Montana Consumer Data Privacy Act (MCA Title 30, ch. 14, part 28)
Below is what the official text of Montana Consumer Data Privacy Act (MCA Title 30, ch. 14, part 28) states about whom it covers, when it applies to a business and since when. Where the pages we read do not say, the row says "not stated".
The wording shown is taken from the official page named in each row. The duties of a business and the contents of a privacy notice are in the paid checklist.
Typical situations, run through the same conditions as the check
- A for-profit US business with 150,000 people in Montana and $30 million revenue: Applies, or may apply: conditions to check.
- The same business with 8,000 people in Montana: Not triggered by these answers.
- A US business with no users in Montana: Not triggered by these answers.
Judged on 2026-10-06. Our law data was last verified on 2026-10-06; a law that took effect after that date is not in it. These situations leave other answers blank or neutral: use the check for your own.
What the official text states
| Question | What the official text states | Source |
|---|---|---|
| What it covers | Part 28 (the Consumer Data Privacy Act) binds persons that conduct business in Montana or produce products or services targeted to Montana residents and that control or process consumers' personal data above stated thresholds.Official wordingapply to persons that conduct business in this state or persons that produce products or services that are targeted to residents of this state and: | mca.legmt.gov read 2026-10-06 |
| When it applies to a business | Applies to persons conducting business in Montana or producing products or services targeted to Montana residents that control or process the personal data of at least 25,000 consumers (excluding data processed solely to complete a payment transaction), or at least 15,000 consumers while deriving more than 25% of gross revenue from the sale of personal data. Conditions to check: Thresholds are those after the 2025 amendment (SB 297, Ch. 567, L. 2025); before it they were 50,000 and 25,000 consumers. Sections 30-14-2811, 30-14-2818 and 30-14-2819 (minors) have no consumer-count threshold: they apply to persons that conduct business in Montana or deliver commercial products or services intentionally targeted to Montana residents. 'Conducts business in this state' and 'targeted' are not defined in the quoted text. Exemptions in 30-14-2804 (not covered by our questions): state and local government bodies, institutions of higher education, banks/credit unions and affiliates principally engaged in financial activities, GLBA-regulated data, HIPAA covered entities and business associates, insurers, an insurance-fraud nonprofit, a national securities association; certain data types are also exempt. Nonprofits are not exempted generally. Official wording(a) control or process the personal data of not less than 25,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or (b) control or process the personal data of not less than 15,000 consumers and derive more than 25% of gross revenue from the sale of personal data. | mca.legmt.gov read 2026-10-06 |
| In force from | 2024-10-01 As enacted by SB 384 (Ch. 681, L. 2023): 'This act is effective October 1, 2024.' SB 297 (Ch. 567, L. 2025) amended the part; its minors provisions (30-14-2811 etc.) and data protection assessment rules for minors are stated to apply on or after October 1, 2025. Official wordingSection 14. Effective date. [This act] is effective October 1, 2024. | archive.legmt.gov read 2026-10-06 |
| Privacy notice | Included in the paid checklist. See the checklist | — |
| Consent and opt-out | Included in the paid checklist. See the checklist | — |
| Rights of individuals | Included in the paid checklist. See the checklist | — |
| Data protection officer | Not stated on the official pages we read. the text we read does not say whether a data protection officer must be appointed | — |
| Breach notification | Not stated on the official pages we read. separate breach-notification statute not read | — |
| What the privacy notice must contain | Included in the paid checklist. See the checklist | — |
What we do not cover
These areas are outside this site, so nothing on this page says anything about them:
- Privacy laws for particular sectors (for example health care, banking and credit, education)
- Rules specific to children's online privacy
- Cookie and electronic-communications rules (including consent for cookies and marketing messages)
- Employee, job applicant and contractor data
- Rules on sending personal data to other countries
- US state data-breach notification laws (a separate set of state laws)
- US state privacy laws that are not yet in force, and state laws on particular topics (for example biometric or health data)
- Privacy laws of countries that are not listed here
- Planned changes to the laws listed here