Minnesota's Consumer Data Privacy Act Exempts Small Businesses — and Then Regulates Them Anyway

August 21, 2026 · David J.S. Madgett

Most companies assess the Minnesota Consumer Data Privacy Act the way they assess every other state privacy law: run the applicability thresholds, and if you are under them, close the file. Minnesota’s thresholds are high — 100,000 consumers, or 25,000 plus a quarter of gross revenue from selling data — so most Minnesota businesses close the file quickly.

That is the wrong place to stop reading. The Act’s exclusion list runs 21 clauses, and two of them do something unusual. The small-business exclusion is not an exclusion; it is a substitution, and the substituted obligation applies to a business of any size with no consumer-count threshold at all. And there is no general exclusion for nonprofits — the only nonprofit the list names is an insurance anti-fraud organization.

A Minnesota company that is comfortably below both thresholds can still be sued by the Attorney General under this statute. Very few of them know it.


Where is the Minnesota Consumer Data Privacy Act actually codified?

At Minn. Stat. §§ 325M.10 to 325M.21. The Act does not have a chapter of its own:

Sections 325M.10 to 325M.21 may be cited as the “Minnesota Consumer Data Privacy Act.”

Minn. Stat. § 325M.10.

This matters more than a citation quibble. Chapter 325M now carries three separate enactments: the older internet-service-provider privacy sections at §§ 325M.01–.09, the MCDPA at §§ 325M.10–.21, and the Prohibiting Social Media Manipulation Act beginning at § 325M.30. A citation to “chapter 325M” no longer identifies a statute. Every proposition below is tied to a specific section for that reason.

It is also worth stating what does not exist: Minnesota Statutes contain no chapter 325O. The Revisor returns nothing for it. A compliance memo, vendor questionnaire, or multistate chart that cites “Minn. Stat. ch. 325O” is citing an authority that will not resolve — and if the chapter number is wrong, the substance behind it deserves a second look too.

For how the MCDPA sits alongside Minnesota’s breach statute and the Government Data Practices Act, see our comparison of Minnesota’s three privacy regimes. This piece is the deep read on the MCDPA itself.


When did it take effect, and did anyone get extra time?

July 31, 2025 — with one nine-figure-endowment-sized exception. The effective-date section of the enacting article reads in full:

This article is effective July 31, 2025, except that postsecondary institutions regulated by the Office of Higher Education are not required to comply with this article until July 31, 2029.

Laws 2024, ch. 121, art. 5, § 14.

There is no other delayed-compliance date in the Act, and no phase-in by company size. Every covered entity that is not a postsecondary institution regulated by the Office of Higher Education has been fully subject to the MCDPA for more than a year.


Which companies are covered?

Two gates, and a company must clear both. Section 325M.12, subd. 1(a), applies the Act:

to legal entities that conduct business in Minnesota or produce products or services that are targeted to residents of Minnesota, and that satisfy one or more of the following thresholds:

(1) during a calendar year, controls or processes personal data of 100,000 consumers or more, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or

(2) derives over 25 percent of gross revenue from the sale of personal data and processes or controls personal data of 25,000 consumers or more.

Three things in that text are load-bearing.

“Targeted to residents of Minnesota” is a separate hook from doing business here. A company with no Minnesota presence that markets into the state is inside the first gate.

The 100,000 count excludes payment-transaction data. Personal data “controlled or processed solely for the purpose of completing a payment transaction” does not count toward the threshold. For a retailer whose customer volume is mostly card swipes, that exclusion can be the difference between covered and not — and the calculation is worth documenting contemporaneously, because the burden of establishing an exemption falls on the controller. Section 325M.19(g): “the controller bears the burden of demonstrating that the processing qualifies for the exemption.”

“Consumer” is narrower than “person.” Section 325M.11(g): “‘Consumer’ means a natural person who is a Minnesota resident acting only in an individual or household context. Consumer does not include a natural person acting in a commercial or employment context.” Business contacts and employees are not consumers, so they do not count toward 100,000 — and, as discussed below, their data is outside the Act twice over.

One structural rule attaches at the scope stage. A controller or processor acting as a technology provider under Minn. Stat. § 13.32 must comply with both statutes, “except that when the provisions of section 13.32 conflict with sections 325M.10 to 325M.21, section 13.32 prevails.” § 325M.12, subd. 1(b). An education-technology vendor serving Minnesota schools is under the Data Practices Act on top of the MCDPA, and the Data Practices Act wins the conflict.


Is a small business exempt from the MCDPA?

No — it is exempt from most of the Act and squarely subject to one prohibition. This is the provision that catches companies out, and it is written as a carve-back inside the exclusion list. Section 325M.12, subd. 2(a)(19), excludes:

a small business, as defined by the United States Small Business Administration under Code of Federal Regulations, title 13, part 121, except that a small business identified in this clause is subject to section 325M.17.

And § 325M.17 provides:

(a) A small business, as defined by the United States Small Business Administration under Code of Federal Regulations, title 13, part 121, that conducts business in Minnesota or produces products or services that are targeted to residents of Minnesota, must not sell a consumer’s sensitive data without the consumer’s prior consent.

(b) Penalties and attorney general enforcement procedures under section 325M.20 apply to a small business that violates this section.

Read § 325M.17(a) against § 325M.12, subd. 1(a). The threshold language is gone. Section 325M.17 reaches any small business that conducts business in Minnesota or targets Minnesota residents. There is no 100,000-consumer floor, no revenue test, no minimum data volume. A four-person Minnesota company that has never held the data of a thousand people is inside § 325M.17 the moment it sells sensitive data without prior consent — and § 325M.17(b) attaches the same Attorney General enforcement and the same civil penalty of up to $7,500 per violation that applies to a company a thousand times its size.

Two definitions decide how much that costs.

“Sale” is broader than a sale. Section 325M.11(u): “‘Sale,’ ‘sell,’ or ‘sold’ means the exchange of personal data for monetary or other valuable consideration by the controller to a third party.” A barter, a data-for-services arrangement, or a co-marketing swap is a sale. The subdivision then excludes six transfers that are not sales: disclosure to a processor acting on the controller’s behalf; disclosure to a third party to provide a product or service the consumer requested; disclosure or transfer to an affiliate; disclosure of information the consumer intentionally made public through mass media without restricting the audience; transfer as an asset in a merger, acquisition, bankruptcy, or similar transaction in which the third party assumes control of the assets; and exchanges between the producer of a good or service and the producer’s authorized sales-and-service agents to enable cooperative provisioning.

“Sensitive data” is four categories, and the fourth surprises people. Section 325M.11(v) defines it as personal data revealing racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, sexual orientation, or citizenship or immigration status; the processing of biometric data or genetic information for the purpose of uniquely identifying an individual; the personal data of a known child; or specific geolocation data.

“Specific geolocation data” is defined with a precision most operators have never checked. Section 325M.11(w) reaches information that “directly identifies the geographic coordinates of a consumer or a device linked to a consumer with an accuracy of more than three decimal degrees of latitude and longitude or the equivalent in an alternative geographic coordinate system, or a street address derived from the coordinates.” A small app developer monetizing location signal — a category that includes a great many businesses that would never describe themselves as data companies — is selling sensitive data.

A “known child,” in turn, is “a person under circumstances where a controller has actual knowledge of, or willfully disregards, that the person is under 13 years of age.” § 325M.11(o). Willful disregard is enough. A business that structures itself not to know the ages of its users has not avoided the definition.

The practical takeaway for a small Minnesota business is short: the MCDPA’s compliance architecture — privacy notices, request handling, assessments — does not apply to you. One rule does, it has no size threshold, and the Attorney General enforces it.


Are nonprofits exempt?

Not as a class. Section 325M.12, subd. 2(a), lists 21 exclusions. Government entities as defined by § 13.02, subd. 7a, are excluded. Federally recognized Indian tribes are excluded. State and federally chartered banks and credit unions are excluded, as are insurance companies, insurance producers, and third-party administrators of self-insurance. Small businesses are excluded, subject to § 325M.17.

The only nonprofit named anywhere in the list is clause (20): “a nonprofit organization that is established to detect and prevent fraudulent acts in connection with insurance.”

There is no clause excluding charitable organizations, foundations, trade associations, membership organizations, or 501(c)(3) entities generally. A Minnesota nonprofit that clears the applicability thresholds in § 325M.12, subd. 1 — a large health-adjacent charity, a statewide membership organization, a major arts institution with a six-figure donor and ticket-buyer file — is a controller with the full set of controller obligations. Many multistate privacy templates assume a nonprofit exemption. This statute does not contain one, and the entity relying on such a template will be relying on nothing.


What else is excluded, and is the exclusion entity-level or data-level?

Both, and the difference decides how much work an exclusion saves you. Some clauses in § 325M.12, subd. 2(a), exclude an entity — the whole organization drops out. Others exclude a category of information — the organization stays in and only that data drops out.

Entity-level exclusions: government entities (clause 1); federally recognized Indian tribes (clause 2); state or federally chartered banks and credit unions, and affiliates or subsidiaries principally engaged in financial activities under 12 U.S.C. § 1843(k) (clause 16); small businesses, subject to § 325M.17 (clause 19); insurance-fraud-prevention nonprofits (clause 20); air carriers subject to the federal Airline Deregulation Act, but only as to personal data related to prices, routes, or services and only to the extent that Act preempts (clause 21); and insurance companies as defined in § 60A.02, subd. 4, insurance producers under § 60K.31, subd. 6, third-party administrators of self-insurance, and their financial-activities affiliates — with an express carve-back that clause 18 “does not apply to a person that, alone or in combination with another person, establishes and maintains a self-insurance program that does not otherwise engage in the business of entering into policies of insurance.”

Data-level exclusions cover the federal-overlay categories. Protected health information under HIPAA, health records under Minn. Stat. § 144.291, subd. 2, and 42 C.F.R. pt. 2 patient-identifying information (clause 3); human-subjects research information under 45 C.F.R. pt. 46, ICH good clinical practice guidelines, or 21 C.F.R. pts. 50 and 56 (clause 3(iv)); Health Care Quality Improvement Act materials and patient safety work product (clause 3(v)–(vi)); data deidentified under 45 C.F.R. pt. 164 (clause 4); information intermingled indistinguishably with health data held by a covered entity, business associate, health care provider, or 42 C.F.R. pt. 2 program (clause 5); limited data sets, self-regulatory-organization records, and mortgage-originator and nonbank-financial-institution data intermingled with Gramm-Leach-Bliley information (clause 6); public health activities data under 45 C.F.R. pt. 164.512 (clause 7); consumer reporting agency, furnisher, and user activity to the extent it is subject to and compliant with the Fair Credit Reporting Act (clause 8); GLBA data (clause 9); Driver’s Privacy Protection Act data (clause 10); FERPA-regulated data (clause 11); Farm Credit Act data (clause 12); data under the Minnesota Insurance Fair Information Reporting Act, §§ 72A.49–.505 (clause 14); payment-only credit, check, or cash transaction data where no consumer data is retained (clause 15); and chapter 56 lender data intermingled with FCRA information (clause 17).

Two features of this list deserve emphasis.

The federal exclusions are conditional. GLBA, DPPA, and Farm Credit data are excluded only “if the collection, processing, sale, or disclosure is in compliance with that law.” The FCRA exclusion applies “only to the extent” the activity is subject to FCRA regulation and the information is not used “except as authorized by the Fair Credit Reporting Act.” A company that mishandles the data federally does not get the state exclusion either — a furnisher that reports outside what the FCRA authorizes loses clause (8) and lands back inside the MCDPA. That is a live problem for anyone in the credit-reporting chain; see our discussion of what happens when a credit report error will not get fixed.

Employee data is excluded twice. Clause (13) removes data collected “in the course of an individual acting as a job applicant to or an employee, owner, director, officer, medical staff member, or contractor of a business if the data is collected and used solely within the context of the role,” along with emergency contact information used solely for emergency contact purposes and data necessary to administer benefits. That is on top of the “consumer” definition in § 325M.11(g), which already excludes a person acting in a commercial or employment context. Build the MCDPA program for the customer file, not the HR file — and note the words “solely within the context of the role,” which is where an employer that repurposes employee data for marketing loses the exclusion.


What rights does a Minnesota consumer actually have?

Seven, set out in § 325M.14, subd. 1, paragraphs (b) through (h). Five are familiar from other states’ statutes. Two are not.

The familiar five: confirm and access the categories of personal data being processed (para. (b)); correct inaccurate personal data (para. (c)); delete personal data (para. (d)); portability — obtain data the consumer previously provided in “a portable and, to the extent technically feasible, readily usable format” that permits transmission to another controller “without hindrance,” where processing is automated (para. (e)); and opt out of processing for targeted advertising, sale, or profiling in furtherance of automated decisions producing legal or similarly significant effects (para. (f)).

The two that are worth knowing by name:

The right to question a profiling result. Section 325M.14, subd. 1(g):

If a consumer’s personal data is profiled in furtherance of decisions that produce legal effects concerning a consumer or similarly significant effects concerning a consumer, the consumer has the right to question the result of the profiling, to be informed of the reason that the profiling resulted in the decision, and, if feasible, to be informed of what actions the consumer might have taken to secure a different decision and the actions that the consumer might take to secure a different decision in the future. The consumer has the right to review the consumer’s personal data used in the profiling. If the decision is determined to have been based upon inaccurate personal data … the consumer has the right to have the data corrected and the profiling decision reevaluated based upon the corrected data.

This is not an opt-out. It is a right to an explanation and, on a showing of inaccurate input data, a right to have the decision made again. “Decisions that produce legal or similarly significant effects” is defined in § 325M.11(i) as controller decisions resulting in “the provision or denial by the controller of financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunities, health care services, or access to essential goods or services.” Any automated underwriting, tenant-screening, or eligibility model touching Minnesota consumers should be built with this paragraph in front of the engineer.

The right to a list of specific third parties. Section 325M.14, subd. 1(h): “A consumer has a right to obtain a list of the specific third parties to which the controller has disclosed the consumer’s personal data. If the controller does not maintain the information in a format specific to the consumer, a list of specific third parties to whom the controller has disclosed any consumers’ personal data may be provided instead.” Specific third parties — not categories. The fallback in the second sentence is real relief, but it produces a document a company may not want to produce: the complete list of everyone it shares data with.

Neither of these rights can be satisfied by a generic multistate privacy portal, and neither is the kind of thing that gets built after a demand letter arrives.


How fast does a controller have to respond?

The Act uses several different clocks, all in § 325M.16 and § 325M.14, and mixing them up is a compliance failure on its own.

An opt-out request under subd. 1(f) must be honored “as soon as feasibly possible, but no later than 45 days of receipt.” § 325M.14, subd. 4(d).

For any request under subd. 1, the controller must inform the consumer of the action taken “without undue delay and in any event within 45 days of receipt,” extendable once by 45 additional days where reasonably necessary — with notice of the extension and its reasons given within the original 45 days. § 325M.14, subd. 4(e).

If the controller takes no action, it must say so within 45 days, give reasons, and give instructions for appealing. § 325M.14, subd. 4(f).

On appeal, the controller has 45 days to inform the consumer of the action taken or not taken with a written explanation, extendable by 60 additional days, again with notice inside the first 45. § 325M.14, subd. 5(c). The appeal response must “clearly and prominently provide the consumer with information about how to file a complaint with the Office of the Attorney General,” and the controller must maintain records of all appeals and its responses for at least 24 months, producible to the Attorney General on written request as part of an investigation. § 325M.14, subd. 5(d).

And the shortest clock in the statute, which is not a request clock at all: when a consumer revokes consent, the controller “shall cease to process the applicable data as soon as practicable, but not later than 15 days after the receipt of the request.” § 325M.16, subd. 2(e). The revocation mechanism must be “at least as easy as the mechanism by which the consent was previously given.”

Responses are free up to twice annually. § 325M.14, subd. 4(g). Where requests are “manifestly unfounded or excessive, in particular because of the repetitive character of the requests,” the controller may charge a reasonable administrative fee or refuse — but “[t]he controller bears the burden of demonstrating the manifestly unfounded or excessive character of the request.”

Two response rules protect the consumer from the response itself. A controller answering an access request must not disclose the consumer’s Social Security number, driver’s license or other government identification number, financial account number, health insurance account or medical identification number, account password or security questions and answers, or biometric data — it must instead say, with sufficient particularity, that it holds that type of information. § 325M.14, subd. 4(i). And a controller is never required to reveal a trade secret. Subd. 4(j).


What must a controller build before any of this happens?

The MCDPA’s controller obligations in § 325M.16 are not a notice statute with rights bolted on. Several of them are affirmative design mandates.

The privacy notice has eight required contents — categories of personal data processed; the purposes of processing; an explanation of the § 325M.14 rights and how and where to exercise them, including how to appeal; categories of personal data sold or shared with third parties; categories of those third parties; the controller’s contact information “including an active email address or other online mechanism”; a description of retention policies; and the date the notice was last updated. § 325M.16, subd. 1(a). It must be posted “through a conspicuous hyperlink using the word ‘privacy’” on the website home page or the app store or download page, with an in-app link in the settings menu; available “in each language in which the controller provides a product or service”; and “reasonably accessible to and usable by individuals with disabilities.” Subd. 1(c), (d), (g). No separate Minnesota-specific notice is required if the general notice covers everything. Subd. 1(f).

A data inventory is mandatory. Section 325M.16, subd. 2(c), requires reasonable administrative, technical, and physical security practices “including the maintenance of an inventory of the data that must be managed to exercise these responsibilities.” The inventory is not best practice under this statute; it is text.

Data minimization and a retention ceiling are substantive rules. Collection must be “limited to what is adequate, relevant, and reasonably necessary in relation to the purposes for which the data are processed, which must be disclosed to the consumer,” subd. 2(a); processing for purposes not reasonably necessary to or compatible with the disclosed purposes requires consent, subd. 2(b); and a controller “may not retain personal data that is no longer relevant and reasonably necessary in relation to the purposes for which the data were collected and processed,” subd. 2(g).

Sensitive data requires consent, not notice. Subd. 2(d). And “consent” is a defined term with teeth: § 325M.11(f) requires a “freely given, specific, informed, and unambiguous indication,” provides that acceptance of broad terms of use containing data-processing descriptions “along with other, unrelated information does not constitute consent,” provides that “[h]overing over, muting, pausing, or closing a given piece of content does not constitute consent,” and provides that consent obtained by a dark pattern is not valid. A “dark pattern” is “a user interface designed or manipulated with the substantial effect of subverting or impairing user autonomy, decision making, or choice.” § 325M.11(j).

Teenagers get an opt-in, not an opt-out. Section 325M.16, subd. 2(f), prohibits processing for targeted advertising or selling personal data without consent “under circumstances where the controller knows that the consumer is between the ages of 13 and 16.” Below 13, the known-child rules and COPPA parental consent apply; a controller in compliance with COPPA “shall be deemed compliant with any obligation to obtain parental consent” under the Act. § 325M.12, subd. 2(b).

Written policies and assessments are documentary obligations the Attorney General can demand. Section 325M.18(a) requires a documented description of the controller’s compliance policies including “the name and contact information for the controller’s chief privacy officer or other individual with primary responsibility.” Section 325M.18(b) requires a documented data privacy and protection assessment for five categories of processing: targeted advertising; sale of personal data; processing of sensitive data; any processing presenting a heightened risk of harm; and profiling that presents a reasonably foreseeable risk of unfair or deceptive treatment or disparate impact, financial, physical, or reputational injury, offensive intrusion upon solitude or seclusion, or other substantial injury.

The assessments are discoverable by the state on demand — “[a]s part of a civil investigative demand, the attorney general may request, in writing, that a controller disclose any data privacy and protection assessment that is relevant to an investigation,” and the controller “must make [it] available.” § 325M.18(f). Two protections travel with that: the assessments are classified as nonpublic data under § 13.02, subd. 9, and disclosure to the Attorney General “does not constitute a waiver of the attorney-client privilege or work product protection.” An assessment prepared for another state’s law “may qualify under this section if the assessments have a similar scope and effect.” § 325M.18(g).

Universal opt-out signals must be honored. Section 325M.14, subd. 3(a), requires controllers to accept an opt-out preference signal for targeted advertising and sale, sent with the consumer’s consent through a platform, technology, or mechanism — expressly including a browser setting, browser extension, or global device setting. § 325M.14, subd. 2(d). The mechanism must not use a default setting; it must “require the consumer to make an affirmative, freely given, and unambiguous choice.” Subd. 3(a)(2). A controller that recognizes opt-out signals approved under other states’ laws complies. Subd. 3(d). And where a signal conflicts with a consumer’s participation in a loyalty or rewards program, “the controller must comply with the consumer’s opt-out preference signal” — it may then notify the consumer of the conflict and offer a chance to confirm the program, but the signal controls in the meantime. Subd. 3(b).


Who enforces the MCDPA, and is there a private right of action?

The Attorney General, exclusively. There is no private right of action, and the statute says so in terms.

Section 325M.20(b) authorizes the Attorney General to bring a civil action under Minn. Stat. § 8.31, and provides that if the state prevails it “may, in addition to penalties provided by paragraph (c) or other remedies provided by law, be allowed an amount determined by the court to be the reasonable value of all or part of the state’s litigation expenses incurred.” Paragraph (c): a violator “is subject to an injunction and liable for a civil penalty of not more than $7,500 for each violation.”

Paragraph (d) closes the private door and names the door it is closing:

Nothing in sections 325M.10 to 325M.21 establishes a private right of action, including under section 8.31, subdivision 3a, for a violation of sections 325M.10 to 325M.21 or any other law.

Section 8.31, subd. 3a, is Minnesota’s private attorney general provision — the mechanism that lets an injured person sue for damages, costs, and attorney fees under statutes the Attorney General enforces. Paragraph (d) was drafted specifically to keep the MCDPA out of it.

And the cure period is over. Section 325M.20(a) required the Attorney General, before suing, to send a warning letter “identifying the specific provisions … the attorney general alleges have been or are being violated,” then wait 30 days for a cure. The paragraph ends: “This paragraph expires January 31, 2026.

That date has passed. For any enforcement action commenced now, there is no statutory warning letter, no statutory cure window, and no 30 days to fix what an investigator finds. A company that built its MCDPA risk model around “we will hear from them first” built it around a paragraph that no longer exists.


Can a contract waive any of this?

No. Section 325M.16, subd. 4: “Any provision of a contract or agreement of any kind that purports to waive or limit in any way a consumer’s rights under sections 325M.10 to 325M.21 is contrary to public policy and is void and unenforceable.”

Nor can a city or county add to it. Section 325M.21(a) provides that the Act “supersede[s] and preempt[s] laws, ordinances, regulations, or the equivalent adopted by any local government regarding the processing of personal data by controllers or processors.” A Minneapolis or St. Paul data ordinance regulating processing by controllers is preempted.

And a controller may not retaliate. Section 325M.16, subd. 3(b), prohibits discriminating against a consumer for exercising MCDPA rights — including “denying goods or services to the consumer, charging different prices or rates for goods or services, and providing a different level of quality of goods and services” — subject to a bona fide loyalty, rewards, premium features, discounts, or club card program exception. Subdivision 3(a) separately prohibits processing personal data on the basis of actual or perceived race, color, ethnicity, religion, national origin, sex, gender, gender identity, sexual orientation, familial status, lawful source of income, or disability “in a manner that unlawfully discriminates” as to housing, employment, credit, education, or public accommodations.


What the MCDPA does not do

Four things, and each of them is a place where a reader may assume more protection than the statute provides.

It does not regulate biometrics as such. Biometric data is sensitive data requiring consent when processed “for the purpose of uniquely identifying an individual,” § 325M.11(v)(2), and it is excluded from access-request disclosure, § 325M.14, subd. 4(i)(6). But there is no Illinois-style per-scan statutory damages claim, because there is no private right of action at all. We wrote separately about why Minnesota has no biometric privacy act.

It does not reach government entities. Government entities as defined in § 13.02, subd. 7a, are excluded outright. § 325M.12, subd. 2(a)(1). Government-held data is chapter 13’s subject, and chapter 13 — unlike the MCDPA — does provide a damages remedy to an injured person.

It does not require breach notice. That obligation lives in Minn. Stat. § 325E.61, a separate statute with a much narrower definition of protected information and its own notice standard and 48-hour credit-bureau rule. The MCDPA’s only mention of breach is § 325M.13(b)(2), requiring a processor to assist the controller with § 325E.61 notification.

It does not regulate platform design. Content-recommendation and algorithmic-design rules for social platforms are in a different part of chapter 325M — sections that carry their own effective dates and, in one case, a statutory-damages claim that does not come into force until 2027. See our treatment of the Social Media Manipulation Act.


What to do about it

If you are a small business in Minnesota: determine whether you sell sensitive data as § 325M.11(u) and (v) define those terms — remembering that “sale” includes exchange for “other valuable consideration” and that “sensitive data” includes street-address-precision location. If you do, get prior consent that satisfies § 325M.11(f), or stop. That is the entire compliance program § 325M.17 asks of you, and it is not optional because you are small.

If you are a nonprofit above the thresholds: you are a controller. Read § 325M.12, subd. 2(a), clause by clause and confirm for yourself that nothing there excludes you.

If you are near the 100,000 line: document the payment-transaction exclusion computation in writing, now, while the underlying data exists. Section 325M.19(g) puts the burden on you.

If you are covered: the four things that most often do not exist when we look are the data inventory required by § 325M.16, subd. 2(c); the specific-third-party list contemplated by § 325M.14, subd. 1(h); the profiling explanation required by subd. 1(g); and the 24-month appeal records required by subd. 5(d). All four are cheap to build in advance and expensive to reconstruct under a civil investigative demand.

Everyone: the 30-day warning letter expired January 31, 2026. Plan on the first contact from the state being an investigative demand rather than a courtesy.


The observation

The MCDPA was drafted to regulate large data processors, and its thresholds do exactly that. But two provisions escape the threshold structure entirely, and they run in opposite directions from what a reader would expect.

Section 325M.17 pushes the Act down — reaching businesses far below the applicability floor, with a single prohibition backed by the same $7,500-per-violation penalty. And the absence of a nonprofit exclusion pushes it sideways, into a category of organization that in most compliance planning is simply assumed to be out.

Neither of those is visible from the threshold provision. Both are in the exclusion list, which is the part of a privacy statute that companies read fastest and lawyers read last.


Madgett Law, LLC advises Minnesota businesses and nonprofits on MCDPA applicability and compliance — threshold analysis, privacy notices, consumer-request workflows, processor contracting, and data privacy and protection assessments — and represents individuals whose personal information has been misused. If you are working out whether the Act reaches your organization, or have received an inquiry from the Attorney General’s office, send us a message or call 612-470-6529.


Sources: Minn. Stat. § 325M.10 (short title; the Act is §§ 325M.10–325M.21); § 325M.11 (definitions relied on: (f) consent; (g) consumer, excluding commercial and employment context; (i) decisions producing legal or similarly significant effects; (j) dark pattern; (o) known child, including willful disregard; (u) sale, including “other valuable consideration” and the six exclusions; (v) sensitive data, four categories; (w) specific geolocation data, three-decimal-degree accuracy and derived street address); § 325M.12 (subd. 1(a) applicability thresholds and the payment-transaction exclusion; subd. 1(b) § 13.32 technology-provider conflict rule; subd. 2(a) the 21 exclusions, including clause (13) employment-context data, clause (19) small business “except that a small business identified in this clause is subject to section 325M.17,” and clause (20) insurance anti-fraud nonprofit; subd. 2(b) COPPA parental-consent safe harbor); § 325M.13(b)(2) (processor assistance with § 325E.61 breach notice); § 325M.14 (subd. 1(b)–(h) consumer rights, including (g) the right to question a profiling result and (h) the list of specific third parties; subd. 2(d) authorized agents and browser-level signals; subd. 3 universal opt-out mechanisms, including (a)(2) no default setting, (b) loyalty-program conflicts, and (d) other-state signal compliance; subd. 4(d)–(j) response deadlines, free-response limit, burden on the controller, withheld identifiers, and trade secrets; subd. 5(c)–(d) appeal deadlines, Attorney General complaint information, and 24-month record retention); § 325M.15 (deidentified and pseudonymous data); § 325M.16 (subd. 1(a) the eight privacy-notice contents and subd. 1(c), (d), (f), (g) accessibility, language, and placement; subd. 2(a)–(g) data minimization, purpose limitation, the data-inventory requirement, sensitive-data consent, the 15-day consent-revocation deadline, the 13-to-16 opt-in, and the retention ceiling; subd. 3 nondiscrimination; subd. 4 waiver void and unenforceable); § 325M.17 (small-business prohibition on selling sensitive data without prior consent, with no volume threshold, and § 325M.20 penalties applied); § 325M.18 (documented policies and the chief privacy officer contact; the five data privacy and protection assessment triggers; (f) civil investigative demand access, nonpublic classification under § 13.02, subd. 9, and no privilege waiver; (g) other-jurisdiction assessments); § 325M.19 ((a)–(e) limitations and permitted processing; (f) proportionality; (g) controller bears the burden of demonstrating an exemption); § 325M.20 ((a) warning letter and 30-day cure, “This paragraph expires January 31, 2026”; (b) Attorney General action under § 8.31 and litigation expenses; (c) injunction and civil penalty of not more than $7,500 per violation; (d) no private right of action, “including under section 8.31, subdivision 3a”); § 325M.21(a) (preemption of local law) — all from the Minnesota Office of the Revisor of Statutes. Effective date: Laws 2024, ch. 121, art. 5, § 14 (“This article is effective July 31, 2025, except that postsecondary institutions regulated by the Office of Higher Education are not required to comply with this article until July 31, 2029.”). Currency: the Revisor’s history line for each of §§ 325M.10–325M.21 shows a single source act, Laws 2024, ch. 121, art. 5, and no amendment banner; Minnesota Statutes contain no chapter 325O.

This article is general legal information about Minnesota law, not legal advice, and reading it does not create an attorney–client relationship. Whether the Minnesota Consumer Data Privacy Act applies to a particular organization depends on its size, its revenue, the data it holds, the industries it operates in, and other laws that may govern the same information independently. No outcome is promised or implied.

Get new guides by email

Plain-English guides to Minnesota law, sent when a new one is written. No schedule, nothing for sale.

Used only to send these guides. Unsubscribe from any email. This is attorney advertising — subscribing does not create an attorney–client relationship.

← All news & articles