Minnesota Consumer Data Privacy Act (MCDPA) Compliance: The Only Right to Question a Profiling Decision
Minnesota asks you a question no other state asks: why did your system reach that decision about this person, and what could they have done differently? The MCDPA is the only US privacy law that lets a consumer question the result of profiling, review the data behind it, and demand the decision be run again on corrected data. Obtainer finds where that person's data actually lives, compiles one reviewable manifest, drafts the response, and keeps the record on the 45-day clock.
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
In short
The Minnesota Consumer Data Privacy Act (MCDPA) took effect on July 31, 2025, and it is the most profiling-focused of the comprehensive US state privacy laws. It applies to a business that operates in Minnesota or targets Minnesota residents and either controls or processes the personal data of 100,000 or more Minnesota consumers in a calendar year, excluding data processed only to complete a payment transaction, or controls or processes the data of 25,000 or more consumers while deriving more than 25 percent of gross revenue from selling personal data. Small businesses as defined by the US Small Business Administration are exempt, though they still may not sell sensitive data without consent. Minnesota consumers get the familiar rights to confirm and access, correct, delete, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects. Two rights go further than any other state. First, under Minn. Stat. 325M.14 a consumer subject to profiling may question the result, be informed of the reason the profiling produced that decision, be told what actions they might have taken to secure a different decision, review the personal data used in the profiling, and, where that data was inaccurate, have it corrected and the decision reevaluated on the corrected data. No other US state privacy law grants that. Second, a consumer may obtain a list of the specific third parties to which you disclosed their personal data, and if you do not keep that record on a per-consumer basis you must instead provide a list of the specific third parties you disclosed any consumer personal data to. Minnesota also imposes a structural duty most states skip: you must document and maintain a description of the policies and procedures you adopted to comply, including the contact information of your chief privacy officer or the person responsible for privacy, and conduct documented assessments for higher-risk processing such as targeted advertising, sales, and profiling. You respond to a request within 45 days, extendable once by another 45 when reasonably necessary if you notify the consumer inside the first window, and you must run a conspicuous appeal process, answering an appeal within 45 days with a 60-day extension available. The Minnesota Attorney General enforces the law exclusively; there is no private right of action. Civil penalties reach $7,500 per violation, and the 30-day cure period expired on January 31, 2026, so the attorney general can now sue without giving you a warning first. Obtainer covers the operational half of all of that: intake, discovery of where the person's data lives, a source-system manifest, a drafted deadline-safe response, 45-day tracking, and a timestamped record of what was searched, found, reviewed, redacted, and sent. Nothing is disclosed or erased automatically; a human reviews and approves. Obtainer helps you comply. It is not legal advice, so explaining a profiling decision and deciding what to disclose stay with your team. Self-serve from $49/mo.
Why it fits
Companies reaching 100,000 Minnesota consumers, or 25,000 while making more than a quarter of revenue from selling data, especially any business that scores, ranks, prices, or screens people automatically and now has to explain those decisions on request.
The only state where a person can question a decision your model made
Minnesota Statute 325M.14 gives a consumer subject to profiling the right to ask why the profiling produced that result, what they could have done to get a different one, and to review the personal data used in it. If that data was wrong, they can have it corrected and the decision reevaluated. Answering that means knowing exactly which records fed the decision, which is a discovery problem before it is a legal one. Obtainer maps where the person's data lives across your systems so the explanation rests on the actual inputs, not a guess.
A list of the specific third parties, not a category list
Most state laws let you answer a disclosure question with categories of recipients. Minnesota and Oregon do not. A Minnesota consumer can ask for the specific third parties you disclosed their personal data to, and if you do not track it per consumer you must hand over the list of specific third parties you shared any consumer data with instead. That second option is usually the more uncomfortable one, which is a good reason to keep per-request records of where data went.
No cure period since January 31, 2026
Minnesota gave controllers a 30-day right to cure for the first six months, and it expired on January 31, 2026. The attorney general no longer has to warn you before bringing an action, and penalties run to $7,500 per violation. Combined with the duty to document your compliance policies and name a responsible privacy contact, Minnesota rewards teams that can show a consistent, evidenced process rather than a scramble per request.
More use cases
Related features
Questions
Common questions about this
Who has to comply with the Minnesota Consumer Data Privacy Act?
A business that conducts business in Minnesota or produces products or services targeted to Minnesota residents and, during a calendar year, either controls or processes the personal data of 100,000 or more Minnesota consumers, excluding data processed solely to complete a payment transaction, or controls or processes the data of 25,000 or more consumers while deriving over 25 percent of its gross revenue from the sale of personal data. Small businesses as defined by the US Small Business Administration are exempt, but they still cannot sell sensitive data without the consumer's consent.
What is the right to question profiling under Minnesota law?
It is the MCDPA's signature right and no other US state grants it. When a consumer is subject to profiling in furtherance of a decision that produces a legal or similarly significant effect, they may question the result, be informed of the reason the profiling produced that decision, be told what actions they could have taken to secure a different decision, and review the personal data used. If that data turns out to be inaccurate, they can have it corrected and require you to reevaluate the decision based on the corrected data.
How long do I have to respond to a Minnesota data subject request?
Forty-five days from receipt, extendable once by another 45 days when reasonably necessary given the extent or complexity of the request, provided you notify the consumer of the extension and the reason within the original 45 days. You must also offer a conspicuous appeal process for denials, and you have 45 days to answer an appeal, with a 60-day extension available on notice.
Does the MCDPA still have a cure period?
No. The MCDPA included a 30-day right to cure that expired on January 31, 2026. Since then the Minnesota Attorney General may bring an enforcement action without first giving written notice or an opportunity to fix the problem. Minnesota now sits with Colorado, Connecticut, Delaware, Montana, and New Jersey in the group of states whose cure windows have closed.
What are the penalties under the Minnesota Consumer Data Privacy Act?
Civil penalties reach $7,500 per violation, plus injunctive relief. The Minnesota Attorney General has exclusive enforcement authority and there is no private right of action, so consumers cannot sue you directly. Because the cure period expired on January 31, 2026, there is no guaranteed warning before an action, which puts more weight on being able to show a documented, repeatable request process.
What is the Minnesota data inventory requirement?
Controllers must document and maintain a description of the policies and procedures they adopted to comply with the MCDPA, including the name and contact information of the chief privacy officer or other individual responsible for privacy and data security. You also have to conduct and document assessments for higher-risk processing such as targeted advertising, the sale of personal data, and profiling. It is one of the few state laws that makes written compliance documentation an obligation rather than good practice.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.