USPrivacyAtlasState Privacy & Data Security Law Matcher

State Guide

Minnesota Privacy & Data Security Laws

Every statute below can apply to a business handling Minnesota residents' data, depending on your revenue, the number of Minnesota consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

Applies at 100,000+ Minnesota consumers (excluding payment-only data), or 25,000+ if 25%+ of revenue comes from selling personal data — plus a separate small-business exemption layered on top based on SBA size standards. Only insurance-fraud-prevention nonprofits are exempt; nonprofits generally are NOT exempt. Includes a notable data-inventory/documentation requirement not found in most other states' laws.

Minn. Stat. §§ 325M.10–325M.21Read statute →

Data Security & Breach Notification · 1

Varies by state
Minnesota data breach notification law
MN Breach Notification
Verify details

Requires notifying affected residents (and often the state AG/regulator) after a breach of unencrypted personal information such as SSNs, driver's license/state ID numbers, or financial account numbers. Applies regardless of company size whenever you hold covered personal information about a resident of this state.

State breach-notification statute (citation pending verification)

Genetic Privacy · 1

Regulates direct-to-consumer genetic testing companies and/or genetic data generally — typically requiring express consent before collecting, using, or disclosing genetic data, and consent (or destruction) requirements for biological samples.

Minn. Stat. § 325F.995Read statute →