MNCDPA · Opt-out model

Minnesota Privacy Law (MNCDPA): Compliance Guide

The Minnesota Consumer Data Privacy Act (HF 4757), effective July 31, 2025, is the only US state law that gives consumers an explicit right to question automated decisions — a first step toward algorithmic accountability in American privacy law. Beyond that signature right, it delivers the full standard package, requires Global Privacy Control from its very first day, and keeps a 30-day cure period that sunsets January 31, 2026.

Effective
July 31, 2025
GPC / universal opt-out
Required since July 31, 2025
Required link text
Your Privacy Choices
Handle MNCDPA compliance free

Last reviewed July 19, 2026 · Minnesota Consumer Data Privacy Act (HF 4757)

Applicability

Who must comply with the MNCDPA

The Minnesota Consumer Data Privacy Act applies to businesses that meet the following criteria:

  • Controls or processes the personal data of 100,000 or more Minnesota consumers, or
  • Controls or processes the personal data of 25,000 or more Minnesota consumers and derives 50% or more of gross revenue from the sale of personal data

Consumer rights

What Minnesota consumers can demand

  • Right to access personal data
  • Right to correct inaccuracies
  • Right to delete personal data
  • Right to data portability
  • Right to opt out of the sale of personal data, targeted advertising, and profiling
  • Right to question the result of automated decisions — unique to Minnesota

Opt-out mechanics

Minnesota opt-out & GPC requirements

Like every US state privacy law, the MNCDPA uses an opt-out model: you do not need a GDPR-style cookie banner, but you must provide a clear and conspicuous opt-out link. The accepted text for Minnesota is Your Privacy Choices.

Global Privacy Control: Required since July 31, 2025

Minnesota requires covered businesses to honor universal opt-out mechanisms such as Global Privacy Control. The requirement has been in force since July 31, 2025 — the law's first day.

Enforcement

MNCDPA penalties & enforcement

  • Up to $7,500 per violation

Cure period: 30-day cure period, available until January 31, 2026.

State quirks

What makes Minnesota different

Minnesota's signature is algorithmic accountability: consumers can question the result of automated decisions made about them, a right no other state statute grants in this form. Operationally, it is also demanding — universal opt-out signals were mandatory from day one with no phase-in period, and the 30-day cure period expires January 31, 2026, after which violations of up to $7,500 each carry immediate exposure. Thresholds are the standard 100,000 consumers, or 25,000 with 50% of revenue from data sales.

Right to question automated decisions

The only US state law giving consumers an explicit right to question the result of profiling and other automated decisions.

GPC from day one

Universal opt-out signals had to be honored from the law's effective date, July 31, 2025 — no phase-in.

Automation

How ConsentKit handles Minnesota

  • ConsentKit's widget is served from Cloudflare's edge and receives the visitor's US state server-side, so Minnesota visitors are identified before any consent UI renders — no client-side geo-lookup delay.
  • Minnesota visitors see a persistent Your Privacy Choices link — the exact statutory text — available to new and returning visitors alike.
  • Because Minnesota requires universal opt-out signals, ConsentKit automatically honors Global Privacy Control for Minnesota visitors: when the browser broadcasts GPC, the widget applies the opt-out and denies analytics and marketing categories with no click required.
  • Every opt-out is recorded server-side with a timestamp and jurisdiction metadata, reviewable and exportable (CSV) from the dashboard — the audit trail regulators ask for.
  • Google Consent Mode v2 stays in sync: analytics and advertising tags update the moment a Minnesota visitor makes a choice.

For Minnesota's automated-decision right, your privacy policy does the talking; ConsentKit handles the consent mechanics — GPC honoring from day one and recorded opt-outs.

FAQ

Minnesota MNCDPA FAQ

What is Minnesota's right to question automated decisions?

It is unique among US state privacy laws: consumers can question the result of profiling and other automated decisions made about them. Businesses covered by the MNCDPA need a process to receive and respond to those challenges — no other state statute grants this right in this form.

Does the MNCDPA apply to my business?

It applies if you control or process the personal data of 100,000 or more Minnesota consumers, or 25,000 or more while deriving 50% or more of gross revenue from selling personal data.

Is Global Privacy Control required in Minnesota?

Yes — from day one. Unlike states that phased in signal requirements, Minnesota's GPC obligation took effect with the law itself on July 31, 2025.

What are the penalties and cure period in Minnesota?

Violations carry up to $7,500 each. A 30-day cure period applies, but only until January 31, 2026 — after that date, enforcement proceeds without a grace window.

This guide is for informational purposes and is not legal advice. Work with qualified counsel to confirm your obligations under the MNCDPA.

Comply with Minnesota's MNCDPA — and the other 19 state laws

ConsentKit detects each visitor's state at the Cloudflare edge, renders the exact opt-out link their law requires, honors GPC automatically where mandated, and records every choice for your audit trail.