Michigan Privacy Law
Michigan is one of the few states whose most-litigated privacy statute predates the internet. The Preservation of Personal Privacy Act, enacted in 1988 and amended in 2016, bars retailers of books, sound recordings and video recordings from disclosing records that personally identify a customer as having bought or borrowed them, and gives the customer a damages action including emotional-distress damages and attorney fees. Alongside it sits a breach-notification section of the Identity Theft Protection Act that requires no notice to the Attorney General at all, and a Consumer Protection Act whose reach expanded sharply in July 2026 when the Michigan Supreme Court overruled the decisions that had exempted licensed businesses from it.
Sector-Specific Privacy Laws in Michigan
Preservation of Personal Privacy Act (MCL 445.1711 to 445.1715)
Section 445.1712, carrying the popular name “Video Rental Privacy Act”, prohibits a person engaged in the business of selling at retail, renting or lending books or other written materials, sound recordings or video recordings from knowingly disclosing to anyone other than the customer a record or information that personally identifies the customer as having purchased, leased, rented or borrowed those materials. Aggregated or de-identified records are outside the section. Section 445.1713 lists the permitted disclosures: written customer permission, a warrant or court order, collection of payment after written notice and a failure to pay, disclosure incident to the ordinary course of the discloser’s business, a search warrant or grand jury subpoena, and marketing — the last only where the customer has been given written notice of a way to opt out, including a non-electronic method unless the business communicates with customers electronically, with the opt-out taking effect thirty days after the customer’s notice. Section 445.1715 makes a violator liable in a civil action to a customer who suffers actual damages, including damages for emotional distress, together with reasonable costs and attorney fees. The 2016 amendment, 2016 PA 92, was declared “curative” in its own enacting section, which states that the prohibitions do not bar disclosures incident to the ordinary course of business or marketing with written notice, and that a civil action “may only be brought by a customer who has suffered actual damages”.
Michigan Consumer Protection Act (MCL 445.901 to 445.922)
Section 445.905 lets the Attorney General sue for a temporary or permanent injunction on probable cause, after giving the target at least ten days’ notice and an opportunity to cease and desist or confer, and permits a civil fine of up to $25,000 for a persistent and knowing violation, plus $5,000 for each knowing violation of an injunction or judgment. Section 445.911 gives a private plaintiff a declaratory-judgment and injunction action regardless of damages, a damages action for the greater of actual damages or $250 with reasonable attorney fees, and a class action for actual damages, subject to a bona-fide-error defence limiting recovery to actual damages and a limitation period of six years from the practice or one year from the last payment, whichever ends later. The Act’s reach turns on § 445.904(1)(a), which exempts conduct “specifically authorized under laws administered by a regulatory board or officer”, with the burden of proving the exemption on the person claiming it. On July 31, 2026 the Attorney General’s office announced that the Michigan Supreme Court had reversed Smith v Globe Life Insurance Co. and Liss v Lewiston-Richards, Inc., the decisions the office describes as having “rendered Michigan’s Consumer Protection Act inapplicable to deceptive business practices and price gouging when it was done by a business that held a license or similar authorization from a State or Federal agency”.
Identity Theft Protection Act (2004 PA 452, MCL 445.61 et seq.)
The breach section, § 445.72, is section 12 of a wider identity-theft act and applies to breaches discovered on or after July 2, 2006. Subsection 18 declares the subject matter one of statewide concern and preempts any municipal ordinance, resolution, regulation or rule attempting to regulate any matter expressly set out in the section, directly or indirectly. Subsection 12 makes it a misdemeanor to send a breach notice with intent to defraud when no breach has occurred, punishable by up to 93 days’ imprisonment and a fine rising from $250 to $750 for a third or subsequent violation. Subsection 17 excludes access to government records lawfully made available to the general public. Subsections 9 and 10 deem a financial institution examined for compliance with the federal interagency guidance, and an entity complying with HIPAA and 45 C.F.R. parts 160 and 164, to be in compliance.
Data Breach Notification in Michigan
Section 445.72 is built around a harm threshold rather than a deadline. Under subsection 1 the duty to notify residents arises unless the person or agency determines that the breach “has not or is not likely to cause substantial loss or injury to, or result in identity theft with respect to” one or more Michigan residents — and subsection 3 requires that determination to be made with the care an ordinarily prudent person in a like position would exercise. Notice reaches a resident whose unencrypted and unredacted personal information was accessed and acquired, and also a resident whose information was acquired in encrypted form by a person with unauthorized access to the encryption key. Subsection 4 requires notice without unreasonable delay but allows delay for measures to determine the scope of the breach and restore the database’s reasonable integrity, or at the direction of a law enforcement agency. Subsection 5 permits written, electronic, telephone or substitute notice, with substitute notice available where notice would cost more than $250,000 or reach more than 500,000 Michigan residents; telephone notice may not use a recorded message. Subsection 6 prescribes the content: a general description of the breach, the type of personal information involved, what has been done to protect data from further breaches, a telephone number for assistance, and a reminder to remain vigilant for fraud and identity theft. Michigan requires no notice to the Attorney General. Under subsection 8 the only external report is to each nationwide consumer reporting agency, and that is excused where 1,000 or fewer residents are notified or where the entity is subject to the Gramm-Leach-Bliley Act. Subsection 11 gives public utilities that send monthly billing statements an alternative notice route.
Residents must be notified without unreasonable delay, subject to delay for scoping and restoring the database or at the request of law enforcement. No Attorney General notification requirement; notice to nationwide consumer reporting agencies is required above 1,000 residents. Complaints are taken by the Michigan Attorney General, which enforces the statute.
How Michigan Enforces Its Privacy Laws
A $250 fine per failure, capped at $750,000 per breach. Subsection 13 of § 445.72 provides that a person who knowingly fails to give a required notice “may be ordered to pay a civil fine of not more than $250.00 for each failure to provide notice”, and authorises either the Attorney General or a prosecuting attorney to bring the action. Subsection 14 caps aggregate liability for multiple violations arising from the same breach at $750,000. Subsection 15 preserves any other civil remedy available under state or federal law, so the fine schedule is a floor on exposure rather than a ceiling.
The Consumer Protection Act route, after the 2026 reversal. Because § 445.72 sets no Attorney General notification duty, deceptive statements about data handling have historically been pursued under the Consumer Protection Act instead — and that route was narrowed for years by the regulated-conduct exemption in § 445.904(1)(a). The Attorney General’s office states that the Michigan Supreme Court’s July 2026 decisions reversing Smith v Globe Life and Liss v Lewiston-Richards removed that barrier for licensed businesses, and quotes the Attorney General saying the office’s Consumer Protection Team “can go back to helping residents who have been deceived by licensed businesses”.
Recent Enforcement in Michigan
Marriott / Starwood — $52 million multistate settlement, $1,209,097 to Michigan. The Attorney General announced on October 11, 2024 that Michigan was among 50 attorneys general settling with Marriott over the breach of the Starwood guest reservation database, which the office reports exposed 131.5 million guest records in the United States. The office describes an intrusion running from July 2014 until September 2018 — spanning Marriott’s 2016 acquisition of Starwood and its assumption of control over the network — and data including contact information, gender, dates of birth, legacy Starwood Preferred Guest information, reservation and stay-preference information, and a limited number of unencrypted passport numbers and unexpired payment card numbers. Michigan’s share was $1,209,097. The injunctive terms require an information security program built on zero-trust principles, data minimisation and disposal, encryption and network segmentation, oversight of vendors and franchisees, security assessments after future acquisitions, independent third-party assessments every two years for twenty years, and consumer-facing controls including data deletion and multi-factor authentication on loyalty accounts.
Block, Inc. (Cash App) — $45 million multistate settlement, $936,540 to Michigan. The Attorney General announced on July 9, 2026 a multistate settlement with Block, Inc. resolving allegations that it misled consumers about Cash App’s safety and failed to protect them from fraud. The office’s account describes minimal identity verification at sign-up, the absence of phone support (which left users calling fake numbers run by scammers), a “Cash App Fridays” promotion that encouraged users to post their account identifiers publicly, and delays that prevented recovery of stolen funds. Michigan’s share was $936,540. The settlement requires Block to maintain live customer support — phone support at least 13.5 hours a day and live chat at least 18 hours a day — to stop the safety claims, to end marketing practices that increase fraud risk, and to investigate fraud claims and reimburse unauthorized transactions as required by law.
USDA SNAP data demand — multistate suit, N.D. Cal., July 2025. The Attorney General announced on July 28, 2025 that Michigan had joined a suit in the United States District Court for the Northern District of California challenging a federal demand that states hand over personal information about Supplemental Nutrition Assistance Program applicants and recipients going back five years, including Social Security numbers and home addresses. The office reports the demand would reach roughly 1.4 million Michigan residents, that 22 jurisdictions joined, and that the claims include violations of federal privacy laws, failure to meet public-comment requirements, action exceeding the agency’s statutory authority, and violation of the Spending Clause. The office also states that the agency suggested it could withhold administrative funding from non-complying states, against a Michigan SNAP distribution the release puts at $254 million a month.
Pending Privacy Legislation
Senate Bill 359 of 2025, the Personal Data Privacy Act, was introduced by Senator Rosemary Bayer on June 5, 2025, referred to the Committee on Finance, Insurance, and Consumer Protection, reported favourably without amendment on June 11, 2025 and referred to the Committee of the Whole, where it stood as of this review. The legislature’s own summary describes a bill that would establish consumer rights over the collection and use of personal data, require a collector to obtain consent before processing and to publish a privacy notice, and require any person meeting the bill’s definition of a data broker to register annually with the Attorney General, who would publish the register on a public page. The bill is a reintroduction of Senate Bill 659 of the 2023-2024 session, which passed the Senate and was referred to the House Committee on Government Operations without further action.
Federal Privacy Laws That Apply in Michigan
Federal privacy law applies in Michigan by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The state-law counterpart to section 5 is the Michigan Consumer Protection Act (MCL 445.901 to 445.922), which the Michigan Attorney General enforces against businesses whose stated data practices differ from their actual ones.
Industry Rules That Reach Michigan Businesses
With no comprehensive state statute, most privacy obligations on a Michigan business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.
Two of those reach Michigan businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while Michigan itself has none, and any business holding personal information about Michigan residents is subject to the state’s breach-notification statute described above.
Michigan Privacy Law FAQ
Does a Michigan business have to notify the Attorney General after a data breach?
When is breach notice actually required in Michigan?
What must a Michigan breach notice say?
What is the penalty for failing to give breach notice in Michigan?
What does Michigan’s Preservation of Personal Privacy Act cover?
Can a Michigan city pass its own data-breach ordinance?
Did the Michigan Consumer Protection Act change in 2026?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- MCL 445.72 — Notice of security breach (Identity Theft Protection Act, sec. 12) statute
- MCL 445.1712 — Preservation of Personal Privacy Act, disclosure prohibited statute
- MCL 445.1713 — Preservation of Personal Privacy Act, exceptions statute
- MCL 445.1715 — Preservation of Personal Privacy Act, civil action and damages statute
- MCL 445.904 — Michigan Consumer Protection Act, exemptions statute
- MCL 445.905 — Michigan Consumer Protection Act, Attorney General action and civil fines statute
- MCL 445.911 — Michigan Consumer Protection Act, private and class actions statute
- Senate Bill 359 of 2025 — Personal Data Privacy Act (status and history) legislation
- Michigan Attorney General — $52 million multistate settlement with Marriott (October 11, 2024) agency
- Michigan Attorney General — $45 million multistate settlement over Cash App (July 9, 2026) agency
- Michigan Attorney General — Lawsuit challenging federal demands for SNAP recipient data (July 28, 2025) agency
- Michigan Attorney General — On the Michigan Supreme Court reversing consumer protection decisions (July 31, 2026) agency
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.