Traffic-light rationale — GreenCore omnibus instrument is in force with a clear regulator and settled scope; only the registration/filing sub-module is unpopulated.
Sub-modules (5)
Regulator And AuthorityGreen
The Montana Attorney General has exclusive statutory authority to enforce the MTCDPA.
Claims (1):
The Montana Attorney General has exclusive authority to enforce the provisions of the Montana Consumer Data Privacy Act.
Act And InstrumentsGreen
MTCDPA entered into force October 1, 2024; SB 297 amendments entered into force October 1, 2025.
Claims (2):
The Montana Consumer Data Privacy Act came into effect on October 1, 2024, after being signed by the Governor of Montana in May 2023.
Senate Bill 297 revises portions of the Montana Consumer Data Privacy Act and is effective October 1, 2025.
Material ScopeGreen
Personal data is any information linked or reasonably linkable to an identified/identifiable individual, excluding de-identified and publicly available data.
Claims (1):
"Personal data" means any information that is linked or reasonably linkable to an identified or identifiable individual and does not include de-identified data or publicly available information.
Territorial ScopeGreen
Applies to persons conducting business in Montana or targeting Montana residents that meet consumer-volume/revenue thresholds.
Claims (1):
The Act applies to those that conduct business in Montana or deliver commercial products/services intentionally targeted at Montana residents and that control or process the personal data of not less than 25,000 consumers (formerly 50,000), or of 25,000 consumers deriving more than 25% of revenue from data sales.
Regulator Registration And FilingRed
No controller/processor registration or filing obligation with the Montana AG was identified in the MTCDPA or SB 297 text summarized by available sources.
Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act controller registration filing requirement, Montana Attorney General data privacy registration.
Category narrative102 words
Montana's comprehensive consumer privacy regime is the Montana Consumer Data Privacy Act (MTCDPA), enacted 2023 and effective October 1, 2024, amended by SB 297 effective October 1, 2025. Enforcement runs exclusively through the Montana Attorney General's Office of Consumer Protection; there is no dedicated privacy agency. Material scope covers 'personal data' linked/reasonably linkable to identifiable individuals, excluding de-identified and publicly available data. Territorial scope reaches any person conducting business in Montana or targeting products/services at Montana residents, subject to consumer-volume thresholds (25,000 consumers post-SB297, previously 50,000, or 25,000 with 25%+ revenue from data sales). No controller registration or filing regime was identified.
Sources and claims (5)
ConfirmedDataGuidance — The Montana Attorney General has exclusive authority to enforce the provisions of the Montana Consumer Data Privacy Act.observed
ConfirmedDataGuidance — The Montana Consumer Data Privacy Act came into effect on October 1, 2024, after being signed by the Governor of Montana in May 2023.observed
ConfirmedMontana Department of Justice, Office of Consumer Protection — "Personal data" means any information that is linked or reasonably linkable to an identified or identifiable individual and does not include de-identified data or publicly available information.observed
ConfirmedMontana Department of Justice, Office of Consumer Protection — The Act applies to those that conduct business in Montana or deliver commercial products/services intentionally targeted at Montana residents and that control or process the personal data of not less than 25,000 consumers (formerly 50,000), or of 25,000 consumers deriving more than 25% of revenue from data sales.observed
Traffic-light rationale — AmberConsent and sensitive-data protections exist but the regime lacks a GDPR Art 6-equivalent enumerated lawful-basis structure.
Sub-modules (4)
Lawful BasesAmber
Processing is limited to what is adequate, relevant and reasonably necessary for disclosed purposes; processing for new, incompatible purposes requires consent.
Claims (1):
Controllers must not process personal data for purposes that are neither reasonably necessary to, nor compatible with, the disclosed purposes for which the personal data is processed unless the controller obtains the consumer's consent.
Consent ThresholdsGreen
Controllers must provide an easy consent-revocation mechanism and cease processing within 45 days; heightened consent duties apply for minors aged 13 to under 16 regarding targeted ads/sale.
Claims (2):
Controllers must provide an effective mechanism for a consumer to revoke consent that is at least as easy as the mechanism used to grant consent, and must cease processing the personal data no later than 45 days after receipt of the revocation request.
A controller may not process personal data for targeted advertising or sell a consumer's personal data without consent when it has actual knowledge that the consumer is at least 13 but younger than 16 years of age.
Special CategoriesGreen
Sensitive data covers racial/ethnic origin, religious beliefs, health conditions, sex life/sexual orientation, citizenship/immigration status, and genetic/biometric data processed for unique identification.
Claims (1):
Sensitive data means personal data revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis, sex life, sexual orientation, citizenship or immigration status, or genetic/biometric data processed for the purpose of uniquely identifying an individual.
Pseudonymisation And AnonymisationGreen
De-identified data is excluded from the 'personal data' definition, and DPIAs must factor in the use of de-identified data as a risk-mitigation element.
Claims (1):
Personal data excludes de-identified data, and data protection assessments must factor in a controller's use of de-identified data as a risk-mitigating circumstance.
Category narrative76 words
MTCDPA does not use a GDPR-style enumerated list of lawful bases. Instead, processing is generally permitted subject to a data-minimization/purpose-limitation rule, with consent required for secondary/incompatible purposes, for sale/targeted-advertising/profiling opt-outs, for sensitive data, and for minors aged 13 to under 16. Sensitive data is broadly defined (race/ethnicity, religion, health, sex life/orientation, citizenship/immigration status, and genetic/biometric data used for unique identification). De-identified data is carved out of the 'personal data' definition, functioning as a pseudonymisation/anonymisation safe harbour.
Sources and claims (5)
ProbableDataGuidance — Controllers must not process personal data for purposes that are neither reasonably necessary to, nor compatible with, the disclosed purposes for which the personal data is processed unless the controller obtains the consumer's consent.observed
ConfirmedDataGuidance — Controllers must provide an effective mechanism for a consumer to revoke consent that is at least as easy as the mechanism used to grant consent, and must cease processing the personal data no later than 45 days after receipt of the revocation request.observed
ConfirmedDataGuidance — A controller may not process personal data for targeted advertising or sell a consumer's personal data without consent when it has actual knowledge that the consumer is at least 13 but younger than 16 years of age.observed
ConfirmedDataGuidance — Sensitive data means personal data revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis, sex life, sexual orientation, citizenship or immigration status, or genetic/biometric data processed for the purpose of uniquely identifying an individual.observed
ConfirmedMontana Department of Justice, Office of Consumer Protection — Personal data excludes de-identified data, and data protection assessments must factor in a controller's use of de-identified data as a risk-mitigating circumstance.observed
Traffic-light rationale — GreenThe rights catalogue and response-deadline framework are clear, consistent, and in force.
Sub-modules (5)
Access RightGreen
Consumers have a right to know what personal data is collected and processed about them.
Claims (1):
Montanans have a right to know what personal data is collected and processed about them.
Rectification And ErasureGreen
Consumers have rights to correct inaccuracies and to delete personal data.
Claims (1):
Consumers have a right to correct inaccuracies in their personal data and a right to delete personal data about the consumer.
Restriction And ObjectionGreen
Consumers may opt out of the sale of personal data, use for targeted advertising, or use for profiling.
Claims (1):
Consumers have the right to opt out of the sale of personal data, use of personal data for targeted advertisements, or use of personal data for profiling purposes.
Data PortabilityGreen
Consumers have the right to obtain a copy of their personal data from the controller.
Claims (1):
Consumers have a right to obtain a copy of the consumer's personal data from the controller.
Deadlines And Response WindowsGreen
Controllers must respond within 45 days (extendable once by 45 more days with notice), and must provide the first response in a 12-month period free of charge.
Claims (2):
Controllers must respond to consumer requests without undue delay and no later than 45 days after receipt, extendable by an additional 45 days when reasonably necessary, provided the consumer is informed of the extension within the original 45-day period.
Information provided to consumers in response to rights requests must be provided free of charge up to once during any 12-month period per consumer.
Category narrative69 words
Montanans have a right to know/access what personal data is collected and processed, correct inaccuracies, delete personal data, obtain a portable copy, and opt out of sale, targeted advertising, and profiling. Controllers must respond without undue delay and no later than 45 days after receipt of a request, extendable once by an additional 45 days with notice to the consumer; the first response in any 12-month period is free.
ConfirmedMontana Department of Justice, Office of Consumer Protection — Consumers have the right to opt out of the sale of personal data, use of personal data for targeted advertisements, or use of personal data for profiling purposes.observed
ConfirmedDataGuidance — Controllers must respond to consumer requests without undue delay and no later than 45 days after receipt, extendable by an additional 45 days when reasonably necessary, provided the consumer is informed of the extension within the original 45-day period.observed
ConfirmedDataGuidance — Information provided to consumers in response to rights requests must be provided free of charge up to once during any 12-month period per consumer.observed
Traffic-light rationale — AmberSecurity, DPIA and breach-notification duties are robust and in force, but the regime omits GDPR-equivalent DPO and ROPA obligations.
Sub-modules (7)
Accountability And DpiaAmber
DPIAs are required for processing presenting a heightened risk of harm, applicable to activities created/generated after January 1, 2025, weighing benefits against risks, factoring de-identified data use and consumer expectations.
Claims (2):
Controllers must conduct a data protection assessment for processing activities that present a heightened risk of harm to a consumer, applicable to processing activities created or generated after January 1, 2025, and not applied retrospectively.
Data protection assessments must identify and weigh the direct and indirect benefits of processing against potential risks to consumer rights, factoring the use of de-identified data, reasonable consumer expectations, and the controller-consumer relationship.
Dpo RequirementsRed
No DPO-appointment or independence requirement was identified in the MTCDPA text summarized by available sources.
Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act data protection officer requirement.
Ropa RequirementsRed
No standalone records-of-processing-activities obligation distinct from the DPIA duty was identified.
Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act records of processing activities requirement.
Joint Controller ArrangementsGreen
Processor contracts must satisfy MCA §30-14-2813; processors must adhere to controller instructions and assist controllers in meeting MTCDPA obligations.
Claims (1):
A contract between a controller and a processor must satisfy the requirements of MCA §30-14-2813, and a processor must adhere to controller instructions and assist the controller in meeting its MTCDPA obligations.
Security MeasuresGreen
Controllers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices.
Claims (1):
The MTCDPA imposes an obligation on controllers to establish, implement, and maintain reasonable administrative, technical, and physical data security practices.
Breach NotificationGreen
Montana's separate breach-notification statute requires notice to affected Montana residents without unreasonable delay and a simultaneous electronic copy of the notice to the AG's Office of Consumer Protection.
Claims (1):
Montana statutes governing data breaches require businesses to notify affected Montana residents without reasonable delay, and any business required to issue such a notice must simultaneously submit an electronic copy of the notice to the AG's Office of Consumer Protection.
Retention And DisposalAmber
No standalone retention-limit or disposal-duty provision was found beyond the general data-minimization principle limiting collection to what is adequate, relevant and reasonably necessary.
Claims (1):
Controllers must limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the disclosed purposes of processing.
Category narrative78 words
Controllers must maintain reasonable administrative, technical and physical security practices, conduct data protection assessments (DPIAs) for processing presenting a heightened risk of harm (applicable to processing activities created/generated after January 1, 2025, non-retroactively), and bind processors by contract per MCA §30-14-2813. A separate Montana data-breach-notification statute (distinct from the MTCDPA) requires notice to affected residents without unreasonable delay plus a simultaneous notice copy to the AG's Office of Consumer Protection. No DPO-appointment or standalone ROPA requirement was identified.
Sources and claims (6)
ConfirmedDataGuidance — Controllers must conduct a data protection assessment for processing activities that present a heightened risk of harm to a consumer, applicable to processing activities created or generated after January 1, 2025, and not applied retrospectively.observed
ConfirmedDataGuidance — Data protection assessments must identify and weigh the direct and indirect benefits of processing against potential risks to consumer rights, factoring the use of de-identified data, reasonable consumer expectations, and the controller-consumer relationship.observed
ConfirmedMontana Department of Justice, Office of Consumer Protection — A contract between a controller and a processor must satisfy the requirements of MCA §30-14-2813, and a processor must adhere to controller instructions and assist the controller in meeting its MTCDPA obligations.observed
ConfirmedDataGuidance — The MTCDPA imposes an obligation on controllers to establish, implement, and maintain reasonable administrative, technical, and physical data security practices.observed
ConfirmedMontana Department of Justice, Office of Consumer Protection — Montana statutes governing data breaches require businesses to notify affected Montana residents without reasonable delay, and any business required to issue such a notice must simultaneously submit an electronic copy of the notice to the AG's Office of Consumer Protection.observed
ConfirmedMontana Department of Justice, Office of Consumer Protection — Controllers must limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the disclosed purposes of processing.observed
No comprehensive cross-border transfer regime exists in this jurisdiction at the state level.
Traffic-light rationale — RedNo comprehensive cross-border transfer regime exists in this jurisdiction at the state level.
Sub-modules (6)
Transfer MechanismsRed
No transfer-mechanism provisions identified in the MTCDPA.
Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act cross-border data transfer mechanism.
Adequacy ReceivedRed
Not applicable; Montana does not operate an adequacy framework.
Absence provenance: not recorded. Searched: Montana adequacy decision received.
Adequacy GrantedRed
Not applicable; Montana does not issue adequacy decisions.
Absence provenance: not recorded. Searched: Montana adequacy decision granted.
Sccs And BcrsRed
No SCC or BCR framework identified under the MTCDPA.
Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act standard contractual clauses BCR.
Transfer Impact AssessmentRed
No transfer-impact-assessment requirement identified.
Absence provenance: not recorded. Searched: Montana transfer impact assessment requirement.
Data LocalisationRed
No data-localisation mandate identified in Montana law.
Absence provenance: not recorded. Searched: Montana data localisation requirement.
Category narrative87 words
No cross-border transfer mechanism, adequacy-decision framework (received or granted), SCC/BCR regime, transfer-impact-assessment requirement, or data-localisation mandate was identified within the MTCDPA or its SB 297 amendments. Unlike GDPR, US state consumer-privacy statutes including Montana's do not regulate international personal-data transfers as a distinct compliance track; this is a genuine regulatory gap at the state level (federal instruments, e.g., national-security bulk-data-transfer rules, are out of scope for this JID). Searches conducted: 'Montana Consumer Data Privacy Act cross-border data transfer', 'Montana data localisation requirement', 'Montana adequacy decision privacy law'.
Sectoral carve-outs are well-documented for financial services, health and credit reporting, but telecoms/ePrivacy and education overlays are unconfirmed.
Primary frameworkMontana Consumer Data Privacy Act (Title 30, ch. 14, part 28, MCA), as amended by SB 297 (2025)
Traffic-light rationale — AmberSectoral carve-outs are well-documented for financial services, health and credit reporting, but telecoms/ePrivacy and education overlays are unconfirmed.
Sub-modules (7)
Financial Sector OverlayAmber
SB 297 eliminates the GLBA financial-institution entity exemption but retains the GLBA data-level exemption, and adds explicit exemptions for banks, credit unions, insurers and insurance producers.
Claims (1):
SB 297 eliminates the Gramm-Leach-Bliley Act entity ('financial institution') exemption but keeps the GLBA data-level exemption, and adds exemptions for banks, credit unions, insurers, and insurance producers.
Health Sector OverlayAmber
Health-related information regulated under HIPAA, including information de-identified per HIPAA standards, is exempt from the MTCDPA.
Claims (1):
Health-care-related information, including information derived from HIPAA-covered sources and de-identified in accordance with HIPAA privacy regulations, is exempt from the MTCDPA.
Telecoms And EprivacyRed
No Montana-specific telecoms/ePrivacy overlay distinct from the general MTCDPA opt-out/consent regime was identified.
Absence provenance: not recorded. Searched: Montana telecoms ePrivacy cookie law.
Employment DataAmber
The Act's 'consumer' definition excludes individuals acting in a commercial or employment context, effectively carving employment-context data out of MTCDPA coverage.
Claims (1):
The Act defines 'consumer' to exclude individuals acting in a commercial or employment context whose communications or transactions with the controller occur solely within that role.
Credit And ScoringAmber
Consumer-report data regulated under, and authorized by, the Fair Credit Reporting Act is exempt from the MTCDPA.
Claims (1):
Personal information bearing on a consumer's creditworthiness that is regulated by and authorized under the Fair Credit Reporting Act is exempt from the MTCDPA.
EducationRed
No Montana-specific education-sector DP overlay distinct from the general MTCDPA regime was identified.
Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act education sector FERPA overlay.
InsuranceAmber
SB 297 limits the nonprofit exemption to nonprofits detecting/preventing insurance fraud and adds exemptions for insurers and insurance producers.
Claims (1):
SB 297 limits the nonprofit exemption to nonprofit organizations that detect or prevent fraud in connection with insurance, and adds exemptions for insurers and insurance producers.
Category narrative78 words
MTCDPA carves out significant sectoral exemptions: GLBA-regulated data remains exempt though SB 297 removed the blanket GLBA financial-institution entity exemption (replacing it with explicit exemptions for banks, credit unions, insurers and insurance producers); HIPAA-regulated health information (including data de-identified per HIPAA) is exempt; FCRA-regulated consumer-report data is exempt; and the 'consumer' definition excludes individuals in an employment context, effectively carving out employment data. No Montana-specific telecoms/ePrivacy or education-sector DP overlay distinct from the general MTCDPA regime was identified.
Sources and claims (5)
ConfirmedMontana Department of Justice, Office of Consumer Protection — SB 297 eliminates the Gramm-Leach-Bliley Act entity ('financial institution') exemption but keeps the GLBA data-level exemption, and adds exemptions for banks, credit unions, insurers, and insurance producers.observed
ConfirmedDataGuidance — Health-care-related information, including information derived from HIPAA-covered sources and de-identified in accordance with HIPAA privacy regulations, is exempt from the MTCDPA.observed
ConfirmedDataGuidance — The Act defines 'consumer' to exclude individuals acting in a commercial or employment context whose communications or transactions with the controller occur solely within that role.observed
ConfirmedDataGuidance — Personal information bearing on a consumer's creditworthiness that is regulated by and authorized under the Fair Credit Reporting Act is exempt from the MTCDPA.observed
ConfirmedMontana Department of Justice, Office of Consumer Protection — SB 297 limits the nonprofit exemption to nonprofit organizations that detect or prevent fraud in connection with insurance, and adds exemptions for insurers and insurance producers.observed
Opt-out and UOOM rights are confirmed and in force, but several adtech-specific sub-modules (dark patterns, cookies, clean rooms, direct marketing) are unconfirmed.
Primary frameworkMontana Consumer Data Privacy Act (Title 30, ch. 14, part 28, MCA), as amended by SB 297 (2025)
Traffic-light rationale — AmberOpt-out and UOOM rights are confirmed and in force, but several adtech-specific sub-modules (dark patterns, cookies, clean rooms, direct marketing) are unconfirmed.
Sub-modules (6)
Cookies And TrackersRed
No Montana-specific cookie/tracker consent regime distinct from the general targeted-advertising opt-out right was identified.
Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act cookie consent requirement.
Dark PatternsRed
General industry commentary notes that several state privacy laws prohibit consent obtained via dark patterns, but Montana's specific inclusion among those states was not confirmed in available sources.
Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act dark patterns prohibition.
Opt Out SignalsGreen
Montana's universal opt-out mechanism (UOOM) requirements are in effect as of January 1, 2025.
Claims (1):
Montana is among the states where universal opt-out mechanism (UOOM) requirements are already in effect, with the requirement (excluding California and Colorado's variant timing) going into effect January 1, 2025.
Clean Rooms And DcrRed
No clean-room/data-collaboration-room-specific rule identified.
Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act data clean room rule.
Cross Context AdvertisingGreen
Consumers have a right to opt out of the sale of personal data and use for targeted advertising.
Claims (1):
Consumers have the right to opt out of the sale of personal data and of the use of personal data for targeted advertisements.
Direct MarketingAmber
No distinct direct-marketing consent/suppression-list regime beyond the general targeted-advertising opt-out right was identified.
Absence provenance: not recorded. Searched: Montana direct marketing consent suppression list law.
Category narrative57 words
Montana recognises universal opt-out mechanisms (UOOM), with UOOM-related requirements in effect since January 1, 2025, alongside a direct consumer right to opt out of sale of personal data and use for targeted advertising. No Montana-specific dark-patterns prohibition, cookie/tracker-specific consent regime, clean-room/data-collaboration-room rule, or direct-marketing suppression-list requirement distinct from the general opt-out rights was confirmed in available sources.
Sources and claims (2)
ConfirmedInternational Association of Privacy Professionals — Montana is among the states where universal opt-out mechanism (UOOM) requirements are already in effect, with the requirement (excluding California and Colorado's variant timing) going into effect January 1, 2025.observed
Profiling opt-out and a dedicated genetic-privacy statute are confirmed and in force, but ADM transparency, AI-specific risk assessment, and surveillance carve-outs are unconfirmed.
Primary frameworkMontana Consumer Data Privacy Act (Title 30, ch. 14, part 28, MCA); Montana Genetic Information Privacy Act (SB 351, 2023)
Traffic-light rationale — AmberProfiling opt-out and a dedicated genetic-privacy statute are confirmed and in force, but ADM transparency, AI-specific risk assessment, and surveillance carve-outs are unconfirmed.
Sub-modules (6)
Profiling RestrictionsAmber
Consumers have a right to opt out of processing of personal data for profiling purposes.
Claims (1):
Consumers have the right to opt out of the use of personal data for profiling purposes.
Automated Decision Making TransparencyRed
No standalone ADM-transparency or explanation-right provision distinct from the profiling opt-out was identified.
Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act automated decision-making transparency right.
Ai Risk AssessmentsRed
No AI-specific risk-assessment regime distinct from the general heightened-risk DPIA duty was identified.
Absence provenance: not recorded. Searched: Montana AI risk assessment law data protection.
Biometric RegimeAmber
Biometric data processed for the purpose of uniquely identifying an individual is classified as sensitive data requiring consent under the MTCDPA.
Claims (1):
Sensitive data under the MTCDPA includes the processing of genetic or biometric data for the purpose of uniquely identifying an individual, requiring consumer consent.
Genetic DataGreen
The Montana Genetic Information Privacy Act requires express consumer consent for the sale, transfer, or use of genetic data for research, permits deletion of genetic data and destruction of biological samples, and allows revocation of consent.
Claims (1):
Montana law requires companies such as DNA-testing providers to obtain consumers' express consent for the sale, transfer, or use of genetic data for research purposes, to allow deletion of a consumer's genetic data and destruction of a consumer's biological sample, and to permit revocation of previously granted consent.
State Surveillance CarveoutsRed
No state-surveillance/national-security carve-out provision distinct from general law-enforcement cooperation norms was confirmed in available sources.
Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act law enforcement national security exemption.
Category narrative84 words
Consumers may opt out of profiling under the MTCDPA. Sensitive-data protections extend to genetic and biometric data processed for unique identification, requiring consent. Separately, the Montana Genetic Information Privacy Act (SB 351, 2023) imposes express-consent requirements for the sale, transfer, or use of genetic data for research, a right to delete genetic data and destroy biological samples, and a right to revoke consent. No standalone ADM-transparency/explanation right, AI-specific risk-assessment regime, or state-surveillance carve-out provision distinct from the general DPIA and law-enforcement norms was confirmed.
ConfirmedDataGuidance — Sensitive data under the MTCDPA includes the processing of genetic or biometric data for the purpose of uniquely identifying an individual, requiring consumer consent.observed
ConfirmedMontana Department of Justice — Montana law requires companies such as DNA-testing providers to obtain consumers' express consent for the sale, transfer, or use of genetic data for research purposes, to allow deletion of a consumer's genetic data and destruction of a consumer's biological sample, and to permit revocation of previously granted consent.observed
Parental-consent and minor-specific heightened-risk duties are confirmed and in force, but age-verification, education-settings and dependent-adults sub-modules are unconfirmed or narrower than comparable regimes (e.g., COPPA, GDPR Art 8).
Primary frameworkMontana Consumer Data Privacy Act (Title 30, ch. 14, part 28, MCA), as amended by SB 297 (2025)
Traffic-light rationale — AmberParental-consent and minor-specific heightened-risk duties are confirmed and in force, but age-verification, education-settings and dependent-adults sub-modules are unconfirmed or narrower than comparable regimes (e.g., COPPA, GDPR Art 8).
Sub-modules (5)
Age VerificationAmber
The Act uses an actual-knowledge/willful-disregard standard for identifying minors rather than a mandatory age-verification mechanism.
Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act age verification mandate.
Parental ConsentGreen
Consumer rights under the Act may be invoked by a known child's parent or legal guardian on the child's behalf.
Claims (1):
Consumer rights under the Act can be invoked by a known child's parent or legal guardian on behalf of the known child regarding the processing of personal data.
Minor Profiling BansAmber
Consent is required for targeted advertising or sale of personal data of consumers known to be 13 to under 16; SB 297 additionally requires reasonable care to avoid heightened risk of harm to minors from online services/products/features.
Claims (1):
SB 297 requires a controller offering an online service, product, or feature to a consumer whom it knows or willfully disregards is a minor to use reasonable care to avoid a heightened risk of harm to the minor caused by that service, product, or feature.
Education SettingsRed
No education-settings-specific provision distinct from the general MTCDPA regime was identified.
Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act education settings student data.
Dependent AdultsRed
No dependent-adults-specific protection provision was identified.
Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act dependent adults elderly protection.
Category narrative84 words
Rights under the MTCDPA may be invoked by a known child's parent or legal guardian on the child's behalf. Enhanced protections apply to consumers aged 13 to under 16 (consent required for targeted advertising/sale) and, per SB 297, controllers must use reasonable care to avoid a 'heightened risk of harm' to minors they know or willfully disregard as minors. There is no dedicated age-verification mandate (the standard is actual knowledge or willful disregard, not mandatory verification), and no education-settings-specific or dependent-adults-specific provision was confirmed.
Sources and claims (2)
ConfirmedDataGuidance — Consumer rights under the Act can be invoked by a known child's parent or legal guardian on behalf of the known child regarding the processing of personal data.observed
ConfirmedMontana Department of Justice, Office of Consumer Protection — SB 297 requires a controller offering an online service, product, or feature to a consumer whom it knows or willfully disregards is a minor to use reasonable care to avoid a heightened risk of harm to the minor caused by that service, product, or feature.observed
Enforcement powers and penalties are clearly defined and in force, but the absence of a private right of action, the sunsetting cure period, and the lack of confirmed enforcement-activity/funding data temper the overall posture.
Primary frameworkMontana Consumer Data Privacy Act (Title 30, ch. 14, part 28, MCA), as amended by SB 297 (2025)
Traffic-light rationale — AmberEnforcement powers and penalties are clearly defined and in force, but the absence of a private right of action, the sunsetting cure period, and the lack of confirmed enforcement-activity/funding data temper the overall posture.
Sub-modules (6)
Regulator Powers And PenaltiesAmber
The AG may request DPIA disclosure and evaluate compliance; SB 297 sets a maximum civil penalty of up to $7,500 per violation plus injunctive relief and cost/fee recovery.
Claims (2):
The Attorney General is entitled to request that a controller disclose any data protection assessment relevant to an investigation, and may evaluate the assessment for compliance; such assessments remain confidential and exempt from disclosure under the Montana Freedom of Information Act.
SB 297 adds a maximum civil penalty of up to $7,500 per violation and allows the Attorney General to seek an injunction as well as reasonable attorney fees and investigation/enforcement costs.
Enforcement Activity IndexRed
No specific MTCDPA enforcement actions, fines, or settlements in the last 12 months were identified in available sources.
Absence provenance: not recorded. Searched: Montana Attorney General data privacy enforcement action 2025 2026.
Regulator Funding And CapacityRed
No specific headcount or funding data for the AG's Office of Consumer Protection privacy enforcement function was identified.
Absence provenance: not recorded. Searched: Montana Attorney General Office of Consumer Protection funding staffing.
Collective Redress And Class ActionsRed
No collective-redress or class-action mechanism specific to MTCDPA violations was identified; the Act's exclusion of a private right of action limits the availability of such routes.
Absence provenance: not recorded. Searched: Montana Consumer Data Privacy Act class action collective redress.
Private Right Of ActionRed
The Act expressly provides that nothing within it may be construed as creating, or being subject to, a private right of action for violations.
Claims (1):
The Act clarifies that nothing within it may be construed as providing the basis for, or be subject to, a private right of action for violations under the Act or any other law.
Recent Developments 180DAmber
SB 297 amendments (effective October 1, 2025) lowered the applicability threshold to 25,000 consumers, revised financial/insurance exemptions, added the minors 'heightened risk of harm' duty, and introduced a $7,500-per-violation civil penalty cap with injunctive relief.
Claims (1):
The Attorney General must issue a notice of violation to a controller before initiating any enforcement action, and the controller has 60 days to cure the violation, a mandatory-cure requirement that sunsets April 1, 2026.
Category narrative92 words
The Montana Attorney General has exclusive enforcement authority, can compel disclosure of DPIAs relevant to an investigation (which remain confidential/FOIA-exempt), and evaluate compliance. SB 297 introduced a maximum civil penalty of up to $7,500 per violation plus injunctive relief and recovery of attorney fees/investigation costs. A mandatory notice-of-violation and 60-day cure period applies to AG enforcement actions until it sunsets on April 1, 2026. The Act expressly provides no private right of action. No collective-redress/class-action mechanism specific to the MTCDPA, nor recent (180-day) enforcement-activity or regulator-funding data, was identified in available sources.
Sources and claims (4)
ConfirmedDataGuidance — The Attorney General is entitled to request that a controller disclose any data protection assessment relevant to an investigation, and may evaluate the assessment for compliance; such assessments remain confidential and exempt from disclosure under the Montana Freedom of Information Act.observed
ConfirmedMontana Department of Justice, Office of Consumer Protection — SB 297 adds a maximum civil penalty of up to $7,500 per violation and allows the Attorney General to seek an injunction as well as reasonable attorney fees and investigation/enforcement costs.observed
ConfirmedDataGuidance — The Act clarifies that nothing within it may be construed as providing the basis for, or be subject to, a private right of action for violations under the Act or any other law.observed
ConfirmedDataGuidance — The Attorney General must issue a notice of violation to a controller before initiating any enforcement action, and the controller has 60 days to cure the violation, a mandatory-cure requirement that sunsets April 1, 2026.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for United States – Montana
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 38 claim(s), 10 source(s) in the cumulative register.
GDPR article map
Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).
regulator_and_framework, data_subject_rights, controller_processor_duties, and enforcement_and_redress modules are grounded on a mix of T1 (Montana DOJ/AG primary pages) and T3 (DataGuidance/IAPP secondary commentary) sources with strong convergence across independent secondary sources on effective dates, thresholds, and enforcement mechanics. lawful_processing_and_special_data, sectoral_watch, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, and children_and_vulnerable_groups rely predominantly on T3 secondary commentary (DataGuidance opinion pieces, IAPP articles) for granular provisions (DPIA content, sensitive-data definitions, UOOM specifics, minors' heightened-risk duty) because the underlying MCA statutory text was not directly fetched. cross_border_and_adequacy carries no T1/T3 findings at all — confirmed as a genuine regulatory gap at the state level after targeted searches.
Unresolved questions (4):
Exact statutory citations (MCA section numbers) for DPIA triggers, breach-notification timing, and sensitive-data definitions should be verified directly against the Montana Code Annotated rather than secondary commentary.
Whether Montana AG has issued any implementing rulemaking or formal guidance under the MTCDPA beyond the consumer-facing OCP web page was not confirmed.
Whether any MTCDPA enforcement actions, investigations, or settlements have occurred to date was not confirmed in available sources.
Whether Montana's dark-patterns prohibition (referenced generically as applying to 'eight state privacy laws') specifically covers Montana was not confirmed.