Privacy
Minnesota Consumer Data Privacy Act
The law applies to entities that conduct business in Minnesota or target products or services to Minnesota residents and that, during a calendar year, control or process personal data of 100,000 consumers or more, not counting data processed solely to complete a payment transaction. It also applies to entities that derive over 25 percent of gross revenue from the sale of personal data and process or control personal data of 25,000 consumers or more. Small businesses as defined by the U.S. Small Business Administration are excluded, except that § 325M.17 bars them from selling a consumer's sensitive data without the consumer's prior consent.
What the website needs
- A covered controller's privacy notice must list the categories of personal data processed, the purposes of processing, the consumer's rights and how to exercise and appeal them, the categories of personal data sold or shared with third parties, the categories of third parties that receive it, the controller's contact information including an active email address or other online contact method, a description of its data retention policies, and the date the notice was last updated.
- The privacy notice must be posted online through a conspicuous hyperlink that uses the word "privacy" on the controller's website home page, or on a mobile application's app store or download page.
- A controller that sells personal data, processes it for targeted advertising, or uses profiling that produces legal or similarly significant effects must disclose that processing in the privacy notice and must also provide a clear and conspicuous opt-out method outside the notice, which the statute says may include a hyperlink labeled "Your Opt-Out Rights" or "Your Privacy Rights."
- A controller may not process sensitive data without the consumer's consent, and for a known child consent must come from a parent or guardian in line with the Children's Online Privacy Protection Act.


