Minnesota Consumer Data Privacy Act (Minn. Stat. 325M.10 to 325M.21)
Below is what the official text of Minnesota Consumer Data Privacy Act (Minn. Stat. 325M.10 to 325M.21) states about whom it covers, when it applies to a business and since when. Where the pages we read do not say, the row says "not stated".
The wording shown is taken from the official page named in each row. The duties of a business and the contents of a privacy notice are in the paid checklist.
Typical situations, run through the same conditions as the check
- A for-profit US business with 150,000 people in Minnesota and $30 million revenue: Applies, or may apply: conditions to check.
- The same business with 8,000 people in Minnesota: Not triggered by these answers.
- A US business with no users in Minnesota: Not triggered by these answers.
Judged on 2026-10-06. Our law data was last verified on 2026-10-06; a law that took effect after that date is not in it. These situations leave other answers blank or neutral: use the check for your own.
What the official text states
| Question | What the official text states | Source |
|---|---|---|
| What it covers | Sections 325M.10 to 325M.21 apply to legal entities that conduct business in Minnesota or produce products or services targeted to Minnesota residents and that meet one of the stated consumer-count or revenue-from-sale thresholds.Official wordingSections 325M.10 to 325M.21 apply to legal entities that conduct business in Minnesota or produce products or services that are targeted to residents of Minnesota, and that satisfy one or more of the following thresholds: | www.revisor.mn.gov read 2026-10-06 |
| When it applies to a business | Applies to legal entities that conduct business in Minnesota or produce products or services targeted to Minnesota residents and that either, during a calendar year, control or process personal data of 100,000 consumers or more (excluding data processed solely to complete a payment transaction), or derive over 25 percent of gross revenue from the sale of personal data and process or control personal data of 25,000 consumers or more. Conditions to check: Business must conduct business in Minnesota or produce products or services targeted to Minnesota residents. The 100,000 count excludes personal data processed solely to complete a payment transaction. No general nonprofit exemption (only a nonprofit established to detect and prevent insurance fraud is excluded). Exclusions in 325M.12 subd. 2 include government entities, federally recognized tribes, HIPAA-regulated health information, GLBA data, state or federally chartered banks and credit unions, insurers, consumer reporting activity, employee and job-applicant data, and a small business as defined by the U.S. Small Business Administration (13 CFR part 121), except that a small business must not sell sensitive data without consent (325M.17). Postsecondary institutions regulated by the Office of Higher Education need not comply until 2029-07-31. Official wording(1) during a calendar year, controls or processes personal data of 100,000 consumers or more, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or (2) derives over 25 percent of gross revenue from the sale of personal data and processes or controls personal data of 25,000 consumers or more. | www.revisor.mn.gov read 2026-10-06 |
| In force from | 2025-07-31 Effective July 31, 2025, except that postsecondary institutions regulated by the Office of Higher Education are not required to comply until July 31, 2029 (Laws 2024, ch. 121, art. 5, s. 14). Official wordingNOTE: This section, as added by Laws 2024, chapter 121, article 5, section 2, is effective July 31, 2025, except that postsecondary institutions regulated by the Office of Higher Education are not required to comply until July 31, 2029. | www.revisor.mn.gov read 2026-10-06 |
| Privacy notice | Included in the paid checklist. See the checklist | — |
| Consent and opt-out | Included in the paid checklist. See the checklist | — |
| Rights of individuals | Included in the paid checklist. See the checklist | — |
| Data protection officer | Included in the paid checklist. See the checklist | — |
| Breach notification | Not stated on the official pages we read. separate breach-notification statute not read (the text only mentions section 325E.61 in a processor-assistance clause) | — |
| What the privacy notice must contain | Included in the paid checklist. See the checklist | — |
What we do not cover
These areas are outside this site, so nothing on this page says anything about them:
- Privacy laws for particular sectors (for example health care, banking and credit, education)
- Rules specific to children's online privacy
- Cookie and electronic-communications rules (including consent for cookies and marketing messages)
- Employee, job applicant and contractor data
- Rules on sending personal data to other countries
- US state data-breach notification laws (a separate set of state laws)
- US state privacy laws that are not yet in force, and state laws on particular topics (for example biometric or health data)
- Privacy laws of countries that are not listed here
- Planned changes to the laws listed here