Skip to main content
Explainer · Reviewed September 2026

What Is the Minnesota Consumer Data Privacy Act?

MCDPA applies to legal entities that conduct business in Minnesota or target Minnesota residents and meet either the 100,000-consumer branch or the 25,000-consumer-plus-more-than-25%-sale-revenue branch, subject to statutory exclusions. Rights include access, correction, deletion, portability, and opt-outs for sale, targeted advertising, and certain profiling; qualifying opt-out preference signals are required. Controllers generally have 45 days to respond, with a possible 45-day extension. The 30-day warning-letter cure condition expired January 31, 2026; the AG has exclusive enforcement authority under the current statute.

Rahul Kandoriya
Written byRahul Kandoriya·Founder, OfflistMe·Last updated September 7, 2026

At a glance

Full name
Minnesota Consumer Data Privacy Act
Short code
MCDPA
Effective date
July 31, 2025
Response reference
45 days in this snapshot
Cure period
None recorded in this snapshot
Private right of action
No
Enforcement
Minnesota Attorney General
Penalty reference
Up to $7,500 per violation under existing consumer protection authority

Who MCDPA applies to

A business is covered if it meets the applicability thresholds set out in Minn. Stat. §§ 325M.10–325M.21. The thresholds listed below are the research record for this law. Whether one or more applies depends on the current statute, its exceptions, and the business's facts; do not assume a universal threshold structure.

  • Conducts business in Minnesota or produces products or services targeted to Minnesota residents and, during a calendar year, controls or processes personal data of at least 100,000 consumers, excluding data processed solely for payment transactions
  • Conducts business in Minnesota or produces products or services targeted to Minnesota residents and, during a calendar year, controls or processes personal data of at least 25,000 consumers and derives more than 25% of gross revenue from the sale of personal data

Consumer rights under MCDPA

Delete, access, correct, port, opt-out

Right to question profiling results and correct inaccurate data used in the decision

Data-minimization obligations on controllers

Privacy impact assessment requirements

Notable features (vs. CCPA)

MCDPA gives consumers rights to question profiling results used for decisions producing legal or similarly significant effects, review the data used, and have inaccurate data corrected with the decision reevaluated. It also requires data minimization and privacy assessments for specified processing, and the Minnesota Attorney General may request relevant assessments during a civil investigative demand.

Enforcement and penalty reference

Enforcing agency: Minnesota Attorney General

Penalty reference: Up to $7,500 per violation under existing consumer protection authority

Cure period: The 30-day warning-letter cure condition expired on January 31, 2026. The current statute provides Attorney General enforcement and civil penalties; do not assume a general current cure period.

Private right of action: MCDPA has no private right of action. Enforcement is exclusive to the Minnesota Attorney General.

Where to file a complaint: Minnesota Attorney General

How to exercise your MCDPA rights

  1. 1

    Identify the business that holds your data. OfflistMe can help you review a provider route across 1,034 US/global workflow profiles in the 1,052-record research universe; it does not decide whether a law applies to a specific request.

  2. 2

    Submit a request to the business's designated contact using the provider's current verification instructions. Include only the information reasonably needed to match your record and check the applicable Minnesota residency, scope, exemption, and verification rules before sending.

  3. 3

    This research snapshot records a 45-day reference window for the modeled request. Confirm the current statute, request type, controller scope, extension rule, and verification date before treating it as a deadline.

  4. 4

    If the provider does not respond or disputes the request, preserve the request and response record, review the applicable exceptions, and consider the Minnesota Attorney General complaint route at https://www.ag.state.mn.us/Office/Complaint.asp. A complaint route does not itself guarantee deletion or a particular enforcement result.

Generate requests in under 60 seconds

Generate a MCDPA privacy request, $9 one-time

Review the provider route, applicable law, and information you intend to send before dispatch. You remain in control of the request and any evidence kept.

FAQ

What makes MCDPA different from other state privacy laws?+

MCDPA includes automated-decision and data-minimization provisions. The exact explanation, review, deletion, and exemption rules depend on the processing and current statute; ask the controller for the route that applies to the request.

Official sources & citations

Compare with sibling state laws

MCDPA is one of 18 comprehensive US state privacy laws. Its closest peers by effective date, useful when tracking how this law influenced or was influenced by neighboring legislation:

Related concepts & guides