Chat with us, powered by LiveChat

Minnesota Data Privacy: What Your Website Needs by July 31, 2025

By October 24, 2025Uncategorized
Hands typing on a laptop with floating digital security icons, including a lock and email symbol, conveying cybersecurity and data protection concepts.

For Minnesota small businesses, the rules for handling customer data are changing. The Minnesota Consumer Data Privacy Act (MCDPA) takes effect on July 31, 2025. This new law gives customers more control over their personal data. Many business owners are confused about what they need to do for their website and digital marketing. We wrote this guide to give you a clear, non-legal roadmap for compliance.

The First Question: Does My Small Business Need to Comply?

The good news is that most truly small Minnesota businesses are exempt from many of the MCDPA’s requirements. The law defines a small business based on the federal Small Business Administration’s standards.

However, there is one non-negotiable rule: Every small business is strictly prohibited from selling a customer’s sensitive data without their prior consent. This means any business, regardless of size, must be careful with data like health status or precise location.

For larger small businesses, you must comply if, in a year, you:

  • Control or process the data of 100,000 or more Minnesota consumers.
  • OR control or process data for 25,000 or more consumers AND get over 25% of your revenue from selling that personal data.

If you are above these numbers, you need a full compliance plan. If you are below, you still need to follow the core rules below to build trust.

Action Step 1: Update Your Privacy Notice and Policy

The MCDPA requires transparency. Your website’s Privacy Policy must be updated to include specific details about your data practices.

Make it Accessible: Your Privacy Policy needs to be clear, easy to read, and posted on your homepage, often in the footer, with a link that includes the word “Privacy.”

Disclose Everything Clearly: The policy must tell the consumer:

  • What kinds of personal data you collect (e.g., names, email, browsing history).
  • Why you collect it (e.g., order fulfillment, email marketing).
  • How a consumer can ask to see, correct, or delete their data.
  • If you sell data or use it for targeted advertising.

Action Step 2: Implement Opt-Out Mechanisms (The “Cookie Banner”)

If your business uses tools like Google Ads or Meta Ads for targeted advertising, or if you sell customer data, you need to provide a clear way for consumers to say “no.”

Offer a Conspicuous Opt-Out Link: You must provide a link outside of your main Privacy Policy (often in the website footer) labeled something like “Your Privacy Choices” or “Do Not Sell My Data.” This link must lead to a page where users can opt out of:

  1. Targeted advertising.
  2. The sale of their personal data.

Honor Universal Opt-Outs (UOOMs): The MCDPA requires you to honor global privacy signals sent by a user’s web browser, known as UOOMs. Because of this, even if you are a smaller business, integrating a Consent Management Platform (CMP) or smart cookie banner is the most reliable way to manage consent and prove compliance. This platform helps you track consent and automatically honors UOOM signals.

Action Step 3: Prepare for Consumer Data Requests

The MCDPA gives consumers the right to access, correct, or delete their personal data. Your business must have a system in place to handle these requests.

Create a Request Channel: You need at least one reliable way for a customer to submit a request (e.g., a dedicated email address or an online form linked in your Privacy Policy).

Set a 45-Day Response Window: Once a request is submitted, you must respond within 45 days. You need to verify the person making the request is who they say they are before acting.

Data Minimization: Start reviewing your data now. You may only collect personal data that is necessary for the purposes you disclosed. Do not keep data that is no longer needed. This practice reduces your risk and compliance burden.

Disclaimer: The information provided here is for educational purposes only and does not constitute legal advice. Data privacy law is complex and constantly changing. We strongly recommend consulting with a qualified legal professional to determine your specific obligations under the MCDPA. Our team specializes in the technical implementation and digital marketing compliance aspects of these laws, such as cookie banner integration and data auditing.

Our Recommendation: A Proactive Approach

The MCDPA is a significant step forward for consumer privacy in Minnesota. Even if your business falls below the compliance thresholds, being transparent and user-focused is essential for building trust. Start with your Privacy Policy and integrate a simple consent mechanism now.

Ready to secure your website and ensure you are ready for the July 31, 2025 deadline? Our experts can audit your website and integrate the necessary technical tools to manage data consent and comply with the MCDPA’s requirements. Contact us today for an audit of your data privacy posture.

Share