USPrivacyAtlasState Privacy & Data Security Law Matcher

Comprehensive Privacy Law

Minnesota Consumer Data Privacy Act

MNCDPA

Minnesota · Jul 31, 2025

Applies at 100,000+ Minnesota consumers (excluding payment-only data), or 25,000+ if 25%+ of revenue comes from selling personal data — plus a separate small-business exemption layered on top based on SBA size standards. Only insurance-fraud-prevention nonprofits are exempt; nonprofits generally are NOT exempt. Includes a notable data-inventory/documentation requirement not found in most other states' laws. Minnesota's HIPAA carve-outs are data-level only, not a whole-entity exemption. Its GLBA exemption is narrower than it looks: a data-level carve-out for GLBA-regulated data generally, plus a separate entity-level exemption limited to state/federally chartered banks and credit unions (and their financial-activity affiliates) — not GLBA-regulated financial institutions generally. There's no higher-education exemption — postsecondary institutions just get a delayed compliance date (Jul 31, 2029) rather than being exempt.

Minn. Stat. §§ 325M.10–325M.21Read statute →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual revenue, data volume, and data types.