Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
cite MCL 445.72
stage IN FORCE in force since 2006-07-02
source official Michigan Compiled Laws text, Michigan Legislature
The Identity Theft Protection Act (Act 452 of 2004) requires a person or agency to provide breach notice without unreasonable delay, unless the entity determines the breach has not caused and is not likely to cause substantial loss, injury, or identity theft.
The notice trigger turns on the narrower personal information term at MCL 445.63(r), which does not include biometric data; a breach exposing only biometric identifiers, with no accompanying Social Security number, driver's license, or financial account number, does not trigger this notice duty. The publicly-available carve-out for this notice duty is placed in MCL 445.72(17), not in the definitions section, MCL 445.63. This section applies to a breach discovered or noticed on or after July 2, 2006.
What it asks of an app →
cite MCL 445.63(q), (r)
stage IN FORCE in force since 2011-04-01
source official Michigan Compiled Laws text, Michigan Legislature
MCL 445.63 defines two distinct terms that must not be conflated. "Personal information," MCL 445.63(r), is a name combined with a Social Security number, driver's license or state ID number, or financial account or card number with an access code; it does not include biometric data.
"Personal identifying information," MCL 445.63(q), is a broader term, used for the Act's identity-theft-prevention and criminal provisions elsewhere in the chapter, that does include biometrics among many other data elements such as address, employer, government passport number, and account passwords. Only the narrower "personal information" term is the breach-notice trigger at MCL 445.72.
What it asks of an app →
Enforcement supervision
cite MCL 445.72(13)-(15)
stage IN FORCE in force since 2006-07-02
source official Michigan Compiled Laws text, Michigan Legislature
A person that knowingly fails to give required breach notice may be ordered to pay a civil fine of up to $250 per failure to notify, with aggregate liability for multiple violations arising from the same breach capped at $750,000; the Attorney General or a prosecuting attorney may bring the action.
The Act preserves, but does not itself create, any other civil remedy available under state or federal law; no provision ties a violation to the Michigan Consumer Protection Act or any other statute carrying a private right of action.
What it asks of an app →
cite MCL 500.550
stage IN FORCE in force since 2021-01-20
source official Michigan Compiled Laws text, Michigan Legislature
The Insurance Data Security Act expressly does not create or imply a private cause of action for its violation, and does not curtail a private cause of action that would otherwise exist independent of the chapter. The chapter establishes the exclusive Michigan standards for a licensee's data security, cybersecurity-event investigation, and notification to the Director of the Department of Insurance and Financial Services, who enforces it.
What it asks of an app →
Sensitive categories
cite MCL 333.17020
stage IMMINENT commencement not set
source official Michigan Compiled Laws text, Public Health Code, Michigan Legislature
A physician, or an individual to whom the physician has delegated authority to perform a selected act, task, or function, may not order a presymptomatic or predictive genetic test without first obtaining the test subject's written, informed consent.
This is a health-care informed-consent requirement binding a physician's ordering conduct, not a consumer-facing data-privacy or data-processing statute, and it does not reach a direct-to-consumer genetic-testing company; no Michigan statute regulates such a company's privacy practices. The precise commencement date, tied to the expiration of 6 months after the effective date of the amendatory act that added this section, was not independently established this pass.
What it asks of an app →
cite MCL 500.553
stage IN FORCE in force since 2021-01-20
source official Michigan Compiled Laws text, Michigan Legislature
Michigan adopted the NAIC Insurance Data Security Model Law as Chapter 5A of the Insurance Code (MCL 500.550 to 500.565), effective January 20, 2021. Nonpublic information (MCL 500.553(i)) includes electronic information that is not publicly available and that, combined with an identifying element such as a name or number, includes a Social Security number, driver's license or state ID number, financial account or card number, a financial-account access code, or biometric records.
Biometric records appears as a bare, undefined term with no elaboration anywhere in the chapter's definitions and no photograph, video, or audio-recording exclusion or clawback clause of any kind, so excludes_recording_derived cannot be tested against this text and is not recorded. This chapter binds insurance licensees only, not a general private-sector actor.
What it asks of an app →
Social media and minors
Senate Bill 757 (a SAFE for Kids style bill) would bar a covered operator from providing an addictive feed to a minor without verifiable parental consent and from sending addictive feed notifications to minors between 10 p.m. and 6 a.m. or during school hours, with rules on age and parental consent verification.
Senate Bills 758 and 759 (a Kids Code pair) would limit data collection to the minimum needed for age verification with deletion within 60 days, require parental controls, and make violations enforceable under the Michigan Consumer Protection Act. Senate Bill 760 would bar making a companion chatbot available to a minor if it could foreseeably undermine the minor's safety, wellbeing, or development.
The package passed the Senate 20 to 17 on April 29, 2026, and is pending in the House Communications and Technology Committee.
Note and primary source →