# Minnesota — US state consumer data privacy laws: applicability thresholds by state For Minnesota, law name and abbreviation is Minnesota Consumer Data Privacy Act (MCDPA); effective date is July 31, 2025; consumer volume threshold is during a calendar year, controls or processes personal data of 100,000 consumers or more, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; revenue-from-data-sales threshold is derives over 25 percent of gross revenue from the sale of personal data and processes or controls personal data of 25,000 consumers or more; threshold combination logic is OR — satisfies one or more of the following thresholds, recorded from its source on 2026-08-12. - **State:** Minnesota _(our reading, not quoted from the source)_ - **Law name and abbreviation:** Minnesota Consumer Data Privacy Act (MCDPA) - **Effective date:** July 31, 2025 _(verified: appears in the quote below)_ - **Consumer volume threshold:** during a calendar year, controls or processes personal data of 100,000 consumers or more, excluding personal data controlled or processed solely for the purpose of completing a payment transaction _(verified: appears in the quote below)_ - **Revenue-from-data-sales threshold:** derives over 25 percent of gross revenue from the sale of personal data and processes or controls personal data of 25,000 consumers or more _(verified: appears in the quote below)_ - **Threshold combination logic:** OR — satisfies one or more of the following thresholds _(verified: appears in the quote below)_ - **Key exemptions:** State and local government entities; HIPAA-covered entities; GLBA-regulated financial institutions; nonprofit organizations; institutions of higher education (postsecondary institutions regulated by the Office of Higher Education not required to comply until July 31, 2029) - **Enforcement mechanism:** Attorney General; no private right of action - **Statute citation:** Minn. Stat. §§ 325M.10 to 325M.21 - **Notes:** Minnesota uses a 25% revenue threshold (like Colorado and Oregon), lower than the 50% in Virginia-model states. Minnesota has stronger data minimization rules than most states. Postsecondary institutions regulated by the Office of Higher Education have a delayed compliance date of July 31, 2029. _(verified: appears in the quote below)_ ## What the source says > This section, as added by Laws 2024, chapter 121, article 5, section 3, is effective July 31, 2025, except that postsecondary institutions regulated by the Office of Higher Education are not required to comply until July 31, 2029. Laws 2024, chapter 121, article 5, section 14. 325M.12 SCOPE; EXCLUSIONS. § Subdivision 1. Scope. (a) Sections 325M.10 to 325M.21 apply to legal entities that conduct business in Minnesota or produce products or services that are targeted to residents of Minnesota, and that satisfy one or more of the following thresholds: (1) during a calendar year, controls or processes personal data of 100,000 consumers or more, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or (2) derives over 25 percent of gross revenue from the sale of personal data and processes or controls personal data of 25,000 consumers or more. ## Source - https://www.revisor.mn.gov/statutes/cite/325M/full Last verified: 2026-08-12. Review by: 2026-11-10. Part of [US state consumer data privacy laws: applicability thresholds by state](https://referencesource.org/state-data-privacy-applicability-thresholds/).