Law / Michigan

Michigan

age

Michigan has not enacted an age-gating statute in any of the four families.

A Senate package known as Kids Over Clicks (Senate Bills 757 through 760) passed the Senate 20 to 17 on April 29, 2026; it would require verifiable parental consent before a platform may serve an addictive feed to a minor, bar addictive feed notifications to minors overnight and during the school day, impose Kids Code style data minimization and parental control duties, and restrict AI companion chatbots that could undermine a minor's safety.

The package remains pending in the House Communications and Technology Committee in Michigan's divided legislature. Separate bills on social media age verification and parental consent (House Bill 4388) and adult content age verification (Senate Bill 191) remain in committee and have not passed either chamber.

privacy

Michigan has no comprehensive consumer personal-data statute. The Michigan Personal Data Privacy Act, SB 359, was reported favorably from committee in June 2025 but has seen no floor vote in either chamber and does not clear the marquee bar for a proposed instrument.

Michigan's sectoral law covers breach notification under the Identity Theft Protection Act (MCL 445.61 to 445.79d), whose breach-notice trigger turns on the narrower personal information term (MCL 445.63(r)), which excludes biometrics, while a separate, broader personal identifying information term in the same section (MCL 445.63(q)), used elsewhere in the Act for identity-theft and criminal provisions, does include biometrics; the two must not be conflated.

The Insurance Data Security Act (MCL 500.550 to 500.565), adopting the NAIC model law effective January 20, 2021, names biometric records as a protected data element for insurance licensees but defines the term no further and expressly forecloses a private right of action, as does the Identity Theft Protection Act's own breach-notice enforcement provision.

A physician-ordered genetic test informed-consent requirement (MCL 333.17020) binds health care providers but is not a consumer-facing genetic-privacy or data-processing statute; no Michigan law regulates direct-to-consumer genetic-testing companies' privacy practices, and no biometric-privacy statute reaches a general private-sector actor outside the insurance sector.

14 instruments named 7 researched in detail As of 2026-08-28

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

Identity Theft Protection Act, breach of security notice duty

cite MCL 445.72 stage IN FORCE in force since 2006-07-02 source official Michigan Compiled Laws text, Michigan Legislature

The Identity Theft Protection Act (Act 452 of 2004) requires a person or agency to provide breach notice without unreasonable delay, unless the entity determines the breach has not caused and is not likely to cause substantial loss, injury, or identity theft.

The notice trigger turns on the narrower personal information term at MCL 445.63(r), which does not include biometric data; a breach exposing only biometric identifiers, with no accompanying Social Security number, driver's license, or financial account number, does not trigger this notice duty. The publicly-available carve-out for this notice duty is placed in MCL 445.72(17), not in the definitions section, MCL 445.63. This section applies to a breach discovered or noticed on or after July 2, 2006.

What it asks of an app

Identity Theft Protection Act, personal information and personal identifying information defined

cite MCL 445.63(q), (r) stage IN FORCE in force since 2011-04-01 source official Michigan Compiled Laws text, Michigan Legislature

MCL 445.63 defines two distinct terms that must not be conflated. "Personal information," MCL 445.63(r), is a name combined with a Social Security number, driver's license or state ID number, or financial account or card number with an access code; it does not include biometric data.

"Personal identifying information," MCL 445.63(q), is a broader term, used for the Act's identity-theft-prevention and criminal provisions elsewhere in the chapter, that does include biometrics among many other data elements such as address, employer, government passport number, and account passwords. Only the narrower "personal information" term is the breach-notice trigger at MCL 445.72.

What it asks of an app

Enforcement supervision

Identity Theft Protection Act, enforcement

cite MCL 445.72(13)-(15) stage IN FORCE in force since 2006-07-02 source official Michigan Compiled Laws text, Michigan Legislature

A person that knowingly fails to give required breach notice may be ordered to pay a civil fine of up to $250 per failure to notify, with aggregate liability for multiple violations arising from the same breach capped at $750,000; the Attorney General or a prosecuting attorney may bring the action.

The Act preserves, but does not itself create, any other civil remedy available under state or federal law; no provision ties a violation to the Michigan Consumer Protection Act or any other statute carrying a private right of action.

What it asks of an app

Insurance Data Security Act, no private cause of action

cite MCL 500.550 stage IN FORCE in force since 2021-01-20 source official Michigan Compiled Laws text, Michigan Legislature

The Insurance Data Security Act expressly does not create or imply a private cause of action for its violation, and does not curtail a private cause of action that would otherwise exist independent of the chapter. The chapter establishes the exclusive Michigan standards for a licensee's data security, cybersecurity-event investigation, and notification to the Director of the Department of Insurance and Financial Services, who enforces it.

What it asks of an app

Sensitive categories

Genetic test; informed consent

cite MCL 333.17020 stage IMMINENT commencement not set source official Michigan Compiled Laws text, Public Health Code, Michigan Legislature

A physician, or an individual to whom the physician has delegated authority to perform a selected act, task, or function, may not order a presymptomatic or predictive genetic test without first obtaining the test subject's written, informed consent.

This is a health-care informed-consent requirement binding a physician's ordering conduct, not a consumer-facing data-privacy or data-processing statute, and it does not reach a direct-to-consumer genetic-testing company; no Michigan statute regulates such a company's privacy practices. The precise commencement date, tied to the expiration of 6 months after the effective date of the amendatory act that added this section, was not independently established this pass.

What it asks of an app

Insurance Data Security Act, nonpublic information including biometric records

cite MCL 500.553 stage IN FORCE in force since 2021-01-20 source official Michigan Compiled Laws text, Michigan Legislature

Michigan adopted the NAIC Insurance Data Security Model Law as Chapter 5A of the Insurance Code (MCL 500.550 to 500.565), effective January 20, 2021. Nonpublic information (MCL 500.553(i)) includes electronic information that is not publicly available and that, combined with an identifying element such as a name or number, includes a Social Security number, driver's license or state ID number, financial account or card number, a financial-account access code, or biometric records.

Biometric records appears as a bare, undefined term with no elaboration anywhere in the chapter's definitions and no photograph, video, or audio-recording exclusion or clawback clause of any kind, so excludes_recording_derived cannot be tested against this text and is not recorded. This chapter binds insurance licensees only, not a general private-sector actor.

What it asks of an app

Social media and minors

SB 757-760 (2026), Kids Over Clicks package

cite Senate Bills 757, 758, 759, and 760, 2025-2026 Regular Session stage PROPOSED draft date not recorded source official bill status and Senate Fiscal Agency analysis, Michigan Legislature

Senate Bill 757 (a SAFE for Kids style bill) would bar a covered operator from providing an addictive feed to a minor without verifiable parental consent and from sending addictive feed notifications to minors between 10 p.m. and 6 a.m. or during school hours, with rules on age and parental consent verification.

Senate Bills 758 and 759 (a Kids Code pair) would limit data collection to the minimum needed for age verification with deletion within 60 days, require parental controls, and make violations enforceable under the Michigan Consumer Protection Act. Senate Bill 760 would bar making a companion chatbot available to a minor if it could foreseeably undermine the minor's safety, wellbeing, or development.

The package passed the Senate 20 to 17 on April 29, 2026, and is pending in the House Communications and Technology Committee.

Note and primary source

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.