close
close
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Minnesota Privacy Law

MN

Minnesota (MCDPA)

Last updated

MCDPA Enacted, in effect

Who this affects: This page tracks Minnesota’s MCDPA, which governs controllers and processors.

Who it applies to: Legal entities that do business in Minnesota or target its residents, and meet: 100,000+ consumers, or 25,000+ consumers and more than 25% of gross revenue from selling data; some provisions apply under a separate test (see below).

Content on this page is not legal advice This page aggregates publicly cited regulatory facts for informational purposes only. It is not legal advice, and DataGrail is not responsible for decisions made in reliance on it. Consult qualified counsel for your specific compliance obligations.
July 31, 2025
Effective ↗
Attorney General
Enforced by ↗
$7,500
Maximum penalty per violation ↗
None
Private right of action ↗

The law, in plain English

Must · Can’t · Should

MCDPA, distilled to what actually changes your week. Read one column to know your floor, your hard limits, and the further obligations and good practices worth planning for.

Must

  • Honor access, correction, and deletion requests, and report action taken or any extension within 45 days of receipt. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MN-325M.14 “a controller must comply with a request to exercise the consumer rights provided in this subdivision” Read the statute MN-325M.14 “A consumer has the right to confirm whether or not a controller is processing personal data concerning the consumer and access the categories of personal data the controller is processing.” Read the statute MN-325M.14 “A consumer has the right to correct inaccurate personal data concerning the consumer, taking into account the nature of the personal data and the purposes of the processing of the personal data.” Read the statute MN-325M.14 “A consumer has the right to delete personal data concerning the consumer.” Read the statute MN-325M.14 “A controller must inform a consumer of any action taken on a request under subdivision 1 without undue delay and in any event within 45 days of receipt of the request” Read the statute MN-325M.14 “The controller must inform the consumer of any extension within 45 days of receipt of the request, together with the reasons for the delay” Read the statute
  • Honor opt-out preference signals for targeted advertising and sales, even when they conflict with a privacy setting. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MN-325M.14 “A controller must allow a consumer to opt out of any processing of the consumer's personal data for the purposes of targeted advertising, or any sale of the consumer's personal data through an opt-out preference signal” Read the statute MN-325M.14 “If a consumer's opt-out request is exercised through the platform, technology, or mechanism required under paragraph (a), and the request conflicts with the consumer's existing controller-specific privacy setting or voluntary participation in a controller's bona fide loyalty, rewards, premium features, discounts, or club card program, the controller must comply with the consumer's opt-out preference signal but may also notify the consumer of the conflict and provide the consumer a choice to confirm the controller-specific privacy setting or participation in the controller's program.” Read the statute
  • Conduct and document data privacy and protection assessments for listed activities; give them to the attorney general on request. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MN-325M.18 “A controller must conduct and document a data privacy and protection assessment for each of the following processing activities involving personal data” Read the statute MN-325M.18 “The controller must make a data privacy and protection assessment available to the attorney general upon a request made under this paragraph” Read the statute

Can't

  • Process sensitive data without consent, or a known child's personal data without parent or guardian consent per COPPA. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MN-325M.16 “a controller may not process sensitive data concerning a consumer without obtaining the consumer's consent, or, in the case of the processing of personal data concerning a known child, without obtaining consent from the child's parent or lawful guardian, in accordance with the requirement of the Children's Online Privacy Protection Act” Read the statute
  • Use for targeted advertising, or sell, the data of a consumer you know is between the ages of 13 and 16 without their consent. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MN-325M.16 “A controller may not process the personal data of a consumer for purposes of targeted advertising, or sell the consumer's personal data, without the consumer's consent, under circumstances where the controller knows that the consumer is between the ages of 13 and 16” Read the statute
  • Deny goods, charge different prices, or cut quality for exercising rights, except in voluntary bona fide loyalty programs. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MN-325M.16 “A controller may not discriminate against a consumer for exercising any of the rights contained in sections 325M.10 to 325M.21, including denying goods or services to the consumer, charging different prices or rates for goods or services, and providing a different level of quality of goods and services to the consumer. This subdivision does not: (1) require a controller to provide a good or service that requires the consumer's personal data that the controller does not collect or maintain; or (2) prohibit a controller from offering a different price, rate, level, quality, or selection of goods or services to a consumer, including offering goods or services for no fee, if the offering is in connection with a consumer's voluntary participation in a bona fide loyalty, rewards, premium features, discounts, or club card program” Read the statute

Should

  • Bind processors by contract to confidentiality and to delete or return data when services end, unless law requires retention. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MN-325M.13 “A contract between a controller and a processor shall govern the processor's data processing procedures with respect to processing performed on behalf of the controller. The contract shall be binding and clearly set forth instructions for processing data, the nature and purpose of processing, the type of data subject to processing, the duration of processing, and the rights and obligations of both parties.” Read the statute MN-325M.13 “ensure that each person processing the personal data is subject to a duty of confidentiality with respect to the data” Read the statute MN-325M.13 “at the choice of the controller, the processor shall delete or return all personal data to the controller as requested at the end of the provision of services, unless retention of the personal data is required by law” Read the statute
  • Run an appeal process, answer appeals in writing within 45 days, and keep appeal records for at least 24 months. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MN-325M.14 “A controller must establish an internal process whereby a consumer may appeal a refusal to take action on a request to exercise any of the rights under subdivision 1” Read the statute MN-325M.14 “Within 45 days of receipt of an appeal, a controller must inform the consumer of any action taken or not taken in response to the appeal, along with a written explanation of the reasons in support thereof.” Read the statute MN-325M.14 “The controller must maintain records of all appeals and the controller's responses for at least 24 months” Read the statute
  • Post the privacy notice via a conspicuous "privacy" link, in every language you serve, accessible to people with disabilities. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MN-325M.16 “The privacy notice must be posted online through a conspicuous hyperlink using the word "privacy" on the controller's website home page or on a mobile application's app store page or download page.” Read the statute MN-325M.16 “The privacy notice must be made available to the public in each language in which the controller provides a product or service that is subject to the privacy notice or carries out activities related to the product or service.” Read the statute MN-325M.16 “The controller must provide the privacy notice in a manner that is reasonably accessible to and usable by individuals with disabilities.” Read the statute

These are the highlights we judge most important, not everything MCDPA requires. The comprehensive law section below covers the full detail, fact by fact, with the statutory text behind every one.

The comprehensive law

Minnesota Consumer Data Privacy Act

MCDPA (HF 4757) is Minnesota’s comprehensive privacy law. Every fact was extracted from the primary statute by the DataGrail regulation engine and is grounded to the cited source. Scan the facts; the exact statutory text sits one click away on each source link.

Status
Enacted, in effect
Archived excerpt — the text we read 325M.10 CITATION. Sections 325M.10 to 325M.21 may be cited as the "Minnesota Consumer Data Privacy Act." History: 2024 c 121 art 5 s 2 NOTE: This section, as added by Laws 2024, chapter 121, article 5, section 2, is effective July 31, 2025, except that postsecondary institutions regulated by the Office of Higher Education are not required to comply until July 31, 2029. Laws 2024, chapter 121, article 5, section 14. Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
Effective
July 31, 2025
Archived excerpt — the text we read 325M.10 CITATION. Sections 325M.10 to 325M.21 may be cited as the "Minnesota Consumer Data Privacy Act." History: 2024 c 121 art 5 s 2 NOTE: This section, as added by Laws 2024, chapter 121, article 5, section 2, is effective July 31, 2025, except that postsecondary institutions regulated by the Office of Higher Education are not required to comply until July 31, 2029. Laws 2024, chapter 121, article 5, section 14. Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source

Corroborated by Privacy-law tracker

Signed
May 24, 2024
“Signed by the governor May 24, 2024, 9:14 a.m.” View the source
Enforced by
Attorney General
Archived excerpt — the text we read …the attorney general believes the controller or processor has failed to cure any alleged violation, the attorney general may bring an enforcement action under paragraph (b). This paragraph expires January 31, 2026. (b) The attorney general may bring a civil action against a controller or processor to enforce a provision of sections 325M.10 to 325M.21 in accordance with section 8.31. If the state prevails in an action to enforce sections 325M.10 to 325M.21, the state may, in addition to penalties provided by paragraph (c) or other remedies provided by law, be allowed an amount determined by the cour… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
Maximum penalty per violation
$7,500
“is subject to an injunction and liable for a civil penalty of not more than $7,500 for each violation” View the statute

Corroborated by Regulator guidance

Right to cure
30 days (lapsed Jan 31, 2026)
The mandatory 30-day cure (AG warning letter first) ended Jan 31, 2026; the statute has no discretionary cure. Archived excerpt — the text we read …action under paragraph (b), must provide the controller or processor with a warning letter identifying the specific provisions of sections 325M.10 to 325M.21 the attorney general alleges have been or are being violated. If, after 30 days of issuance of the warning letter, the attorney general believes the controller or processor has failed to cure any alleged violation, the attorney general may bring an enforcement action under paragraph (b). This paragraph expires January 31, 2026. (b) The attorney general may bring a civil action against a controller or processor to enforce a provision of sections 325M.10 to 325M.21 in accordance with section 8.31. If the state prevails in an action to enforce s… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
Private right of action
No private right of action.
Archived excerpt — the text we read …tate's litigation expenses incurred. (c) Any controller or processor that violates sections 325M.10 to 325M.21 is subject to an injunction and liable for a civil penalty of not more than $7,500 for each violation. (d) Nothing in sections 325M.10 to 325M.21 establishes a private right of action, including under section 8.31, subdivision 3a, for a violation of sections 325M.10 to 325M.21 or any other law. History: 2024 c 121 art 5 s 12 NOTE: This section, as added by Laws 2024, chapter 121, article 5, section 12, is effective July 31, 2025, except that postsecondary institutions regulated by the Office of Higher Educa… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source

Corroborated by Privacy-law tracker Regulator guidance

Universal opt-out signal
Required
Archived excerpt — the text we read …if the controller is able to verify, with commercially reasonable effort, the identity of the consumer and the authorized agent's authority to act on the consumer's behalf. § Subd. 3.Universal opt-out mechanisms. (a) A controller must allow a consumer to opt out of any processing of the consumer's personal data for the purposes of targeted advertising, or any sale of the consumer's personal data through an opt-out preference signal sent, with the consumer's consent, by a platform, technology, or mechanism to the controller indicating the consumer's intent to opt out of the processing or sale. The platform, technology, or mechanism must: (1) not unfairly disadvantage another controller; (2) not make use of a default setting, but require the consumer to make an affirmative, freely given, and unambiguous choi… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source

Corroborated by Privacy-law tracker

Who it applies to

Legal entities that do business in Minnesota or target its residents, and meet: 100,000+ consumers, or 25,000+ consumers and more than 25% of gross revenue from selling data; some provisions apply under a separate test (see full text)

What the law gives consumers

  • Right to confirm processing and access the categories of personal data processed Archived excerpt — the text we read …DATA RIGHTS. § Subdivision 1.Consumer rights provided. (a) Except as provided in sections 325M.10 to 325M.21, a controller must comply with a request to exercise the consumer rights provided in this subdivision. (b) A consumer has the right to confirm whether or not a controller is processing personal data concerning the consumer and access the categories of personal data the controller is processing. (c) A consumer has the right to correct inaccurate personal data concerning the consumer, taking into account the nature of the personal data and the purposes of the processing of the personal data. (d) A consumer has… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Right to correct Archived excerpt — the text we read …in this subdivision. (b) A consumer has the right to confirm whether or not a controller is processing personal data concerning the consumer and access the categories of personal data the controller is processing. (c) A consumer has the right to correct inaccurate personal data concerning the consumer, taking into account the nature of the personal data and the purposes of the processing of the personal data. (d) A consumer has the right to delete personal data concerning the consumer. (e) A consumer has the right to obtain personal data concerning the consumer, which the consumer previously provided to the controller, in … Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Right to delete Archived excerpt — the text we read …is processing. (c) A consumer has the right to correct inaccurate personal data concerning the consumer, taking into account the nature of the personal data and the purposes of the processing of the personal data. (d) A consumer has the right to delete personal data concerning the consumer. (e) A consumer has the right to obtain personal data concerning the consumer, which the consumer previously provided to the controller, in a portable and, to the extent technically feasible, readily usable format that … Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Right to data portability Archived excerpt — the text we read …a concerning the consumer, taking into account the nature of the personal data and the purposes of the processing of the personal data. (d) A consumer has the right to delete personal data concerning the consumer. (e) A consumer has the right to obtain personal data concerning the consumer, which the consumer previously provided to the controller, in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means. (f) A consumer has the right to opt out of the processing of personal data … Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Right to opt out of sale Archived excerpt — the text we read …portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means. (f) A consumer has the right to opt out of the processing of personal data concerning the consumer for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of automated decisions that produce legal effects concerning a consumer or similarly significant effects concerning a consumer. (g) If a consumer's personal data is profiled in furtherance of decisions that produce legal effects concerning a… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Right to opt out of targeted advertising Archived excerpt — the text we read …portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means. (f) A consumer has the right to opt out of the processing of personal data concerning the consumer for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of automated decisions that produce legal effects concerning a consumer or similarly significant effects concerning a consumer. (g) If a consumer's personal data is profiled in furtherance of decisions that produce legal effects concerning a… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Right to opt out of profiling for significant decisions Archived excerpt — the text we read …portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means. (f) A consumer has the right to opt out of the processing of personal data concerning the consumer for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of automated decisions that produce legal effects concerning a consumer or similarly significant effects concerning a consumer. (g) If a consumer's personal data is profiled in furtherance of decisions that produce legal effects concerning a consumer or similarly significant effects concerning a consumer, the consumer has the right to question … Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Sensitive data: opt-in consent required Archived excerpt — the text we read …t be managed to exercise these responsibilities. The data security practices shall be appropriate to the volume and nature of the personal data at issue. (d) Except as otherwise provided in sections 325M.10 to 325M.21, a controller may not process sensitive data concerning a consumer without obtaining the consumer's consent, or, in the case of the processing of personal data concerning a known child, without obtaining consent from the child's parent or lawful guardian, in accordance with the requirement of the Children's Online Privacy Protection Act, United States Code, title 15, sections 6501 to 6506, and its implementing regulations, rules, and exemptions. (e) A controller shall provide an effective mechanism for a consumer, or, in the case of the processing of … Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Right to appeal Archived excerpt — the text we read …1; or (2) opting the consumer out of the processing of personal data for any purpose except for the purposes exempted pursuant to the provisions of sections 325M.10 to 325M.21. § Subd. 5.Appeal process required. (a) A controller must establish an internal process whereby a consumer may appeal a refusal to take action on a request to exercise any of the rights under subdivision 1 within a reasonable period of time after the consumer's receipt of the notice sent by the controller under subdivision 4, paragraph (f). (b) The appeal process must be conspicuously available. The process must include … Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Right against discrimination Archived excerpt — the text we read …consumers with respect to the offering or provision of: housing, employment, credit, or education; or the goods, services, facilities, privileges, advantages, or accommodations of any place of public accommodation. (b) A controller may not discriminate against a consumer for exercising any of the rights contained in sections 325M.10 to 325M.21, including denying goods or services to the consumer, charging different prices or rates for goods or services, and providing a different level of quality of goods and services to the consumer. This subdivision does not… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Right to a list of the specific third parties data was disclosed to If the controller does not keep this per consumer, it may instead list the specific third parties it disclosed any consumer's data to. Archived excerpt — the text we read …t the nature of the personal data and the purposes of the processing of the personal data, the consumer has the right to have the data corrected and the profiling decision reevaluated based upon the corrected data. (h) A consumer has a right to obtain a list of the specific third parties to which the controller has disclosed the consumer's personal data. If the controller does not maintain the information in a format specific to the consumer, a list of specific third parties to whom the controller has disclosed any consumers' personal data may be provided instead. § Subd. 2.Exercising consumer rights. (a) A consumer may exercise the rights set forth in this section by submitting a request, at any time, to a controller specifying which rights the consumer wishes to exercise. (… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Right to question a profiling decision Applies to profiling for legal or similarly significant decisions (not limited to automated). Also: review the data used; correct inaccurate data and have the decision reevaluated. Archived excerpt — the text we read …rposes of targeted advertising, the sale of personal data, or profiling in furtherance of automated decisions that produce legal effects concerning a consumer or similarly significant effects concerning a consumer. (g) If a consumer's personal data is profiled in furtherance of decisions that produce legal effects concerning a consumer or similarly significant effects concerning a consumer, the consumer has the right to question the result of the profiling, to be informed of the reason that the profiling resulted in the decision, and, if feasible, to be informed of what actions the consumer might have taken to secure a different decision and the actions that the consumer might take to secure a different decision in the future. The consumer has the right to review the consumer's personal data used in the profiling. If the decision is determined to have been based upon inaccurate personal data, taking into account the nature of the personal data and the purposes of the processing of the personal data, the consumer has the right to have the data corrected and the profiling decision reevaluated based upon the corrected data. (h) A consumer has a right to obtain a list of the specific third parties to which the controller has disclosed the consumer's personal data. If the controller does not maintain the information in a format specific to … Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Not granted: Private right of action Archived excerpt — the text we read …tate's litigation expenses incurred. (c) Any controller or processor that violates sections 325M.10 to 325M.21 is subject to an injunction and liable for a civil penalty of not more than $7,500 for each violation. (d) Nothing in sections 325M.10 to 325M.21 establishes a private right of action, including under section 8.31, subdivision 3a, for a violation of sections 325M.10 to 325M.21 or any other law. History: 2024 c 121 art 5 s 12 NOTE: This section, as added by Laws 2024, chapter 121, article 5, section 12, is effective July 31, 2025, except that postsecondary institutions regulated by the Office of Higher Educa… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source

Who the law governs

  • Controllers Archived excerpt — the text we read …25M.21. (g) "Consumer" means a natural person who is a Minnesota resident acting only in an individual or household context. Consumer does not include a natural person acting in a commercial or employment context. (h) "Controller" means the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data. (i) "Decisions that produce legal or similarly significant effects concerning the consumer" means decisions made by the controller that result in the provision or denial by the controller of financial or lending servic… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Processors Archived excerpt — the text we read …erformed on personal data or on sets of personal data, whether or not by automated means, including but not limited to the collection, use, storage, disclosure, analysis, deletion, or modification of personal data. (r) "Processor" means a natural or legal person who processes personal data on behalf of a controller. (s) "Profiling" means any form of automated processing of personal data to evaluate, analyze, or predict personal aspects related to an identified or identifiable natural person's economic situation, health, personal p… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source

Exemptions

  • Government entity Archived excerpt — the text we read …section 13.32 conflict with sections 325M.10 to 325M.21, section 13.32 prevails. § Subd. 2.Exclusions. (a) Sections 325M.10 to 325M.21 do not apply to the following entities, activities, or types of information: (1) a government entity, as defined by section 13.02, subdivision 7a; (2) a federally recognized Indian tribe; (3) information that meets the definition of: (i) protected health information, as defined by and for purposes of the Health Insurance Portability and Accountability Act of 1… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Federally recognized Indian tribe Archived excerpt — the text we read …prevails. § Subd. 2.Exclusions. (a) Sections 325M.10 to 325M.21 do not apply to the following entities, activities, or types of information: (1) a government entity, as defined by section 13.02, subdivision 7a; (2) a federally recognized Indian tribe; (3) information that meets the definition of: (i) protected health information, as defined by and for purposes of the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191, and related regul… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • HIPAA protected health information Archived excerpt — the text we read …llowing entities, activities, or types of information: (1) a government entity, as defined by section 13.02, subdivision 7a; (2) a federally recognized Indian tribe; (3) information that meets the definition of: (i) protected health information, as defined by and for purposes of the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191, and related regulations; (ii) health records, as defined in section 144.291, subdivision 2; (iii) patient identifying information for purposes of Code of Federal Regulations, title 42, part 2, established pursuant to United States Code, titl… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Health records Archived excerpt — the text we read …tion that meets the definition of: (i) protected health information, as defined by and for purposes of the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191, and related regulations; (ii) health records, as defined in section 144.291, subdivision 2; (iii) patient identifying information for purposes of Code of Federal Regulations, title 42, part 2, established pursuant to United States Code, title 42, section 290dd-2; (iv) identifiable private information for pu… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Substance use disorder patient identifying information Archived excerpt — the text we read … as defined by and for purposes of the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191, and related regulations; (ii) health records, as defined in section 144.291, subdivision 2; (iii) patient identifying information for purposes of Code of Federal Regulations, title 42, part 2, established pursuant to United States Code, title 42, section 290dd-2; (iv) identifiable private information for purposes of the federal policy for the protection of human subjects, Code of Federal Regulations, title 45, part 46; identifiable private information that is otherwise informa… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Human subjects research information Archived excerpt — the text we read …fined in section 144.291, subdivision 2; (iii) patient identifying information for purposes of Code of Federal Regulations, title 42, part 2, established pursuant to United States Code, title 42, section 290dd-2; (iv) identifiable private information for purposes of the federal policy for the protection of human subjects, Code of Federal Regulations, title 45, part 46; identifiable private information that is otherwise information collected as part of human subjects research pursuant to the good clinical practice guidelines issued by the International Council for Harmonisation; the p… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Health Care Quality Improvement Act information Archived excerpt — the text we read … of human subjects under Code of Federal Regulations, title 21, parts 50 and 56; or personal data used or shared in research conducted in accordance with one or more of the requirements set forth in this paragraph; (v) information and documents created for purposes of the federal Health Care Quality Improvement Act of 1986, Public Law 99-660, and related regulations; or (vi) patient safety work product for purposes of Code of Federal Regulations, title 42, part 3, established pursuant to United States Code, title 42, sections 299b-21 to 299b-26; (4) information that is derived fr… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Patient safety work product Archived excerpt — the text we read … more of the requirements set forth in this paragraph; (v) information and documents created for purposes of the federal Health Care Quality Improvement Act of 1986, Public Law 99-660, and related regulations; or (vi) patient safety work product for purposes of Code of Federal Regulations, title 42, part 3, established pursuant to United States Code, title 42, sections 299b-21 to 299b-26; (4) information that is derived from any of the health care-related information listed in clause (3), but that has been deidentified in accordance with the requirements for deidentification set forth in Code of Federa… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • HIPAA deidentified health information Archived excerpt — the text we read …9-660, and related regulations; or (vi) patient safety work product for purposes of Code of Federal Regulations, title 42, part 3, established pursuant to United States Code, title 42, sections 299b-21 to 299b-26; (4) information that is derived from any of the health care-related information listed in clause (3), but that has been deidentified in accordance with the requirements for deidentification set forth in Code of Federal Regulations, title 45, part 164; (5) information originating from, and intermingled to be indistinguishable with, any of the health care-related information listed in clause (3) that is maintained by: (i) a covered entity or business associate, as d… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Information intermingled with exempt health information Data-level When maintained by a HIPAA covered entity/business associate, a health care provider (144.291) or a 42 CFR part 2 program/QSO (data-level). Archived excerpt — the text we read …any of the health care-related information listed in clause (3), but that has been deidentified in accordance with the requirements for deidentification set forth in Code of Federal Regulations, title 45, part 164; (5) information originating from, and intermingled to be indistinguishable with, any of the health care-related information listed in clause (3) that is maintained by: (i) a covered entity or business associate, as defined by the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191, and related regulations; (ii) a health care provider, as defined in section 144.291, subdivision 2; or (iii) a program or a qualified service organization, as defined by Code of Federal Regulations, title 42, part 2, established pursuant to United States Code, title 42, section 290dd-2; (6) information that is: (i) maintained by an entity that meets the definition of health care provider under Code of Federal Regulations, title 45, section 160.103, to the extent that the entity maintains the informa… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Health care provider information under HIPAA-manner maintenance Archived excerpt — the text we read …or (iii) a program or a qualified service organization, as defined by Code of Federal Regulations, title 42, part 2, established pursuant to United States Code, title 42, section 290dd-2; (6) information that is: (i) maintained by an entity that meets the definition of health care provider under Code of Federal Regulations, title 45, section 160.103, to the extent that the entity maintains the information in the manner required of covered entities with respect to protected health information for purposes of the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191, and related regulations; (ii) included in a limited data set, as described under Code of Federal Regulations, title 45, part 164.514(e), to the extent that the information is used, disclosed, and maintained in the manner specified by that par… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • HIPAA limited data set Archived excerpt — the text we read …in the manner required of covered entities with respect to protected health information for purposes of the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191, and related regulations; (ii) included in a limited data set, as described under Code of Federal Regulations, title 45, part 164.514(e), to the extent that the information is used, disclosed, and maintained in the manner specified by that part; (iii) maintained by, or maintained to comply with the rules or orders of, a self-regulatory organization as defined by United States Code, title 15, section 78c(a)(26); (iv) originated from, or intermingled with, inf… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Self-regulatory organization records Archived excerpt — the text we read …cluded in a limited data set, as described under Code of Federal Regulations, title 45, part 164.514(e), to the extent that the information is used, disclosed, and maintained in the manner specified by that part; (iii) maintained by, or maintained to comply with the rules or orders of, a self-regulatory organization as defined by United States Code, title 15, section 78c(a)(26); (iv) originated from, or intermingled with, information described in clause (9) and that a licensed residential mortgage originator, as defined under section 58.02, subdivision 19, or residential mortgage servicer, as… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • GLBA-intermingled data of licensed mortgage originators Data-level GLBA-intermingled information held by licensed residential mortgage originators/servicers (data-level). Archived excerpt — the text we read …ained in the manner specified by that part; (iii) maintained by, or maintained to comply with the rules or orders of, a self-regulatory organization as defined by United States Code, title 15, section 78c(a)(26); (iv) originated from, or intermingled with, information described in clause (9) and that a licensed residential mortgage originator, as defined under section 58.02, subdivision 19, or residential mortgage servicer, as defined under section 58.02, subdivision 20, collects, processes, uses, or maintains in the same manner as required under the laws and regulations specified in clause (9); or (v) originated from, or intermingled with, information described in clause (9) and that a nonbank financial institution, as defined by section 46A.01, subdivision 12, collects, processes, uses, or maintains in the … Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • GLBA-intermingled information held by nonbank financial institutions (data-level) Data-level Archived excerpt — the text we read …9, or residential mortgage servicer, as defined under section 58.02, subdivision 20, collects, processes, uses, or maintains in the same manner as required under the laws and regulations specified in clause (9); or (v) originated from, or intermingled with, information described in clause (9) and that a nonbank financial institution, as defined by section 46A.01, subdivision 12, collects, processes, uses, or maintains in the same manner as required under the laws and regulations specified in clause (9); (7) information used only for public health activities and purposes, as described under Code of Federal Regulations, title 45, part 164.512; (8) an activity involving the collection, maintenance, disclosure, sale, co… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Public health activities information Archived excerpt — the text we read …and that a nonbank financial institution, as defined by section 46A.01, subdivision 12, collects, processes, uses, or maintains in the same manner as required under the laws and regulations specified in clause (9); (7) information used only for public health activities and purposes, as described under Code of Federal Regulations, title 45, part 164.512; (8) an activity involving the collection, maintenance, disclosure, sale, communication, or use of any personal data bearing on a consumer's credit worthiness, credit standing, credit capacity, character, general reput… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • FCRA-regulated data Archived excerpt — the text we read …nner as required under the laws and regulations specified in clause (9); (7) information used only for public health activities and purposes, as described under Code of Federal Regulations, title 45, part 164.512; (8) an activity involving the collection, maintenance, disclosure, sale, communication, or use of any personal data bearing on a consumer's credit worthiness, credit standing, credit capacity, character, general reputation, personal characteristics, or mode of living by a consumer reporting agency, as defined in United States Code, title 15, section 1681a(f), by a furnisher of information, as set forth in United States Code, title 15, section 1681s-2, who provides information for use in a consumer report, as defined in United States Code, title 15, section 1681a(d), and by a user of a consumer report, as set forth in United States Code, title 15, section 1681b, except that information is only excluded under this paragraph to the extent that the activity involving the collection, maintenance, disclosure, sale, communication, or use of the information by the agency, furnisher, or user is subject to regulation under the federal Fair Credit Reporting Act, United States Code, title 15, sections 1681 to 1681x, and the information is not collected, maintained, used, communicated, disclosed, or sold except as authorized by the Fair Credit Reporting Act; (9) personal data collected, processed, sold, or disclosed pursuant to the federal Gramm-Leach-Bliley Act, Public Law 106-102, and implementing regulations, if the collection, processing, sale, or disclosure is in com… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Personal data handled under GLBA Data-level Data-level; state- or federally chartered banks and credit unions are separately exempt at entity level under clause (16). Archived excerpt — the text we read …t Reporting Act, United States Code, title 15, sections 1681 to 1681x, and the information is not collected, maintained, used, communicated, disclosed, or sold except as authorized by the Fair Credit Reporting Act; (9) personal data collected, processed, sold, or disclosed pursuant to the federal Gramm-Leach-Bliley Act, Public Law 106-102, and implementing regulations, if the collection, processing, sale, or disclosure is in compliance with that law; (10) personal data collected, processed, sold, or disclosed pursuant to the federal Driver's Privacy Protection Act of 1994, United States Code, title 18, sections 2721 to 2725, if the collection, processing, sale, or… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Driver's Privacy Protection Act data Archived excerpt — the text we read …d, processed, sold, or disclosed pursuant to the federal Gramm-Leach-Bliley Act, Public Law 106-102, and implementing regulations, if the collection, processing, sale, or disclosure is in compliance with that law; (10) personal data collected, processed, sold, or disclosed pursuant to the federal Driver's Privacy Protection Act of 1994, United States Code, title 18, sections 2721 to 2725, if the collection, processing, sale, or disclosure is in compliance with that law; (11) personal data regulated by the federal Family Educational Rights and Privacy Act, United States Code, title 20, section 1232g, and implementing regulations; (12) personal data collected, processed, sold, or disc… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • FERPA-regulated data Archived excerpt — the text we read …or disclosed pursuant to the federal Driver's Privacy Protection Act of 1994, United States Code, title 18, sections 2721 to 2725, if the collection, processing, sale, or disclosure is in compliance with that law; (11) personal data regulated by the federal Family Educational Rights and Privacy Act, United States Code, title 20, section 1232g, and implementing regulations; (12) personal data collected, processed, sold, or disclosed pursuant to the federal Farm Credit Act of 1971, as amended, United States Code, title 12, sections 2001 to 2279cc, and implementing regulations, Code of Fed… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Farm Credit Act data Archived excerpt — the text we read …ale, or disclosure is in compliance with that law; (11) personal data regulated by the federal Family Educational Rights and Privacy Act, United States Code, title 20, section 1232g, and implementing regulations; (12) personal data collected, processed, sold, or disclosed pursuant to the federal Farm Credit Act of 1971, as amended, United States Code, title 12, sections 2001 to 2279cc, and implementing regulations, Code of Federal Regulations, title 12, part 600, if the collection, processing, sale, or disclosure is in compliance with that law; (13) data collected or maintained: (i) in the course of an individual acting as a job applicant to or an employee, owner, director, officer, medical staff member, or contractor of a business if the data is collected … Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Employment data Archived excerpt — the text we read … 2001 to 2279cc, and implementing regulations, Code of Federal Regulations, title 12, part 600, if the collection, processing, sale, or disclosure is in compliance with that law; (13) data collected or maintained: (i) in the course of an individual acting as a job applicant to or an employee, owner, director, officer, medical staff member, or contractor of a business if the data is collected and used solely within the context of the role; (ii) as the emergency contact information of an individual under item (i) if used solely for emergency contact purposes; or (iii) that is necessary for the business to retain to administer benefits for another indivi… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Emergency contact information Archived excerpt — the text we read …se of an individual acting as a job applicant to or an employee, owner, director, officer, medical staff member, or contractor of a business if the data is collected and used solely within the context of the role; (ii) as the emergency contact information of an individual under item (i) if used solely for emergency contact purposes; or (iii) that is necessary for the business to retain to administer benefits for another individual relating to the individual under item (i) if used solely for the purposes of administering those benefits; (14) pers… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Benefits administration data Archived excerpt — the text we read … of a business if the data is collected and used solely within the context of the role; (ii) as the emergency contact information of an individual under item (i) if used solely for emergency contact purposes; or (iii) that is necessary for the business to retain to administer benefits for another individual relating to the individual under item (i) if used solely for the purposes of administering those benefits; (14) personal data collected, processed, sold, or disclosed pursuant to the Minnesota Insurance Fair Information Reporting Act in sections 72A.49 to 72A.505; (15) data collected, processed, sold, or disclosed as part… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Minnesota Insurance Fair Information Reporting Act data Archived excerpt — the text we read …oses; or (iii) that is necessary for the business to retain to administer benefits for another individual relating to the individual under item (i) if used solely for the purposes of administering those benefits; (14) personal data collected, processed, sold, or disclosed pursuant to the Minnesota Insurance Fair Information Reporting Act in sections 72A.49 to 72A.505; (15) data collected, processed, sold, or disclosed as part of a payment-only credit, check, or cash transaction where no data about consumers, as defined in section 325M.11, are retained; (16) a state or federally ch… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Payment-only transaction data Archived excerpt — the text we read …lely for the purposes of administering those benefits; (14) personal data collected, processed, sold, or disclosed pursuant to the Minnesota Insurance Fair Information Reporting Act in sections 72A.49 to 72A.505; (15) data collected, processed, sold, or disclosed as part of a payment-only credit, check, or cash transaction where no data about consumers, as defined in section 325M.11, are retained; (16) a state or federally chartered bank or credit union, or an affiliate or subsidiary that is principally engaged in financial activities, as described in United States Code, title 12, section 1843(k); (17) informa… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Banks and credit unions Archived excerpt — the text we read …tions 72A.49 to 72A.505; (15) data collected, processed, sold, or disclosed as part of a payment-only credit, check, or cash transaction where no data about consumers, as defined in section 325M.11, are retained; (16) a state or federally chartered bank or credit union, or an affiliate or subsidiary that is principally engaged in financial activities, as described in United States Code, title 12, section 1843(k); (17) information that originates from, or is intermingled so as to be indistinguishable from, information described in clause (8) and that a person licensed under chapter 56 collects, processes, uses, or maintains in … Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • FCRA-intermingled information held by chapter 56 licensees (data-level) Data-level Archived excerpt — the text we read …etained; (16) a state or federally chartered bank or credit union, or an affiliate or subsidiary that is principally engaged in financial activities, as described in United States Code, title 12, section 1843(k); (17) information that originates from, or is intermingled so as to be indistinguishable from, information described in clause (8) and that a person licensed under chapter 56 collects, processes, uses, or maintains in the same manner as is required under the laws and regulations specified in clause (8); (18) an insurance company, as defined in section 60A.02, subdivision 4, an insurance producer, as defined in section 60K.31, subdivision 6, a third-party administrator of self-insurance, or an affiliate or subsidiary … Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Insurance companies, producers, and others Insurance companies, producers, TPAs of self-insurance and their financial-activity affiliates. Not a person that only maintains a self-insurance program. Archived excerpt — the text we read …om, information described in clause (8) and that a person licensed under chapter 56 collects, processes, uses, or maintains in the same manner as is required under the laws and regulations specified in clause (8); (18) an insurance company, as defined in section 60A.02, subdivision 4, an insurance producer, as defined in section 60K.31, subdivision 6, a third-party administrator of self-insurance, or an affiliate or subsidiary of any entity identified in this clause that is principally engaged in financial activities, as described in United States Code, title 12, section 1843(k), except that this clause does not apply to a person that, alone or in combination with another person, establishes and maintains a self-insurance program that does not otherwise engage in the business of entering into policies of insurance; (19) a small business, as defined by the United States Small Business Administration under Code of Federal Regulations, title 13, part 121, except that a small business identified in this clause is subject to section … Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Small business (except section 325M.17) Archived excerpt — the text we read …es not apply to a person that, alone or in combination with another person, establishes and maintains a self-insurance program that does not otherwise engage in the business of entering into policies of insurance; (19) a small business, as defined by the United States Small Business Administration under Code of Federal Regulations, title 13, part 121, except that a small business identified in this clause is subject to section 325M.17; (20) a nonprofit organization that is established to detect and prevent fraudulent acts in connection with insurance; and (21) an air carrier subject to the federal Airline Deregulation Act, Public Law 95-504, only t… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Nonprofit fraud-prevention organizations for insurance Archived excerpt — the text we read … business, as defined by the United States Small Business Administration under Code of Federal Regulations, title 13, part 121, except that a small business identified in this clause is subject to section 325M.17; (20) a nonprofit organization that is established to detect and prevent fraudulent acts in connection with insurance; and (21) an air carrier subject to the federal Airline Deregulation Act, Public Law 95-504, only to the extent that an air carrier collects personal data related to prices, routes, or services and only to the extent t… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Air carriers under Airline Deregulation Act Archived excerpt — the text we read …121, except that a small business identified in this clause is subject to section 325M.17; (20) a nonprofit organization that is established to detect and prevent fraudulent acts in connection with insurance; and (21) an air carrier subject to the federal Airline Deregulation Act, Public Law 95-504, only to the extent that an air carrier collects personal data related to prices, routes, or services and only to the extent that the provisions of the Airline Deregulation Act preempt the requirements of sections 325M.10 to 325M.21. (b) Controllers that are in compliance with the Children's Online Privacy Protection Act, United States Code, title 15, sections 6501 to 6506, and implementing regulations, shall be deemed compliant with any obligatio… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Evidentiary privilege (compliance would violate a Minnesota evidentiary privilege) Archived excerpt — the text we read …or service specifically requested by a consumer or the performance of a contract to which the consumer is a party; or (3) conduct internal research to develop, improve, or repair products, services, or technology. (c) The obligations imposed on controllers or processors under sections 325M.10 to 325M.21 do not apply where compliance by the controller or processor with sections 325M.10 to 325M.21 would violate an evidentiary privilege under Minnesota law and do not prevent a controller or processor from providing personal data concerning a consumer to a person covered by an evidentiary privilege under Minnesota law as part of a privileged communication. (d) A controlle… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Purely personal or household activity Archived excerpt — the text we read …ections 325M.10 to 325M.21 shall not: (1) adversely affect the rights or freedoms of any persons, including exercising the right of free speech pursuant to the First Amendment of the United States Constitution; or (2) apply to the processing of personal data by a natural person in the course of a purely personal or household activity. (f) Personal data that are processed by a controller pursuant to this section may be processed solely to the extent that the processing is: (1) necessary, reasonable, and proportionate to the purposes listed in this … Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Privileged communications to a person covered by an evidentiary privilege Archived excerpt — the text we read …on controllers or processors under sections 325M.10 to 325M.21 do not apply where compliance by the controller or processor with sections 325M.10 to 325M.21 would violate an evidentiary privilege under Minnesota law and do not prevent a controller or processor from providing personal data concerning a consumer to a person covered by an evidentiary privilege under Minnesota law as part of a privileged communication. (d) A controller or processor that discloses personal data to a third-party controller or processor in compliance with the requirements of sections 325M.10 to 325M.21 is not in violation of sections 325M.10 to 325M.21 … Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Rights and freedoms of others, including free speech Archived excerpt — the text we read …ts of sections 325M.10 to 325M.21 is not in violation of sections 325M.10 to 325M.21 for the obligations of the controller or processor from which the third-party controller or processor receives the personal data. (e) Obligations imposed on controllers and processors under sections 325M.10 to 325M.21 shall not: (1) adversely affect the rights or freedoms of any persons, including exercising the right of free speech pursuant to the First Amendment of the United States Constitution; or (2) apply to the processing of personal data by a natural person in the course of a purely personal or household activity. (f) Personal data that are processed by a controller pursuant to this section may be proce… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Human subjects research under ICH good clinical practice guidelines Data-level Archived excerpt — the text we read … pursuant to United States Code, title 42, section 290dd-2; (iv) identifiable private information for purposes of the federal policy for the protection of human subjects, Code of Federal Regulations, title 45, part 46; identifiable private information that is otherwise information collected as part of human subjects research pursuant to the good clinical practice guidelines issued by the International Council for Harmonisation; the protection of human subjects under Code of Federal Regulations, title 21, parts 50 and 56; or personal data used or shared in research conducted in accordance with one or more of the requirements set forth in this … Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Human subjects protections under FDA regulations (21 C.F.R. parts 50 and 56) Data-level Archived excerpt — the text we read …rt 46; identifiable private information that is otherwise information collected as part of human subjects research pursuant to the good clinical practice guidelines issued by the International Council for Harmonisation; the protection of human subjects under Code of Federal Regulations, title 21, parts 50 and 56; or personal data used or shared in research conducted in accordance with one or more of the requirements set forth in this paragraph; (v) information and documents created for purposes of the federal Health Care Quali… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source
  • Human subjects research data Data-level Personal data used or shared in research conducted under these human subjects research requirements. Archived excerpt — the text we read …ubjects research pursuant to the good clinical practice guidelines issued by the International Council for Harmonisation; the protection of human subjects under Code of Federal Regulations, title 21, parts 50 and 56; or personal data used or shared in research conducted in accordance with one or more of the requirements set forth in this paragraph; (v) information and documents created for purposes of the federal Health Care Quality Improvement Act of 1986, Public Law 99-660, and related regulations; or (vi) patient safety work product for purposes of Code of F… Archived from source — captured 2026-07-27 · snapshot 55b9f8c8 Verify at the source

Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source.

Timeline

MCDPA milestones

This state currently has one dated milestone on the books.

Enforcement July 31, 2025

MCDPA took effect

Enforcement began — obligations have been live since this date.

Source: primary citation

Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source. Reference only, not legal advice.

When staying on top of the law isn't enough, DataGrail automates the work.
DSR automation and regulatory tracking — handled by the platform behind this reference.
How DataGrail helps
Back to the Regulations Hub Reference only — not legal advice. Published Sep 29, 2026