Minnesota Privacy Law (MNCDPA): Compliance Guide
The Minnesota Consumer Data Privacy Act (HF 4757), effective July 31, 2025, is the only US state law that gives consumers an explicit right to question automated decisions — a first step toward algorithmic accountability in American privacy law. Beyond that signature right, it delivers the full standard package, requires Global Privacy Control from its very first day, and keeps a 30-day cure period that sunsets January 31, 2026.
- Effective
- July 31, 2025
- GPC / universal opt-out
- Required since July 31, 2025
- Required link text
- “Your Privacy Choices”
Last reviewed July 19, 2026 · Minnesota Consumer Data Privacy Act (HF 4757)
Applicability
Who must comply with the MNCDPA
The Minnesota Consumer Data Privacy Act applies to businesses that meet the following criteria:
- Controls or processes the personal data of 100,000 or more Minnesota consumers, or
- Controls or processes the personal data of 25,000 or more Minnesota consumers and derives 50% or more of gross revenue from the sale of personal data
Consumer rights
What Minnesota consumers can demand
- Right to access personal data
- Right to correct inaccuracies
- Right to delete personal data
- Right to data portability
- Right to opt out of the sale of personal data, targeted advertising, and profiling
- Right to question the result of automated decisions — unique to Minnesota
Opt-out mechanics
Minnesota opt-out & GPC requirements
Like every US state privacy law, the MNCDPA uses an opt-out model: you do not need a GDPR-style cookie banner, but you must provide a clear and conspicuous opt-out link. The accepted text for Minnesota is “Your Privacy Choices”.
Global Privacy Control: Required since July 31, 2025
Minnesota requires covered businesses to honor universal opt-out mechanisms such as Global Privacy Control. The requirement has been in force since July 31, 2025 — the law's first day.
Enforcement
MNCDPA penalties & enforcement
- Up to $7,500 per violation
Cure period: 30-day cure period, available until January 31, 2026.
State quirks
What makes Minnesota different
Minnesota's signature is algorithmic accountability: consumers can question the result of automated decisions made about them, a right no other state statute grants in this form. Operationally, it is also demanding — universal opt-out signals were mandatory from day one with no phase-in period, and the 30-day cure period expires January 31, 2026, after which violations of up to $7,500 each carry immediate exposure. Thresholds are the standard 100,000 consumers, or 25,000 with 50% of revenue from data sales.
Right to question automated decisions
The only US state law giving consumers an explicit right to question the result of profiling and other automated decisions.
GPC from day one
Universal opt-out signals had to be honored from the law's effective date, July 31, 2025 — no phase-in.
Automation
How ConsentKit handles Minnesota
- ConsentKit's widget is served from Cloudflare's edge and receives the visitor's US state server-side, so Minnesota visitors are identified before any consent UI renders — no client-side geo-lookup delay.
- Minnesota visitors see a persistent “Your Privacy Choices” link — the exact statutory text — available to new and returning visitors alike.
- Because Minnesota requires universal opt-out signals, ConsentKit automatically honors Global Privacy Control for Minnesota visitors: when the browser broadcasts GPC, the widget applies the opt-out and denies analytics and marketing categories with no click required.
- Every opt-out is recorded server-side with a timestamp and jurisdiction metadata, reviewable and exportable (CSV) from the dashboard — the audit trail regulators ask for.
- Google Consent Mode v2 stays in sync: analytics and advertising tags update the moment a Minnesota visitor makes a choice.
For Minnesota's automated-decision right, your privacy policy does the talking; ConsentKit handles the consent mechanics — GPC honoring from day one and recorded opt-outs.
FAQ
Minnesota MNCDPA FAQ
What is Minnesota's right to question automated decisions?
It is unique among US state privacy laws: consumers can question the result of profiling and other automated decisions made about them. Businesses covered by the MNCDPA need a process to receive and respond to those challenges — no other state statute grants this right in this form.
Does the MNCDPA apply to my business?
It applies if you control or process the personal data of 100,000 or more Minnesota consumers, or 25,000 or more while deriving 50% or more of gross revenue from selling personal data.
Is Global Privacy Control required in Minnesota?
Yes — from day one. Unlike states that phased in signal requirements, Minnesota's GPC obligation took effect with the law itself on July 31, 2025.
What are the penalties and cure period in Minnesota?
Violations carry up to $7,500 each. A 30-day cure period applies, but only until January 31, 2026 — after that date, enforcement proceeds without a grace window.
This guide is for informational purposes and is not legal advice. Work with qualified counsel to confirm your obligations under the MNCDPA.
Comply with Minnesota's MNCDPA — and the other 19 state laws
ConsentKit detects each visitor's state at the Cloudflare edge, renders the exact opt-out link their law requires, honors GPC automatically where mandated, and records every choice for your audit trail.