Minnesota's Privacy Law Gives Consumers a Right No Other State Grants
Most state privacy laws let a consumer ask what categories of data you've sold, and to what type of company. Minnesota's law goes further. A Minnesota consumer can ask for the specific list of third parties you've actually sold their data to, by name. That's a meaningfully different obligation, and it's one your store needs to actually be able to produce an answer to, not just describe in general terms.
Who the Minnesota Consumer Data Privacy Act Applies To
The threshold looks familiar at first: 100,000 or more Minnesota consumers processed annually triggers the law. But the secondary path differs from most of its peers. Minnesota's law applies to businesses processing data for 25,000 or more consumers while deriving 25% or more of gross revenue from the sale of personal data, a notably lower bar than the 50% threshold used in Virginia, Colorado, Kentucky, and most other comparable states.
The Rights Minnesota Grants
Consumers get the standard core set: access, correction, deletion, data portability, and opt-out of targeted advertising, sale, and profiling. Then Minnesota adds one more, and it's the one worth paying attention to: the right to obtain a list of the specific third parties, not just categories, that a business has sold or shared the consumer's personal data with.
If your store works with data brokers, ad networks, or any third party you share customer data with for compensation, you need to actually be able to name them if a Minnesota consumer asks. A vague answer or a policy that only lists general categories doesn't satisfy this right.
Sensitive Data, and One Unusual Inclusion
Sensitive data requires opt-in consent before processing, consistent with most comprehensive state laws. Minnesota's definition of sensitive data explicitly includes citizenship and immigration status, a category not every state's law names specifically. If your store collects any information touching on this, it's worth double-checking your consent flow covers it.
The Cure Period Already Ended
Minnesota gave businesses a temporary cure period after the law took effect, but that window closed on January 31, 2026. If you're checking Minnesota compliance today, there's no grace period left to rely on. Enforcement can proceed without a warning notice first.
Effective Date and Enforcement
The Minnesota Consumer Data Privacy Act took effect July 31, 2025. The Minnesota Attorney General enforces the law exclusively; there is no private right of action. Civil penalties can reach up to $7,500 per violation.
What This Means Practically
If your store has ever sold or shared customer data with an ad platform, analytics provider, or any third party for compensation, and you serve Minnesota customers, it's worth actually documenting who those parties are now, rather than waiting for a request to force the question. A generic "we may share data with our partners" line in a privacy policy doesn't satisfy this specific right if a real request comes in.
Check Your Minnesota Exposure
All information in this article is sourced from Minnesota Statutes § 325M.10 through § 325M.21 and the Minnesota Attorney General's published guidance. Regulens is informational only and this article is not legal advice. Speak to a licensed privacy attorney about your specific compliance situation.
Regulens tracks Minnesota as part of its ongoing state-by-state privacy coverage. Your store's readiness is calculated based on your actual inputs and current policy documents.
Free to check, takes three minutes, no credit card needed. Not legal advice. Informational only.
Check your store's Minnesota privacy readiness at getregulens.com
Further Reading
Does Your Store Need to Detect a Browser Signal? A State-by-State Guide
Some states require your store to automatically recognize a consumer's opt-out preference through their browser settings, with no click required on your site at all. Here's exactly which states require it.
Four More States Are About to Get Privacy Laws — Here's Your Advance Notice
Alabama, Oklahoma, Louisiana, and Vermont have all signed comprehensive privacy laws into effect between 2027 and 2028. None are enforceable yet, but each is worth understanding well before its clock starts.