Montana Consumer Data Privacy Act
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Consumer Rights - Montana CDPA
Provide statutory consumer rights under MCA 30-14-2807. (1) Right to confirm processing + access personal data; (2) Right to correct inaccuracies; (3) Right to delete personal data provided by or about consumer; (4) Right to data portability in structured commonly-used machine-readable format where processed automatically; (5) Right to opt out of (a) targeted advertising (b) sale of personal data (c) profiling in furtherance of decisions producing legal or similarly significant effects; (6) Right to appeal denied requests with AG complaint referral within reasonable time. Response within 45 days extendable once for an additional 45 days for complex requests with notice + free of charge first request per 12-month period + authentication of consumer identity without creating new account + authorised agent permitted including via Universal Opt-Out Mechanism + appeal process with denial reas
- Consumer rights register with 45-day SLA evidence
- Free first request per 12-month period evidence
- Identity authentication without new account creation
- Authorised agent processing including UOOM/GPC
- Appeal mechanism with denial reasoning + AG complaint referral
- Sale exception documentation for M&A/bankruptcy transfers
- 45-day SLA not tracked
- New account creation required for authentication
- Authorised agent processing not operationalised
- Appeal process missing or no AG referral path
Data Protection Assessment - Montana CDPA
Conduct Data Protection Assessment (DPA) under MCA 30-14-2815 for high-risk processing activities. MANDATORY DPA triggers: (a) processing of sensitive data; (b) processing for purposes of targeted advertising; (c) sale of personal data; (d) processing for profiling presenting reasonably foreseeable risk of (i) unfair or deceptive treatment of or unlawful disparate impact on consumers + (ii) financial physical or reputational injury + (iii) physical or other intrusion upon solitude or seclusion or private affairs + (iv) other substantial injury to consumers. DPA contents: categories of personal data + processing purposes + necessity assessment + benefit-vs-risk analysis + risks to consumers + safeguards employed + data flows + sharing arrangements + retention periods. DPA available to Montana Attorney General upon investigation request. Single assessment may cover comparable processing ac
- DPA register per MCA 30-14-2815 for sensitive + targeted ad + sale + profiling heightened risk
- Algorithm impact assessment for AI/ML profiling including bias testing + explainability + accuracy + human oversight + appeal pathway
- DPA contents per statutory requirements (categories + risks + safeguards + data flows + retention)
- AG availability of DPAs upon investigation preparedness
- No DPA for profiling activities
- Algorithm impact assessment lacks bias testing + appeal pathway
- DPA not retrievable for AG within reasonable time
- Comparable processing activity grouping evidence missing
Enforcement Sanctions and Cure Sunset - Montana CDPA
Manage Montana Attorney General enforcement under MCA 30-14-2818 + Montana Consumer Protection Act (Mont. Code Ann. 30-14-101 et seq). Montana AG (Austin Knudsen) Office of Consumer Protection EXCLUSIVE enforcement authority - NO private right of action. Violations enforced as unfair or deceptive trade practices under Montana Consumer Protection Act + civil penalties up to USD 10,000 per violation + restitution + injunctive relief + AG investigations + AG subpoenas + AG court actions. **60-DAY CURE PERIOD THROUGH 1 APRIL 2026** then NO CURE PERIOD permanent (6-month cure window from effective date 1 October 2024 - one of earliest cure sunsets among US state privacy laws). AG must provide written notice of violation + 60 days to cure + sworn statement that violation has been cured and reasonable processes are in place to prevent further violations. After 1 April 2026 cure period eliminate
- Montana AG correspondence and inquiry response evidence
- Penalty exposure assessment (USD 10,000 per violation under Montana Consumer Protection Act)
- **60-day cure tracking through 1 APRIL 2026** + sworn statement template + post-sunset no-cure preparedness
- Written notice from AG response process within 60 days
- Multistate Privacy AG Coalition coordination records
- Montana Consumer Protection Act 30-14-101 alignment evidence
- No 60-day cure tracking during sunset window 1 April 2026
- Post 1 April 2026 no-cure preparedness gap (one of earliest US state sunset)
- Sworn statement template missing
- Multistate AG coordination not engaged
Privacy Notice - Montana CDPA
Provide reasonably accessible clear and meaningful privacy notice under MCA 30-14-2806 disclosing: categories of personal data processed + purposes of processing + how consumers may exercise rights under MCA 30-14-2807 including appeal + categories of personal data shared with third parties + categories of third parties + active online mechanism for consumer to contact controller + sale disclosure (whether controller sells personal data + opt-out mechanism) + targeted advertising disclosure + universal opt-out mechanism (UOOM) recognition + biometric and consumer health data specific disclosures where applicable + minor processing disclosure (children under 13 + minors 13-16). Notice must be in plain language and accessible format. Update procedure with material change notification. Bilingual notice where workforce or consumer population requires (Spanish + indigenous Native American lan
- Montana-compliant privacy notice with MCA 30-14-2806 mandatory elements
- Active online contact mechanism evidence
- Universal opt-out mechanism (UOOM/GPC) description in notice
- Material change notification audit log
- Children under 13 + minors 13-16 disclosure if processing minor data
- No active online mechanism for consumer contact
- UOOM/GPC not described in notice (1 January 2025 requirement)
- Minor processing disclosure missing or generic
- Sale and targeted advertising disclosure incomplete
Processor Contract Security and Pseudonymisation - Montana CDPA
Operate processor contracts + security measures + pseudonymisation under MCA 30-14-2809 + 30-14-2811. Processor contracts MCA 30-14-2809 mandatory containing: (a) clear instructions for processing + nature and purpose + type of data + duration + rights and obligations; (b) processor confidentiality obligation including employees + subcontractors; (c) processor security including technical and organisational measures appropriate to nature and risk + alignment with NIST CSF + ISO 27001 baselines; (d) at controller direction delete or return all personal data at end of provision (default delete) unless retention required by law; (e) make available to controller information necessary to demonstrate compliance + cooperate with assessments and audits; (f) engage subprocessors only after providing opportunity to controller to object + flow down same obligations; (g) ROPA records of processing a
- Processor contracts with MCA 30-14-2809 mandatory clauses (instructions + confidentiality + security + return/delete + cooperate + subprocessor + ROPA)
- Reasonable security practices appropriate to risk + NIST CSF + ISO 27001 baselines + Montana Online Personal Information Theft Prevention Act parallel
- Pseudonymisation procedures per MCA 30-14-2811 with separation of identifier and additional information
- De-identification public commitment + contractual binding + technical safeguards
- Aggregated consumer information procedures
- Processor contracts pre-MTCDPA not refreshed with MCA 30-14-2809 clauses
- Security practices not appropriate to data volume + nature
- Pseudonymisation weak separation allowing re-identification
- De-identification public commitment missing
Scope and Authority - Montana CDPA
Establish the legal foundation of Montana Consumer Data Privacy Act + Senate Bill 384 (SB 384) sponsored by Senator Daniel Zolnikov + signed by Governor Greg Gianforte 19 May 2023 + codified at Montana Code Annotated Title 30 Chapter 14 Part 28 (MCA 30-14-2801 through 30-14-2818) + effective 1 October 2024 + 9th US state to enact comprehensive consumer privacy law. Constitutional anchor Montana Constitution Article II Section 10 right of individual privacy (one of strongest state constitutional privacy protections in US). Montana Attorney General (Austin Knudsen) Office of Consumer Protection EXCLUSIVE enforcement - NO private right of action. **LOWEST THRESHOLD OF US STATE PRIVACY LAWS**: 50,000 Montana consumers controlled/processed (excluding payment transactions) OR 25,000 consumers AND 25% revenue from sale of personal data + reflecting Montana population ~1.1M + emphasizes Montana
- Montana CDPA threshold assessment (50K consumers OR 25K + 25% revenue from sale)
- Carve-out analysis (HIPAA + GLBA + FCRA + DPPA + FERPA + Air Carrier + state/local govt + small business + tax-exempt + Montana Insurance Code)
- Constitution Article II Section 10 anchor documentation
- Montana AG correspondence records
- Effective 1 October 2024 readiness gap analysis + 1 January 2025 UOOM readiness
- 50K threshold not assessed against lowest US state trigger
- Carve-out claimed but unsupported documentation
- Coordination with Montana Genetic Information Privacy Act 2023 not assessed
- Online Personal Information Theft Prevention Act parallel compliance gap
Sensitive Data and Children - Montana CDPA
Process sensitive data and minor data under enhanced conditions in MCA 30-14-2802 + 30-14-2810. Sensitive Data definition: racial or ethnic origin + religious beliefs + mental or physical health condition or diagnosis + sex life or sexual orientation + citizenship or immigration status + genetic data + biometric data + precise geolocation data + personal data collected from known child. Affirmative opt-in consent required for sensitive data processing. Children under 13 (FERPA-style) require parental consent + COPPA-style age verification + age-gate. Minors 13-16 processing requires opt-in. NOTE: NO opt-in required for sale to or targeted advertising of consumers under 16 (DELTA from other state laws including MD MODPA + MN CDPA + CT CTDPA + CO CPA - significant criticism that 13-16 opt-in is insufficient protection). Coordinate with Montana Genetic Information Privacy Act 2023 for genet
- Sensitive data inventory under MCA 30-14-2802 with affirmative opt-in records
- Children under 13 COPPA-style verification + parental consent records
- Minors 13-16 opt-in evidence (NOTE: NO opt-in for sale to or targeted advertising of consumers under 16 - delta from other states)
- Montana Genetic Information Privacy Act 2023 cross-walk for genetic data
- Health data coordination with Montana Insurance Code
- Affirmative opt-in implied not explicit for sensitive data
- Children under 13 age verification weak (knowledge-based only)
- Minors 13-16 opt-in not operationalised
- Genetic data dual-statute compliance not mapped
Universal Opt-Out Mechanism - Montana CDPA
Recognise Universal Opt-Out Mechanism (UOOM) under MCA 30-14-2807 mandatory from 1 January 2025 (delayed from effective date 1 October 2024 to give industry preparation time). Controllers MUST allow consumers to opt out of targeted advertising and sale of personal data through user-selected universal opt-out mechanism (Global Privacy Control GPC + equivalent signals). Mechanism must be (a) unaffiliated with the controller; (b) easy for reasonable consumer to use; (c) clearly described to consumer; (d) does not unfairly disadvantage another controller; (e) does not use a default that opt-out signal is set or unset which the consumer did not affirmatively select. Multistate GPC recognition coordination with Colorado + Connecticut + Texas + California + Delaware + Nebraska + New Hampshire + New Jersey + Oregon + Minnesota. Implement signal detection + audit log + consumer confirmation + UOO
- GPC opt-out preference signal detection implementation evidence (effective 1 January 2025)
- Signal detection audit log + consumer confirmation records
- Browser fingerprinting and inference-based tracking opt-out evidence
- Multistate GPC recognition cross-walk (CO + CT + TX + CA + DE + NE + NH + NJ + OR + MN coordination)
- GPC not honoured from 1 January 2025 effective date
- Default opt-out set without affirmative selection
- Browser fingerprinting still tracking opt-out consumers
- Multistate GPC recognition inconsistent
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Montana Consumer Data Privacy Act framework page.