iQ Cookie  State Law Series

State 12 of 25 · Minnesota

Cookie & Privacy Law in Minnesota

Published August 2026
Law in effect
Cure period expired Jan 31, 2026

Educational purposes only — not legal advice. This guide is intended to help you understand Minnesota’s data privacy law as it relates to cookie consent and website compliance. Laws change, and your specific situation may vary. Always consult a qualified legal professional before making compliance decisions. iQ Cookie is a technology tool, not a law firm.

LAW
MCDPA
Minn. Stat. 325M
SIGNED
May 24, 2024
Effective Jul 31, 2025
CURE PERIOD
Expired
Jan 31, 2026
STATE RANK
#18
To enact a law

The short version

Minnesota took effect July 31, 2025 and immediately stood out from the Virginia-model crowd with two genuinely novel provisions: a consumer right to question and get an explanation for automated profiling decisions, and a mandatory internal data inventory requirement — the first state to make data mapping a strict legal obligation rather than just a best practice. Its 90-day cure period already expired on January 31, 2026, so enforcement is now immediate.

Minnesota does not have a separate cookie law. Cookie compliance flows from the MCDPA itself — its opt-out, profiling, and sensitive-data rules apply directly to cookies and tracking technology.

Minnesota Legislature — Official Text
Minnesota Consumer Data Privacy Act — Minn. Stat. § 325M.01 et seq.

Who does it apply to?

The MCDPA covers businesses that conduct business in Minnesota or target Minnesota residents, and meet at least one of these thresholds:

THRESHOLD 1

Controls or processes personal data of 100,000 or more Minnesota consumers during a calendar year.

THRESHOLD 2

Controls or processes data of 25,000 or more consumers AND derives more than 25% of gross revenue from selling personal data.

GLBA and HIPAA-regulated data carry their usual exemptions. Check current statute text for nonprofit treatment, which is narrower than some peer states.

Consumer rights

Minnesota residents whose data is covered by the MCDPA have an unusually rich set of rights:

Access
Confirm processing and receive a copy of their data
Correct
Fix inaccurate personal data
Delete
Request removal of personal data
Portability
Receive data in a usable, portable format
Know recipients
Get a list of third parties data was disclosed to
Question profiling
Review the data used and request reevaluation if inaccurate

Businesses must respond within 45 days, extendable once by 45 more. There is no private right of action — only the Attorney General can enforce.

What makes Minnesota different

A right to explanation for profiling — a first among these states. Consumers can question a "consequential" profiling decision, review the data behind it, and get a plain explanation of how the result was reached and what could change it. If inaccurate data drove the outcome, they can demand a reevaluation.

Mandatory internal data inventory. Minnesota is the first state to require an actual data map/inventory as a strict legal obligation, not just a best practice recommendation. If you have not documented what personal data you hold and where, that is now a compliance gap on its own.

The cure period is already gone. Minnesota’s 90-day cure window expired January 31, 2026. The Attorney General can now pursue enforcement immediately, with no advance notice-and-fix requirement.

GPC is mandatory, with real technical requirements. The opt-out mechanism must be consumer-friendly, non-default (no dark patterns), and capable of reasonably determining Minnesota residency — a higher bar than "just recognize the signal."

Sensitive data access requests are limited by design. If a consumer requests access to data like Social Security numbers or biometric identifiers, you only have to confirm it was collected — not hand over the actual values. This protects consumers from a new exposure risk created by the access right itself.

Sensitive data & children

Processing sensitive data requires opt-in consent before any collection begins. Sensitive data includes:

Racial / ethnic origin
Religious beliefs
Health diagnosis
Sexual orientation
Citizenship / immigration status
Biometric data
Children’s data (under 13)

For known children under 13, their data is treated as sensitive across the board, requiring COPPA-aligned parental consent. For ages 13–16, opt-in consent is required specifically before targeted advertising or selling that person’s data.

What this means for your cookies

Cookie / data typeRequirementWhat to do
Sensitive data cookies (health, biometric)Opt-in requiredGate these behind affirmative consent before they fire.
Targeted advertising cookiesOpt-out requiredProvide a clear opt-out mechanism for sale and targeted ads.
GPC / opt-out signalsRequired, no dark patternsConfirm your tool honors GPC by default with no manipulative friction added.
Profiling / decisioning cookiesExplainability requiredIf cookies feed consequential automated decisions, be ready to explain and reevaluate on request.
Any cookies — users 13–16Opt-in requiredNo targeted-ad or sale cookies without consent for known minors.

Enforcement

$7,500
Max penalty per violation
Expired
Cure period ended Jan 31, 2026
AG only
No private right of action

The Minnesota Attorney General has exclusive enforcement authority, with penalties up to $7,500 per violation. With the cure period already expired, businesses that have not yet closed compliance gaps — especially around the data inventory requirement and profiling explanation right — are exposed to enforcement action without advance warning.

Your action checklist

With no cure period left, these need to be handled now, not eventually:

1

Check your thresholds. Do you process data on 100,000+ Minnesota consumers, or 25,000+ while earning over a quarter of your revenue from data sales? If yes, you are in scope.

2

Build your data inventory. Document what personal data you collect, where it lives, and who touches it. This is now a strict legal requirement in Minnesota, not just good practice.

3

Prepare a profiling explanation process. If you use automated decisioning that materially affects consumers, be ready to explain the logic and reevaluate on request.

4

Verify GPC recognition has no dark patterns. The mechanism must be genuinely consumer-friendly and default-on — test it end to end.

5

Audit sensitive data cookies. Health and biometric data need opt-in consent before collection.

6

Update your privacy policy. Cover data categories, purposes, third-party recipients, and how to exercise every right — including the profiling question-and-explain right.

7

Review vendor contracts. Any processor handling Minnesota resident data must be covered by a written agreement specifying processing instructions and confidentiality obligations.

Not sure where your site stands with Minnesota?

iQ Cookie scans your site for compliance gaps and deploys a lightweight US-built consent banner.

iQ Cookie State Law Series  ·  Guide 12 of 25  ·  Next: Montana →