{
  "type": "practice-guide",
  "canonical": "https://openagreements.org/practice-guides/privacy/us/minnesota",
  "links": [
    {
      "rel": "self",
      "href": "https://openagreements.org/practice-guides/privacy/us/minnesota.json",
      "type": "application/json"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/minnesota",
      "type": "text/html"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/minnesota/markdown",
      "type": "text/markdown"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/minnesota/json",
      "type": "application/json"
    }
  ],
  "data": {
    "topic": "privacy",
    "state": "minnesota",
    "frontmatter": {
      "title": "Minnesota Consumer Privacy Law (MCDPA)",
      "description": "The Minnesota Consumer Data Privacy Act gives Minnesota consumers rights over their personal data and imposes notice, contracting, and consent duties on controllers above defined thresholds. Built on the Virginia model but distinctively stricter — it lets consumers demand a list of the specific third parties their data was disclosed to, grants profiling-reevaluation rights, has no general nonprofit exemption, and its right to cure has already sunset. Enforced exclusively by the Attorney General with no private right of action.",
      "state": "Minnesota",
      "lastReviewed": "2026-06-06",
      "license": "CC BY 4.0",
      "authors": [
        "steven-obiajulu"
      ],
      "summary": {
        "keyLaw": "Minn. Stat. §§ 325M.10–325M.21 (Minnesota Consumer Data Privacy Act), effective July 31, 2025",
        "appliesTo": "Legal entities doing business in Minnesota (or targeting residents) that control or process the data of 100,000+ consumers a year (excluding payment-only data), or 25,000+ while deriving over 25% of gross revenue from selling data — no general nonprofit exemption; small businesses exempt except they still cannot sell sensitive data without consent",
        "privacyPolicyRequired": "Yes — a reasonably accessible, clear, and meaningful notice with statutorily fixed contents",
        "privateRightOfAction": "No — enforcement is exclusively the Attorney General's",
        "regulator": "Minnesota Attorney General (exclusive)",
        "bottomLine": "If you control or process the data of 100,000+ Minnesota consumers (or 25,000+ plus over 25% of revenue from data sales), the MCDPA requires a privacy notice, opt-in consent to process sensitive data, and processor contracts — plus a uniquely strict list-of-third-parties right and profiling-reevaluation rights. The Attorney General enforces it; there are no consumer lawsuits, and the 30-day cure period has already expired.",
        "lawCoverage": "comprehensive",
        "policyMandate": "statutoryContents",
        "consumersCanSue": "no",
        "sensitiveDataConsent": "optIn",
        "universalOptOutSignal": "required"
      },
      "about": [
        "Minnesota Consumer Data Privacy Act MCDPA",
        "Minnesota privacy policy requirements",
        "Minnesota privacy notice contents",
        "MCDPA applicability thresholds",
        "MCDPA sensitive data consent",
        "MCDPA processor contract requirements",
        "MCDPA list of third parties right",
        "Minnesota Attorney General privacy enforcement",
        "MCDPA no private right of action"
      ],
      "translations": [
        {
          "language": "中文",
          "status": "planned"
        },
        {
          "language": "Español",
          "status": "planned"
        },
        {
          "language": "Português",
          "status": "planned"
        },
        {
          "language": "Deutsch",
          "status": "planned"
        }
      ]
    },
    "questions": [
      {
        "slug": "does-mcdpa-apply",
        "label": "Does the Minnesota Consumer Data Privacy Act apply to your business?",
        "heading": "Does the Minnesota Consumer Data Privacy Act apply to your business?",
        "answerText": "It turns on how much consumer data you handle. The MCDPA applies to entities that do business in Minnesota or target its residents and that, in a calendar year, control or process the personal data of at least 100,000 consumers (excluding data used only to complete a payment), or at least 25,000 consumers while deriving over 25% of gross revenue from selling personal data. A consumer means a Minnesota resident acting in an individual or household context, not someone acting in a commercial or employment role.",
        "sources": [
          {
            "id": "stat-12-scope",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Minn. Stat. § 325M.12",
            "citation": "Minn. Stat. § 325M.12, subd. 1(a).",
            "url": "https://www.revisor.mn.gov/statutes/cite/325M.12",
            "proposition": "The MCDPA applies to entities doing business in Minnesota or targeting its residents that control or process the data of at least 100,000 consumers (excluding payment-only data), or 25,000+ while deriving over 25% of gross revenue from selling personal data.",
            "verbatimQuote": "Sections 325M.10 to 325M.21 apply to legal entities that conduct business in Minnesota or produce products or services that are targeted to residents of Minnesota, and that satisfy one or more of the following thresholds: (1) during a calendar year, controls or processes personal data of 100,000 consumers or more, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or (2) derives over 25 percent of gross revenue from the sale of personal data and processes or controls personal data of 25,000 consumers or more.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/minnesota#src-stat-12-scope"
          },
          {
            "id": "stat-17-smallbiz",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Minn. Stat. § 325M.17",
            "citation": "Minn. Stat. § 325M.17(a).",
            "url": "https://www.revisor.mn.gov/statutes/cite/325M.17",
            "proposition": "A small business that is otherwise exempt must still not sell a consumer's sensitive data without the consumer's prior consent.",
            "verbatimQuote": "A small business, as defined by the United States Small Business Administration under Code of Federal Regulations, title 13, part 121, that conducts business in Minnesota or produces products or services that are targeted to residents of Minnesota, must not sell a consumer's sensitive data without the consumer's prior consent.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/minnesota#src-stat-17-smallbiz"
          }
        ]
      },
      {
        "slug": "privacy-policy-contents",
        "label": "What must your Minnesota privacy policy contain?",
        "heading": "What must your Minnesota privacy policy contain?",
        "answerText": "A controller must provide a reasonably accessible, clear, and meaningful privacy notice that lists the categories of personal data processed, the purposes for processing, how consumers exercise and appeal their rights, the categories of data sold or shared and the categories of third parties involved, the controller's contact information, its retention policies, and the date the notice was last updated. Minnesota also makes you document your compliance program internally — including naming a privacy lead and keeping a data inventory.",
        "sources": [
          {
            "id": "stat-16-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Minn. Stat. § 325M.16",
            "citation": "Minn. Stat. § 325M.16, subd. 1(a).",
            "url": "https://www.revisor.mn.gov/statutes/cite/325M.16",
            "proposition": "A controller must provide a reasonably accessible, clear, and meaningful privacy notice that includes the categories of personal data processed and the purposes for processing, among other required disclosures.",
            "verbatimQuote": "Controllers must provide consumers with a reasonably accessible, clear, and meaningful privacy notice that includes: (1) the categories of personal data processed by the controller; (2) the purposes for which the categories of personal data are processed;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/minnesota#src-stat-16-notice"
          },
          {
            "id": "stat-18-policies",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Minn. Stat. § 325M.18",
            "citation": "Minn. Stat. § 325M.18(a).",
            "url": "https://www.revisor.mn.gov/statutes/cite/325M.18",
            "proposition": "A controller must document and maintain a description of the policies and procedures it has adopted to comply with the Act, including who is responsible for compliance.",
            "verbatimQuote": "A controller must document and maintain a description of the policies and procedures the controller has adopted to comply with sections 325M.10 to 325M.21 .",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/minnesota#src-stat-18-policies"
          }
        ]
      },
      {
        "slug": "vendor-contracts",
        "label": "What must your contracts with processors say?",
        "heading": "What must your contracts with processors say?",
        "answerText": "A contract between a controller and a processor must govern the processor's data processing on the controller's behalf — so a data processing agreement is a statutory requirement, not a best practice. That contract has to be binding and spell out the processing instructions, the nature and purpose of processing, the type of data, the duration, and each side's rights and obligations.",
        "sources": [
          {
            "id": "stat-13-contract",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Minn. Stat. § 325M.13",
            "citation": "Minn. Stat. § 325M.13(c).",
            "url": "https://www.revisor.mn.gov/statutes/cite/325M.13",
            "proposition": "A contract between a controller and a processor must govern the processor's data processing performed on behalf of the controller; it must set out the processing instructions, nature and purpose, type of data, duration, and the parties' rights and obligations, and must require a duty of confidentiality and that subcontractors be engaged only after the controller has an opportunity to object and under a flow-down written contract.",
            "verbatimQuote": "A contract between a controller and a processor shall govern the processor's data processing procedures with respect to processing performed on behalf of the controller. The contract shall be binding and clearly set forth instructions for processing data, the nature and purpose of processing, the type of data subject to processing, the duration of processing, and the rights and obligations of both parties. The contract shall also require that the processor: (1) ensure that each person processing the personal data is subject to a duty of confidentiality with respect to the data; and (2) engage a subcontractor only (i) after providing the controller with an opportunity to object, and (ii) pursuant to a written contract in accordance with paragraph (e) that requires the subcontractor to meet the obligations of the processor with respect to the personal data.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/minnesota#src-stat-13-contract"
          },
          {
            "id": "stat-13-terms",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Minn. Stat. § 325M.13",
            "citation": "Minn. Stat. § 325M.13(e).",
            "url": "https://www.revisor.mn.gov/statutes/cite/325M.13",
            "proposition": "The controller-processor contract must require the processor to delete or return all personal data at the end of services, make available all information necessary to demonstrate compliance, and allow for and contribute to reasonable assessments and inspections — or, alternatively, arrange a qualified and independent assessor at least annually and at the processor's expense.",
            "verbatimQuote": "(e) Processing by a processor shall be governed by a contract between the controller and the processor that is binding on both parties and that sets out the processing instructions to which the processor is bound, including the nature and purpose of the processing, the type of personal data subject to the processing, the duration of the processing, and the obligations and rights of both parties. The contract shall include the requirements imposed by this paragraph, paragraphs (c) and (d), as well as the following requirements: (1) at the choice of the controller, the processor shall delete or return all personal data to the controller as requested at the end of the provision of services, unless retention of the personal data is required by law; (2) upon a reasonable request from the controller, the processor shall make available to the controller all information necessary to demonstrate compliance with the obligations in sections 325M.10 to 325M.21 ; and (3) the processor shall allow for, and contribute to, reasonable assessments and inspections by the controller or the controller's designated assessor. Alternatively, the processor may arrange for a qualified and independent assessor to conduct, at least annually and at the processor's expense, an assessment of the processor's policies and technical and organizational measures in support of the obligations under sections 325M.10 to 325M.21 . The assessor must use an appropriate and accepted control standard or framework and assessment procedure for assessments as applicable, and shall provide a report of an assessment to the controller upon request.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/minnesota#src-stat-13-terms"
          },
          {
            "id": "stat-13-liability",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Minn. Stat. § 325M.13",
            "citation": "Minn. Stat. § 325M.13(f).",
            "url": "https://www.revisor.mn.gov/statutes/cite/325M.13",
            "proposition": "No contract may relieve a controller or processor from the liabilities imposed on it by virtue of its role in the processing relationship.",
            "verbatimQuote": "(f) In no event shall any contract relieve a controller or a processor from the liabilities imposed on a controller or processor by virtue of the controller's or processor's roles in the processing relationship under sections 325M.10 to 325M.21 .",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/minnesota#src-stat-13-liability"
          }
        ]
      },
      {
        "slug": "sensitive-data",
        "label": "Do you need consent to process sensitive data?",
        "heading": "Do you need consent to process sensitive data?",
        "answerText": "Yes. Except as the Act otherwise allows, a controller may not process a consumer's sensitive data without obtaining consent, and for a known child it must instead follow the federal Children's Online Privacy Protection Act. Sensitive data includes personal data revealing race or ethnicity, religious beliefs, a mental or physical health condition or diagnosis, sexual orientation, or citizenship or immigration status; biometric or genetic information used to uniquely identify someone; the data of a known child; and specific geolocation data.",
        "sources": [
          {
            "id": "stat-16-consent",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Minn. Stat. § 325M.16",
            "citation": "Minn. Stat. § 325M.16, subd. 2(d).",
            "url": "https://www.revisor.mn.gov/statutes/cite/325M.16",
            "proposition": "A controller may not process sensitive data without consent, and must handle a known child's data in accordance with COPPA.",
            "verbatimQuote": "a controller may not process sensitive data concerning a consumer without obtaining the consumer's consent, or, in the case of the processing of personal data concerning a known child, without obtaining consent from the child's parent or lawful guardian, in accordance with the requirement of the Children's Online Privacy Protection Act",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/minnesota#src-stat-16-consent"
          },
          {
            "id": "stat-11-sensitive",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Minn. Stat. § 325M.11",
            "citation": "Minn. Stat. § 325M.11(v).",
            "url": "https://www.revisor.mn.gov/statutes/cite/325M.11",
            "proposition": "Sensitive data includes personal data revealing race or ethnicity, religious beliefs, health condition or diagnosis, sexual orientation, or citizenship or immigration status; biometric or genetic data used for identification; a known child's data; and specific geolocation data.",
            "verbatimQuote": "Sensitive data is a form of personal data. “Sensitive data” means: (1) personal data revealing racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, sexual orientation, or citizenship or immigration status; (2) the processing of biometric data or genetic information for the purpose of uniquely identifying an individual; (3) the personal data of a known child; or (4) specific geolocation data.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/minnesota#src-stat-11-sensitive"
          }
        ]
      },
      {
        "slug": "consumer-lawsuit",
        "label": "Can a consumer sue your business under the MCDPA?",
        "heading": "Can a consumer sue your business under the MCDPA?",
        "answerText": "No. Nothing in the MCDPA creates a private right of action, so consumers cannot sue under it — the Minnesota Attorney General enforces the law. And unlike several peer states, Minnesota's right to cure was time-limited: the warning-letter-and-30-day-cure provision expired January 31, 2026, so the Attorney General can now bring an enforcement action without first offering a window to fix the problem.",
        "sources": [
          {
            "id": "stat-20-no-pra",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Minn. Stat. § 325M.20",
            "citation": "Minn. Stat. § 325M.20(d).",
            "url": "https://www.revisor.mn.gov/statutes/cite/325M.20",
            "proposition": "Nothing in the MCDPA establishes a private right of action; enforcement rests with the Attorney General.",
            "verbatimQuote": "Nothing in sections 325M.10 to 325M.21 establishes a private right of action, including under section 8.31, subdivision 3a , for a violation of sections 325M.10 to 325M.21 or any other law.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/minnesota#src-stat-20-no-pra"
          },
          {
            "id": "stat-20-cure",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Minn. Stat. § 325M.20",
            "citation": "Minn. Stat. § 325M.20(a).",
            "url": "https://www.revisor.mn.gov/statutes/cite/325M.20",
            "proposition": "The Attorney General's obligation to issue a warning letter and allow a 30-day cure before filing an enforcement action expired January 31, 2026.",
            "verbatimQuote": "If, after 30 days of issuance of the warning letter, the attorney general believes the controller or processor has failed to cure any alleged violation, the attorney general may bring an enforcement action under paragraph (b). This paragraph expires January 31, 2026.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/minnesota#src-stat-20-cure"
          }
        ]
      }
    ]
  }
}
