Skip to main content
MCDPA · Effective 2025-07-31

Minnesota Data Removal Guide (2026)

Minnesota's Consumer Data Privacy Act took effect July 2025. The law includes data-minimization obligations and profile-based decision transparency provisions that may matter when a controller uses personal data for high-impact or targeted processing.

Research status: published state guide pending fresh official-source re-verification.

This page is educational orientation, not legal advice. Scope, exemptions, deadlines, penalties, regulator powers and broker routes can change. Verify the current statute and state regulator guidance before relying on a right or deadline.

Rahul Kandoriya
Written byRahul Kandoriya·Founder, OfflistMe·Last updated August 13, 2026

At a glance

Comprehensive state privacy law
Recorded: MCDPA
Broker response deadline
45 days in this research snapshot for qualifying requests; extensions and exemptions may apply
Enforcement
Minnesota Attorney General

Minnesota Consumer Data Privacy Act (MCDPA)

MCDPA applies to legal entities that conduct business in Minnesota or target Minnesota residents and meet either the 100,000-consumer branch or the 25,000-consumer-plus-more-than-25%-sale-revenue branch, subject to statutory exclusions. Rights include access, correction, deletion, portability, and opt-outs for sale, targeted advertising, and certain profiling; qualifying opt-out preference signals are required. Controllers generally have 45 days to respond, with a possible 45-day extension. The 30-day warning-letter cure condition expired January 31, 2026; the AG has exclusive enforcement authority under the current statute.

Read the full MCDPAexplainer →Scope, thresholds, exceptions, cure rules, and enforcement details where documented.

What rights do Minnesota residents have?

  • Delete, access, correct, port, opt-out
  • Right to question profiling results and correct inaccurate data used in the decision
  • Data-minimization obligations on controllers
  • Privacy impact assessment requirements

Where does your data leak from in Minnesota?

The FTC explains that people-search sites may combine public records, public social profiles, and information from other brokers. The examples below are a research snapshot, not an exhaustive or person-specific source map for Minnesota:

  • Hennepin, Ramsey County property records
  • Minnesota Judicial Branch case search (MNCIS)
  • Minnesota DVS driver records

Generate requests in under 60 seconds

Generate requests for 1009 US/global broker workflows for $9

OfflistMe prepares user-reviewed request drafts for the selected catalog routes. You choose the jurisdictional wording, review each draft, and send or submit it yourself; broker verification and outcomes remain outside OfflistMe's control.

What if a broker ignores your request?

If a qualifying request does not receive a response within the applicable window, review the current extension and exemption rules, then consider the Minnesota Attorney General complaint route. The authority's jurisdiction and available remedies vary.

File a complaint with Minnesota Attorney General

FAQ: Minnesota data removal

What makes MCDPA different from other state privacy laws?+

MCDPA includes automated-decision and data-minimization provisions. The exact explanation, review, deletion, and exemption rules depend on the processing and current statute; ask the controller for the route that applies to the request.

Related resources

Other state guides