The Minnesota Consumer Data Privacy Act applies to businesses processing personal data of at least 100,000 Minnesota consumers, or 25,000 if more than a quarter of revenue comes from selling personal data. Qualifying small businesses under SBA standards are exempt, though even exempt small businesses may not sell sensitive data without consent.
What the Minnesota Consumer Data Privacy Act Requires
Covered businesses must post a privacy notice, honor access, correction, deletion, and portability rights, obtain consent for sensitive data, and offer opt-outs from targeted advertising, sale, and profiling. Two distinctive additions: consumers can question the result of automated profiling decisions, and businesses must maintain a written data privacy policy with a named individual responsible for compliance. Universal opt-out signals must be honored.
Enforcement and Penalties
The Attorney General enforces with penalties up to $7,500 per violation. A 30-day cure period expired January 31, 2026, so a chance to fix violations is now at the enforcer’s discretion.
Source: Minnesota Office of the Revisor of Statutes: HF 4757, Minn. Stat. 325M.10-325M.21
Report a violation: If you believe a business is violating this law, you can file a complaint with the Minnesota Attorney General’s Office.