Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
cite Minn. Stat. § 325E.61
stage IMMINENT commencement not set
source official Minnesota statute text, Minn. Stat. § 325E.61, Office of the Revisor of Statutes
Minnesota's breach notification duty, a separate and pre-existing chapter from MCDPA, was originally enacted by 2005 Minn. Laws ch. 167, section 1, and has since been amended by 2006 Minn. Laws ch. 212, article 1, sections 17 and 24, and ch. 233, sections 7 and 8. The Revisor's own history note for this section carries only chapter and year, with no day-precise commencement date, so effective_date is left unset here rather than invented; the section is currently in force.
A person or business must disclose a breach of the security of the system, following discovery or notification of the breach, to any Minnesota resident whose unencrypted personal information was or is reasonably believed to have been acquired by an unauthorized person, made in the most expedient time possible and without unreasonable delay.
Unlike Maryland's or Tennessee's fixed-day deadlines, Minnesota uses a reasonableness standard with no numeric cap; a data maintainer that does not own the information must notify the owner immediately upon discovery.
What it asks of an app →
Comprehensive regime
cite Minn. Stat. §§ 325M.10 to 325M.21
stage IN FORCE in force since 2025-07-31
source official Minnesota statute text, Minn. Stat. Chapter 325M, Office of the Revisor of Statutes
MCDPA governs private-sector processing of Minnesota residents' personal data, enacted as Laws of Minnesota 2024, chapter 121, article 5. A controller must limit collection to what is adequate, relevant, and reasonably necessary for the disclosed processing purpose, and must obtain consent before processing for an undisclosed, incompatible secondary purpose.
The general effective date, July 31, 2025, binds every controller except postsecondary institutions regulated by the Office of Higher Education, which are not required to comply until July 31, 2029, per the statute's own history note.
What it asks of an app →
Data subject rights
cite Minn. Stat. § 325M.14
stage IN FORCE in force since 2025-07-31
source official Minnesota statute text, Minn. Stat. Chapter 325M, Office of the Revisor of Statutes
MCDPA grants a Minnesota consumer the rights to confirm processing, access, correct, delete, port their personal data, and opt out of targeted advertising, sale, and certain profiling, with an appeal right for denials.
A consumer may also demand a list of the specific third parties a controller disclosed their personal data to, going further than the multi-state model's usual categories-only disclosure, and may opt out of automated profiling for decisions with legal or similarly significant effects, question such a decision, receive an explanation, and have it reevaluated if based on inaccurate data.
A controller must respond within 45 days of receipt, extendable once by 45 additional days, and must respond to an appeal within 45 days, extendable by 60 additional days.
What it asks of an app →
Enforcement supervision
cite Minn. Stat. § 325M.20
stage IN FORCE in force since 2025-07-31
source official Minnesota statute text, Minn. Stat. Chapter 325M, Office of the Revisor of Statutes
The Minnesota Attorney General may bring a civil action to enforce MCDPA under the general false-advertising and consumer-protection statute, Minn. Stat. § 8.31, with a civil penalty of up to $7,500 per violation plus litigation costs and injunctive relief. MCDPA expressly bars any private right of action, including one brought under § 8.31's own private-attorney-general provision.
A discretionary warning-letter and 30-day cure opportunity existed but has already sunset, expiring January 31, 2026; the Attorney General may now sue directly without first offering a cure window.
What it asks of an app →
Sensitive categories
cite Minn. Stat. §§ 325M.11, 325M.16
stage IN FORCE in force since 2025-07-31
source official Minnesota statute text, Minn. Stat. Chapter 325M, Office of the Revisor of Statutes
MCDPA classifies data revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis, sexual orientation, or citizenship or immigration status; the processing of biometric data or genetic information to uniquely identify an individual; a known child's data; and precise geolocation data as sensitive data, processable only with the consumer's opt-in consent, the ordinary multi-state model rather than Maryland's outright sale ban.
"Biometric data" means data generated by automatic measurement of biological characteristics used to identify a specific individual, and it excludes a bare photograph, video, or audio recording, but claws that exclusion back the moment data generated from one is used to identify a specific individual.
What it asks of an app →
Social media and minors
Requires a covered social media platform (10,000 or more account holders, or at least $1 billion in worldwide revenue) to estimate a new account holder's age after 25 hours of use within six months, treating the user as a child (age 15 or younger) unless it can conclude with 80 percent confidence the user is 16 or older, rising to a 90 percent confidence threshold at 50 hours of use.
Child accounts require verifiable parental consent, must default to the most private settings, and may not display addictive interface features such as infinite scroll, autoplay, push notifications, or targeted advertising.
Note and primary source →