iQ Cookie  State Law Series

State 13 of 25 · Montana

Cookie & Privacy Law in Montana

Published August 2026
Law in effect
Amended by SB 297, effective Oct 1, 2025

Educational purposes only — not legal advice. This guide is intended to help you understand Montana’s data privacy law as it relates to cookie consent and website compliance. Laws change, and your specific situation may vary. Always consult a qualified legal professional before making compliance decisions. iQ Cookie is a technology tool, not a law firm.

LAW
MCDPA
Mont. Code Ann. 30-14-2801
SIGNED
May 19, 2023
Effective Oct 1, 2024
CURE PERIOD
None
Removed by SB 297
STATE RANK
#7
To enact a law

The short version

Montana’s original MCDPA took effect October 1, 2024, but the version in force today looks meaningfully different. Senate Bill 297, signed May 8, 2025 and effective October 1, 2025, lowered the applicability thresholds, eliminated the 60-day cure period entirely, and layered on new minors’ protections and transparency requirements. If your compliance notes are still describing the 2024 original, they are out of date.

Montana does not have a separate cookie law. Cookie compliance flows from the MCDPA itself — its opt-out, sale, and targeted-advertising rules apply directly to cookies and tracking technology.

Montana Legislature — Official Text
Montana Consumer Data Privacy Act — Mont. Code Ann. § 30-14-2801 et seq.

Who does it apply to?

Since SB 297 took effect, the MCDPA covers businesses that conduct business in Montana or target Montana residents, and meet at least one of these lowered thresholds:

THRESHOLD 1

Controls or processes personal data of 25,000 or more Montana consumers during a calendar year — down from 50,000 under the original 2024 law.

THRESHOLD 2

Controls or processes data of 15,000 or more consumers AND derives more than 25% of gross revenue from selling personal data.

Government entities, higher-education institutions, HIPAA-covered entities, banks, credit unions, and insurers are exempt. Nonprofits are exempt only for fraud detection/prevention in an insurance context — a narrower carve-out than some peer states.

Consumer rights

Montana residents whose data is covered by the MCDPA can:

Access
Confirm processing and receive a copy of their data
Correct
Fix inaccurate personal data
Delete
Request removal of personal data
Portability
Receive data in a usable, portable format
Opt out of sale
Stop the sale of personal data to third parties
Opt out of profiling
Stop targeted ads and profiling with legal/significant effects

Businesses must respond within 45 days, extendable once by 45 more. There is no private right of action — only the Attorney General can enforce.

What makes Montana different

The cure period is gone — not sunset, removed. SB 297 struck the original law’s guaranteed 60-day cure window outright. Unlike states where cure periods expired on a schedule, Montana’s legislature eliminated it by amendment, and enforcement can now begin without any notice-and-fix opportunity.

Thresholds moved the wrong direction for covered businesses. Most states that adjust thresholds raise them over time. Montana cut its consumer-count threshold in half (50,000 to 25,000) and its revenue-based threshold from 25,000 to 15,000 consumers, pulling more mid-sized businesses into scope.

A new duty of care for minors. SB 297 added an explicit duty of reasonable care for online services accessible to minors, requiring businesses to avoid heightened risks of harm to that age group — a standard that goes beyond the consent-only approach most peer states use.

Privacy notices got a lot more specific. Notices must now show a last-updated date, be available in every language the business operates in, include a conspicuous "privacy" link on the homepage and in app stores, and meet disability accessibility standards.

Access requests exclude the most sensitive identifiers. As amended, controllers no longer have to disclose Social Security numbers, government ID numbers, or financial account numbers in response to an access request — only confirm they were collected.

Sensitive data & children

Processing sensitive data requires opt-in consent before any collection begins. Sensitive data includes:

Racial / ethnic origin
Religious beliefs
Mental / physical health conditions
Sexual orientation
Citizenship / immigration status
Genetic / biometric data
Precise geolocation (1,750 ft)
Children’s data (under 13)

Data from known children under 13 is sensitive by default and follows federal COPPA parental-consent standards. For ages 13–15, the minor’s own opt-in consent is required before processing for sale or targeted advertising. SB 297’s duty-of-care provision layers on top of these consent rules.

What this means for your cookies

Cookie / data typeRequirementWhat to do
Sensitive data cookies (health, biometric, geolocation)Opt-in requiredGate these behind affirmative consent before they fire.
Sale / targeted advertising cookiesOpt-out requiredProvide a clear opt-out mechanism outside your privacy notice itself.
GPC / opt-out signalsRequired since Jan 1, 2025Confirm your consent tool honors GPC automatically.
Profiling cookies (legal/significant effects)Opt-out requiredOffer an opt-out for profiling that materially affects consumers.
Any cookies — users 13–15Opt-in requiredNo sale or targeted-ad cookies without consent for known minors.

Enforcement

$7,500
Max penalty per violation, no overall cap
None
Cure period removed by SB 297
AG only
No private right of action

The Montana Attorney General has exclusive enforcement authority and can now seek civil investigative demands for data protection assessments during investigations. With no cure period and no cap on total penalties, businesses that fall below the new, lower thresholds should not assume they are still exempt — and those already in scope should not expect advance warning before an enforcement action.

Your action checklist

With no cure period and lowered thresholds, these need to be handled now:

1

Re-check your thresholds. If you were exempt under the original 50,000-consumer bar, run the numbers again against the new 25,000/15,000 figures — you may be in scope now.

2

Confirm GPC recognition is live. Required since January 1, 2025 for controllers that sell data or process for targeted advertising.

3

Update your privacy notice for SB 297. Add a last-updated date, a conspicuous homepage "privacy" link, and confirm multi-language and accessibility coverage.

4

Move your opt-out link outside the privacy notice. Sale and targeted-advertising opt-outs now need a clear method separate from the notice text itself.

5

Review services used by minors for the new duty-of-care standard. Consider whether design choices create heightened risks of harm to users under 18.

6

Audit sensitive data cookies. Health, biometric, and precise geolocation data need opt-in consent before collection.

7

Review vendor contracts. Any processor handling Montana resident data must be covered by a written agreement specifying processing instructions and confidentiality obligations.

Not sure where your site stands with Montana?

iQ Cookie scans your site for compliance gaps and deploys a lightweight US-built consent banner.

iQ Cookie State Law Series  ·  Guide 13 of 25  ·  Next: Nebraska →