Consumer Data Privacy
Minnesota Consumer Data Privacy Law: Thresholds, Consumer Rights & Deadlines
What Minnesota’s consumer data privacy law requires, maintained by Stauss PLLC. Last reviewed August 2026.
What You Need to Know
The law applies the standard 100,000-consumer threshold, exempting small businesses (though even they cannot sell sensitive data without consent). Consumer rights include a right to obtain a list of third parties to whom personal data was transferred. The law creates a first-in-the-nation right to question profiling results and receive information about the profiling process. Privacy policy requirements draw on California and Colorado rulemaking for cross-state interoperability. Controllers must maintain a data inventory and document their compliance policies and procedures in detail. The non-discrimination provision is distinctive, bearing some resemblance to Maryland's recent law but with meaningful differences.
Official law text
Who the law applies to
| Threshold | Requirement |
|---|---|
| Annual gross revenue | N/A |
| Consumers whose data is processed | 100,000 consumers 1.75% of state's 5.7 million population |
| Revenue from sale of personal data | Derives more than 25% of gross revenue from sale of personal data and controls or processes personal data of 25,000 consumers or more. |
Consumer rights under Minnesota's law15
| Right | Provided? |
|---|---|
| Know | Yes |
| Access | Yes |
| Obtain list of third parties to which personal data was disclosed | Yes |
| Data portability | Yes |
| Delete | Yes |
| Correct inaccuracies | Yes |
| Not be discriminated against for exercising rights | Yes |
| Opt-out of sale | Yes |
| Opt-out of targeted advertising/sharing | Yes |
Opt-out of certain types of profilingnoteIf a consumer's personal data is profiled in furtherance of decisions that produce legal effects concerning a consumer or similarly significant effects concerning a consumer, the consumer has the right to question the result of the profiling, to be informed of the reason that the profiling resulted in the decision, and, if feasible, to be informed of what actions the consumer might have taken to secure a different decision and the actions that the consumer might take to secure a different decision in the future. The consumer has the right to review the consumer's personal data used in the profiling. If the decision is determined to have been based upon inaccurate personal data, taking into account the nature of the personal data and the purposes of the processing of the personal data, the consumer has the right to have the data corrected and the profiling decision reevaluated based upon the corrected data. | Yes |
| Opt-out of ADMT | No |
| Recognize opt-out signals | Yes |
| Revoke consent | Yes |
| Not process data in discriminatory manner | Yes |
| Appeal | Yes |
Categories treated as sensitive data9
- Racial or ethnic origin
- Religious beliefs
- Mental or physical health diagnosis
- Mental or physical health condition
- Sexual orientation
- Citizenship or immigration status
- Genetic or biometric data for purposes of uniquely identifying an individual
- Personal data of known child
- Precise geolocation
note
Connecticut, Maryland, Oregon, and Virginia ban the sale of precise geolocation data.
How sensitive data must be treated2
- Obtain Consent to Process
- Conduct Data Protection or Risk Assessment
Requirements for minors' data2
- Process personal data of children under 13 in accordance with COPPA or parental/legal guardian consent
- Opt-in for selling or sharing of personal data of children ages 13-15
Activities that trigger a risk or impact assessment5
- Targeted advertising (“sharing”)
- Sale of personal data
- Processing of sensitive data
- Processing personal data for purposes of profiling where it presents reasonably foreseeable risk of unfair or deceptive treatment of, or unlawful disparate impact on, consumers; financial, physical, or reputational injury to consumers; physical or other intrusion upon the solitude or seclusion, or the private affairs or concerns, of consumers, where such intrusion would be offensive to a reasonable person; other subject injury to consumers
- Any processing activities involving personal data that present a heightened risk of harm to consumers
Other notable provisions10
- Definition of “Sale” Includes “Other Valuable Consideration”
- Applies to Nonprofits
- Data Processing Agreements
- Privacy Policy
- Implement Reasonable Data Security Measures
- Duty to Avoid Secondary Use
- Data Minimization
- Data Inventory
- Data Retention Limit
- Attorney General Enforcement
Key dates2
| Date | What happens |
|---|---|
| July 31, 2025 | Minnesota's consumer data privacy law takes effect |
| July 31, 2029 | Minnesota's consumer data privacy law becomes effective for post-secondary institutions |
One link, every dated item SPARC tracks — Consumer Privacy, Data Broker, and AI Laws, not just this table.
Subscribe now (opens your default calendar app)
https://staussfirm.com/sparc/calendar.ics
Google Calendar: Settings → Add calendar → From URL → paste the link above.
Outlook: Add calendar → Subscribe from web → paste the link above.
Questions about Minnesota’s privacy law?
Stauss PLLC advises companies on state privacy, AI, and data broker compliance.
Contact Stauss PLLCFollow Minnesota’s privacy law
Our analysis, by email, as the law moves.
This page is provided for general informational purposes only, is not legal advice, and does not create an attorney-client relationship. State laws change frequently; coverage reflects this tool’s most recent update. Contact Stauss PLLC to confirm how these requirements apply to your organization.
