Back to the hub

Does Minnesota's Consumer Data Privacy Act apply to your business?

Minnesota's Consumer Data Privacy Act applies to businesses that operate in Minnesota or target its residents and, in a calendar year, control or process personal data of at least 100,000 consumers, or at least 25,000 consumers while deriving over 25 percent of gross revenue from selling personal data. It took effect July 31, 2025.

Applies to: Businesses that operate in Minnesota or target Minnesota residents and meet either the 100,000-consumer threshold or the 25,000-consumer-plus-25%-data-sales threshold, and that are not otherwise excluded.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

Minnesota's privacy law took effect on July 31, 2025, and its applicability test looks familiar next to Colorado and Oregon, with one number that is easy to miss. Minnesota counts people, not dollars, and the second trigger uses a 25 percent data-sale figure rather than the 50 percent most states use. If you are trying to work out whether it reaches your business, start with how many Minnesotans' data you handle.

Who the Minnesota Consumer Data Privacy Act covers

Under Minn. Stat. 325M.12, the act applies to a legal entity that conducts business in Minnesota, or produces products or services targeted to Minnesota residents, and that in a calendar year either controls or processes the personal data of at least 100,000 consumers, or controls or processes the personal data of at least 25,000 consumers while deriving over 25 percent of gross revenue from the sale of personal data. Data processed solely to complete a payment transaction does not count toward the 100,000 figure. A consumer here means a Minnesota resident acting for a personal, family, or household purpose, so business contacts and your own employees fall outside the count.

The 25 percent trigger that catches people out

Most product companies reach coverage through the 100,000 figure. The second prong is where Minnesota differs from Virginia-style laws. If more than a quarter, not half, of your gross revenue comes from selling personal data, the bar drops to 25,000 consumers. A business with a modest audience but a data-sales revenue line can cross into scope on this prong even though it would sit outside Virginia or Iowa. If you never sell data in the statutory sense, this second prong rarely applies.

Who is carved out

Section 325M.12 excludes whole categories: government entities, federally recognized tribes, HIPAA-regulated health data, GLBA financial institutions and data, FCRA activity, banks and credit unions, insurance companies, and air carriers, among others. It also carves out a small business as defined by the US Small Business Administration, but only partly. A small business is still subject to Section 325M.17, which bars it from selling a consumer's sensitive data without consent. Compare the thresholds with the Oregon Consumer Privacy Act, which uses the same 25 percent figure, and the Colorado Privacy Act. The US state privacy laws hub lines the states up side by side.

Next step

Because Minnesota counts people and uses a lower data-sale trigger, a real count of your Minnesota users usually settles the question. The free 2-minute Obligation Scan runs the 325M.12 thresholds against your business and flags the notice, opt-out, consent, and profiling duties that follow, so you spend your time on the obligations rather than the arithmetic.

Compliance checklist

  • Count the Minnesota consumers whose personal data you controlled or processed over the calendar year, excluding data used only to complete a payment transaction, against the 100,000 and 25,000 figures.
  • If you are near 25,000, work out whether over 25 percent of your gross revenue comes from selling personal data, since that lower bar then applies.
  • Check the Section 325M.12 exclusions before assuming you are in scope: government entities, HIPAA and GLBA data, small businesses, and others are carved out.
  • If covered, publish a privacy notice and honor consumer rights to access, correct, delete, port, and opt out of sale, targeted advertising, and profiling.
  • Get consent before processing sensitive data, and note Minnesota's distinctive right for a consumer to question the result of profiling.

Sources

Last verified: 2026-07-23

Informational, not legal advice.