Law / Minnesota

Minnesota

age

Minnesota enacted the STOP HARMS from Addictive Social Media Act as part of House File 4138, signed May 26, 2026, which will require covered social media platforms to estimate users' ages, obtain verifiable parental consent for accounts they must treat as belonging to a child, default to the most private settings, and disable addictive interface features such as infinite scroll and autoplay for children, effective July 1, 2027.

The Act includes a private right of action for children and parents in addition to Attorney General enforcement as a deceptive trade practice. A separate bill that would require anonymous age verification for websites with material harmful to minors (HF 1434, companion SF 2105) has not advanced past committee, so Minnesota has no adult content age verification, app store age verification, or comprehensive design code law.

A related 2025 law, Minn. Stat. 325M.335, requires a mental health warning label on social media platforms effective July 1, 2026; it applies to users of all ages rather than gating by age, and the state has agreed not to enforce it while NetChoice's First Amendment challenge (NetChoice v. Ellison, D. Minn. No. 0:26-cv-2405) is pending.

privacy

Minnesota's comprehensive private-sector privacy law is the Minnesota Consumer Data Privacy Act (MCDPA), codified at Minn. Stat. §§ 325M.10 to 325M.21 (the surrounding Chapter 325M also holds two unrelated statutes, an older internet-service-provider disclosure law and a separate social-media-manipulation act, so the MCDPA citation is narrower than the bare chapter number).

MCDPA took effect July 31, 2025 for most controllers, with postsecondary institutions regulated by the Office of Higher Education deferred to July 31, 2029. MCDPA claws back a recording-derived biometric identifier the moment it is generated to identify a specific individual, follows the ordinary multi-state opt-in consent model for sensitive data rather than Maryland's outright sale ban, and gives consumers a distinctive right to a list of the specific third parties their data was disclosed to.

Breach notification is a separate, older statute, Minn. Stat. § 325E.61, using a reasonableness standard with no fixed numeric deadline. MCDPA's own 30-day cure opportunity has already sunset (January 31, 2026), and MCDPA bars any private right of action, including through the general private-attorney-general mechanism in Minn. Stat. § 8.31.

12 instruments named 6 researched in detail As of 2026-08-27

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

Minnesota breach notification

cite Minn. Stat. § 325E.61 stage IMMINENT commencement not set source official Minnesota statute text, Minn. Stat. § 325E.61, Office of the Revisor of Statutes

Minnesota's breach notification duty, a separate and pre-existing chapter from MCDPA, was originally enacted by 2005 Minn. Laws ch. 167, section 1, and has since been amended by 2006 Minn. Laws ch. 212, article 1, sections 17 and 24, and ch. 233, sections 7 and 8. The Revisor's own history note for this section carries only chapter and year, with no day-precise commencement date, so effective_date is left unset here rather than invented; the section is currently in force.

A person or business must disclose a breach of the security of the system, following discovery or notification of the breach, to any Minnesota resident whose unencrypted personal information was or is reasonably believed to have been acquired by an unauthorized person, made in the most expedient time possible and without unreasonable delay.

Unlike Maryland's or Tennessee's fixed-day deadlines, Minnesota uses a reasonableness standard with no numeric cap; a data maintainer that does not own the information must notify the owner immediately upon discovery.

What it asks of an app

Comprehensive regime

Minnesota Consumer Data Privacy Act (MCDPA), general applicability

cite Minn. Stat. §§ 325M.10 to 325M.21 stage IN FORCE in force since 2025-07-31 source official Minnesota statute text, Minn. Stat. Chapter 325M, Office of the Revisor of Statutes

MCDPA governs private-sector processing of Minnesota residents' personal data, enacted as Laws of Minnesota 2024, chapter 121, article 5. A controller must limit collection to what is adequate, relevant, and reasonably necessary for the disclosed processing purpose, and must obtain consent before processing for an undisclosed, incompatible secondary purpose.

The general effective date, July 31, 2025, binds every controller except postsecondary institutions regulated by the Office of Higher Education, which are not required to comply until July 31, 2029, per the statute's own history note.

What it asks of an app

Data subject rights

Minnesota Consumer Data Privacy Act, consumer rights and profiling

cite Minn. Stat. § 325M.14 stage IN FORCE in force since 2025-07-31 source official Minnesota statute text, Minn. Stat. Chapter 325M, Office of the Revisor of Statutes

MCDPA grants a Minnesota consumer the rights to confirm processing, access, correct, delete, port their personal data, and opt out of targeted advertising, sale, and certain profiling, with an appeal right for denials.

A consumer may also demand a list of the specific third parties a controller disclosed their personal data to, going further than the multi-state model's usual categories-only disclosure, and may opt out of automated profiling for decisions with legal or similarly significant effects, question such a decision, receive an explanation, and have it reevaluated if based on inaccurate data.

A controller must respond within 45 days of receipt, extendable once by 45 additional days, and must respond to an appeal within 45 days, extendable by 60 additional days.

What it asks of an app

Enforcement supervision

Minnesota Consumer Data Privacy Act, Attorney General enforcement

cite Minn. Stat. § 325M.20 stage IN FORCE in force since 2025-07-31 source official Minnesota statute text, Minn. Stat. Chapter 325M, Office of the Revisor of Statutes

The Minnesota Attorney General may bring a civil action to enforce MCDPA under the general false-advertising and consumer-protection statute, Minn. Stat. § 8.31, with a civil penalty of up to $7,500 per violation plus litigation costs and injunctive relief. MCDPA expressly bars any private right of action, including one brought under § 8.31's own private-attorney-general provision.

A discretionary warning-letter and 30-day cure opportunity existed but has already sunset, expiring January 31, 2026; the Attorney General may now sue directly without first offering a cure window.

What it asks of an app

Sensitive categories

Minnesota Consumer Data Privacy Act, sensitive data and biometric consent

cite Minn. Stat. §§ 325M.11, 325M.16 stage IN FORCE in force since 2025-07-31 source official Minnesota statute text, Minn. Stat. Chapter 325M, Office of the Revisor of Statutes

MCDPA classifies data revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis, sexual orientation, or citizenship or immigration status; the processing of biometric data or genetic information to uniquely identify an individual; a known child's data; and precise geolocation data as sensitive data, processable only with the consumer's opt-in consent, the ordinary multi-state model rather than Maryland's outright sale ban.

"Biometric data" means data generated by automatic measurement of biological characteristics used to identify a specific individual, and it excludes a bare photograph, video, or audio recording, but claws that exclusion back the moment data generated from one is used to identify a specific individual.

What it asks of an app

Social media and minors

HF 4138 (2026), STOP HARMS from Addictive Social Media Act

cite Minn. Stat. §§ 325M.33, 325M.40 (2026 Minn. Laws ch. 111) stage IMMINENT in force in 306 days effective 2027-07-01 source official session law text, Minnesota Revisor of Statutes

Requires a covered social media platform (10,000 or more account holders, or at least $1 billion in worldwide revenue) to estimate a new account holder's age after 25 hours of use within six months, treating the user as a child (age 15 or younger) unless it can conclude with 80 percent confidence the user is 16 or older, rising to a 90 percent confidence threshold at 50 hours of use.

Child accounts require verifiable parental consent, must default to the most private settings, and may not display addictive interface features such as infinite scroll, autoplay, push notifications, or targeted advertising.

Note and primary source

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.