Three Minnesota Privacy Laws Apply to Your Company. The One Nobody Plans For Is the Only One With a Private Right of Action.

July 17, 2026 · David J.S. Madgett

Ask a Minnesota company what its privacy obligations are and you will usually hear one statute named: the breach notification law. It is in the incident response plan, it is in the vendor contracts, and it is the thing the board has heard of.

It is also the narrowest of the three Minnesota regimes that may apply, and the only one of the three with no private right of action to worry about.

The other two are the Minnesota Consumer Data Privacy Act, which protects a category of information roughly ten times broader, and the Minnesota Government Data Practices Act — chapter 13 — which most private companies believe does not apply to them and which, if they contract with any Minnesota government entity, does.


Regime one: § 325E.61, the breach statute

The trigger is acquisition, not access. “Breach of the security of the system” means “unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by the person or business.” Minn. Stat. § 325E.61, subd. 1(d). Good-faith acquisition by an employee or agent for the business’s purposes is not a breach, “provided that the personal information is not used or subject to further unauthorized disclosure.”

The protected category is three data elements long. “Personal information” means a first name or first initial and last name in combination with any one or more of: Social Security number; driver’s license number or Minnesota identification card number; or “account number or credit or debit card number, in combination with any required security code, access code, or password that would permit access to an individual’s financial account” — each only “when the data element is not secured by encryption or another method of technology that makes electronic data unreadable or unusable.” Subd. 1(e). Publicly available government-record information is excluded. Subd. 1(f).

Email addresses, passwords standing alone, health information, biometric data, precise location — none of it is inside that definition.

The timing rule is a standard, not a deadline. Disclosure must be made “in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement … or with any measures necessary to determine the scope of the breach, identify the individuals affected, and restore the reasonable integrity of the data system.” Subd. 1(a).

There is exactly one number in the statute, and it is short. Where notification of “more than 500 persons at one time” is required, the person must “also notify, within 48 hours, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis.” Subd. 2.

Enforcement is the Attorney General’s alone: “The attorney general shall enforce this section … under section 8.31.” Subd. 6. Waivers are “contrary to public policy and … void and unenforceable.” Subd. 3.

And one exemption that gets missed entirely. Subdivision 4 provides that the section does not apply to any “financial institution” as defined by 15 U.S.C. § 6809(3) — the Gramm-Leach-Bliley definition, which is considerably broader than “bank.” A company that concluded it was covered without checking that subdivision may have the analysis backward.

We wrote about the mechanics of complying with this statute here. The point of this piece is what sits on either side of it.


Regime two: the MCDPA, chapter 325M

Chapter 325M is no longer one act. It now carries three: the older internet-privacy sections (§§ 325M.01–.09), the Minnesota Consumer Data Privacy Act (§§ 325M.10–.21), and the Prohibiting Social Media Manipulation Act (§§ 325M.30–.34, with a new § 325M.40 added in 2026). Citing “chapter 325M” without a section is now ambiguous.

The MCDPA took effect July 31, 2025 — with postsecondary institutions regulated by the Office of Higher Education not required to comply until July 31, 2029. (Laws 2024, ch. 121, art. 5, § 14.)

It reaches far fewer companies and far more data. Sections 325M.10 to 325M.21 apply to legal entities that conduct business in Minnesota or produce products or services targeted to Minnesota residents and that either (1) “during a calendar year, control[] or process[] personal data of 100,000 consumers or more, excluding personal data controlled or processed solely for the purpose of completing a payment transaction,” or (2) “derive[] over 25 percent of gross revenue from the sale of personal data and process[] or control[] personal data of 25,000 consumers or more.” § 325M.12, subd. 1(a).

“Personal data” is defined by linkability, not by enumeration:

“Personal data” means any information that is linked or reasonably linkable to an identified or identifiable natural person. Personal data does not include deidentified data or publicly available information.

§ 325M.11(p). That is not a list of three data elements. That is nearly everything.

But “consumer” is narrower than people assume. It means “a natural person who is a Minnesota resident acting only in an individual or household context,” and it “does not include a natural person acting in a commercial or employment context.” § 325M.11(g). Employee data is outside the MCDPA. That single clause removes the entire HR file from the statute — and it is the clause most often missed by companies building an MCDPA program.

Two of the consumer rights in § 325M.14 are unusual and worth knowing by name. A consumer has “a right to obtain a list of the specific third parties to which the controller has disclosed the consumer’s personal data,” subd. 1(h). And where personal data is profiled in furtherance of decisions producing legal or similarly significant effects, the consumer “has the right to question the result of the profiling, to be informed of the reason that the profiling resulted in the decision, and, if feasible, to be informed of what actions the consumer might have taken to secure a different decision.” Subd. 1(g). The consumer may also require correction and reevaluation if the decision rested on inaccurate data.

Enforcement, and the grace period that is over. The Attorney General may bring a civil action under § 8.31; a violator “is subject to an injunction and liable for a civil penalty of not more than $7,500 for each violation.” § 325M.20(b)–(c).

The 30-day cure letter is gone. Section 325M.20(a) required the Attorney General to send a warning letter identifying the alleged violations and to wait 30 days before suing. The subdivision ends with a sentence companies should read carefully: “This paragraph expires January 31, 2026.” As of that date, the warning-letter step is no longer part of the statute.

And there is no private right of action — expressly: “Nothing in sections 325M.10 to 325M.21 establishes a private right of action, including under section 8.31, subdivision 3a.” § 325M.20(d). That is a deliberate closing of the door to Minnesota’s private attorney general statute.


Regime three: chapter 13, the one private companies do not plan for

Here is the sentence. Minn. Stat. § 13.05, subd. 11(a):

If a government entity enters into a contract with a private person to perform any of its functions, all of the data created, collected, received, stored, used, maintained, or disseminated by the private person in performing those functions is subject to the requirements of this chapter and the private person must comply with those requirements as if it were a government entity. All contracts entered into by a government entity must include a notice that the requirements of this subdivision apply to the contract. Failure to include the notice in the contract does not invalidate the application of this subdivision. The remedies in section 13.08 apply to the private person under this subdivision.

Read the last two sentences twice. The obligation does not depend on the contract saying so, and the remedies run against the private contractor directly.

Those remedies are the reason this regime matters more than its obscurity suggests. Section 13.08, subd. 1, makes a violator “liable to a person … who suffers any damage as a result of the violation,” who may sue “to cover any damages sustained, plus costs and reasonable attorney fees.” And: “In the case of a willful violation, the government entity shall, in addition, be liable to exemplary damages of not less than $1,000, nor more than $15,000 for each violation.” Subdivision 2 authorizes an injunction; subdivision 4 permits an action to compel compliance with costs and fees.

One drafting wrinkle worth noting rather than papering over: § 13.08, subd. 1, speaks of liability of “a responsible authority or government entity,” and the exemplary-damages sentence names “the government entity.” The bridge to a private contractor is § 13.05, subd. 11(a)’s last sentence — “[t]he remedies in section 13.08 apply to the private person under this subdivision.” How far that sentence carries the exemplary-damages provision is a question we would expect a defendant to raise.

Compare that to the other two regimes. Section 325E.61 gives the Attorney General exclusive enforcement. The MCDPA expressly forecloses a private right of action. Chapter 13 provides actual damages, attorney fees, and per-violation exemplary damages with a statutory floor — to a private plaintiff.

The definitions and the trigger are different again. Chapter 13 does not classify data by “personal information” or “personal data.” It classifies by the chapter’s own scheme — public, private, confidential, nonpublic, protected nonpublic — and the obligations attach to the classification, not to a breach. For breach notification specifically, § 13.055 requires a government entity to disclose a breach of private or confidential data, prepare an investigation report, and — under subd. 1(a) — treats “data maintained by a person under a contract with the government entity that provides for the acquisition of or access to the data” as data maintained by the government entity.

And chapter 13 can override the MCDPA. Section 325M.12, subd. 1(b), provides that a controller or processor acting as a technology provider under § 13.32 must comply with both, “except that when the provisions of section 13.32 conflict with sections 325M.10 to 325M.21, section 13.32 prevails.” An edtech vendor serving Minnesota schools is inside all three regimes at once, with chapter 13 on top.


The three regimes side by side

§ 325E.61 MCDPA, §§ 325M.10–.21 Chapter 13
Who is covered Any person or business conducting business in Minnesota that owns or licenses computerized personal data; GLBA “financial institutions” exempt, subd. 4 Entities meeting a 100,000-consumer or 25%-revenue/25,000-consumer threshold, § 325M.12, subd. 1 Government entities — and any private person under contract to perform a government function, § 13.05, subd. 11
What is protected Name + SSN, driver’s license/state ID, or financial account number with access credential, subd. 1(e) “[A]ny information that is linked or reasonably linkable to an identified or identifiable natural person,” § 325M.11(p) Government data, by statutory classification
Excluded Encrypted data; public government-record information Employment and commercial context — “consumer” excludes them, § 325M.11(g) Data outside the government function performed
Trigger Unauthorized acquisition, subd. 1(d) Processing personal data at all Collection, use, or dissemination — plus breach under § 13.055
Deadline “[M]ost expedient time possible and without unreasonable delay”; 48 hours to nationwide CRAs if more than 500 persons, subd. 2 45 days to inform a consumer of action on a request, extendable once by 45 days; 45 days on an appeal, extendable by 60, § 325M.14, subds. 4(e), 5(c) Notice “in the most expedient time possible and without unreasonable delay,” § 13.055, subd. 2
Enforcer Attorney General only, subd. 6 Attorney General only; $7,500 per violation, § 325M.20 Any damaged person, § 13.08
Private right of action None Expressly none, § 325M.20(d) Yes — damages, costs, attorney fees; $1,000–$15,000 exemplary for a willful violation

What to do about it

If you contract with any Minnesota government entity — city, county, school district, state agency:

  1. Assume chapter 13 applies to the data you touch in performing that contract. Section 13.05, subd. 11(a), says the notice requirement is on the government entity and that its absence “does not invalidate the application of this subdivision.”
  2. Identify the boundary between contract data and your own data, in writing, before performance. The chapter attaches to data created or received “in performing those functions” — so the scope of the function defines the scope of the obligation.
  3. Designate someone to handle data requests. A contractor performing a government function will receive requests it is not built to answer, and § 13.08, subd. 4, makes failure to respond independently actionable.
  4. Price the exposure. Actual damages plus fees plus $1,000-to-$15,000 per willful violation is a materially different risk profile from an Attorney General inquiry.

If you are above the MCDPA thresholds:

  1. Recheck the count. The 100,000-consumer threshold excludes personal data processed “solely for the purpose of completing a payment transaction” — which moves some retailers below the line and is worth documenting either way.
  2. Do not build employee data into the program. “Consumer” excludes the employment context. Build it for the customer file.
  3. Note the date. The Attorney General’s 30-day warning-letter step expired January 31, 2026.
  4. Build the two Minnesota-specific rights — the list of specific third parties, and the profiling explanation — because they do not exist in every state statute and cannot be satisfied by a generic multi-state privacy portal.

For everyone:

  1. Stop treating § 325E.61 as the perimeter. It is the floor, it is narrow, and a multi-state incident is almost always governed by a stricter statute somewhere else.
  2. Calendar the 48 hours the moment the affected count approaches 500.
  3. Individuals whose data was exposed should still start with a credit freeze and a police report — see our identity theft steps.

The observation

The three statutes were written in three different decades to solve three different problems, and it shows.

Section 325E.61 is a 2005-era statute that assumes the harm is financial account fraud, defines protected data as the three fields a thief would need for it, and gives the state a policing role. Chapter 325M’s consumer-privacy article is a 2024 statute that assumes the harm is the commercial use of personal information itself, defines protected data by linkability, and gives consumers rights against companies large enough to be worth regulating. Chapter 13 is a 1970s-era statute about the state’s power over its citizens’ records, and it swept private contractors in because the state kept outsourcing the functions that generate those records.

Only the oldest of the three gives an individual a way into court. That is not a design choice anyone made deliberately. It is what happens when a government-accountability statute acquires a privatization provision, and when two later privacy statutes are written to be enforced by a public official whose office has finite capacity.

The practical consequence for a Minnesota company is uncomfortable and worth stating plainly: the statute creating the most exposure is the one least likely to appear in your privacy program, and it applies because of a contract your operations team signed, not because of anything your privacy team did.


Madgett Law, LLC advises Minnesota businesses on breach response, Data Practices Act obligations arising from government contracts, and MCDPA compliance — and represents individuals whose information has been misused. If you are in the first days of an incident, or have just discovered that a government contract carries chapter 13 obligations, send us a message or call 612-470-6529.


Sources: Minn. Stat. § 325E.61 (subd. 1(a) notice standard; subd. 1(d) definition of breach and good-faith acquisition; subd. 1(e)–(f) definition and exclusions of “personal information”; subd. 2, 48-hour notice to nationwide consumer reporting agencies where more than 500 persons are notified at one time; subd. 3, waiver void; subd. 4, exemption for “financial institution” as defined by 15 U.S.C. § 6809(3); subd. 6, Attorney General enforcement under § 8.31); Minn. Stat. §§ 325M.10 (citation and effective-date note, Laws 2024, ch. 121, art. 5, § 14), 325M.11(g) and (p) (definitions of “consumer” and “personal data”), 325M.12, subd. 1 (scope thresholds and the § 13.32 technology-provider rule), 325M.14, subds. 1, 4, and 5 (consumer rights; controller response and appeal deadlines), and 325M.20 (Attorney General enforcement; expiration of the warning-letter paragraph on January 31, 2026; $7,500 civil penalty; no private right of action); Minn. Stat. § 13.05, subd. 11 (privatization), § 13.055 (disclosure of breach in security; subd. 1(a) treatment of data maintained by a contractor; subd. 2 notice standard), and § 13.08 (civil remedies — damages, costs, attorney fees, and exemplary damages of not less than $1,000 nor more than $15,000 for a willful violation) — all from the Minnesota Office of the Revisor of Statutes, 2025 Minnesota Statutes.

Currency: Revisor Table 2 (Statutes Changed) shows no amendment to § 325E.61, § 13.05, § 13.055, § 13.08, or §§ 325M.10–.21 in the 2025 or 2026 legislative sessions. Chapter 13 was amended extensively elsewhere in 2026, and chapter 325M’s social media article was amended and expanded — § 325M.33 amended and § 325M.40 added by Laws 2026, ch. 111 (H.F. No. 4138) — so a chapter-level citation to either chapter should be checked against the current text.

This article is general legal information about Minnesota law, not legal advice, and reading it does not create an attorney–client relationship. Which regime applies to a given organization depends on its size, its contracts, the data it holds, and the residency of the individuals involved, and federal and other states’ laws frequently apply independently. No outcome is promised or implied.

Get new guides by email

Plain-English guides to Minnesota law, sent when a new one is written. No schedule, nothing for sale.

Used only to send these guides. Unsubscribe from any email. This is attorney advertising — subscribing does not create an attorney–client relationship.

← All news & articles