Montana Consumer Data Privacy Act (MCA Title 30, ch. 14, part 28)

Below is what the official text of Montana Consumer Data Privacy Act (MCA Title 30, ch. 14, part 28) states about whom it covers, when it applies to a business and since when. Where the pages we read do not say, the row says "not stated".

The wording shown is taken from the official page named in each row. The duties of a business and the contents of a privacy notice are in the paid checklist.

Typical situations, run through the same conditions as the check

Judged on 2026-10-06. Our law data was last verified on 2026-10-06; a law that took effect after that date is not in it. These situations leave other answers blank or neutral: use the check for your own.

What the official text states

QuestionWhat the official text statesSource
What it coversPart 28 (the Consumer Data Privacy Act) binds persons that conduct business in Montana or produce products or services targeted to Montana residents and that control or process consumers' personal data above stated thresholds.
Official wording
apply to persons that conduct business in this state or persons that produce products or services that are targeted to residents of this state and:
mca.legmt.gov
read 2026-10-06
When it applies to a businessApplies to persons conducting business in Montana or producing products or services targeted to Montana residents that control or process the personal data of at least 25,000 consumers (excluding data processed solely to complete a payment transaction), or at least 15,000 consumers while deriving more than 25% of gross revenue from the sale of personal data.
Conditions to check: Thresholds are those after the 2025 amendment (SB 297, Ch. 567, L. 2025); before it they were 50,000 and 25,000 consumers. Sections 30-14-2811, 30-14-2818 and 30-14-2819 (minors) have no consumer-count threshold: they apply to persons that conduct business in Montana or deliver commercial products or services intentionally targeted to Montana residents. 'Conducts business in this state' and 'targeted' are not defined in the quoted text. Exemptions in 30-14-2804 (not covered by our questions): state and local government bodies, institutions of higher education, banks/credit unions and affiliates principally engaged in financial activities, GLBA-regulated data, HIPAA covered entities and business associates, insurers, an insurance-fraud nonprofit, a national securities association; certain data types are also exempt. Nonprofits are not exempted generally.
Official wording
(a) control or process the personal data of not less than 25,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or (b) control or process the personal data of not less than 15,000 consumers and derive more than 25% of gross revenue from the sale of personal data.
mca.legmt.gov
read 2026-10-06
In force from2024-10-01
As enacted by SB 384 (Ch. 681, L. 2023): 'This act is effective October 1, 2024.' SB 297 (Ch. 567, L. 2025) amended the part; its minors provisions (30-14-2811 etc.) and data protection assessment rules for minors are stated to apply on or after October 1, 2025.
Official wording
Section 14. Effective date. [This act] is effective October 1, 2024.
archive.legmt.gov
read 2026-10-06
Privacy noticeIncluded in the paid checklist. See the checklist—
Consent and opt-outIncluded in the paid checklist. See the checklist—
Rights of individualsIncluded in the paid checklist. See the checklist—
Data protection officerNot stated on the official pages we read.
the text we read does not say whether a data protection officer must be appointed
—
Breach notificationNot stated on the official pages we read.
separate breach-notification statute not read
—
What the privacy notice must containIncluded in the paid checklist. See the checklist—

What we do not cover

These areas are outside this site, so nothing on this page says anything about them:

Check my business All laws