Law / United States / Michigan

Identity Theft Protection Act, destruction of data no longer needed

MCL 445.72a (Sec. 12a of Act 452 of 2004, added by 2006 PA 566)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 2 July 2007.

A security baseline statutes rule binding public and private bodies.

As of 14 September 2026.

What it requires

  • This binds a person (a private business or other legal entity) or an agency (a Michigan state government department, board, commission, office, authority, or unit, including a public university, but not a court) that maintains a database including personal information about multiple Michigan residents.
  • Destroy, or arrange for the destruction of, any data containing personal information about an individual once that data is removed from the database and is not being retained elsewhere for a purpose state or federal law does not prohibit; retaining the data for an investigation, audit, or internal review does not violate this duty. Destroy the data by shredding, erasing, or otherwise modifying it so it cannot be read, deciphered, or reconstructed through generally available means.
  • You are considered compliant here if you are already subject to, and in compliance with, a federal law governing the disposal of records containing personal identifying information.
  • A knowing violation is a misdemeanor punishable by a fine of up to $250 for each violation; this section creates no private right of action, though it preserves whatever other civil remedy state or federal law might otherwise provide.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

A person who knowingly fails to destroy data containing personal information as required is guilty of a misdemeanor punishable by a fine of not more than $250 for each violation.

Penalty structure

This is a criminal misdemeanor fine under subsection (2), not a civil penalty; the statute names no aggregate cap for this section, unlike the Act's separate breach-notice civil fine (MCL 445.72(13)-(15), capped at $750,000 in aggregate per breach, filed under this jurisdiction's privacy row).

Rule
Per violation only
As of
14 September 2026
Currency
USD
Per violation unit
Violation
Per violation amount
250

What it reaches

Obligation class

Retention, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

MCL 445.72a requires a person (a private business or other legal entity) or agency (a Michigan state government department, board, commission, office, authority, or unit, including a public university, but not a court) that maintains a database including personal information about multiple Michigan residents to destroy, or arrange for the destruction of, any data containing an individual's personal information once that data is removed from the database and is not retained elsewhere for a purpose state or federal law does not prohibit.

Retaining data for an investigation, audit, or internal review is not itself a violation of this duty. "Destroy" means shredding, erasing, or otherwise modifying the data so it cannot be read, deciphered, or reconstructed through generally available means. An entity already subject to, and in compliance with, a federal law governing the disposal of records containing personal identifying information is considered compliant with this section too.

A knowing violation is a misdemeanor punishable by a fine of up to $250 for each violation, and the section neither creates a private right of action nor displaces whatever other civil remedy state or federal law might otherwise provide.

This is a narrower, disposal-only duty that does not, by its own text, impose the broader administrative, technical, and physical safeguards program that New York's SHIELD Act (General Business Law 899-bb) or Utah's Protection of Personal Information Act (Utah Code 13-44-201) require.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

official Michigan Compiled Laws text, Michigan Legislature

Back to the example  ·  Lint your app