close
close
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Montana Privacy Law

MT

Montana (MCDPA)

Last updated

MCDPA Enacted, in effect

Who this affects: This page tracks Montana’s MCDPA, which governs controllers and processors.

Who it applies to: Persons that do business in Montana or target its residents, and meet: 25,000+ consumers, or 15,000+ consumers and more than 25% of gross revenue from selling data; some provisions apply under a separate test (see below).

Content on this page is not legal advice This page aggregates publicly cited regulatory facts for informational purposes only. It is not legal advice, and DataGrail is not responsible for decisions made in reliance on it. Consult qualified counsel for your specific compliance obligations.
Oct 1, 2024
Effective ↗
Attorney General
Enforced by ↗
$7,500
Maximum penalty per violation ↗
None
Private right of action ↗

The law, in plain English

Must · Can’t · Should

MCDPA, distilled to what actually changes your week. Read one column to know your floor, your hard limits, and the further obligations and good practices worth planning for.

Must

  • Respond to rights requests within 45 days and answer appeals in writing, with reasons, within 60 days of receiving them. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MT-30-14-2808 “A controller shall respond to the consumer without undue delay, but not later than 45 days after receipt of the request.” Read the statute MT-30-14-2808 “Not later than 60 days after receipt of an appeal, a controller shall inform the consumer in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions.” Read the statute
  • Offer an opt-out of sale and targeted ads outside your privacy notice; since January 1, 2025, honor opt-out preference signals. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MT-30-14-2812 “the controller shall clearly and conspicuously disclose the processing in its privacy notice and provide access to a clear and conspicuous method outside the privacy notice for a consumer to opt out of the sale or processing” Read the statute MT-30-14-2809 “provide a clear and conspicuous link on the controller's internet website to an internet web page that enables a consumer, or an agent of the consumer, to opt out of the targeted advertising or sale of the consumer's personal data” Read the statute MT-30-14-2809 “by no later than January 1, 2025, allow a consumer to opt out of any processing of the consumer's personal data for the purposes of targeted advertising, or any sale of such personal data through an opt-out preference signal sent with the consumer's consent” Read the statute
  • Conduct and document a data protection assessment for each processing activity presenting a heightened risk of harm to consumers. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MT-30-14-2814 “A controller shall conduct and document a data protection assessment for each of the controller's processing activities that presents a heightened risk of harm to a consumer.” Read the statute

Can't

  • Sell or target ads using data of a consumer you know or willfully disregard is at least 13 but younger than 16, without consent. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MT-30-14-2812 “process the personal data of a consumer for the purposes of targeted advertising or sell the consumer's personal data without the consumer's consent under circumstances in which a controller has actual knowledge or willfully disregards that the consumer is at least 13 years of age but younger than 16 years of age” Read the statute
  • Process a consumer's sensitive data without consent, or a known child's sensitive data other than in accordance with COPPA. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MT-30-14-2812 “process sensitive data concerning a consumer without obtaining the consumer's consent or, in the case of the processing of sensitive data concerning a known child, without processing the sensitive data in accordance with the Children's Online Privacy Protection Act of 1998, 15 U.S.C. 6501, et seq.” Read the statute
  • Require a consumer to create a new account to exercise privacy rights, though you may require use of an existing account. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MT-30-14-2812 “A controller may not require a consumer to create a new account to exercise consumer rights but may require a consumer to use an existing account.” Read the statute

Should

  • Track each rights request against its 45-day clock so any extension notice, with its reason, is sent within the initial 45 days. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MT-30-14-2808 “A controller shall respond to the consumer without undue delay, but not later than 45 days after receipt of the request.” Read the statute MT-30-14-2808 “provided the controller informs the consumer of the extension within the initial 45-day response period and the reason for the extension” Read the statute
  • Assess services offered to anyone you know or willfully disregard is a minor for heightened risk, and plan to mitigate any found. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MT-30-14-2819 “A controller that, on or after October 1, 2025, offers an online service, product, or feature to a consumer whom the controller actually knows or willfully disregards is a minor shall conduct a data protection assessment for the online service, product, or feature if there is a heightened risk of harm to minors.” Read the statute MT-30-14-2819 “the controller shall establish and implement a plan to mitigate or eliminate the heightened risk” Read the statute
  • Audit processor contracts so each is binding and sets out instructions, purpose, data type, duration, and each party's duties. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. MT-30-14-2813 “A contract between a controller and a processor must govern the processor's data processing procedures with respect to processing performed on behalf of the controller. The contract must be binding and clearly set forth instructions for processing data, the nature and purpose of processing, the type of data subject to processing, the duration of processing, and the rights and obligations of both parties.” Read the statute

These are the highlights we judge most important, not everything MCDPA requires. The comprehensive law section below covers the full detail, fact by fact, with the statutory text behind every one.

The comprehensive law

Montana Consumer Data Privacy Act

MCDPA (SB 384) is Montana’s comprehensive privacy law. Every fact was extracted from the primary statute by the DataGrail regulation engine and is grounded to the cited source. Scan the facts; the exact statutory text sits one click away on each source link.

Status
Enacted, in effect
Archived excerpt — the text we read 30-14-2803. Applicability. (1) The provisions of this part, excluding 30-14-2811, 30-14-2818, and 30-14-2819, apply to persons that conduct business in this state or persons that produce products or services that are targeted to residents of this state and: (a) control or process the personal data of not less than 25,000 consumers, excluding personal data controlled or processed… Archived from source — captured 2026-08-15 · snapshot 4c243c2a Verify at the source

Corroborated by Privacy-law tracker

Effective
October 1, 2024
“Section 14. Effective date. [This act] is effective October 1, 2024.” View the source
Signed
May 19, 2023
“SB 384, sponsored by Sen. Daniel Zolnikov (R – SD22), was signed into law on May 19, 2023, and will take effect October 1, 2024.” View the source
Enforced by
Attorney General
Archived excerpt — the text we read 30-14-2817. Enforcement. (1) The attorney general has exclusive authority and may use the duties and powers provided by Title 30, chapter 14, parts 1 and 2, to enforce violations pursuant to this part. (2) The attorney general shall post on the attorney general's website: (a) information relating to: (i) the responsibilities of a controller pursuant to this part; (ii) the responsibilities of a processor pursuant t… Archived from source — captured 2026-08-15 · snapshot 8c5cafe0 Verify at the source
Maximum penalty per violation
$7,500
Consumer protection fines of up to $10,000 (willful or injunction violations) may also apply; not settled. “is liable for a civil penalty in an amount not to exceed $7,500 for each violation” View the statute
Right to cure
60 days (lapsed Sep 30, 2025)
The 60-day cure was removed effective Oct 1, 2025 (SB 297); no cure applies to enforcement today. Archived excerpt — the text we read …subject to the statute of limitations pursuant to 27-2-231. (5) Nothing in this part may be construed as providing the basis for or be subject to a private right of action for violations of this part or any other law. History: En. Sec. 12, Ch. 681, L. 2023; amd. Sec. 8, Ch. 567, L. 2025. Archived from source — captured 2026-09-18 · snapshot 2940c8c3 Verify at the source
Private right of action
No private right of action.
Archived excerpt — the text we read …the data protection assessment for compliance with the requirements pursuant to this part. (4) Actions brought by the department to enforce this part are subject to the statute of limitations pursuant to 27-2-231. (5) Nothing in this part may be construed as providing the basis for or be subject to a private right of action for violations of this part or any other law. History: En. Sec. 12, Ch. 681, L. 2023; amd. Sec. 8, Ch. 567, L. 2025. Archived from source — captured 2026-08-15 · snapshot 8c5cafe0 Verify at the source

Corroborated by Privacy-law tracker

Universal opt-out signal
Required
Archived excerpt — the text we read …s internet website to an internet web page that enables a consumer, or an agent of the consumer, to opt out of the targeted advertising or sale of the consumer's personal data; and (b) by no later than January 1, 2025, allow a consumer to opt out of any processing of the consumer's personal data for the purposes of targeted advertising, or any sale of such personal data through an opt-out preference signal sent with the consumer's consent, to the controller by a platform, technology, or mechanism that: (i) may not unfairly disadvantage another controller; (ii) may not make use of a default setting, but require the consumer to make an affirmative, freel… Archived from source — captured 2026-08-15 · snapshot c7749f03 Verify at the source

Corroborated by Privacy-law tracker

Who it applies to

Persons that do business in Montana or target its residents, and meet: 25,000+ consumers, or 15,000+ consumers and more than 25% of gross revenue from selling data; some provisions apply under a separate test (see full text)

What the law gives consumers

  • Right to access Archived excerpt — the text we read 30-14-2808. Consumer personal data -- opt-out -- compliance -- appeals. (1) A consumer must have the right to: (a) confirm whether a controller is processing the consumer's personal data and access the consumer's personal data, unless such confirmation or access would require the controller to reveal a trade secret; (b) correct inaccuracies in the consumer's personal data, considering the nature of the personal data and the purposes of the processing of the consumer's personal data; (c) delete personal data about the consumer; … Archived from source — captured 2026-09-18 · snapshot 55e5fe87 Verify at the source
  • Right to correct Archived excerpt — the text we read …ht to: (a) confirm whether a controller is processing the consumer's personal data and access the consumer's personal data, unless such confirmation or access would require the controller to reveal a trade secret; (b) correct inaccuracies in the consumer's personal data, considering the nature of the personal data and the purposes of the processing of the consumer's personal data; (c) delete personal data about the consumer; (d) obtain a copy of the consumer's personal data previously provided by the consumer to the controller in a portable and, to the extent technically feasible, readily usab… Archived from source — captured 2026-09-18 · snapshot 55e5fe87 Verify at the source
  • Right to delete Archived excerpt — the text we read …re the controller to reveal a trade secret; (b) correct inaccuracies in the consumer's personal data, considering the nature of the personal data and the purposes of the processing of the consumer's personal data; (c) delete personal data about the consumer; (d) obtain a copy of the consumer's personal data previously provided by the consumer to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit… Archived from source — captured 2026-09-18 · snapshot 55e5fe87 Verify at the source
  • Right to data portability Archived excerpt — the text we read …b) correct inaccuracies in the consumer's personal data, considering the nature of the personal data and the purposes of the processing of the consumer's personal data; (c) delete personal data about the consumer; (d) obtain a copy of the consumer's personal data previously provided by the consumer to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the personal data to another controller without hindrance when the processing is carried out by automated means, provided the controller is not required to reveal any trade secret; and (e) opt out of the processing of the consumer's personal data for the purposes of: (i) targeted advertising; (ii) the sale of the consumer's personal data, except as provided in 30-14-2812(2); or (iii) profilin… Archived from source — captured 2026-09-18 · snapshot 55e5fe87 Verify at the source
  • Right to opt out of sale Archived excerpt — the text we read …arried out by automated means, provided the controller is not required to reveal any trade secret; and (e) opt out of the processing of the consumer's personal data for the purposes of: (i) targeted advertising; (ii) the sale of the consumer's personal data, except as provided in 30-14-2812(2); or (iii) profiling in furtherance of automated decisions that produce legal or similarly significant effects concerning the consumer. (2) A consumer may exercise rights under this section by a secure and reliable mea… Archived from source — captured 2026-09-18 · snapshot 55e5fe87 Verify at the source
  • Right to opt out of targeted advertising Archived excerpt — the text we read …nce when the processing is carried out by automated means, provided the controller is not required to reveal any trade secret; and (e) opt out of the processing of the consumer's personal data for the purposes of: (i) targeted advertising; (ii) the sale of the consumer's personal data, except as provided in 30-14-2812(2); or (iii) profiling in furtherance of automated decisions that produce legal or similarly significant effects concerning the consumer… Archived from source — captured 2026-09-18 · snapshot 55e5fe87 Verify at the source
  • Right to opt out of profiling for significant decisions Archived excerpt — the text we read …e secret; and (e) opt out of the processing of the consumer's personal data for the purposes of: (i) targeted advertising; (ii) the sale of the consumer's personal data, except as provided in 30-14-2812(2); or (iii) profiling in furtherance of automated decisions that produce legal or similarly significant effects concerning the consumer. (2) A consumer may exercise rights under this section by a secure and reliable means established by the controller and described to the consumer in the controller's privacy notice. (3) (a) A consumer may designate an… Archived from source — captured 2026-09-18 · snapshot 55e5fe87 Verify at the source
  • Sensitive data: opt-in consent required Archived excerpt — the text we read …or purposes that are not reasonably necessary to or compatible with the disclosed purposes for which the personal data is processed as disclosed to the consumer unless the controller obtains the consumer's consent; (b) process sensitive data concerning a consumer without obtaining the consumer's consent or, in the case of the processing of sensitive data concerning a known child, without processing the sensitive data in accordance with the Children's Online Privacy Protection Act of 1998, 15 U.S.C. 6501, et seq.; (c) … Archived from source — captured 2026-09-18 · snapshot d55d015b Verify at the source
  • Right to appeal Archived excerpt — the text we read …purpose pursuant to the provisions of this part; or (ii) opting the consumer out of the processing of the consumer's personal data for any purpose except for those exempted pursuant to the provisions of this part. (5) A controller shall establish a process for a consumer to appeal the controller's refusal to act on a request within a reasonable period after the consumer's receipt of the decision. The appeal process must be conspicuously available and like the process for submitting requests to initiate action pursuant to this section. Not later than 60 days after receipt of an appeal, a controller shall inform t… Archived from source — captured 2026-09-18 · snapshot 55e5fe87 Verify at the source
  • Right against discrimination Archived excerpt — the text we read …personal data without the consumer's consent under circumstances in which a controller has actual knowledge or willfully disregards that the consumer is at least 13 years of age but younger than 16 years of age; or (e) discriminate against a consumer for exercising any of the consumer rights contained in this part, including denying goods or services, charging different prices or rates for goods or services, or providing a different level of quality of goods or services to the consumer. (3) Nothing in subsection (1) or (2) may be construed to require a controller to provide a product or service that requires the personal data of a consumer that the controller does not collect or maintain or prohibit … Archived from source — captured 2026-09-18 · snapshot d55d015b Verify at the source
  • Not granted: Private right of action Archived excerpt — the text we read …the data protection assessment for compliance with the requirements pursuant to this part. (4) Actions brought by the department to enforce this part are subject to the statute of limitations pursuant to 27-2-231. (5) Nothing in this part may be construed as providing the basis for or be subject to a private right of action for violations of this part or any other law. History: En. Sec. 12, Ch. 681, L. 2023; amd. Sec. 8, Ch. 567, L. 2025. Archived from source — captured 2026-08-15 · snapshot 8c5cafe0 Verify at the source

Who the law governs

  • Controllers Archived excerpt — the text we read …any; (b) control in any manner over the election of a majority of the directors or of individuals exercising similar functions; or (c) the power to exercise controlling influence over the management of a company. (9) "Controller" means an individual who or legal entity that, alone or jointly with others, determines the purpose and means of processing personal data. (10) "Dark pattern" means a user interface designed or manipulated with the effect of substantially subverting or impairing user autonomy, decision-making, or choice. (11) "Decisions that produce legal or similarly si… Archived from source — captured 2026-09-18 · snapshot 59f85f88 Verify at the source
  • Processors Archived excerpt — the text we read … of operations performed, whether by manual or automated means, on personal data or on sets of personal data, such as the collection, use, storage, disclosure, analysis, deletion, or modification of personal data. (22) "Processor" means an individual who or legal entity that processes personal data on behalf of a controller. (23) "Profiling" means any form of automated processing performed on personal data to evaluate, analyze, or predict personal aspects related to an identified or identifiable individual's economic situation, health, per… Archived from source — captured 2026-09-18 · snapshot 59f85f88 Verify at the source

Exemptions

  • State and local government Archived excerpt — the text we read 30-14-2804. Exemptions. (1) This part does not apply to any: (a) body, authority, board, bureau, commission, district, or agency of this state or any political subdivision of this state; (b) nonprofit organization that is established to detect and prevent fraudulent acts in connection with insurance; (c) institution of higher education; (d) national securities association that is registered under 15… Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • Nonprofit organizations established to detect and prevent insurance fraud Archived excerpt — the text we read 30-14-2804. Exemptions. (1) This part does not apply to any: (a) body, authority, board, bureau, commission, district, or agency of this state or any political subdivision of this state; (b) nonprofit organization that is established to detect and prevent fraudulent acts in connection with insurance; (c) institution of higher education; (d) national securities association that is registered under 15 U.S.C. 78o-3 of the federal Securities Exchange Act of 1934, as amended; (e) state or federally chartered bank or … Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • Institutions of higher education Archived excerpt — the text we read … bureau, commission, district, or agency of this state or any political subdivision of this state; (b) nonprofit organization that is established to detect and prevent fraudulent acts in connection with insurance; (c) institution of higher education; (d) national securities association that is registered under 15 U.S.C. 78o-3 of the federal Securities Exchange Act of 1934, as amended; (e) state or federally chartered bank or credit union or an affiliate or subsid… Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • Registered national securities associations Archived excerpt — the text we read …cy of this state or any political subdivision of this state; (b) nonprofit organization that is established to detect and prevent fraudulent acts in connection with insurance; (c) institution of higher education; (d) national securities association that is registered under 15 U.S.C. 78o-3 of the federal Securities Exchange Act of 1934, as amended; (e) state or federally chartered bank or credit union or an affiliate or subsidiary that is principally engaged in financial activities as described in 12 U.S.C. 1843(k); (f) personal data collected, processed, sold,… Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • Banks and credit unions and their financial affiliates State or federally chartered banks or credit unions, and their affiliates/subsidiaries principally engaged in financial activities (12 U.S.C. 1843(k)). Archived excerpt — the text we read …ent acts in connection with insurance; (c) institution of higher education; (d) national securities association that is registered under 15 U.S.C. 78o-3 of the federal Securities Exchange Act of 1934, as amended; (e) state or federally chartered bank or credit union or an affiliate or subsidiary that is principally engaged in financial activities as described in 12 U.S.C. 1843(k); (f) personal data collected, processed, sold, or disclosed in accordance with, Title V of the Gramm-Leach-Bliley Act, 15 U.S.C. 6801, et seq.; (g) covered entity or business associate as defined in the privacy regula… Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • GLBA-regulated data Archived excerpt — the text we read …curities Exchange Act of 1934, as amended; (e) state or federally chartered bank or credit union or an affiliate or subsidiary that is principally engaged in financial activities as described in 12 U.S.C. 1843(k); (f) personal data collected, processed, sold, or disclosed in accordance with, Title V of the Gramm-Leach-Bliley Act, 15 U.S.C. 6801, et seq.; (g) covered entity or business associate as defined in the privacy regulations of the federal Health Insurance Portability and Accountability Act of 1996, 45 CFR 160.103; or (h) insurer as defined in 33-1-201, an ins… Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • HIPAA covered entities and business associates Archived excerpt — the text we read …lly engaged in financial activities as described in 12 U.S.C. 1843(k); (f) personal data collected, processed, sold, or disclosed in accordance with, Title V of the Gramm-Leach-Bliley Act, 15 U.S.C. 6801, et seq.; (g) covered entity or business associate as defined in the privacy regulations of the federal Health Insurance Portability and Accountability Act of 1996, 45 CFR 160.103; or (h) insurer as defined in 33-1-201, an insurance producer as defined in 33-17-102, a third-party administrator of self-insurance, or an affiliate or subsidiary of an entity identified in this subsection (1)(h) that… Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • Insurers, insurance producers, third-party administrators of self-insurance, and others Insurers, insurance producers, third-party administrators of self-insurance, and their financial-activity affiliates/subsidiaries. Not a self-insurance program that does not otherwise write insurance. Archived excerpt — the text we read …ch-Bliley Act, 15 U.S.C. 6801, et seq.; (g) covered entity or business associate as defined in the privacy regulations of the federal Health Insurance Portability and Accountability Act of 1996, 45 CFR 160.103; or (h) insurer as defined in 33-1-201, an insurance producer as defined in 33-17-102, a third-party administrator of self-insurance, or an affiliate or subsidiary of an entity identified in this subsection (1)(h) that is principally engaged in financial activities as described in 12 U.S.C. 1843(k), except that this subsection (1)(h) does not apply to a person who, alone or in combination with another person, establishes and maintains a self-insurance program that does not otherwise engage in the business of entering into policies of insurance. (2) Information and data exempt from this part include: (a) protected health information under the privacy regulations of the federal Health Insurance Portability and Accountability Act of 1996; (b) patient-identify… Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • Protected health information Archived excerpt — the text we read …ith another person, establishes and maintains a self-insurance program that does not otherwise engage in the business of entering into policies of insurance. (2) Information and data exempt from this part include: (a) protected health information under the privacy regulations of the federal Health Insurance Portability and Accountability Act of 1996; (b) patient-identifying information for the purposes of 42 U.S.C. 290dd-2; (c) identifiable private information for the purposes of the federal policy for the protection of human subjects of 1991, 45 CFR, part 46; (… Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • Patient-identifying information under 42 U.S.C. 290dd-2 Archived excerpt — the text we read …ies of insurance. (2) Information and data exempt from this part include: (a) protected health information under the privacy regulations of the federal Health Insurance Portability and Accountability Act of 1996; (b) patient-identifying information for the purposes of 42 U.S.C. 290dd-2; (c) identifiable private information for the purposes of the federal policy for the protection of human subjects of 1991, 45 CFR, part 46; (d) identifiable private information that is otherwise information collected … Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • Human subjects research information under federal policy Archived excerpt — the text we read …(a) protected health information under the privacy regulations of the federal Health Insurance Portability and Accountability Act of 1996; (b) patient-identifying information for the purposes of 42 U.S.C. 290dd-2; (c) identifiable private information for the purposes of the federal policy for the protection of human subjects of 1991, 45 CFR, part 46; (d) identifiable private information that is otherwise information collected as part of human subjects research pursuant to the good clinical practice guidelines issued by the international council for harmonisation o… Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • Human subjects research under good clinical practice guidelines Archived excerpt — the text we read …(b) patient-identifying information for the purposes of 42 U.S.C. 290dd-2; (c) identifiable private information for the purposes of the federal policy for the protection of human subjects of 1991, 45 CFR, part 46; (d) identifiable private information that is otherwise information collected as part of human subjects research pursuant to the good clinical practice guidelines issued by the international council for harmonisation of technical requirements for pharmaceuticals for human use; (e) the protection of human subjects under 21 CFR, parts 6, 50, and 56, or personal data used or shared in research as defined in the federal Health Insurance Portability and Accountability Act of 1996, 45 CFR 164.501… Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • Human subjects research data 21 CFR parts 6, 50, 56; HIPAA research under 45 CFR 164.501; or other research conducted in accordance with applicable law. Archived excerpt — the text we read …tion collected as part of human subjects research pursuant to the good clinical practice guidelines issued by the international council for harmonisation of technical requirements for pharmaceuticals for human use; (e) the protection of human subjects under 21 CFR, parts 6, 50, and 56, or personal data used or shared in research as defined in the federal Health Insurance Portability and Accountability Act of 1996, 45 CFR 164.501, that is conducted in accordance with the standards set forth in this subsection (2)(e), or other research conducted in accordance with applicable law; (f) information and documents created for the purposes of the Health Care Quality Improvement Act of 1986, 42 U.S.C. 11101, et seq.; (g) patient safety work products for the purposes of the Patient Safety and Quality… Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • Health Care Quality Improvement Act information Archived excerpt — the text we read …nce Portability and Accountability Act of 1996, 45 CFR 164.501, that is conducted in accordance with the standards set forth in this subsection (2)(e), or other research conducted in accordance with applicable law; (f) information and documents created for the purposes of the Health Care Quality Improvement Act of 1986, 42 U.S.C. 11101, et seq.; (g) patient safety work products for the purposes of the Patient Safety and Quality Improvement Act of 2005, 42 U.S.C. 299b-21, et seq., as amended; (h) information derived from any of the health care-related informa… Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • Patient safety work products Archived excerpt — the text we read …ubsection (2)(e), or other research conducted in accordance with applicable law; (f) information and documents created for the purposes of the Health Care Quality Improvement Act of 1986, 42 U.S.C. 11101, et seq.; (g) patient safety work products for the purposes of the Patient Safety and Quality Improvement Act of 2005, 42 U.S.C. 299b-21, et seq., as amended; (h) information derived from any of the health care-related information listed in this subsection (2) that is: (i) de-identified in accordance with the requirements for de-identification pursuant to the privacy regul… Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • De-identified health-related information Archived excerpt — the text we read …ses of the Patient Safety and Quality Improvement Act of 2005, 42 U.S.C. 299b-21, et seq., as amended; (h) information derived from any of the health care-related information listed in this subsection (2) that is: (i) de-identified in accordance with the requirements for de-identification pursuant to the privacy regulations of the federal Health Insurance Portability and Accountability Act of 1996; or (ii) included in a limited data set as described in 45 CFR 164.514(e), to the extent that the information is used, disclosed, and maintained in a manner specified in 45 CFR 164.514(e); (i) information originating … Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • HIPAA limited data set information Archived excerpt — the text we read …bsection (2) that is: (i) de-identified in accordance with the requirements for de-identification pursuant to the privacy regulations of the federal Health Insurance Portability and Accountability Act of 1996; or (ii) included in a limited data set as described in 45 CFR 164.514(e), to the extent that the information is used, disclosed, and maintained in a manner specified in 45 CFR 164.514(e); (i) information originating from and intermingled to be indistinguishable with or information treated in the same manner as information exempt under this subsection (2) that is maintained by a covered entity or busine… Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • Health information intermingled with exempt HIPAA data Archived excerpt — the text we read …countability Act of 1996; or (ii) included in a limited data set as described in 45 CFR 164.514(e), to the extent that the information is used, disclosed, and maintained in a manner specified in 45 CFR 164.514(e); (i) information originating from and intermingled to be indistinguishable with or information treated in the same manner as information exempt under this subsection (2) that is maintained by a covered entity or business associate as defined in the privacy regulations of the federal Health Insurance Portability and Accountability Act of 1996, 45 CFR 160.103, or a program or qualified service organization, as specified in 42 U.S.C. 290dd-2, as amended; (j) information used for public health activities and purposes as authorized by the federal Health Insurance Portability and Accountability Act of 1996, community health activities, and population health activities; … Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • Public health activities information Archived excerpt — the text we read … in the privacy regulations of the federal Health Insurance Portability and Accountability Act of 1996, 45 CFR 160.103, or a program or qualified service organization, as specified in 42 U.S.C. 290dd-2, as amended; (j) information used for public health activities and purposes as authorized by the federal Health Insurance Portability and Accountability Act of 1996, community health activities, and population health activities; (k) the collection, maintenance, disclosure, sale, communication, or use of any personal information bearing on a consumer's credit worthiness, credit standing, credit capacity, character, general reputation, personal… Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • FCRA-regulated data Archived excerpt — the text we read …j) information used for public health activities and purposes as authorized by the federal Health Insurance Portability and Accountability Act of 1996, community health activities, and population health activities; (k) the collection, maintenance, disclosure, sale, communication, or use of any personal information bearing on a consumer's credit worthiness, credit standing, credit capacity, character, general reputation, personal characteristics, or mode of living by a consumer reporting agency, furnisher, or user that provides information for use in a consumer report and by a user of a consumer report, but only to the extent that the activity is regulated by and authorized under the Fair Credit Reporting Act, 15 U.S.C. 1681, as amended; (l) personal data collected, processed, sold, or disclosed in compliance with the Driver's Privacy Protection Act of 1994, 18 U.S.C. 2721, et seq., as amended; (m) personal data regulated by the Family Educational Ri… Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • Driver's Privacy Protection Act data Archived excerpt — the text we read … information for use in a consumer report and by a user of a consumer report, but only to the extent that the activity is regulated by and authorized under the Fair Credit Reporting Act, 15 U.S.C. 1681, as amended; (l) personal data collected, processed, sold, or disclosed in compliance with the Driver's Privacy Protection Act of 1994, 18 U.S.C. 2721, et seq., as amended; (m) personal data regulated by the Family Educational Rights and Privacy Act of 1974, 20 U.S.C. 1232g, et seq., as amended; (n) personal data collected, processed, sold, or disclosed in compliance with the Farm Credi… Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • FERPA-regulated data Archived excerpt — the text we read …air Credit Reporting Act, 15 U.S.C. 1681, as amended; (l) personal data collected, processed, sold, or disclosed in compliance with the Driver's Privacy Protection Act of 1994, 18 U.S.C. 2721, et seq., as amended; (m) personal data regulated by the Family Educational Rights and Privacy Act of 1974, 20 U.S.C. 1232g, et seq., as amended; (n) personal data collected, processed, sold, or disclosed in compliance with the Farm Credit Act of 1993, 12 U.S.C. 2001, et seq., as amended; (o) data processed or maintained: (i) by an individual applying to, emp… Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • Farm Credit Act data Archived excerpt — the text we read …ce with the Driver's Privacy Protection Act of 1994, 18 U.S.C. 2721, et seq., as amended; (m) personal data regulated by the Family Educational Rights and Privacy Act of 1974, 20 U.S.C. 1232g, et seq., as amended; (n) personal data collected, processed, sold, or disclosed in compliance with the Farm Credit Act of 1993, 12 U.S.C. 2001, et seq., as amended; (o) data processed or maintained: (i) by an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party to the extent that the data is collected and… Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • Employment data Archived excerpt — the text we read …U.S.C. 1232g, et seq., as amended; (n) personal data collected, processed, sold, or disclosed in compliance with the Farm Credit Act of 1993, 12 U.S.C. 2001, et seq., as amended; (o) data processed or maintained: (i) by an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party to the extent that the data is collected and used within the context of that role; (ii) as the emergency contact information of an individual under this part and used for emergency contact purposes; or (iii) that is necessary to retain to administer benefits for another individual relating to the i… Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • Emergency contact information Archived excerpt — the text we read …an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party to the extent that the data is collected and used within the context of that role; (ii) as the emergency contact information of an individual under this part and used for emergency contact purposes; or (iii) that is necessary to retain to administer benefits for another individual relating to the individual who is the subject of the information under subsection (2)(a) and is used for the purposes of administering… Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • Benefits administration data Archived excerpt — the text we read …ird party to the extent that the data is collected and used within the context of that role; (ii) as the emergency contact information of an individual under this part and used for emergency contact purposes; or (iii) that is necessary to retain to administer benefits for another individual relating to the individual who is the subject of the information under subsection (2)(a) and is used for the purposes of administering the benefits; and (p) personal data collected, processed, sold, or disclosed in relation to price, route, or service, as these terms are used in the Airline Deregulation Act of 1978, 49 U.S.C. 40101, et seq., as amended, by an air … Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • Airline Deregulation Act preempted data Archived excerpt — the text we read …ssary to retain to administer benefits for another individual relating to the individual who is the subject of the information under subsection (2)(a) and is used for the purposes of administering the benefits; and (p) personal data collected, processed, sold, or disclosed in relation to price, route, or service, as these terms are used in the Airline Deregulation Act of 1978, 49 U.S.C. 40101, et seq., as amended, by an air carrier subject to the Airline Deregulation Act of 1978, to the extent this part is preempted by the Airline Deregulation Act of 1978, 49 U.S.C. 41713, as amended. (3) Controllers and processors that comply with the verifiable parental consent requirements of the Children's Online Privacy Protection Act of 1998, 15 U.S.C. 6501, et seq., shall be considered compliant with any obl… Archived from source — captured 2026-09-18 · snapshot 744f5c21 Verify at the source
  • Evidentiary privilege (compliance would violate a Montana evidentiary privilege) Archived excerpt — the text we read …oller or are otherwise compatible with processing data in furtherance of the provision of a product or service specifically requested by a consumer or the performance of a contract to which the consumer is a party. (3) The obligations imposed on controllers or processors under this part may not apply when compliance by the controller or processor with this part would violate an evidentiary privilege under the laws of this state. Nothing in this part may be construed to prevent a controller or processor from providing personal data concerning a consumer to a person covered by an evidentiary privilege under the laws of this state as part of a pr… Archived from source — captured 2026-09-18 · snapshot d6aaf554 Verify at the source
  • Personal or household activities Archived excerpt — the text we read … limited to the rights of any person: (i) to freedom of speech or freedom of the press guaranteed in the first amendment to the United States constitution; or (ii) under Rule 504 of the Montana Rules of Evidence; (b) apply to a person's processing of personal data during the person's personal or household activities; or (c) require a controller or processor to implement an age verification or age-gating system or otherwise affirmatively collect the age of consumers, but a controller that chooses to conduct commercially reasonable … Archived from source — captured 2026-09-18 · snapshot d6aaf554 Verify at the source
  • Privileged communications to a person covered by an evidentiary privilege Archived excerpt — the text we read … (3) The obligations imposed on controllers or processors under this part may not apply when compliance by the controller or processor with this part would violate an evidentiary privilege under the laws of this state. Nothing in this part may be construed to prevent a controller or processor from providing personal data concerning a consumer to a person covered by an evidentiary privilege under the laws of this state as part of a privileged communication. (4) A controller or processor that discloses personal data to a processor or third-party controller in accordance with this part may not be considered to have violated this part if the processor or third-party controll… Archived from source — captured 2026-09-18 · snapshot d6aaf554 Verify at the source
  • Rights and freedoms of others, including free speech and press Archived excerpt — the text we read … of this part for the transgressions of the disclosing controller or processor from which the receiving processor or third-party controller receives the personal data. (5) Nothing in this part may be construed to: (a) impose any obligation on a controller or processor that adversely affects the rights or freedoms of any person, including but not limited to the rights of any person: (i) to freedom of speech or freedom of the press guaranteed in the first amendment to the United States constitution; or (ii) under Rule 504 of the Montana Rules of Evidence; (b) apply to a person's processing of personal data during the person's personal or household activities; or (c) require a controller or processor to implement an age verification or age-gating system or otherwise af… Archived from source — captured 2026-09-18 · snapshot d6aaf554 Verify at the source

Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source.

Timeline

MCDPA milestones

This state currently has one dated milestone on the books.

Enforcement October 1, 2024

MCDPA took effect

Enforcement began — obligations have been live since this date.

Source: primary citation

Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source. Reference only, not legal advice.

When staying on top of the law isn't enough, DataGrail automates the work.
DSR automation and regulatory tracking — handled by the platform behind this reference.
How DataGrail helps
Back to the Regulations Hub Reference only — not legal advice. Published Sep 29, 2026