Law note · Minnesota
Minnesota breach notification
Minnesota's breach notification duty, a separate and pre-existing chapter from MCDPA, was originally enacted by 2005 Minn. Laws ch. 167, section 1, and has since been amended by 2006 Minn. Laws ch. 212, article 1, sections 17 and 24, and ch. 233, sections 7 and 8. The Revisor's own history note for this section carries only chapter and year, with no day-precise commencement date, so effective_date is left unset here rather than invented; the section is currently in force.
A person or business must disclose a breach of the security of the system, following discovery or notification of the breach, to any Minnesota resident whose unencrypted personal information was or is reasonably believed to have been acquired by an unauthorized person, made in the most expedient time possible and without unreasonable delay.
Unlike Maryland's or Tennessee's fixed-day deadlines, Minnesota uses a reasonableness standard with no numeric cap; a data maintainer that does not own the information must notify the owner immediately upon discovery.
What it asks of an app
- Disclose a breach of the security of the system to an affected Minnesota resident in the most expedient time possible and without unreasonable delay. Minnesota sets no fixed numeric-day cap, unlike several peer states.
- Notify the data owner immediately upon discovering a breach if you maintain, but do not own, the affected data.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach
Primary source: official Minnesota statute text, Minn. Stat. § 325E.61, Office of the Revisor of Statutes