The first hours after a breach go to a question nobody has a clean answer to: when do we have to tell people?
Minnesota’s answer, in Minn. Stat. § 325E.61, isn’t a number. It’s a standard. And I’d rather advise a client against a deadline than a standard, because you only know for sure that you met a standard in hindsight. Usually somebody else’s hindsight.
The obligation, the trigger, and the data it covers
Any person or business that conducts business in Minnesota and owns or licenses computerized personal data must notify affected Minnesota residents following a breach of the security of the system. There are parallel obligations for entities that maintain data they don’t own, typically vendors and processors, and those generally run to the data owner rather than straight to consumers.
The statute defines “breach of the security of the system” as the “unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information.” That definition has two limits. Good-faith acquisition by an employee for business purposes isn’t a breach, provided the information isn’t used or subject to further unauthorized disclosure. And “Acquisition” is the word doing the work: unauthorized access without acquisition is analyzed differently, and that difference carries real weight in incident response. I’ve never let a client lean on it fast to reach a comfortable answer.
The statute’s definition of “personal information” is an individual’s name in combination with one or more of:
- Social Security number
- Driver’s license number or Minnesota identification card number
- Financial account number, or credit or debit card number, together with any required security code, access code, or password permitting access to the account
Publicly available information lawfully made available from government records is excluded.
Look at what’s not on that list. Email addresses and passwords alone, health information standing by itself, and biometric data aren’t within this definition. That doesn’t mean exposing them is free. HIPAA, the Gramm-Leach-Bliley Act, the FTC Act, other states’ statutes, and contracts all apply on their own, and a multi-state breach is almost always governed by the strictest regime that applies, not Minnesota’s.
The timing standard is not permission to deliberate
Disclosure must be made “in the most expedient time possible and without unreasonable delay,” consistent with the legitimate needs of law enforcement and with measures necessary to determine the scope of the breach and restore the integrity of the system. Law enforcement may request a delay where notification would impede a criminal investigation.
There’s no fixed day count. Here’s what I tell clients that means in practice. Write your timeline down as it happens. Every day of delay has to be explainable later by the investigation, the restoration, or a law enforcement request. Scheduling, internal debate, and waiting to hire outside counsel don’t count. A delay backed by a documented forensic timeline is defensible. A delay explained by “we were deciding what to do” isn’t. And don’t treat the standard’s give as permission to be slow: regulators and plaintiffs read “most expedient time possible” against what a diligent company would have done.
The 48-hour credit bureau rule is the one that gets missed
Minn. Stat. § 325E.61, subd. 2:
If a person discovers circumstances requiring notification under this section and section 13.055, subdivision 6, of more than 500 persons at one time, the person shall also notify, within 48 hours, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, as defined by United States Code, title 15, section 1681a, of the timing, distribution, and content of the notices.
Read the threshold exactly: “more than 500,” not “500 or more.” A notice to exactly 500 people doesn’t trigger it. That’s a one-person difference on a 48-hour clock, and it’s exactly the kind of detail your incident response plan should state in the statute’s own words instead of a paraphrase.
Forty-eight hours is a real deadline sitting in a statute that’s otherwise built on a standard, and it runs while your response team is still getting on the phone. Put it in the plan by name.
One exemption decides coverage entirely
Minn. Stat. § 325E.61, subd. 4 is one sentence, and for a big category of Minnesota businesses it ends the conversation:
This section and section 13.055, subdivision 6, do not apply to any “financial institution” as defined by United States Code, title 15, section 6809(3).
That’s the Gramm-Leach-Bliley Act definition, and it’s a lot broader than “bank.” Institutions inside it are outside § 325E.61 altogether. They’re still regulated. Their breach obligations just come from the federal financial privacy rules and their regulators instead, and a response plan built on this section would be built on the wrong statute. I check this before anything else, because whether § 325E.61 applies to you at all comes first.
Who enforces it — and why the private-action question doesn’t end the case
The statute names one enforcer: “The attorney general shall enforce this section and section 13.055, subdivision 6, under section 8.31.” Subd. 6. It gives consumers no remedy of its own. Whether a consumer can sue anyway, through the private attorney general provision in § 8.31, subd. 3a, is less settled than it’s usually made to sound. In the Target breach litigation, the federal court in Minnesota said no: the argument “stretches the language of the statute beyond the breaking point,” because the statute “provides that the ‘attorney general shall’ enforce the statute; that language is unambiguous.” That’s one federal district court decision, and it doesn’t bind a Minnesota state court. Nine years later, in a medical-records case, the Minnesota Supreme Court read subd. 3a to reach the laws the Attorney General can enforce under § 8.31, whether or not they’re on its named list. It didn’t mention § 325E.61 or Target, and I haven’t found a Minnesota appellate decision on § 325E.61 itself. The statute also makes waivers of its requirements void and unenforceable, so a contract term that tries to release these obligations doesn’t.
Compare the Minnesota Consumer Data Privacy Act, Minn. Stat. ch. 325M, which also leaves enforcement to the Attorney General but closes the door in so many words: “Nothing in sections 325M.10 to 325M.21 establishes a private right of action, including under section 8.31, subdivision 3a, for a violation of sections 325M.10 to 325M.21 or any other law.” § 325M.20(d). Section 325E.61 has no sentence like that. I wrote about that pattern, real rights with government-only enforcement, here.
But don’t read the absence of a remedy in § 325E.61 itself as “no litigation exposure.” Breach class actions in Minnesota run on other theories entirely: negligence, breach of contract, breach of implied contract, unjust enrichment, and consumer protection statutes including the private attorney general provision at Minn. Stat. § 8.31, subd. 3a. Even if a court follows Target and refuses a private claim under § 325E.61, that takes away one claim. It doesn’t take away the case.
What a defensible response looks like
Hours 0–24
- Contain. Isolate affected systems, and don’t destroy evidence doing it.
- Call counsel before forensics, so the investigation is set up with privilege in mind from day one, not patched up after the fact.
- Preserve logs, images, and artifacts. Your retention policies will delete the evidence you’re going to need.
- Start the timeline now. Every decision, with the time and the reason.
Days 1–7 5. Scope it. Whose data, what fields, how many, and in which states. The state count drives which laws apply. 6. Figure out whether the definition is met under Minnesota law and under every other statute that applies. 7. Notify your cyber insurer. Policies have notice conditions, and panel-counsel requirements are common. 8. Calendar the 48-hour credit bureau obligation if the count is getting near 500. The trigger is more than 500 notified at one time.
Notification 9. Notify without unreasonable delay, in the manner the statute permits. 10. Say something useful. What happened, what data, what you’re doing, what the recipient should do. Notices that read like legal throat-clearing draw complaints and regulator attention. 11. Offer credit monitoring where the exposed data warrants it. It isn’t required in every case. It’s often expected. 12. Get ready for what comes next: regulator inquiries, contractual notice obligations to business customers, and litigation.
If your data was the data exposed, my advice runs five steps. Freeze your credit with all three bureaus. It’s free, it’s the single most effective step, and it blocks new-account fraud in a way monitoring doesn’t. Take the offered monitoring, but read the enrollment terms before you accept, so you know what, if anything, you’re agreeing to. Read your statements, and dispute in writing. Keep the breach notice, because it’s evidence of the source if fraud follows. And know your credit-report remedies: unlike § 325E.61, the FCRA gives consumers an express private right of action with fees. See my FCRA piece.
Build for the hardest statute you face, not this one
Minnesota’s breach statute dates from 2005, and it shows: a narrow definition of personal information tied to Social Security numbers and financial accounts, a flexible timing standard, and enforcement assigned by name only to the Attorney General. The MCDPA, effective in 2025, is the modern layer. It protects more, requires more, and is likewise enforced only by the Attorney General.
For a Minnesota business, that means your breach obligations are rarely set by Minnesota law alone. They’re set by the strictest statute that reaches any affected person, and by your contracts. A response plan built around § 325E.61 by itself is a plan for the easiest case you’ll ever face.
Madgett Law, LLC advises Minnesota businesses on breach response, multi-state notification analysis, and the contractual and regulatory exposure that follows, and represents individuals whose information has been misused. If you’re in the first days of an incident, the timeline you write down now is what defends your decisions later. Send us a message or call 612-470-6529.
Sources: Minn. Stat. § 325E.61 (enacted 2005 c 167 s 1; breach of the security of the system; definition of personal information; notification in the most expedient time possible and without unreasonable delay; law enforcement delay; subd. 2, 48-hour notice to nationwide consumer reporting agencies where more than 500 persons are notified at one time, as defined by 15 U.S.C. § 1681a; subd. 3, waiver prohibited, reaching this section and § 13.055, subd. 6; subd. 4, exemption for any “financial institution” as defined by 15 U.S.C. § 6809(3); Attorney General enforcement); Minn. Stat. ch. 325M (Minnesota Consumer Data Privacy Act), including § 325M.20(d); Minn. Stat. § 8.31, subd. 3a (Minnesota Office of the Revisor of Statutes); In re Target Corp. Customer Data Security Breach Litigation, 66 F. Supp. 3d 1154, 1168 (D. Minn. 2014) (rejecting a private claim under § 325E.61 through § 8.31, subd. 3a) (Caselaw Access Project, static.case.law/f-supp-3d/66/cases/1154-01.json); Findling v. Group Health Plan, Inc., 998 N.W.2d 1 (Minn. 2023) (Nos. A21-1518, A21-1527, A21-1528, A21-1530, decided December 6, 2023), slip op. at 7–8 (the § 8.31, subd. 1 list is not exclusive; the laws enforceable privately under subd. 3a align with those the Attorney General may enforce under § 8.31) (CourtListener); 15 U.S.C. § 1681 et seq. This article is general legal information about Minnesota law, not legal advice, and reading it does not create an attorney–client relationship. Breach obligations depend on the data involved and the residency of affected individuals, and other federal, state, and contractual requirements frequently apply. No outcome is promised or implied.