Minnesota Consumer Data Privacy Act
Minnesota · Consumer Digital and Data Privacy · §§ 325M.10 to 325M.21 · 12 sections
Overview
The act governs how businesses collect, use, and share consumers' personal data, dividing responsibility between the controllers who determine why data is processed and the processors who handle it on their behalf, while carving out categories of entities and data that fall outside its reach. It gives consumers rights over their own information — including the ability to opt out of certain processing, to exercise those rights through an authorized agent, and to appeal a controller's response — and imposes on controllers a duty of care, limits on how collected data may be used, standards for treating data as de-identified, and an obligation to conduct data protection assessments before undertaking processing that carries heightened risk. Additional duties attach to the personal data of minors, and compliance is backed by enforcement authority that includes civil penalties and injunctive relief.
Editorial summary generated from the text of this act. It is not part of the statute — read the sections below for the operative language.
Sections covered
- Minn. Stat. § 325M.10CITATION.
- Minn. Stat. § 325M.11DEFINITIONS.
- Minn. Stat. § 325M.12SCOPE; EXCLUSIONS.
- Minn. Stat. § 325M.13RESPONSIBILITY ACCORDING TO ROLE.
- Minn. Stat. § 325M.14CONSUMER PERSONAL DATA RIGHTS.
- Minn. Stat. § 325M.15PROCESSING DEIDENTIFIED DATA OR PSEUDONYMOUS DATA.
- Minn. Stat. § 325M.16RESPONSIBILITIES OF CONTROLLERS.
- Minn. Stat. § 325M.17REQUIREMENTS FOR SMALL BUSINESSES.
- Minn. Stat. § 325M.18DATA PRIVACY POLICIES; DATA PRIVACY AND PROTECTION ASSESSMENTS.
- Minn. Stat. § 325M.19LIMITATIONS AND APPLICABILITY.
- Minn. Stat. § 325M.20ATTORNEY GENERAL ENFORCEMENT.
- Minn. Stat. § 325M.21PREEMPTION OF LOCAL LAW; SEVERABILITY.
Enacted in other states
All Minnesota named statutes →
Download
Copy
Embed on your site
Hover to preview · click to copy the code