Minnesota — Comprehensive Law

Minnesota Privacy Law

Minnesota packed three unrelated privacy regimes into one chapter. Sections 325M.01 to 325M.10 are an internet service provider privacy act that has been on the books since 2002; sections 325M.11 to 325M.21 are the Consumer Data Privacy Act of 2024; and sections 325M.30 to 325M.34, added in 2025, impose transparency duties on social media platforms and, at § 325M.335, require a conspicuous mental health warning label on every access to a social media platform from July 1, 2026. The comprehensive law itself carries the most demanding profiling provision in the country: a consumer subject to a profiling decision may question the result, learn the reason, and be told what actions might have produced a different one. Elsewhere in the statutes, the Plastic Card Security Act makes a merchant that retained prohibited card data reimburse the issuing financial institution for the cost of the breach.

The Minnesota Consumer Data Privacy Act (MCDPA)

Enacted by Laws 2024, ch. 121, art. 5, the Minnesota Consumer Data Privacy Act was codified into chapter 325M — a chapter that already held the state’s 2002 internet service provider privacy act — and took effect July 31, 2025, with one carve-out: postsecondary institutions regulated by the Office of Higher Education are not required to comply until July 31, 2029. Section 325M.12, subd. 1(a) sets the thresholds and excludes payment-transaction-only data from the count; subdivision 1(b) provides that a controller or processor acting as a technology provider under § 13.32 complies with both that section and the Act, and that § 13.32 prevails where they conflict. The exclusions in subdivision 2 begin with government entities as defined in § 13.02, subd. 7a and, unusually, a federally recognised Indian tribe. Section 325M.17 keeps a duty on small businesses as defined by the Small Business Administration that the thresholds otherwise exclude: they may not sell a consumer’s sensitive data without prior consent, and § 325M.20 penalties apply to them for that section.

Effective dateJuly 31, 2025
CitationMinn. Stat. §§ 325M.10 to 325M.21
Enforced byMinnesota Attorney General
Maximum penaltyInjunction and a civil penalty of not more than $7,500 for each violation under Minn. Stat. § 325M.20(c)
Private right of actionNo, enforcement by the state only
Right to cure30 days after a warning letter; the paragraph expired January 31, 2026

Who Must Comply

The MCDPA reaches a business that conducts business in Minnesota or produces products or services targeted to Minnesota residents, and during a calendar year controls or processes the personal data of 100,000 consumers or more, excluding data processed solely to complete a payment transaction, or derives over 25% of gross revenue from the sale of personal data and processes or controls the personal data of 25,000 consumers or more.

The profiling right runs further than any other state’s, reaching the reason for a decision and what might have changed it, and postsecondary institutions regulated by the Office of Higher Education have until July 31, 2029 to comply.

Consumer Rights Under the MCDPA

Residents of Minnesota can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.

Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.

Sector-Specific Privacy Laws in Minnesota

Access devices and card security (Minn. Stat. § 325E.64)

Minnesota’s Plastic Card Security Act converts a data-retention rule into a private reimbursement obligation running to banks. Subdivision 2 bars any person or entity conducting business in Minnesota that accepts an access device from retaining the card security code data, the PIN verification code number, or the full contents of any track of magnetic stripe data after authorization of the transaction — or, for a PIN debit transaction, more than 48 hours after authorization — and provides that the person is in violation if its service provider retains the data. Subdivision 3 supplies the consequence: where there is a breach of the security of the system of a person that violated the section, or of that person’s service provider, the person must reimburse the financial institution that issued the affected access devices for the costs of reasonable actions taken as a result of the breach to protect cardholder information or to continue providing services, including the cancellation or reissuance of any affected access device, the closure of affected accounts and any action to stop payments or block transactions, and the opening or reopening of accounts. Subdivision 1 defines an access device as a card issued by a financial institution containing a magnetic stripe, microprocessor chip or other storage, expressly including a stored value card.

Internet service provider privacy (Minn. Stat. §§ 325M.01 to 325M.10)

The first ten sections of chapter 325M long predate the comprehensive law and remain in force alongside it. Section 325M.02 states when disclosure of personal information is prohibited; § 325M.03 when disclosure is required; and § 325M.04 when it is permitted and how authorisation operates. Section 325M.05 imposes a security duty and § 325M.06 an exclusion from evidence. Section 325M.07 supplies enforcement, civil liability and the available defence, and § 325M.08 addresses the relationship with other law. Section 325M.09 sets the application of the sections and § 325M.10 the citation. Because the 2024 Act was codified into the same chapter beginning at § 325M.10, the enforcement provision of the comprehensive law at § 325M.20 is expressed as reaching violations of “sections 325M.10 to 325M.21”, leaving the older internet service provider sections to their own remedy in § 325M.07.

Social media transparency and the mental health warning label (Minn. Stat. §§ 325M.30 to 325M.34)

Added by Laws 2025, 1st Spec. Sess., ch. 3, art. 19, these sections sit at the end of the same chapter. Section 325M.33 imposes transparency requirements on social media platforms and § 325M.34 supplies enforcement authority. Section 325M.335 is the unusual one. Subdivision 1(a) provides that, effective July 1, 2026, a social media platform must ensure that a conspicuous mental health warning label appears each time a user accesses the platform and disappears only when the user exits the platform or acknowledges the potential for harm and chooses to proceed. Subdivision 1(b) requires the label to warn of potential negative mental health impacts in a manner conforming to guidelines, and to provide access to resources including the website and telephone number of a national suicide prevention and mental health crisis hotline system such as the 988 Suicide and Crisis Lifeline. Subdivision 1(c) bars a platform from placing the warning only in its terms and conditions, from including extraneous information that obscures its visibility or prominence, and from allowing a user to disable it except as subdivision 1(a) permits. Subdivision 2 required the commissioner of health, in consultation with the commissioner of commerce, to develop the guidelines by March 1, 2026 based on current evidence, and exempts that work from the rulemaking chapter.

Data Breach Notification in Minnesota

Section 325E.61, headed “Data warehouses; notice required for certain disclosures”, applies to any person or business conducting business in the state that owns or licenses data including personal information. Subdivision 1(a) requires disclosure to any Minnesota resident whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person, in the most expedient time possible and without unreasonable delay, consistent with law enforcement needs or with the measures necessary to determine the scope of the breach, identify the individuals affected and restore the reasonable integrity of the data system. Paragraph (e) defines personal information as a first name or first initial and last name with a Social Security number, a driver’s license or Minnesota identification card number, or an account, credit or debit card number with its security or access code — and, distinctively, treats data as unprotected where it was encrypted but the encryption key, password or other means of reading it was also acquired. The section directs no notice to the Attorney General from private businesses. What it does impose is a hard clock on credit-bureau notice: subdivision 2 requires a person who discovers circumstances requiring notification of more than 500 persons at one time to notify all nationwide consumer reporting agencies of the timing, distribution and content of the notices within 48 hours. Substitute notice is available under subdivision 1(g)(3) above $250,000 in cost or 500,000 affected persons. Government entities are handled separately, under § 13.055, subd. 6, which the section cross-references throughout.

Residents must be notified in the most expedient time possible and without unreasonable delay. No notice to the Attorney General is required of private businesses; nationwide consumer reporting agencies are notified within 48 hours above 500 persons. Complaints are taken by the Minnesota Attorney General, which enforces the statute.

Recent Enforcement in Minnesota

Marriott International — $52 million multistate settlement, October 2024. The Attorney General announced on October 9, 2024 that he and a coalition of 50 attorneys general had settled with Marriott International over a multi-year breach of a guest reservation database, alongside a parallel Federal Trade Commission settlement. Minnesota’s share of the $52 million payment to the states was $814,847. The office states that intruders were present in the Starwood network from July 2014 until September 2018 without detection, and that 131.5 million guest records of United States customers were breached, including contact information, gender, dates of birth, Starwood Preferred Guest information, reservation and stay preferences, and a limited number of unencrypted passport numbers and unexpired payment card information. The settlement resolves allegations that Marriott violated state consumer protection, personal information protection and breach notification laws by failing to implement reasonable data security and to remediate deficiencies. Its injunctive terms include a comprehensive information security program incorporating zero-trust principles, data minimisation and disposal requirements, segmentation and patch management, increased vendor and franchisee oversight, and an independent third-party assessment every two years for twenty years.

23andMe — $18 million bankruptcy settlement, July 2026. The Attorney General announced on July 14, 2026 that he had joined 42 attorneys general in a settlement with the bankruptcy trustee for 23andMe resolving allegations arising from a 2023 breach that compromised the genetic data of 6.9 million customers worldwide, including 92,385 in Minnesota. Because of the finite bankruptcy estate and competing claims, recovery was limited to $18 million paid immediately from available funds; Minnesota’s share is $514,871. The office states that the multistate investigation found unreasonable data security practices including a failure to employ safeguards against credential stuffing — among them comparing passwords against blocklists of known breached passwords or requiring multifactor authentication — and that the company learned of the breach months after the affected information was publicly available, first denied a breach, and then attributed it to how consumers had configured their accounts or used passwords.

MCDPA enforcement in the first six months. In a public update issued February 5, 2026, the Attorney General described the office’s early enforcement of the Consumer Data Privacy Act and the end of the statutory warning period. The office states that it sent hundreds of education letters to companies, presented on the law and compliance resources in public settings, and built both a consumer-facing site at privacymn.com with template rights-request forms and a privacy-complaint portal. It reports receiving more than 200 complaints under the Act in the first six months, reviewed by privacy attorneys, many of them from consumers whose attempts to exercise the new rights — particularly the right to delete — were unsuccessful. The update notes that the notice period sunset on January 31, 2026 and that the office is therefore no longer required to give 30 days’ notice before bringing an enforcement action.

Pending Privacy Legislation

Chapter 325M has been amended in each session since the comprehensive law passed. Laws 2025, 1st Spec. Sess., ch. 3, art. 19 added the social media sections at §§ 325M.30 to 325M.34, including the mental health warning label at § 325M.335 with its July 1, 2026 effective date and its March 1, 2026 deadline for the commissioner of health’s guidelines. The 2026 regular session amended § 325M.33 and added § 325M.40 by chapter 111, with effective dates set by the session law rather than in the chapter. Within the comprehensive sections themselves the significant date has passed rather than arrived: the warning-letter paragraph in § 325M.20(a), which required the Attorney General to identify the specific provisions alleged to be violated and to wait 30 days before filing, states that it “expires January 31, 2026”.

Federal Privacy Laws That Apply in Minnesota

Federal privacy law applies in Minnesota by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The MCDPA sits alongside those rules rather than displacing them: the Minnesota Attorney General enforces the state law, while the federal regulators continue to reach the sectors and activities they cover.

Minnesota Privacy Law FAQ

Where is Minnesota’s comprehensive privacy law codified?
In chapter 325M of the Minnesota Statutes, headed “Consumer Digital and Data Privacy”, at §§ 325M.10 to 325M.21. The chapter is shared: §§ 325M.01 to 325M.10 are the older internet service provider privacy sections, and §§ 325M.30 to 325M.34 are the 2025 social media transparency and mental-health-label provisions. The enforcement section at § 325M.20 is drafted by reference to “sections 325M.10 to 325M.21” rather than to the chapter as a whole.
What can a Minnesotan ask about an automated decision?
Section 325M.14, subd. 1(g) gives a consumer whose personal data is profiled in furtherance of decisions producing legal or similarly significant effects the right to question the result of the profiling, to be informed of the reason that the profiling resulted in the decision and, if feasible, to be informed of what actions the consumer might have taken to secure a different decision and might take to secure a different one in future. The consumer may review the personal data used in the profiling, and if the decision was based on inaccurate data may have the data corrected and the decision reevaluated on the corrected data.
Can a Minnesota consumer learn which companies received their data?
Section 325M.14, subd. 1(h) gives a consumer the right to obtain a list of the specific third parties to which the controller has disclosed the consumer’s personal data. The subdivision includes a fallback: if the controller does not maintain the information in a format specific to the consumer, a list of the specific third parties to whom the controller has disclosed any consumers’ personal data may be provided instead.
Which Minnesota institutions have longer to comply?
Postsecondary institutions regulated by the Office of Higher Education. The note appended to each section of the Act, drawn from Laws 2024, ch. 121, art. 5, § 14, provides that the sections are effective July 31, 2025 “except that postsecondary institutions regulated by the Office of Higher Education are not required to comply until July 31, 2029”. That four-year deferral applies to the substantive sections and to the enforcement section at § 325M.20 alike.
Does Minnesota’s breach statute require notice to the Attorney General?
Section 325E.61 imposes no such duty on private businesses. What it does impose is a 48-hour clock on credit-bureau notice: subdivision 2 requires a person who discovers circumstances requiring notification of more than 500 persons at one time to notify all nationwide consumer reporting agencies of the timing, distribution and content of the notices within 48 hours. Government entities are dealt with separately under § 13.055, subd. 6, which § 325E.61 cross-references throughout.
What does the Plastic Card Security Act require a merchant to pay?
Section 325E.64, subd. 3 provides that where there is a breach of the security of the system of a person that violated the section — or of that person’s service provider — the person shall reimburse the financial institution that issued the affected access devices for the costs of reasonable actions taken as a result of the breach to protect cardholder information or continue providing services. The enumerated costs include cancelling or reissuing affected access devices, closing affected deposit, transaction or share draft accounts and stopping payments or blocking transactions on them, and opening or reopening accounts.
What is the Minnesota social media mental health warning label?
Section 325M.335, subd. 1(a) provides that effective July 1, 2026 a social media platform must ensure a conspicuous mental health warning label appears each time a user accesses the platform, disappearing only when the user exits or acknowledges the potential for harm and chooses to proceed. Subdivision 1(b) requires it to warn of potential negative mental health impacts and to give access to resources including the website and telephone number of a national crisis hotline system such as the 988 Suicide and Crisis Lifeline. Subdivision 2 directed the commissioner of health, with the commissioner of commerce, to develop guidelines by March 1, 2026 based on current evidence.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.