Minnesota Consumer Data Privacy Act
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Chief Privacy Officer Governance - Minnesota CDPA
Designate Chief Privacy Officer (CPO) per **MINNESOTA-UNIQUE** Section 325O.06 requirement among US state privacy laws. Controllers processing personal data of 100,000 or more consumers MUST designate a Chief Privacy Officer or equivalent senior officer responsible for: (a) coordinating overall compliance with Chapter 325O; (b) privacy programme oversight including policies + procedures + training; (c) responding to consumer requests + appeals; (d) Minnesota Attorney General liaison; (e) privacy training programme for workforce including initial training within 90 days of hire + annual refresh; (f) maintaining data inventory of categories + purposes + sources + retention; (g) DPIA programme oversight; (h) breach response coordination. CPO must have sufficient seniority + authority + independence + resources + reporting line to senior management. CPO contact information published in priva
- **MINNESOTA-UNIQUE** Chief Privacy Officer designation letter + seniority + authority + independence + reporting line + budget per Section 325O.06
- CPO contact published in privacy notice
- Privacy training programme records (initial within 90 days + annual)
- Data inventory of categories + purposes + sources + retention maintained
- CPO-led DPIA programme oversight
- CPO breach response coordination role
- No CPO designated despite 100K consumer threshold (Section 325O.06 violation - **MINNESOTA-UNIQUE** requirement)
- CPO designated nominally without senior authority + budget + reporting line
- Privacy training not annual + not all-hands
- Data inventory not refreshed annually
Consumer Rights and AI Profiling Question - Minnesota CDPA
Provide statutory consumer rights under Section 325O.04 including MINNESOTA-UNIQUE rights. (1) Right to confirm processing + access + portable format; (2) Right to correct inaccuracies; (3) Right to delete; (4) **MINNESOTA-UNIQUE** Right to obtain a list of specific third parties to whom personal data has been disclosed (or categories where specifics impossible) - this third-party disclosure list right is unique among US state privacy laws; (5) Right to opt out of (a) sale (b) targeted advertising (c) profiling in furtherance of decisions producing legal or similarly significant effects; (6) Right to appeal denied requests with AG complaint referral; (7) **MINNESOTA-UNIQUE Right to Question Profiling Decisions** - if profiling produces legal or similarly significant effects consumer has right to (a) meaningful explanation of decision + general factors and contributions to outcome; (b) re
- Consumer rights register with 45-day SLA evidence
- **MINNESOTA-UNIQUE** list of third parties response capability evidence (specific third parties or categories where impossible)
- **MINNESOTA-UNIQUE** Right to Question Profiling workflow including meaningful explanation + data review + correction + retaking of decision without disputed data
- Algorithm explainability and human review pathway for profiling decisions producing legal or similarly significant effects
- Appeal mechanism with denial reasoning + AG complaint referral
- Authorised agent processing including GPC
- Authentication without new account creation
- List of third parties right not operationalised (Minnesota-unique requirement missed)
- Right to Question Profiling lacks explainability + retake capability (Minnesota-unique)
- Categories-only list of third parties when specifics possible
- Profile decision human review not documented
Data Privacy Assessment - Minnesota CDPA
Conduct Data Privacy Assessment (DPIA) under Section 325O.07 for high-risk processing activities. MANDATORY DPIA triggers: (a) processing of sensitive data; (b) processing for purposes of targeted advertising; (c) sale of personal data; (d) processing for profiling presenting reasonably foreseeable risk of (i) unfair or deceptive treatment of or unlawful disparate impact on consumers + (ii) financial physical or reputational injury + (iii) physical or other intrusion upon solitude or seclusion or private affairs + (iv) other substantial injury to consumers; (e) processing of consumer health data; (f) other processing presenting heightened risk of harm including AI/ML training (Minnesota-explicit). DPIA contents: (a) categories of personal data + processing purposes + necessity assessment + benefit-vs-risk analysis; (b) risks to consumers; (c) safeguards employed; (d) data flows + sharing
- DPIA register per Section 325O.07 for sensitive + targeted ad + sale + profiling heightened risk + consumer health + AI/ML training
- Algorithm impact assessment for AI/ML processing including bias testing + explainability + accuracy + human oversight + appeal pathway
- DPIA contents per statutory requirements (categories + risks + safeguards + data flows + retention)
- Annual DPIA review + 5-year retention
- AG availability of DPIAs upon investigation preparedness
- No DPIA for AI/ML training despite Minnesota-explicit trigger
- Algorithm impact assessment lacks bias testing + appeal pathway
- DPIA retention under 5 years
- AG-availability process not pre-defined
Enforcement Sanctions and Data Broker Registration - Minnesota CDPA
Manage Minnesota Attorney General enforcement + data broker registration under Sections 325O.10 + 325O.13. Section 325O.10 Minnesota AG (Keith Ellison) EXCLUSIVE enforcement - NO private right of action. Violations enforced as unfair or deceptive trade practices under Minnesota Consumer Fraud Act (Minn Stat Section 325F.69) + Minnesota Consumer Fraud Act 325F.68-70 + Minnesota False Statement in Advertisement Act 325F.67. Civil penalties up to USD 7,500 per violation + restitution + injunctive relief + AG investigations + AG subpoenas + AG court actions. 30-day cure period applies for first 6 months until 25 JANUARY 2026 then **NO CURE PERIOD** permanent. AG may consider in penalty determination: number of violations + persistence + willfulness + size + economic impact + harm to consumers + remedial actions. Section 325O.13 **MINNESOTA-UNIQUE DATA BROKER REGISTRATION** - data brokers mus
- Minnesota AG correspondence and inquiry response evidence
- Penalty exposure assessment (USD 7,500 per violation)
- 30-day cure tracking until 25 January 2026 + post-sunset no-cure preparedness
- **MINNESOTA-UNIQUE** Data Broker Registration with Minnesota Secretary of State + USD 200 annual fee + Section 325O.13 disclosure obligations (if data broker)
- Data broker enforcement preparedness (USD 200/day + USD 10K per registration period)
- Multistate Privacy AG Coalition coordination records
- Minnesota Consumer Fraud Act Section 325F.69 alignment evidence
- No 30-day cure tracking during sunset window
- Post 25 January 2026 no-cure preparedness gap
- **Data broker registration missed** (Section 325O.13 - Minnesota-unique requirement)
- Multistate AG coordination not engaged
Privacy Notice - Minnesota CDPA
Provide reasonably accessible clear and meaningful privacy notice under Section 325O.05 disclosing: categories of personal data processed + purposes of processing + how consumers may exercise rights including appeal + categories of personal data shared with third parties + categories of third parties + ACTIVE EMAIL ADDRESS or other online mechanism for consumer contact + sale disclosure + targeted advertising disclosure + universal opt-out mechanism recognition + Chief Privacy Officer contact information + biometric data disclosure + consumer health data disclosure + processing of children data disclosure + appeal process. Privacy notice must be available in plain language and accessible format. Notice update procedure with material change notification. Bilingual notice where workforce or customer population requires.
- MNCDPA-compliant privacy notice with Section 325O.05 mandatory elements
- Active email or online contact mechanism evidence
- Universal opt-out mechanism (GPC) description in notice
- Chief Privacy Officer contact information published
- Material change notification audit log + version control
- No active email or online contact mechanism
- CPO contact missing from notice (Section 325O.05 breach)
- GPC opt-out not described
- Material change notification missing
Processor Contract Security and Pseudonymisation - Minnesota CDPA
Operate processor contracts + security measures + pseudonymisation under Sections 325O.08 + 325O.09. Processor contracts Section 325O.08 mandatory containing: (a) clear instructions for processing + nature and purpose + type of data + duration + rights and obligations; (b) processor confidentiality obligation including processors employees and subcontractors; (c) processor security including technical and organisational measures appropriate to nature and risk + alignment with NIST CSF + ISO 27001 + Minnesota security baselines; (d) at controller direction delete or return all personal data at end of provision (default delete) unless retention required by law; (e) make available to controller information necessary to demonstrate compliance + cooperate with assessments and audits; (f) engage subprocessors only after providing opportunity to controller to object + flow down same obligations
- Processor contracts with Section 325O.08 mandatory clauses (instructions + confidentiality + security + return/delete + cooperate + subprocessor + ROPA)
- Reasonable security practices appropriate to risk + NIST CSF + ISO 27001 + Minnesota baselines
- Pseudonymisation procedures per Section 325O.09 with separation of identifier and additional information + technical/organisational measures preventing re-identification
- De-identification public commitment + contractual binding + technical safeguards
- Aggregated consumer information procedures
- Internal research exemption documentation
- Processor contracts pre-MNCDPA not refreshed with Section 325O.08 clauses
- Security practices not appropriate to data volume + nature
- Pseudonymisation weak separation allowing re-identification
- De-identification public commitment missing
Scope and Authority - Minnesota CDPA
Establish the legal foundation of Minnesota Consumer Data Privacy Act enacted by Minnesota Legislature 24 May 2024 + Governor Tim Walz signature + House File 1367 included in Omnibus Commerce Policy Bill Chapter 121 of Laws of Minnesota 2024 Article 2 + codified at Minnesota Statutes Chapter 325O Sections 01-14 + effective 31 July 2025 (tribal governments delayed to 31 July 2029). 19th US state comprehensive privacy law. Minnesota Attorney General (Keith Ellison) Office of the Attorney General EXCLUSIVE enforcement authority - NO private right of action. Targeted thresholds: 100,000+ Minnesota consumers controlled/processed (excluding payment transactions) OR 25%+ gross revenue from sale of personal data AND 25,000+ consumers. Carve-outs: HIPAA + GLBA + FCRA + DPPA + FERPA + Air Carrier Access Act + Minnesota Government Data Practices Act + small businesses under 25 FTE (with conditions)
- Minnesota CDPA threshold assessment (100K consumers OR 25K + 25% revenue from sale)
- Carve-out analysis (HIPAA + GLBA + FCRA + DPPA + FERPA + Air Carrier + MGDPA + small business + tax-exempt + insurance MIIPDA)
- Minnesota AG correspondence records
- Constitutional anchor Article I Section 10 documentation
- 31 July 2025 effectiveness gap analysis + tribal nation 2029 path
- Threshold not assessed against new 25K-with-25%-revenue trigger
- Small business carve-out claimed without 25 FTE + condition verification
- 31 July 2025 readiness gap not assessed
- Minnesota Government Data Practices Act scope intersection not documented
Universal Opt-Out Sensitive and Health Data - Minnesota CDPA
Recognise Universal Opt-Out Mechanism (Global Privacy Control GPC) mandatory from 31 July 2025 + process sensitive data and consumer health data under enhanced conditions. GPC alignment with Colorado + Connecticut + Texas + California + Delaware + Montana + Nebraska + New Hampshire + New Jersey + Oregon. Sensitive Data Section 325O.02 Subdivision 32: racial or ethnic origin + religious beliefs + mental or physical health diagnosis + sexual orientation + citizenship or immigration status + genetic data + biometric data + precise geolocation data + personal data of known child + transgender or nonbinary status (Minnesota-specific addition during legislative process). Affirmative opt-in consent required for sensitive data processing. Consumer Health Data Section 325O.02 Subdivision 10 SEPARATELY defined category covering mental/physical health + reproductive/sexual health + gender-affirming
- GPC opt-out preference signal detection implementation evidence
- Sensitive data inventory under Section 325O.02 Subdivision 32 with affirmative opt-in records (including transgender or nonbinary status Minnesota addition)
- Consumer Health Data inventory under Subdivision 10 separate from sensitive
- Children under 13 parental consent records + minors 13-16 opt-in
- Minnesota Genetic Information Privacy Act cross-walk
- Minnesota Health Records Act Chapter 144.291-298 coordination
- GPC not honoured from 31 July 2025 effective
- Transgender/nonbinary status not classified as sensitive (Minnesota-specific addition missed)
- Consumer Health Data treated as ordinary sensitive (separate Subdivision 10 not implemented)
- Minors 13-16 opt-in not operationalised
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Minnesota Consumer Data Privacy Act framework page.