Minnesota Consumer Data Privacy Act (MNCDPA)
A practical compliance guide for website owners. Learn what Minnesota's privacy law requires and how to implement it on your site.
Who Must Comply
Conducts business in Minnesota or targets Minnesota residents AND controls/processes personal data of 100K+ consumers, OR controls/processes data of 25K+ consumers and derives 25%+ of gross revenue from selling personal data
What Your Website Must Do
| Requirement | Status |
|---|---|
| Cookie consent banner | Recommended |
| Do Not Sell link | Required |
| Do Not Share link | Required |
| Honor GPC browser signals | Required |
| Universal opt-out mechanism | Required |
| Sensitive data opt-in consent | Required |
Checked against the MNCDPA on August 29, 2026. Read the source This is a summary, not legal advice.
Required Links & Notices
The MNCDPA requires the following links or notices to be visible on your website:
- 1Do Not Sell or Share My Personal Data
- 2Privacy Policy
Enforcement & Penalties
Key Things to Know
The Minnesota Consumer Data Privacy Act (MNCDPA) has applied in Minnesota since July 31, 2025.
Who it covers: Conducts business in Minnesota or targets Minnesota residents AND controls/processes personal data of 100K+ consumers, OR controls/processes data of 25K+ consumers and derives 25%+ of gross revenue from selling personal data.
Do Not Sell and opt-out rights: residents may opt out of the sale of their personal data and opt out of targeted advertising. MNCDPA expects the choice to be reachable from your site under the heading “Do Not Sell or Share My Personal Data”, and you may not degrade the service of someone who exercises it.
Global Privacy Control: MNCDPA requires you to honour a universal opt-out mechanism sent by the visitor’s browser. A GPC signal has to be treated as the opt-out itself — not as a request to show someone a banner — and it applies to that browser without any further action from the person.
Cookie banner: MNCDPA is an opt-out law, so it does not require the opt-in banner the GDPR does. What it does require is that the tracking you run for advertising can be switched off on request, which in practice means a preference control that actually blocks tags rather than a notice that only records a click. Sensitive data is the exception: that needs consent before you process it.
Enforcement: $7,500 per violation. 30-day cure period (sunset July 2026). Enforced by the Minnesota Attorney General.
How to Configure LegalBanner for MNCDPA
- 1
Create your site
Sign up for free and add your website domain in the dashboard.
- 2
Set consent mode to "Opt-out"
In Settings, select the consent mode that matches Minnesota's requirements.
- 3
Install the snippet
Add the one-line script tag to your website. The banner, opt-out links, and GPC support are automatic.
- 4
Generate your Privacy Policy
Use the built-in policy wizard to generate a MNCDPA-compliant privacy policy.
Set up MNCDPA compliance in 5 minutes
LegalBanner handles Minnesota privacy requirements automatically — cookie banner, opt-out links, and GPC support included.
Frequently Asked Questions
When does the Minnesota MNCDPA take effect?
The MNCDPA takes effect July 31, 2025.
Does Minnesota cover data 'sharing'?
Yes. Minnesota covers both sale and sharing of personal data, providing broader consumer protections than states that only cover 'sale.'
What profiling protections does Minnesota provide?
Consumers can opt out of profiling that produces legal or similarly significant effects. Businesses must provide notice when engaging in such profiling and offer an opt-out mechanism.
Does Minnesota require honoring GPC signals?
The MNCDPA does not explicitly require GPC support, but implementing it is recommended best practice.
What are the penalties for MNCDPA violations?
Up to $7,500 per violation. The 30-day cure period sunsets in July 2026, after which the AG can take direct enforcement action.