Minnesota has a statute that tells private businesses, in seven numbered clauses, what they may not do with a Social Security number. It bars printing the number on a membership card. It bars using it as a customer account number. It bars selling it. It bars mailing it. It requires the business to lock down internal access to the numbers it holds.
Then it stops.
Minn. Stat. § 325E.59 has five subdivisions — subdivision 2 was repealed in 2007 — and not one of them creates a penalty, a damages remedy, an injunction, or an assignment of enforcement authority to anyone. There is no “Remedies” subdivision. There is no “Enforcement” subdivision. There is no civil penalty figure, no criminal grade, and no sentence naming the attorney general.
That is unusual, and it is not an accident of drafting age. The section immediately next door in the same chapter — Minnesota’s breach-notification statute — closes with exactly the sentence § 325E.59 lacks. So the interesting question about this statute is not what it prohibits. It is what happens when someone violates it, and the honest answer requires reading three other provisions.
Start with what the section actually says.
What are the seven things a Minnesota business may not do with a Social Security number?
Subdivision 1(a) opens with a scope line and then lists seven prohibitions. The scope line is short: “A person or entity, not including a government entity, may not do any of the following:”. The seven:
- Publicly post or publicly display it. The statute defines its own terms in the clause: “publicly post or publicly display in any manner an individual’s Social Security number. ‘Publicly post’ or ‘publicly display’ means to intentionally communicate or otherwise make available to the general public”.
- Print it on an access card. No printing an individual’s Social Security number “on any card required for the individual to access products or services provided by the person or entity.”
- Require unsecured internet transmission. No requiring an individual to transmit the number over the internet “unless the connection is secure or the Social Security number is encrypted,” with an exception for what is required by titles XVIII and XIX of the Social Security Act and 42 C.F.R. § 483.20.
- Require it as a website credential, standing alone. No requiring an individual to use the number to access a website “unless a password or unique personal identification number or other authentication device is also required to access the Internet website.” Note the shape of this one: it does not ban Social Security numbers as login identifiers. It bans them as the only factor.
- Print it on mailed materials. No printing a number the business knows to be an individual’s Social Security number on materials mailed to that individual, “unless state or federal law requires the Social Security number to be on the document to be mailed.” Clause (5) then supplies a safe harbor for numbers received from third parties: a business that receives a number from a third party in connection with a transaction “is under no duty to inquire or otherwise determine whether the number is or includes that individual’s Social Security number,” and may print it, unless it has actual knowledge that the number is or includes the Social Security number.
- Use it as the primary account identifier. No “assign[ing] or us[ing] a number as the primary account identifier that is identical to or incorporates an individual’s complete Social Security number, except in conjunction with an employee or member retirement or benefit plan or human resource or payroll administration”. The carve-out is narrow and functional — payroll and benefits administration, not customer accounts.
- Sell it. No selling “Social Security numbers obtained from individuals in the course of business.”
Paragraph (b) then defines the seventh prohibition down: “sell” does not include a release that “is incidental to a larger transaction and is necessary to identify the individual in order to accomplish a legitimate business purpose.” And it closes that door on the obvious abuse: “The release of a Social Security number for the purpose of marketing is not a legitimate business purpose under this paragraph.”
Does the statute also impose an affirmative duty?
Yes, and it is the sleeper provision. Subdivision 1(d) is not a prohibition; it is a security obligation:
A person or entity, not including a government entity, must restrict access to individual Social Security numbers it holds so that only its employees, agents, or contractors who require access to records containing the numbers in order to perform their job duties have access to the numbers, except as required by titles XVIII and XIX of the Social Security Act and by Code of Federal Regulations, title 42, section 483.20.
That is a role-based access-control mandate written into Minnesota consumer law, applicable to any private person or entity holding Social Security numbers — no revenue threshold, no minimum number of records, no industry limitation. A small employer with a shared drive that every employee can open is outside what subdivision 1(d) requires.
It also travels well with the breach-notification regime. If a business cannot say who had access to a set of Social Security numbers, it will have a hard time analyzing the notice question under Minn. Stat. § 325E.61 after an incident.
When may a business still put a Social Security number in the mail?
Applications, enrollment documents, and account paperwork — but never on the outside of the envelope. Paragraph (c) is the exception to the mailing prohibitions, and it is broader than most compliance policies assume:
Notwithstanding paragraph (a), clauses (1) to (5), Social Security numbers may be included in applications and forms sent by mail, including documents sent as part of an application or enrollment process, or to establish, amend, or terminate an account, contract, or policy, or to confirm the accuracy of the Social Security number. Nothing in this paragraph authorizes inclusion of a Social Security number on the outside of a mailing or in the bulk mailing of a credit card solicitation offer.
Two operative limits sit in that second sentence, and both are absolute: nothing on the outside of a mailing, and nothing in a bulk-mailed credit card solicitation.
Why are the University of Minnesota and MnSCU treated as private businesses here?
Because subdivision 5 says so, expressly. Every prohibition in subdivision 1 applies to “a person or entity, not including a government entity.” Subdivision 5 then defines that exclusion:
For purposes of this section, “government entity” has the meaning given in section 13.02, subdivision 7a, but does not include the Minnesota State Colleges and Universities or the University of Minnesota.
Section 13.02, subd. 7a, defines “government entity” as “a state agency, statewide system, or political subdivision.” Subdivision 5 then pulls two institutions back out of that definition — which means they are not excluded from § 325E.59, and the seven prohibitions and the access-control duty apply to them the way they apply to a bank.
Public bodies that are government entities are not unregulated on this subject; they are regulated somewhere else. Minn. Stat. § 13.355, subd. 1, classifies Social Security numbers collected or maintained by a government entity as private data on individuals “except to the extent that access to the Social Security number is specifically authorized by law,” and subdivision 3 bars a government entity from mailing or delivering an item that displays a Social Security number on the outside, or where it is visible without opening the item, and from requiring or requesting anyone else to do so. Subdivision 2 carves out numbers appearing in documents filed or recorded with the county recorder or registrar of titles, other than documents filed under § 600.23.
What does § 325E.59 not reach?
Three carve-outs, and the third is a hard date. Subdivision 3 provides that the section does not prevent (1) collection, use, or release of a Social Security number as required by state or federal law; (2) collection, use, or release for a purpose specifically authorized or specifically allowed by a state or federal law that itself includes restrictions on the use and release of information on individuals that would apply to Social Security numbers; or (3) “the use of a Social Security number for internal verification or administrative purposes.”
Subdivision 4 adds: “This section does not apply to documents that are recorded or required to be open to the public under chapter 13 or by other law.”
And subdivision 1(e) is a one-sentence temporal limit: “This section applies only to the use of Social Security numbers on or after July 1, 2008.”
Clause (3) of subdivision 3 — internal verification and administrative purposes — does substantial work. Read together with the payroll-and-benefits carve-out in subdivision 1(a)(6), the statute is aimed at external exposure of the number, not at the fact that a business holds it and uses it to run itself.
Can a Minnesota consumer sue a business for violating § 325E.59?
The statute does not say, and that silence is the whole issue. Treat any confident answer in either direction with suspicion.
Here is the full state of the text.
First, § 325E.59 supplies nothing. Its five subdivisions are: subdivision 1 (the prohibitions and the access-control duty), subdivision 2 (repealed by Laws 2007, ch. 129, § 58), subdivision 3 (coordination with other law), subdivision 4 (public records), and subdivision 5 (definitions). Read end to end, none of them mentions damages, penalties, injunctions, the attorney general, a county attorney, or a private action.
Second, the section next door shows what an express grant looks like. Minn. Stat. § 325E.61, subd. 6, is a single sentence: “The attorney general shall enforce this section and section 13.055, subdivision 6, under section 8.31.” By its terms that sentence reaches § 325E.61 and § 13.055, subd. 6. It does not reach § 325E.59.
Third, the legislature also knows how to close the door. In the Minnesota Consumer Data Privacy Act, Minn. Stat. § 325M.20(b) routes enforcement to the attorney general “in accordance with section 8.31,” and paragraph (d) then says: “Nothing in sections 325M.10 to 325M.21 establishes a private right of action, including under section 8.31, subdivision 3a, for a violation of sections 325M.10 to 325M.21 or any other law.” Section 325E.59 contains no equivalent of either sentence.
Fourth, § 8.31 itself is not a closed list. Subdivision 1 begins by directing that “[t]he attorney general shall investigate violations of the law of this state respecting unfair, discriminatory, and other unlawful practices in business, commerce, or trade, and specifically, but not exclusively,” a set of named statutes. The only chapter 325E provision named in that list is § 325E.39, the telephone-advertising-services act. Section 325E.59 is not enumerated. But the phrase “but not exclusively” means the enumeration does not, on its own, settle the question.
That matters because the private remedy in Minn. Stat. § 8.31, subd. 3a, is keyed to the same set:
In addition to the remedies otherwise provided by law, any person injured by a violation of any of the laws referred to in subdivision 1 may bring a civil action and recover damages, together with costs and disbursements, including costs of investigation and reasonable attorney’s fees, and receive other equitable relief as determined by the court.
So a private § 8.31, subd. 3a, claim premised on a § 325E.59 violation depends on § 325E.59 being one of “the laws referred to in subdivision 1” through the general clause rather than the enumerated list. The statutes do not answer that on their face, and we do not assert an answer here. Anyone who intends to plead it should expect the threshold question to be litigated before the merits are.
There is a further filter even if the door is open. In Ly v. Nystrom, 615 N.W.2d 302 (Minn. 2000), the Minnesota Supreme Court held “that the Private AG Statute applies only to those claimants who demonstrate that their cause of action benefits the public,” and overruled its earlier Church of Nativity decision to the extent that decision could be construed to permit recovery without proof of public benefit. Two justices wrote separately, taking the position that the statute’s plain language contains no such requirement. The public benefit filter is discussed at length in our guide to Minnesota’s private attorney general statute. A standardized business practice affecting a whole customer base — printing Social Security numbers on every mailed statement, say — sits very differently under Ly than a single misdirected envelope.
What actually happens after a Social Security number is exposed?
In practice, the claim usually travels under something other than § 325E.59. The statute is most useful as a compliance standard and as evidence of a Minnesota public policy — not as a stand-alone cause of action, because it does not describe one.
The provisions that do carry stated consequences and that commonly overlap the same facts are the breach-notification statute at § 325E.61, which is enforced by the attorney general under § 8.31 by its own terms; the federal Fair Credit Reporting Act, where the exposure produces a fraudulent tradeline; and Minnesota’s criminal identity theft statute at § 609.527, which is what makes the police report described in our identity theft response guide obtainable. Where a business made affirmative representations about how it protects the number, the Consumer Fraud Act analysis in our consumer protection statutes guide is often the more direct route. And for how § 325E.59 sits relative to Minnesota’s other data statutes, see Minnesota’s three privacy regimes.
For a business, the analysis runs the other way and is simpler. Subdivision 1 is a checklist, and it is short enough to audit in an afternoon: no Social Security number on a member card, no Social Security number as a customer account number, no unencrypted transmission required, no single-factor Social Security number login, nothing on the outside of an envelope, no bulk credit card solicitation carrying the number, no sale, and documented role-based access to wherever the numbers live. Every item on that list is in the statute. What is not in the statute is a number telling you what noncompliance costs — which is a reason to comply, not a reason to relax.
Madgett Law, LLC works on Minnesota consumer privacy and credit reporting matters — including exposure of Social Security numbers, disputes with credit reporting agencies and furnishers, and identity theft recovery — and advises Minnesota businesses on data-handling obligations under state law. If your Social Security number was exposed, or your business needs its handling practices reviewed against § 325E.59, send us a message or call 612-470-6529.
Sources: Minn. Stat. § 325E.59 (2025 Minnesota Statutes, Minnesota Office of the Revisor of Statutes, revisor.mn.gov/statutes/cite/325E.59): subd. 1(a) opening scope line and clauses (1)–(7) (public posting or display and its definition; access-card printing; unsecured internet transmission; single-factor website access; printing on mailed materials, including the third-party actual-knowledge safe harbor; primary account identifier and the retirement, benefit, human resource, and payroll carve-out; and sale); subd. 1(b) (definition of “sell,” the incidental-and-necessary-for-a-legitimate-business-purpose exclusion, and the marketing sentence); subd. 1(c) (applications and forms sent by mail; the bar on the outside of a mailing and on bulk credit card solicitation offers); subd. 1(d) (mandatory restriction of internal access to employees, agents, or contractors who require access to perform their job duties); subd. 1(e) (applies only to use on or after July 1, 2008); subd. 2 (repealed, Laws 2007, ch. 129, § 58, per the Revisor’s codified note); subd. 3, clauses (1)–(3) (coordination with other law; internal verification or administrative purposes); subd. 4 (documents recorded or required to be open to the public under chapter 13 or other law); subd. 5 (definition of “government entity,” excluding the Minnesota State Colleges and Universities and the University of Minnesota from that definition). Minn. Stat. § 13.02, subd. 7a (2025) (“Government entity” means a state agency, statewide system, or political subdivision). Minn. Stat. § 13.355 (2025): subd. 1 (government-held Social Security numbers are private data unless access is specifically authorized by law); subd. 2 (county recorder and registrar of titles exception, other than documents filed under § 600.23); subd. 3(1)–(2) (no display on the outside of a mailed item; no requiring or requesting another to do so). Minn. Stat. § 325E.61, subd. 6 (2025) (“The attorney general shall enforce this section and section 13.055, subdivision 6, under section 8.31.”). Minn. Stat. § 325M.20 (2025), paragraphs (b) and (d) (attorney general enforcement in accordance with § 8.31; express statement that nothing in §§ 325M.10 to 325M.21 establishes a private right of action, including under § 8.31, subd. 3a). Minn. Stat. § 8.31 (2025): subd. 1 (duty to investigate violations of laws respecting unfair, discriminatory, and other unlawful practices in business, commerce, or trade, “specifically, but not exclusively,” the enumerated acts, of which § 325E.39 is the only chapter 325E section named); subd. 3a (private civil action for damages, costs and disbursements, costs of investigation, reasonable attorney’s fees, and equitable relief, for “any person injured by a violation of any of the laws referred to in subdivision 1”). Minn. Stat. § 609.527 is named only as Minnesota’s criminal identity theft statute; no subdivision of it is relied on in this article. Case law: Hoang Minh Ly v. Nystrom, 615 N.W.2d 302 (Minn. 2000) (No. C6-99-565, decided August 3, 2000), for the holding that the private attorney general statute applies only to claimants who demonstrate that their cause of action benefits the public, the overruling of Church of Nativity to the extent it permitted recovery without proof of public benefit, and the existence of separate opinions disagreeing on that point — read from the Caselaw Access Project archive at static.case.law/nw2d/615/cases/0302-01.json.
Currency note: §§ 325E.59, 8.31, 13.02, 13.355, 325E.61, and 325M.20 were each retrieved on 2026-08-10 and none returned a 2026 currency banner. This article does not assert that a private right of action exists under § 325E.59, and it does not assert that none exists; the statutory text does not resolve the question and no Minnesota decision addressing it was located or relied on for this article.
This article is general legal information about Minnesota law, not legal advice, and reading it does not create an attorney–client relationship. Whether particular conduct violates § 325E.59, and what remedy if any is available for a violation, depends on facts this article does not know. No outcome is promised or implied.