Minnesota Privacy Law
Minnesota packed three unrelated privacy regimes into one chapter. Sections 325M.01 to 325M.10 are an internet service provider privacy act that has been on the books since 2002; sections 325M.11 to 325M.21 are the Consumer Data Privacy Act of 2024; and sections 325M.30 to 325M.34, added in 2025, impose transparency duties on social media platforms and, at § 325M.335, require a conspicuous mental health warning label on every access to a social media platform from July 1, 2026. The comprehensive law itself carries the most demanding profiling provision in the country: a consumer subject to a profiling decision may question the result, learn the reason, and be told what actions might have produced a different one. Elsewhere in the statutes, the Plastic Card Security Act makes a merchant that retained prohibited card data reimburse the issuing financial institution for the cost of the breach.
The Minnesota Consumer Data Privacy Act (MCDPA)
Enacted by Laws 2024, ch. 121, art. 5, the Minnesota Consumer Data Privacy Act was codified into chapter 325M — a chapter that already held the state’s 2002 internet service provider privacy act — and took effect July 31, 2025, with one carve-out: postsecondary institutions regulated by the Office of Higher Education are not required to comply until July 31, 2029. Section 325M.12, subd. 1(a) sets the thresholds and excludes payment-transaction-only data from the count; subdivision 1(b) provides that a controller or processor acting as a technology provider under § 13.32 complies with both that section and the Act, and that § 13.32 prevails where they conflict. The exclusions in subdivision 2 begin with government entities as defined in § 13.02, subd. 7a and, unusually, a federally recognised Indian tribe. Section 325M.17 keeps a duty on small businesses as defined by the Small Business Administration that the thresholds otherwise exclude: they may not sell a consumer’s sensitive data without prior consent, and § 325M.20 penalties apply to them for that section.
| Effective date | July 31, 2025 |
|---|---|
| Citation | Minn. Stat. §§ 325M.10 to 325M.21 |
| Enforced by | Minnesota Attorney General |
| Maximum penalty | Injunction and a civil penalty of not more than $7,500 for each violation under Minn. Stat. § 325M.20(c) |
| Private right of action | No, enforcement by the state only |
| Right to cure | 30 days after a warning letter; the paragraph expired January 31, 2026 |
Who Must Comply
The MCDPA reaches a business that conducts business in Minnesota or produces products or services targeted to Minnesota residents, and during a calendar year controls or processes the personal data of 100,000 consumers or more, excluding data processed solely to complete a payment transaction, or derives over 25% of gross revenue from the sale of personal data and processes or controls the personal data of 25,000 consumers or more.
The profiling right runs further than any other state’s, reaching the reason for a decision and what might have changed it, and postsecondary institutions regulated by the Office of Higher Education have until July 31, 2029 to comply.
Consumer Rights Under the MCDPA
Residents of Minnesota can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.
Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.
Sector-Specific Privacy Laws in Minnesota
Access devices and card security (Minn. Stat. § 325E.64)
Minnesota’s Plastic Card Security Act converts a data-retention rule into a private reimbursement obligation running to banks. Subdivision 2 bars any person or entity conducting business in Minnesota that accepts an access device from retaining the card security code data, the PIN verification code number, or the full contents of any track of magnetic stripe data after authorization of the transaction — or, for a PIN debit transaction, more than 48 hours after authorization — and provides that the person is in violation if its service provider retains the data. Subdivision 3 supplies the consequence: where there is a breach of the security of the system of a person that violated the section, or of that person’s service provider, the person must reimburse the financial institution that issued the affected access devices for the costs of reasonable actions taken as a result of the breach to protect cardholder information or to continue providing services, including the cancellation or reissuance of any affected access device, the closure of affected accounts and any action to stop payments or block transactions, and the opening or reopening of accounts. Subdivision 1 defines an access device as a card issued by a financial institution containing a magnetic stripe, microprocessor chip or other storage, expressly including a stored value card.
Internet service provider privacy (Minn. Stat. §§ 325M.01 to 325M.10)
The first ten sections of chapter 325M long predate the comprehensive law and remain in force alongside it. Section 325M.02 states when disclosure of personal information is prohibited; § 325M.03 when disclosure is required; and § 325M.04 when it is permitted and how authorisation operates. Section 325M.05 imposes a security duty and § 325M.06 an exclusion from evidence. Section 325M.07 supplies enforcement, civil liability and the available defence, and § 325M.08 addresses the relationship with other law. Section 325M.09 sets the application of the sections and § 325M.10 the citation. Because the 2024 Act was codified into the same chapter beginning at § 325M.10, the enforcement provision of the comprehensive law at § 325M.20 is expressed as reaching violations of “sections 325M.10 to 325M.21”, leaving the older internet service provider sections to their own remedy in § 325M.07.
Social media transparency and the mental health warning label (Minn. Stat. §§ 325M.30 to 325M.34)
Added by Laws 2025, 1st Spec. Sess., ch. 3, art. 19, these sections sit at the end of the same chapter. Section 325M.33 imposes transparency requirements on social media platforms and § 325M.34 supplies enforcement authority. Section 325M.335 is the unusual one. Subdivision 1(a) provides that, effective July 1, 2026, a social media platform must ensure that a conspicuous mental health warning label appears each time a user accesses the platform and disappears only when the user exits the platform or acknowledges the potential for harm and chooses to proceed. Subdivision 1(b) requires the label to warn of potential negative mental health impacts in a manner conforming to guidelines, and to provide access to resources including the website and telephone number of a national suicide prevention and mental health crisis hotline system such as the 988 Suicide and Crisis Lifeline. Subdivision 1(c) bars a platform from placing the warning only in its terms and conditions, from including extraneous information that obscures its visibility or prominence, and from allowing a user to disable it except as subdivision 1(a) permits. Subdivision 2 required the commissioner of health, in consultation with the commissioner of commerce, to develop the guidelines by March 1, 2026 based on current evidence, and exempts that work from the rulemaking chapter.
Data Breach Notification in Minnesota
Section 325E.61, headed “Data warehouses; notice required for certain disclosures”, applies to any person or business conducting business in the state that owns or licenses data including personal information. Subdivision 1(a) requires disclosure to any Minnesota resident whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person, in the most expedient time possible and without unreasonable delay, consistent with law enforcement needs or with the measures necessary to determine the scope of the breach, identify the individuals affected and restore the reasonable integrity of the data system. Paragraph (e) defines personal information as a first name or first initial and last name with a Social Security number, a driver’s license or Minnesota identification card number, or an account, credit or debit card number with its security or access code — and, distinctively, treats data as unprotected where it was encrypted but the encryption key, password or other means of reading it was also acquired. The section directs no notice to the Attorney General from private businesses. What it does impose is a hard clock on credit-bureau notice: subdivision 2 requires a person who discovers circumstances requiring notification of more than 500 persons at one time to notify all nationwide consumer reporting agencies of the timing, distribution and content of the notices within 48 hours. Substitute notice is available under subdivision 1(g)(3) above $250,000 in cost or 500,000 affected persons. Government entities are handled separately, under § 13.055, subd. 6, which the section cross-references throughout.
Residents must be notified in the most expedient time possible and without unreasonable delay. No notice to the Attorney General is required of private businesses; nationwide consumer reporting agencies are notified within 48 hours above 500 persons. Complaints are taken by the Minnesota Attorney General, which enforces the statute.
Recent Enforcement in Minnesota
Marriott International — $52 million multistate settlement, October 2024. The Attorney General announced on October 9, 2024 that he and a coalition of 50 attorneys general had settled with Marriott International over a multi-year breach of a guest reservation database, alongside a parallel Federal Trade Commission settlement. Minnesota’s share of the $52 million payment to the states was $814,847. The office states that intruders were present in the Starwood network from July 2014 until September 2018 without detection, and that 131.5 million guest records of United States customers were breached, including contact information, gender, dates of birth, Starwood Preferred Guest information, reservation and stay preferences, and a limited number of unencrypted passport numbers and unexpired payment card information. The settlement resolves allegations that Marriott violated state consumer protection, personal information protection and breach notification laws by failing to implement reasonable data security and to remediate deficiencies. Its injunctive terms include a comprehensive information security program incorporating zero-trust principles, data minimisation and disposal requirements, segmentation and patch management, increased vendor and franchisee oversight, and an independent third-party assessment every two years for twenty years.
23andMe — $18 million bankruptcy settlement, July 2026. The Attorney General announced on July 14, 2026 that he had joined 42 attorneys general in a settlement with the bankruptcy trustee for 23andMe resolving allegations arising from a 2023 breach that compromised the genetic data of 6.9 million customers worldwide, including 92,385 in Minnesota. Because of the finite bankruptcy estate and competing claims, recovery was limited to $18 million paid immediately from available funds; Minnesota’s share is $514,871. The office states that the multistate investigation found unreasonable data security practices including a failure to employ safeguards against credential stuffing — among them comparing passwords against blocklists of known breached passwords or requiring multifactor authentication — and that the company learned of the breach months after the affected information was publicly available, first denied a breach, and then attributed it to how consumers had configured their accounts or used passwords.
MCDPA enforcement in the first six months. In a public update issued February 5, 2026, the Attorney General described the office’s early enforcement of the Consumer Data Privacy Act and the end of the statutory warning period. The office states that it sent hundreds of education letters to companies, presented on the law and compliance resources in public settings, and built both a consumer-facing site at privacymn.com with template rights-request forms and a privacy-complaint portal. It reports receiving more than 200 complaints under the Act in the first six months, reviewed by privacy attorneys, many of them from consumers whose attempts to exercise the new rights — particularly the right to delete — were unsuccessful. The update notes that the notice period sunset on January 31, 2026 and that the office is therefore no longer required to give 30 days’ notice before bringing an enforcement action.
Pending Privacy Legislation
Chapter 325M has been amended in each session since the comprehensive law passed. Laws 2025, 1st Spec. Sess., ch. 3, art. 19 added the social media sections at §§ 325M.30 to 325M.34, including the mental health warning label at § 325M.335 with its July 1, 2026 effective date and its March 1, 2026 deadline for the commissioner of health’s guidelines. The 2026 regular session amended § 325M.33 and added § 325M.40 by chapter 111, with effective dates set by the session law rather than in the chapter. Within the comprehensive sections themselves the significant date has passed rather than arrived: the warning-letter paragraph in § 325M.20(a), which required the Attorney General to identify the specific provisions alleged to be violated and to wait 30 days before filing, states that it “expires January 31, 2026”.
Federal Privacy Laws That Apply in Minnesota
Federal privacy law applies in Minnesota by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The MCDPA sits alongside those rules rather than displacing them: the Minnesota Attorney General enforces the state law, while the federal regulators continue to reach the sectors and activities they cover.
Minnesota Privacy Law FAQ
Where is Minnesota’s comprehensive privacy law codified?
What can a Minnesotan ask about an automated decision?
Can a Minnesota consumer learn which companies received their data?
Which Minnesota institutions have longer to comply?
Does Minnesota’s breach statute require notice to the Attorney General?
What does the Plastic Card Security Act require a merchant to pay?
What is the Minnesota social media mental health warning label?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- Minn. Stat. ch. 325M — Consumer Digital and Data Privacy (full chapter text) statute
- Minn. Stat. ch. 325M — table of sections statute
- Minn. Stat. § 325E.61 — Data warehouses; notice required for certain disclosures statute
- Minn. Stat. § 325E.64 — Access devices; breach of security statute
- Minn. Stat. § 325F.69 — Unlawful practices statute
- Minnesota Attorney General — Minnesota Consumer Data Privacy Act takes full effect (Feb. 5, 2026) agency
- Minnesota Attorney General — Marriott data-breach settlement (Oct. 9, 2024) agency
- Minnesota Attorney General — 23andMe bankruptcy settlement (July 14, 2026) agency
- Minnesota Attorney General — Blackbaud data-breach settlement (Oct. 5, 2023) agency
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.