-equivalent enumerated lawful-basis structure.

Sub-modules (4)

Lawful BasesAmber

Processing is limited to what is adequate, relevant and reasonably necessary for disclosed purposes; processing for new, incompatible purposes requires consent.

Claims (1):

  • Controllers must not process personal data for purposes that are neither reasonably necessary to, nor compatible with, the disclosed purposes for which the personal data is processed unless the controller obtains the consumer's consent.

Special CategoriesGreen

Sensitive data covers racial/ethnic origin, religious beliefs, health conditions, sex life/sexual orientation, citizenship/immigration status, and genetic/biometric data processed for unique identification.

Claims (1):

  • Sensitive data means personal data revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis, sex life, sexual orientation, citizenship or immigration status, or genetic/biometric data processed for the purpose of uniquely identifying an individual.

Pseudonymisation And AnonymisationGreen

De-identified data is excluded from the 'personal data' definition, and DPIAs must factor in the use of de-identified data as a risk-mitigation element.

Claims (1):

  • Personal data excludes de-identified data, and data protection assessments must factor in a controller's use of de-identified data as a risk-mitigating circumstance.
Category narrative76 words

MTCDPA does not use a GDPR-style enumerated list of lawful bases. Instead, processing is generally permitted subject to a data-minimization/purpose-limitation rule, with consent required for secondary/incompatible purposes, for sale/targeted-advertising/profiling opt-outs, for sensitive data, and for minors aged 13 to under 16. Sensitive data is broadly defined (race/ethnicity, religion, health, sex life/orientation, citizenship/immigration status, and genetic/biometric data used for unique identification). De-identified data is carved out of the 'personal data' definition, functioning as a pseudonymisation/anonymisation safe harbour.

Sources and claims (5)
  1. ProbableDataGuidanceControllers must not process personal data for purposes that are neither reasonably necessary to, nor compatible with, the disclosed purposes for which the personal data is processed unless the controller obtains the consumer's consent.observed
  2. ConfirmedDataGuidanceControllers must provide an effective mechanism for a consumer to revoke consent that is at least as easy as the mechanism used to grant consent, and must cease processing the personal data no later than 45 days after receipt of the revocation request.observed
  3. ConfirmedDataGuidanceA controller may not process personal data for targeted advertising or sell a consumer's personal data without consent when it has actual knowledge that the consumer is at least 13 but younger than 16 years of age.observed
  4. ConfirmedDataGuidanceSensitive data means personal data revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis, sex life, sexual orientation, citizenship or immigration status, or genetic/biometric data processed for the purpose of uniquely identifying an individual.observed
  5. ConfirmedMontana Department of Justice, Office of Consumer ProtectionPersonal data excludes de-identified data, and data protection assessments must factor in a controller's use of de-identified data as a risk-mitigating circumstance.observed

#

The rights catalogue and response-deadline framework are clear, consistent, and in force.

Primary frameworkMontana Consumer Data Privacy Act (Title 30, ch. 14, part 28, MCA), as amended by SB 297 (2025)
Traffic-light rationale — GreenThe rights catalogue and response-deadline framework are clear, consistent, and in force.

Sub-modules (5)

Access RightGreen

Consumers have a right to know what personal data is collected and processed about them.

Claims (1):

  • Montanans have a right to know what personal data is collected and processed about them.

Rectification And ErasureGreen

Consumers have rights to correct inaccuracies and to delete personal data.

Claims (1):

  • Consumers have a right to correct inaccuracies in their personal data and a right to delete personal data about the consumer.

Restriction And ObjectionGreen

Consumers may opt out of the sale of personal data, use for targeted advertising, or use for profiling.

Claims (1):

  • Consumers have the right to opt out of the sale of personal data, use of personal data for targeted advertisements, or use of personal data for profiling purposes.

Data PortabilityGreen

Consumers have the right to obtain a copy of their personal data from the controller.

Claims (1):

  • Consumers have a right to obtain a copy of the consumer's personal data from the controller.

Deadlines And Response WindowsGreen

Controllers must respond within 45 days (extendable once by 45 more days with notice), and must provide the first response in a 12-month period free of charge.

Claims (2):

  • Controllers must respond to consumer requests without undue delay and no later than 45 days after receipt, extendable by an additional 45 days when reasonably necessary, provided the consumer is informed of the extension within the original 45-day period.
  • Information provided to consumers in response to rights requests must be provided free of charge up to once during any 12-month period per consumer.
Category narrative69 words

Montanans have a right to know/access what personal data is collected and processed, correct inaccuracies, delete personal data, obtain a portable copy, and opt out of sale, targeted advertising, and profiling. Controllers must respond without undue delay and no later than 45 days after receipt of a request, extendable once by an additional 45 days with notice to the consumer; the first response in any 12-month period is free.

Sources and claims (6)
  1. ConfirmedMontana Department of Justice, Office of Consumer ProtectionMontanans have a right to know what personal data is collected and processed about them.observed
  2. ConfirmedMontana Department of Justice, Office of Consumer ProtectionConsumers have a right to correct inaccuracies in their personal data and a right to delete personal data about the consumer.observed
  3. ConfirmedMontana Department of Justice, Office of Consumer ProtectionConsumers have the right to opt out of the sale of personal data, use of personal data for targeted advertisements, or use of personal data for profiling purposes.observed
  4. ConfirmedMontana Department of Justice, Office of Consumer ProtectionConsumers have a right to obtain a copy of the consumer's personal data from the controller.observed
  5. ConfirmedDataGuidanceControllers must respond to consumer requests without undue delay and no later than 45 days after receipt, extendable by an additional 45 days when reasonably necessary, provided the consumer is informed of the extension within the original 45-day period.observed
  6. ConfirmedDataGuidanceInformation provided to consumers in response to rights requests must be provided free of charge up to once during any 12-month period per consumer.observed

#

Security, DPIA and breach-notification duties are robust and in force, but the regime omits GDPR-equivalent DPO and ROPA obligations.

Primary frameworkMontana Consumer Data Privacy Act (Title 30, ch. 14, part 28, MCA); Montana data breach notification statute (Title 30, ch. 14, part 17, MCA)
Traffic-light rationale — AmberSecurity, DPIA and breach-notification duties are robust and in force, but the regime omits GDPR-equivalent DPO and ROPA obligations.

Sub-modules (7)

Accountability And DpiaAmber

DPIAs are required for processing presenting a heightened risk of harm, applicable to activities created/generated after January 1, 2025, weighing benefits against risks, factoring de-identified data use and consumer expectations.

Claims (2):

  • Controllers must conduct a data protection assessment for processing activities that present a heightened risk of harm to a consumer, applicable to processing activities created or generated after January 1, 2025, and not applied retrospectively.
  • Data protection assessments must identify and weigh the direct and indirect benefits of processing against potential risks to consumer rights, factoring the use of de-identified data, reasonable consumer expectations, and the controller-consumer relationship.

Dpo RequirementsRed

No DPO-appointment or independence requirement was identified in the MTCDPA text summarized by available sources.

Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act data protection officer requirement.

Ropa RequirementsRed

No standalone records-of-processing-activities obligation distinct from the DPIA duty was identified.

Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act records of processing activities requirement.

Joint Controller ArrangementsGreen

Processor contracts must satisfy MCA §30-14-2813; processors must adhere to controller instructions and assist controllers in meeting MTCDPA obligations.

Claims (1):

  • A contract between a controller and a processor must satisfy the requirements of MCA §30-14-2813, and a processor must adhere to controller instructions and assist the controller in meeting its MTCDPA obligations.

Security MeasuresGreen

Controllers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices.

Claims (1):

  • The MTCDPA imposes an obligation on controllers to establish, implement, and maintain reasonable administrative, technical, and physical data security practices.

Breach NotificationGreen

Montana's separate breach-notification statute requires notice to affected Montana residents without unreasonable delay and a simultaneous electronic copy of the notice to the AG's Office of Consumer Protection.

Claims (1):

  • Montana statutes governing data breaches require businesses to notify affected Montana residents without reasonable delay, and any business required to issue such a notice must simultaneously submit an electronic copy of the notice to the AG's Office of Consumer Protection.

Retention And DisposalAmber

No standalone retention-limit or disposal-duty provision was found beyond the general data-minimization principle limiting collection to what is adequate, relevant and reasonably necessary.

Claims (1):

  • Controllers must limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the disclosed purposes of processing.
Category narrative78 words

Controllers must maintain reasonable administrative, technical and physical security practices, conduct data protection assessments (DPIAs) for processing presenting a heightened risk of harm (applicable to processing activities created/generated after January 1, 2025, non-retroactively), and bind processors by contract per MCA §30-14-2813. A separate Montana data-breach-notification statute (distinct from the MTCDPA) requires notice to affected residents without unreasonable delay plus a simultaneous notice copy to the AG's Office of Consumer Protection. No DPO-appointment or standalone ROPA requirement was identified.

Sources and claims (6)
  1. ConfirmedDataGuidanceControllers must conduct a data protection assessment for processing activities that present a heightened risk of harm to a consumer, applicable to processing activities created or generated after January 1, 2025, and not applied retrospectively.observed
  2. ConfirmedDataGuidanceData protection assessments must identify and weigh the direct and indirect benefits of processing against potential risks to consumer rights, factoring the use of de-identified data, reasonable consumer expectations, and the controller-consumer relationship.observed
  3. ConfirmedMontana Department of Justice, Office of Consumer ProtectionA contract between a controller and a processor must satisfy the requirements of MCA §30-14-2813, and a processor must adhere to controller instructions and assist the controller in meeting its MTCDPA obligations.observed
  4. ConfirmedDataGuidanceThe MTCDPA imposes an obligation on controllers to establish, implement, and maintain reasonable administrative, technical, and physical data security practices.observed
  5. ConfirmedMontana Department of Justice, Office of Consumer ProtectionMontana statutes governing data breaches require businesses to notify affected Montana residents without reasonable delay, and any business required to issue such a notice must simultaneously submit an electronic copy of the notice to the AG's Office of Consumer Protection.observed
  6. ConfirmedMontana Department of Justice, Office of Consumer ProtectionControllers must limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the disclosed purposes of processing.observed

#

No comprehensive cross-border transfer regime exists in this jurisdiction at the state level.

Traffic-light rationale — RedNo comprehensive cross-border transfer regime exists in this jurisdiction at the state level.

Sub-modules (6)

Transfer MechanismsRed

No transfer-mechanism provisions identified in the MTCDPA.

Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act cross-border data transfer mechanism.

Adequacy ReceivedRed

Not applicable; Montana does not operate an adequacy framework.

Absence provenance: not recorded. Searched: Montana adequacy decision received.

Adequacy GrantedRed

Not applicable; Montana does not issue adequacy decisions.

Absence provenance: not recorded. Searched: Montana adequacy decision granted.

Sccs And BcrsRed

No SCC or BCR framework identified under the MTCDPA.

Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act standard contractual clauses BCR.

Transfer Impact AssessmentRed

No transfer-impact-assessment requirement identified.

Absence provenance: not recorded. Searched: Montana transfer impact assessment requirement.

Data LocalisationRed

No data-localisation mandate identified in Montana law.

Absence provenance: not recorded. Searched: Montana data localisation requirement.

Category narrative87 words

No cross-border transfer mechanism, adequacy-decision framework (received or granted), SCC/BCR regime, transfer-impact-assessment requirement, or data-localisation mandate was identified within the MTCDPA or its SB 297 amendments. Unlike GDPR, US state consumer-privacy statutes including Montana's do not regulate international personal-data transfers as a distinct compliance track; this is a genuine regulatory gap at the state level (federal instruments, e.g., national-security bulk-data-transfer rules, are out of scope for this JID). Searches conducted: 'Montana Consumer Data Privacy Act cross-border data transfer', 'Montana data localisation requirement', 'Montana adequacy decision privacy law'.

#

Sectoral carve-outs are well-documented for financial services, health and credit reporting, but telecoms/ePrivacy and education overlays are unconfirmed.

Primary frameworkMontana Consumer Data Privacy Act (Title 30, ch. 14, part 28, MCA), as amended by SB 297 (2025)
Traffic-light rationale — AmberSectoral carve-outs are well-documented for financial services, health and credit reporting, but telecoms/ePrivacy and education overlays are unconfirmed.

Sub-modules (7)

Financial Sector OverlayAmber

SB 297 eliminates the GLBA financial-institution entity exemption but retains the GLBA data-level exemption, and adds explicit exemptions for banks, credit unions, insurers and insurance producers.

Claims (1):

  • SB 297 eliminates the Gramm-Leach-Bliley Act entity ('financial institution') exemption but keeps the GLBA data-level exemption, and adds exemptions for banks, credit unions, insurers, and insurance producers.

Health Sector OverlayAmber

Health-related information regulated under HIPAA, including information de-identified per HIPAA standards, is exempt from the MTCDPA.

Claims (1):

  • Health-care-related information, including information derived from HIPAA-covered sources and de-identified in accordance with HIPAA privacy regulations, is exempt from the MTCDPA.

Telecoms And EprivacyRed

No Montana-specific telecoms/ePrivacy overlay distinct from the general MTCDPA opt-out/consent regime was identified.

Absence provenance: not recorded. Searched: Montana telecoms ePrivacy cookie law.

Employment DataAmber

The Act's 'consumer' definition excludes individuals acting in a commercial or employment context, effectively carving employment-context data out of MTCDPA coverage.

Claims (1):

  • The Act defines 'consumer' to exclude individuals acting in a commercial or employment context whose communications or transactions with the controller occur solely within that role.

Credit And ScoringAmber

Consumer-report data regulated under, and authorized by, the Fair Credit Reporting Act is exempt from the MTCDPA.

Claims (1):

  • Personal information bearing on a consumer's creditworthiness that is regulated by and authorized under the Fair Credit Reporting Act is exempt from the MTCDPA.

EducationRed

No Montana-specific education-sector DP overlay distinct from the general MTCDPA regime was identified.

Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act education sector FERPA overlay.

InsuranceAmber

SB 297 limits the nonprofit exemption to nonprofits detecting/preventing insurance fraud and adds exemptions for insurers and insurance producers.

Claims (1):

  • SB 297 limits the nonprofit exemption to nonprofit organizations that detect or prevent fraud in connection with insurance, and adds exemptions for insurers and insurance producers.
Category narrative78 words

MTCDPA carves out significant sectoral exemptions: GLBA-regulated data remains exempt though SB 297 removed the blanket GLBA financial-institution entity exemption (replacing it with explicit exemptions for banks, credit unions, insurers and insurance producers); HIPAA-regulated health information (including data de-identified per HIPAA) is exempt; FCRA-regulated consumer-report data is exempt; and the 'consumer' definition excludes individuals in an employment context, effectively carving out employment data. No Montana-specific telecoms/ePrivacy or education-sector DP overlay distinct from the general MTCDPA regime was identified.

Sources and claims (5)
  1. ConfirmedMontana Department of Justice, Office of Consumer ProtectionSB 297 eliminates the Gramm-Leach-Bliley Act entity ('financial institution') exemption but keeps the GLBA data-level exemption, and adds exemptions for banks, credit unions, insurers, and insurance producers.observed
  2. ConfirmedDataGuidanceHealth-care-related information, including information derived from HIPAA-covered sources and de-identified in accordance with HIPAA privacy regulations, is exempt from the MTCDPA.observed
  3. ConfirmedDataGuidanceThe Act defines 'consumer' to exclude individuals acting in a commercial or employment context whose communications or transactions with the controller occur solely within that role.observed
  4. ConfirmedDataGuidancePersonal information bearing on a consumer's creditworthiness that is regulated by and authorized under the Fair Credit Reporting Act is exempt from the MTCDPA.observed
  5. ConfirmedMontana Department of Justice, Office of Consumer ProtectionSB 297 limits the nonprofit exemption to nonprofit organizations that detect or prevent fraud in connection with insurance, and adds exemptions for insurers and insurance producers.observed

#

Opt-out and UOOM rights are confirmed and in force, but several adtech-specific sub-modules (dark patterns, cookies, clean rooms, direct marketing) are unconfirmed.

Primary frameworkMontana Consumer Data Privacy Act (Title 30, ch. 14, part 28, MCA), as amended by SB 297 (2025)
Traffic-light rationale — AmberOpt-out and UOOM rights are confirmed and in force, but several adtech-specific sub-modules (dark patterns, cookies, clean rooms, direct marketing) are unconfirmed.

Sub-modules (6)

Cookies And TrackersRed

No Montana-specific cookie/tracker consent regime distinct from the general targeted-advertising opt-out right was identified.

Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act cookie consent requirement.

Dark PatternsRed

General industry commentary notes that several state privacy laws prohibit consent obtained via dark patterns, but Montana's specific inclusion among those states was not confirmed in available sources.

Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act dark patterns prohibition.

Opt Out SignalsGreen

Montana's universal opt-out mechanism (UOOM) requirements are in effect as of January 1, 2025.

Claims (1):

  • Montana is among the states where universal opt-out mechanism (UOOM) requirements are already in effect, with the requirement (excluding California and Colorado's variant timing) going into effect January 1, 2025.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room-specific rule identified.

Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act data clean room rule.

Cross Context AdvertisingGreen

Consumers have a right to opt out of the sale of personal data and use for targeted advertising.

Claims (1):

  • Consumers have the right to opt out of the sale of personal data and of the use of personal data for targeted advertisements.

Direct MarketingAmber

No distinct direct-marketing consent/suppression-list regime beyond the general targeted-advertising opt-out right was identified.

Absence provenance: not recorded. Searched: Montana direct marketing consent suppression list law.

Category narrative57 words

Montana recognises universal opt-out mechanisms (UOOM), with UOOM-related requirements in effect since January 1, 2025, alongside a direct consumer right to opt out of sale of personal data and use for targeted advertising. No Montana-specific dark-patterns prohibition, cookie/tracker-specific consent regime, clean-room/data-collaboration-room rule, or direct-marketing suppression-list requirement distinct from the general opt-out rights was confirmed in available sources.

Sources and claims (2)
  1. ConfirmedInternational Association of Privacy ProfessionalsMontana is among the states where universal opt-out mechanism (UOOM) requirements are already in effect, with the requirement (excluding California and Colorado's variant timing) going into effect January 1, 2025.observed
  2. ConfirmedMontana Department of Justice, Office of Consumer ProtectionConsumers have the right to opt out of the sale of personal data and of the use of personal data for targeted advertisements.observed

#

Profiling opt-out and a dedicated genetic-privacy statute are confirmed and in force, but ADM transparency, AI-specific risk assessment, and surveillance carve-outs are unconfirmed.

Primary frameworkMontana Consumer Data Privacy Act (Title 30, ch. 14, part 28, MCA); Montana Genetic Information Privacy Act (SB 351, 2023)
Traffic-light rationale — AmberProfiling opt-out and a dedicated genetic-privacy statute are confirmed and in force, but ADM transparency, AI-specific risk assessment, and surveillance carve-outs are unconfirmed.

Sub-modules (6)

Profiling RestrictionsAmber

Consumers have a right to opt out of processing of personal data for profiling purposes.

Claims (1):

  • Consumers have the right to opt out of the use of personal data for profiling purposes.

Automated Decision Making TransparencyRed

No standalone ADM-transparency or explanation-right provision distinct from the profiling opt-out was identified.

Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act automated decision-making transparency right.

Ai Risk AssessmentsRed

No AI-specific risk-assessment regime distinct from the general heightened-risk DPIA duty was identified.

Absence provenance: not recorded. Searched: Montana AI risk assessment law data protection.

Biometric RegimeAmber

Biometric data processed for the purpose of uniquely identifying an individual is classified as sensitive data requiring consent under the MTCDPA.

Claims (1):

  • Sensitive data under the MTCDPA includes the processing of genetic or biometric data for the purpose of uniquely identifying an individual, requiring consumer consent.

Genetic DataGreen

The Montana Genetic Information Privacy Act requires express consumer consent for the sale, transfer, or use of genetic data for research, permits deletion of genetic data and destruction of biological samples, and allows revocation of consent.

Claims (1):

  • Montana law requires companies such as DNA-testing providers to obtain consumers' express consent for the sale, transfer, or use of genetic data for research purposes, to allow deletion of a consumer's genetic data and destruction of a consumer's biological sample, and to permit revocation of previously granted consent.

State Surveillance CarveoutsRed

No state-surveillance/national-security carve-out provision distinct from general law-enforcement cooperation norms was confirmed in available sources.

Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act law enforcement national security exemption.

Category narrative84 words

Consumers may opt out of profiling under the MTCDPA. Sensitive-data protections extend to genetic and biometric data processed for unique identification, requiring consent. Separately, the Montana Genetic Information Privacy Act (SB 351, 2023) imposes express-consent requirements for the sale, transfer, or use of genetic data for research, a right to delete genetic data and destroy biological samples, and a right to revoke consent. No standalone ADM-transparency/explanation right, AI-specific risk-assessment regime, or state-surveillance carve-out provision distinct from the general DPIA and law-enforcement norms was confirmed.

Sources and claims (3)
  1. ConfirmedMontana Department of Justice, Office of Consumer ProtectionConsumers have the right to opt out of the use of personal data for profiling purposes.observed
  2. ConfirmedDataGuidanceSensitive data under the MTCDPA includes the processing of genetic or biometric data for the purpose of uniquely identifying an individual, requiring consumer consent.observed
  3. ConfirmedMontana Department of JusticeMontana law requires companies such as DNA-testing providers to obtain consumers' express consent for the sale, transfer, or use of genetic data for research purposes, to allow deletion of a consumer's genetic data and destruction of a consumer's biological sample, and to permit revocation of previously granted consent.observed

#

Parental-consent and minor-specific heightened-risk duties are confirmed and in force, but age-verification, education-settings and dependent-adults sub-modules are unconfirmed or narrower than comparable regimes (e.g., COPPA, GDPR Art 8).

Primary frameworkMontana Consumer Data Privacy Act (Title 30, ch. 14, part 28, MCA), as amended by SB 297 (2025)
Traffic-light rationale — AmberParental-consent and minor-specific heightened-risk duties are confirmed and in force, but age-verification, education-settings and dependent-adults sub-modules are unconfirmed or narrower than comparable regimes (e.g., COPPA, GDPR Art 8).

Sub-modules (5)

Age VerificationAmber

The Act uses an actual-knowledge/willful-disregard standard for identifying minors rather than a mandatory age-verification mechanism.

Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act age verification mandate.

Minor Profiling BansAmber

Consent is required for targeted advertising or sale of personal data of consumers known to be 13 to under 16; SB 297 additionally requires reasonable care to avoid heightened risk of harm to minors from online services/products/features.

Claims (1):

  • SB 297 requires a controller offering an online service, product, or feature to a consumer whom it knows or willfully disregards is a minor to use reasonable care to avoid a heightened risk of harm to the minor caused by that service, product, or feature.

Education SettingsRed

No education-settings-specific provision distinct from the general MTCDPA regime was identified.

Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act education settings student data.

Dependent AdultsRed

No dependent-adults-specific protection provision was identified.

Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act dependent adults elderly protection.

Category narrative84 words

Rights under the MTCDPA may be invoked by a known child's parent or legal guardian on the child's behalf. Enhanced protections apply to consumers aged 13 to under 16 (consent required for targeted advertising/sale) and, per SB 297, controllers must use reasonable care to avoid a 'heightened risk of harm' to minors they know or willfully disregard as minors. There is no dedicated age-verification mandate (the standard is actual knowledge or willful disregard, not mandatory verification), and no education-settings-specific or dependent-adults-specific provision was confirmed.

Sources and claims (2)
  1. ConfirmedDataGuidanceConsumer rights under the Act can be invoked by a known child's parent or legal guardian on behalf of the known child regarding the processing of personal data.observed
  2. ConfirmedMontana Department of Justice, Office of Consumer ProtectionSB 297 requires a controller offering an online service, product, or feature to a consumer whom it knows or willfully disregards is a minor to use reasonable care to avoid a heightened risk of harm to the minor caused by that service, product, or feature.observed

#

Enforcement powers and penalties are clearly defined and in force, but the absence of a private right of action, the sunsetting cure period, and the lack of confirmed enforcement-activity/funding data temper the overall posture.

Primary frameworkMontana Consumer Data Privacy Act (Title 30, ch. 14, part 28, MCA), as amended by SB 297 (2025)
Traffic-light rationale — AmberEnforcement powers and penalties are clearly defined and in force, but the absence of a private right of action, the sunsetting cure period, and the lack of confirmed enforcement-activity/funding data temper the overall posture.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The AG may request DPIA disclosure and evaluate compliance; SB 297 sets a maximum civil penalty of up to $7,500 per violation plus injunctive relief and cost/fee recovery.

Claims (2):

  • The Attorney General is entitled to request that a controller disclose any data protection assessment relevant to an investigation, and may evaluate the assessment for compliance; such assessments remain confidential and exempt from disclosure under the Montana Freedom of Information Act.
  • SB 297 adds a maximum civil penalty of up to $7,500 per violation and allows the Attorney General to seek an injunction as well as reasonable attorney fees and investigation/enforcement costs.

Enforcement Activity IndexRed

No specific MTCDPA enforcement actions, fines, or settlements in the last 12 months were identified in available sources.

Absence provenance: not recorded. Searched: Montana Attorney General data privacy enforcement action 2025 2026.

Regulator Funding And CapacityRed

No specific headcount or funding data for the AG's Office of Consumer Protection privacy enforcement function was identified.

Absence provenance: not recorded. Searched: Montana Attorney General Office of Consumer Protection funding staffing.

Collective Redress And Class ActionsRed

No collective-redress or class-action mechanism specific to MTCDPA violations was identified; the Act's exclusion of a private right of action limits the availability of such routes.

Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act class action collective redress.

Private Right Of ActionRed

The Act expressly provides that nothing within it may be construed as creating, or being subject to, a private right of action for violations.

Claims (1):

  • The Act clarifies that nothing within it may be construed as providing the basis for, or be subject to, a private right of action for violations under the Act or any other law.

Recent Developments 180DAmber

SB 297 amendments (effective October 1, 2025) lowered the applicability threshold to 25,000 consumers, revised financial/insurance exemptions, added the minors 'heightened risk of harm' duty, and introduced a $7,500-per-violation civil penalty cap with injunctive relief.

Claims (1):

  • The Attorney General must issue a notice of violation to a controller before initiating any enforcement action, and the controller has 60 days to cure the violation, a mandatory-cure requirement that sunsets April 1, 2026.
Category narrative92 words

The Montana Attorney General has exclusive enforcement authority, can compel disclosure of DPIAs relevant to an investigation (which remain confidential/FOIA-exempt), and evaluate compliance. SB 297 introduced a maximum civil penalty of up to $7,500 per violation plus injunctive relief and recovery of attorney fees/investigation costs. A mandatory notice-of-violation and 60-day cure period applies to AG enforcement actions until it sunsets on April 1, 2026. The Act expressly provides no private right of action. No collective-redress/class-action mechanism specific to the MTCDPA, nor recent (180-day) enforcement-activity or regulator-funding data, was identified in available sources.

Sources and claims (4)
  1. ConfirmedDataGuidanceThe Attorney General is entitled to request that a controller disclose any data protection assessment relevant to an investigation, and may evaluate the assessment for compliance; such assessments remain confidential and exempt from disclosure under the Montana Freedom of Information Act.observed
  2. ConfirmedMontana Department of Justice, Office of Consumer ProtectionSB 297 adds a maximum civil penalty of up to $7,500 per violation and allows the Attorney General to seek an injunction as well as reasonable attorney fees and investigation/enforcement costs.observed
  3. ConfirmedDataGuidanceThe Act clarifies that nothing within it may be construed as providing the basis for, or be subject to, a private right of action for violations under the Act or any other law.observed
  4. ConfirmedDataGuidanceThe Attorney General must issue a notice of violation to a controller before initiating any enforcement action, and the controller has 60 days to cure the violation, a mandatory-cure requirement that sunsets April 1, 2026.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Montana
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 38 claim(s), 10 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressregulator powers and penalties
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressprivate right of action

Self-audit

regulator_and_framework, data_subject_rights, controller_processor_duties, and enforcement_and_redress modules are grounded on a mix of T1 (Montana DOJ/AG primary pages) and T3 (DataGuidance/IAPP secondary commentary) sources with strong convergence across independent secondary sources on effective dates, thresholds, and enforcement mechanics. lawful_processing_and_special_data, sectoral_watch, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, and children_and_vulnerable_groups rely predominantly on T3 secondary commentary (DataGuidance opinion pieces, IAPP articles) for granular provisions (DPIA content, sensitive-data definitions, UOOM specifics, minors' heightened-risk duty) because the underlying MCA statutory text was not directly fetched. cross_border_and_adequacy carries no T1/T3 findings at all — confirmed as a genuine regulatory gap at the state level after targeted searches.

Unresolved questions (4):

  • Exact statutory citations (MCA section numbers) for DPIA triggers, breach-notification timing, and sensitive-data definitions should be verified directly against the Montana Code Annotated rather than secondary commentary.
  • Whether Montana AG has issued any implementing rulemaking or formal guidance under the MTCDPA beyond the consumer-facing OCP web page was not confirmed.
  • Whether any MTCDPA enforcement actions, investigations, or settlements have occurred to date was not confirmed in available sources.
  • Whether Montana's dark-patterns prohibition (referenced generically as applying to 'eight state privacy laws') specifically covers Montana was not confirmed.

Escalate to primary-source review: yes