Skip to content

Evidence request lists

Minnesota Consumer Data Privacy Act

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Chief Privacy Officer Governance - Minnesota CDPA

MN-CDPA-Chief-Privacy-Officer-Section-325O-06-MN-UNIQUE-Designation-Privacy-Programme-Training
Minnesota CDPA Chief Privacy Officer + Section 325O.06 + MINNESOTA-UNIQUE Designation + Privacy Programme + Training

Designate Chief Privacy Officer (CPO) per **MINNESOTA-UNIQUE** Section 325O.06 requirement among US state privacy laws. Controllers processing personal data of 100,000 or more consumers MUST designate a Chief Privacy Officer or equivalent senior officer responsible for: (a) coordinating overall compliance with Chapter 325O; (b) privacy programme oversight including policies + procedures + training; (c) responding to consumer requests + appeals; (d) Minnesota Attorney General liaison; (e) privacy training programme for workforce including initial training within 90 days of hire + annual refresh; (f) maintaining data inventory of categories + purposes + sources + retention; (g) DPIA programme oversight; (h) breach response coordination. CPO must have sufficient seniority + authority + independence + resources + reporting line to senior management. CPO contact information published in priva

Artefacts an auditor will ask for
  • **MINNESOTA-UNIQUE** Chief Privacy Officer designation letter + seniority + authority + independence + reporting line + budget per Section 325O.06
  • CPO contact published in privacy notice
  • Privacy training programme records (initial within 90 days + annual)
  • Data inventory of categories + purposes + sources + retention maintained
  • CPO-led DPIA programme oversight
  • CPO breach response coordination role
Where this commonly fails
  • No CPO designated despite 100K consumer threshold (Section 325O.06 violation - **MINNESOTA-UNIQUE** requirement)
  • CPO designated nominally without senior authority + budget + reporting line
  • Privacy training not annual + not all-hands
  • Data inventory not refreshed annually

Consumer Rights and AI Profiling Question - Minnesota CDPA

MN-CDPA-Consumer-Rights-Section-325O-04-Access-Correct-Delete-Portability-List-Third-Parties-Opt-Out-Appeal-AIQUEST-Profile
Minnesota CDPA Consumer Rights + Section 325O.04 + Access + Correct + Delete + Portability + List of Third Parties + Opt-Out + Appeal + AI Question Profile

Provide statutory consumer rights under Section 325O.04 including MINNESOTA-UNIQUE rights. (1) Right to confirm processing + access + portable format; (2) Right to correct inaccuracies; (3) Right to delete; (4) **MINNESOTA-UNIQUE** Right to obtain a list of specific third parties to whom personal data has been disclosed (or categories where specifics impossible) - this third-party disclosure list right is unique among US state privacy laws; (5) Right to opt out of (a) sale (b) targeted advertising (c) profiling in furtherance of decisions producing legal or similarly significant effects; (6) Right to appeal denied requests with AG complaint referral; (7) **MINNESOTA-UNIQUE Right to Question Profiling Decisions** - if profiling produces legal or similarly significant effects consumer has right to (a) meaningful explanation of decision + general factors and contributions to outcome; (b) re

Artefacts an auditor will ask for
  • Consumer rights register with 45-day SLA evidence
  • **MINNESOTA-UNIQUE** list of third parties response capability evidence (specific third parties or categories where impossible)
  • **MINNESOTA-UNIQUE** Right to Question Profiling workflow including meaningful explanation + data review + correction + retaking of decision without disputed data
  • Algorithm explainability and human review pathway for profiling decisions producing legal or similarly significant effects
  • Appeal mechanism with denial reasoning + AG complaint referral
  • Authorised agent processing including GPC
  • Authentication without new account creation
Where this commonly fails
  • List of third parties right not operationalised (Minnesota-unique requirement missed)
  • Right to Question Profiling lacks explainability + retake capability (Minnesota-unique)
  • Categories-only list of third parties when specifics possible
  • Profile decision human review not documented

Data Privacy Assessment - Minnesota CDPA

MN-CDPA-Data-Privacy-Assessment-DPIA-Section-325O-07-Sensitive-Targeted-Sale-Profiling-AI-Consumer-Health
Minnesota CDPA DPIA + Section 325O.07 + Sensitive + Targeted + Sale + Profiling + AI + Consumer Health

Conduct Data Privacy Assessment (DPIA) under Section 325O.07 for high-risk processing activities. MANDATORY DPIA triggers: (a) processing of sensitive data; (b) processing for purposes of targeted advertising; (c) sale of personal data; (d) processing for profiling presenting reasonably foreseeable risk of (i) unfair or deceptive treatment of or unlawful disparate impact on consumers + (ii) financial physical or reputational injury + (iii) physical or other intrusion upon solitude or seclusion or private affairs + (iv) other substantial injury to consumers; (e) processing of consumer health data; (f) other processing presenting heightened risk of harm including AI/ML training (Minnesota-explicit). DPIA contents: (a) categories of personal data + processing purposes + necessity assessment + benefit-vs-risk analysis; (b) risks to consumers; (c) safeguards employed; (d) data flows + sharing

Artefacts an auditor will ask for
  • DPIA register per Section 325O.07 for sensitive + targeted ad + sale + profiling heightened risk + consumer health + AI/ML training
  • Algorithm impact assessment for AI/ML processing including bias testing + explainability + accuracy + human oversight + appeal pathway
  • DPIA contents per statutory requirements (categories + risks + safeguards + data flows + retention)
  • Annual DPIA review + 5-year retention
  • AG availability of DPIAs upon investigation preparedness
Where this commonly fails
  • No DPIA for AI/ML training despite Minnesota-explicit trigger
  • Algorithm impact assessment lacks bias testing + appeal pathway
  • DPIA retention under 5 years
  • AG-availability process not pre-defined

Enforcement Sanctions and Data Broker Registration - Minnesota CDPA

MN-CDPA-Enforcement-AG-Ellison-Section-325O-10-USD-7500-Per-Violation-Data-Broker-Registration-325O-13-Sunset-25-Jan-2026
Minnesota CDPA Enforcement + AG Ellison + Section 325O.10 + USD 7,500 Per Violation + Data Broker Registration + Sunset 25 January 2026

Manage Minnesota Attorney General enforcement + data broker registration under Sections 325O.10 + 325O.13. Section 325O.10 Minnesota AG (Keith Ellison) EXCLUSIVE enforcement - NO private right of action. Violations enforced as unfair or deceptive trade practices under Minnesota Consumer Fraud Act (Minn Stat Section 325F.69) + Minnesota Consumer Fraud Act 325F.68-70 + Minnesota False Statement in Advertisement Act 325F.67. Civil penalties up to USD 7,500 per violation + restitution + injunctive relief + AG investigations + AG subpoenas + AG court actions. 30-day cure period applies for first 6 months until 25 JANUARY 2026 then **NO CURE PERIOD** permanent. AG may consider in penalty determination: number of violations + persistence + willfulness + size + economic impact + harm to consumers + remedial actions. Section 325O.13 **MINNESOTA-UNIQUE DATA BROKER REGISTRATION** - data brokers mus

Artefacts an auditor will ask for
  • Minnesota AG correspondence and inquiry response evidence
  • Penalty exposure assessment (USD 7,500 per violation)
  • 30-day cure tracking until 25 January 2026 + post-sunset no-cure preparedness
  • **MINNESOTA-UNIQUE** Data Broker Registration with Minnesota Secretary of State + USD 200 annual fee + Section 325O.13 disclosure obligations (if data broker)
  • Data broker enforcement preparedness (USD 200/day + USD 10K per registration period)
  • Multistate Privacy AG Coalition coordination records
  • Minnesota Consumer Fraud Act Section 325F.69 alignment evidence
Where this commonly fails
  • No 30-day cure tracking during sunset window
  • Post 25 January 2026 no-cure preparedness gap
  • **Data broker registration missed** (Section 325O.13 - Minnesota-unique requirement)
  • Multistate AG coordination not engaged

Privacy Notice - Minnesota CDPA

MN-CDPA-Privacy-Notice-Section-325O-05-Categories-Purposes-Rights-Email-Online-Mechanism-Appeal
Minnesota CDPA Privacy Notice + Section 325O.05 + Categories + Purposes + Rights + Email + Online + Appeal

Provide reasonably accessible clear and meaningful privacy notice under Section 325O.05 disclosing: categories of personal data processed + purposes of processing + how consumers may exercise rights including appeal + categories of personal data shared with third parties + categories of third parties + ACTIVE EMAIL ADDRESS or other online mechanism for consumer contact + sale disclosure + targeted advertising disclosure + universal opt-out mechanism recognition + Chief Privacy Officer contact information + biometric data disclosure + consumer health data disclosure + processing of children data disclosure + appeal process. Privacy notice must be available in plain language and accessible format. Notice update procedure with material change notification. Bilingual notice where workforce or customer population requires.

Artefacts an auditor will ask for
  • MNCDPA-compliant privacy notice with Section 325O.05 mandatory elements
  • Active email or online contact mechanism evidence
  • Universal opt-out mechanism (GPC) description in notice
  • Chief Privacy Officer contact information published
  • Material change notification audit log + version control
Where this commonly fails
  • No active email or online contact mechanism
  • CPO contact missing from notice (Section 325O.05 breach)
  • GPC opt-out not described
  • Material change notification missing

Processor Contract Security and Pseudonymisation - Minnesota CDPA

MN-CDPA-Processor-Contract-Security-Section-325O-08-Pseudonymisation-Section-325O-09-De-Identification
Minnesota CDPA Processor + Section 325O.08 + Security + Pseudonymisation + Section 325O.09 + De-Identification

Operate processor contracts + security measures + pseudonymisation under Sections 325O.08 + 325O.09. Processor contracts Section 325O.08 mandatory containing: (a) clear instructions for processing + nature and purpose + type of data + duration + rights and obligations; (b) processor confidentiality obligation including processors employees and subcontractors; (c) processor security including technical and organisational measures appropriate to nature and risk + alignment with NIST CSF + ISO 27001 + Minnesota security baselines; (d) at controller direction delete or return all personal data at end of provision (default delete) unless retention required by law; (e) make available to controller information necessary to demonstrate compliance + cooperate with assessments and audits; (f) engage subprocessors only after providing opportunity to controller to object + flow down same obligations

Artefacts an auditor will ask for
  • Processor contracts with Section 325O.08 mandatory clauses (instructions + confidentiality + security + return/delete + cooperate + subprocessor + ROPA)
  • Reasonable security practices appropriate to risk + NIST CSF + ISO 27001 + Minnesota baselines
  • Pseudonymisation procedures per Section 325O.09 with separation of identifier and additional information + technical/organisational measures preventing re-identification
  • De-identification public commitment + contractual binding + technical safeguards
  • Aggregated consumer information procedures
  • Internal research exemption documentation
Where this commonly fails
  • Processor contracts pre-MNCDPA not refreshed with Section 325O.08 clauses
  • Security practices not appropriate to data volume + nature
  • Pseudonymisation weak separation allowing re-identification
  • De-identification public commitment missing

Scope and Authority - Minnesota CDPA

MN-CDPA-Scope-HF-1367-Chapter-325O-Walz-24-May-2024-Effective-31-July-2025-AG-Ellison-100K-25K-Threshold
Minnesota CDPA Scope + HF 1367 + Chapter 325O + Walz + 24 May 2024 + Effective 31 July 2025 + AG Ellison + 100K/25K

Establish the legal foundation of Minnesota Consumer Data Privacy Act enacted by Minnesota Legislature 24 May 2024 + Governor Tim Walz signature + House File 1367 included in Omnibus Commerce Policy Bill Chapter 121 of Laws of Minnesota 2024 Article 2 + codified at Minnesota Statutes Chapter 325O Sections 01-14 + effective 31 July 2025 (tribal governments delayed to 31 July 2029). 19th US state comprehensive privacy law. Minnesota Attorney General (Keith Ellison) Office of the Attorney General EXCLUSIVE enforcement authority - NO private right of action. Targeted thresholds: 100,000+ Minnesota consumers controlled/processed (excluding payment transactions) OR 25%+ gross revenue from sale of personal data AND 25,000+ consumers. Carve-outs: HIPAA + GLBA + FCRA + DPPA + FERPA + Air Carrier Access Act + Minnesota Government Data Practices Act + small businesses under 25 FTE (with conditions)

Artefacts an auditor will ask for
  • Minnesota CDPA threshold assessment (100K consumers OR 25K + 25% revenue from sale)
  • Carve-out analysis (HIPAA + GLBA + FCRA + DPPA + FERPA + Air Carrier + MGDPA + small business + tax-exempt + insurance MIIPDA)
  • Minnesota AG correspondence records
  • Constitutional anchor Article I Section 10 documentation
  • 31 July 2025 effectiveness gap analysis + tribal nation 2029 path
Where this commonly fails
  • Threshold not assessed against new 25K-with-25%-revenue trigger
  • Small business carve-out claimed without 25 FTE + condition verification
  • 31 July 2025 readiness gap not assessed
  • Minnesota Government Data Practices Act scope intersection not documented

Universal Opt-Out Sensitive and Health Data - Minnesota CDPA

MN-CDPA-Universal-Opt-Out-GPC-Sensitive-Data-Section-325O-02-Consumer-Health-Data-Children-Known-Child-Transgender
Minnesota CDPA Universal Opt-Out + GPC + Sensitive + Section 325O.02 + Consumer Health Data + Children + Known Child + Transgender

Recognise Universal Opt-Out Mechanism (Global Privacy Control GPC) mandatory from 31 July 2025 + process sensitive data and consumer health data under enhanced conditions. GPC alignment with Colorado + Connecticut + Texas + California + Delaware + Montana + Nebraska + New Hampshire + New Jersey + Oregon. Sensitive Data Section 325O.02 Subdivision 32: racial or ethnic origin + religious beliefs + mental or physical health diagnosis + sexual orientation + citizenship or immigration status + genetic data + biometric data + precise geolocation data + personal data of known child + transgender or nonbinary status (Minnesota-specific addition during legislative process). Affirmative opt-in consent required for sensitive data processing. Consumer Health Data Section 325O.02 Subdivision 10 SEPARATELY defined category covering mental/physical health + reproductive/sexual health + gender-affirming

Artefacts an auditor will ask for
  • GPC opt-out preference signal detection implementation evidence
  • Sensitive data inventory under Section 325O.02 Subdivision 32 with affirmative opt-in records (including transgender or nonbinary status Minnesota addition)
  • Consumer Health Data inventory under Subdivision 10 separate from sensitive
  • Children under 13 parental consent records + minors 13-16 opt-in
  • Minnesota Genetic Information Privacy Act cross-walk
  • Minnesota Health Records Act Chapter 144.291-298 coordination
Where this commonly fails
  • GPC not honoured from 31 July 2025 effective
  • Transgender/nonbinary status not classified as sensitive (Minnesota-specific addition missed)
  • Consumer Health Data treated as ordinary sensitive (separate Subdivision 10 not implemented)
  • Minors 13-16 opt-in not operationalised
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Minnesota Consumer Data Privacy Act framework page.