On July 31, 2025, Minnesota's Consumer Data Privacy Act took effect, and it is genuinely one of the best in the country. It gives Minnesotans rights most Americans don't have. A year later, the honest question is the one this series always asks: is anyone actually using it?
As best I can determine from the public record, the answer so far is no. And that gap — between a powerful law and an invisible enforcement record — is the whole story.
What the law actually gives you (and it's more than you'd guess)
Most state privacy laws hand you the familiar basics: see your data, correct it, delete it, opt out of its sale. Minnesota's law (Minn. Stat. §§ 325M.10–.21) does all that, and then does two things almost no other state does.
You can interrogate the algorithm. If a company uses automated profiling to make a decision about you with legal or similarly significant effects — a loan, an apartment, a job screen — Minnesota gives you the right to question the result, be told the reason it came out the way it did, and be told what you might have done differently. You can review the data that fed the decision, and if it was wrong, have it corrected and the decision reevaluated. Think about how radical that is: the black box has to open and explain itself, in Minnesota, on your request.
You can get the list of who has your data. Under the same law, you can demand the specific third parties a company disclosed your personal data to. Not vague categories — the actual list. That's a window into the data economy that residents of most states simply don't have.
The law also treats your precise location and your immigration status as "sensitive data" that can't be processed without your consent, requires companies to honor a universal opt-out signal from your browser, imposes data minimization, and — unusually — makes companies keep an inventory of the data they hold and name a privacy officer accountable for it.
That is a strong law. It was authored by Rep. Steve Elkins and passed in 2024. On paper, Minnesotans are better protected than almost anyone.
The two words that hollow it out: "Attorney General"
Now the fine print, which is where this series lives.
Minnesota's privacy law can be enforced by exactly one person: the Attorney General. The statute says in plain terms that nothing in it "establishes a private right of action." So if a company ignores your request to open the algorithm, or sells your location data without consent, you cannot sue. You can complain to the Attorney General's office, and then you wait for that office to act.
That design choice puts enormous weight on one office actually enforcing — which makes the first-year record the thing that matters. And here's what I found: the Attorney General's office has a website for the law (privacymn.com, which redirects to a real page with consumer and business sections and a complaint form). What it does not have, anywhere I could find, is a single published enforcement action, settlement, or even a count of complaints received. No press release. No case. No public numbers on whether the office hired the enforcement staff it said it would.
I want to be fair about one structural reason for the quiet: the law included a 30-day "right to cure" that required the Attorney General to send a warning letter and give companies a month to fix violations before suing — and that cure requirement covered the entire first six months. It sunset on January 31, 2026, so real enforcement teeth only arrived about seven months into the law's life. Some early warning letters may exist that aren't public. So the accurate statement is not "zero enforcement" — it's "no enforcement we can see, in a law where seeing it is the public's only assurance it's working."
Other states with weaker laws are actually bringing cases
Here's what makes the silence conspicuous rather than excusable. States with privacy laws no stronger than ours — some weaker — are enforcing.
- California fined Sephora $1.2 million for failing to honor opt-out signals, and its privacy agency has since penalized Honda ($632,500) and the retailer Todd Snyder ($345,178).
- Texas sued Allstate and its data arm Arity in January 2025 over the driving-data scheme — the first enforcement action any state attorney general had ever filed under a comprehensive privacy law, covering more than 45 million consumers.
- Connecticut publishes an annual enforcement report and has issued more than two dozen cure notices.
Minnesota wrote a stronger law than several of those states and, so far, has the quietest enforcement record of the bunch. A right the enforcer doesn't enforce, in a law where the enforcer is the only one allowed to, is the fine-print problem in its most concentrated form: a promise on paper that produces nothing in practice.
And the blind spot it can't reach at all
One more gap, because it connects directly to the surveillance article in this series. Minnesota's privacy law categorically exempts government entities. So it does not touch police license-plate readers, government facial recognition, or any data the state itself collects about you. The strongest consumer-privacy tool Minnesota has stops at the government's own door — which is exactly where a lot of the surveillance actually happens.
What we can do
Enforce it — visibly. The single most valuable thing the Attorney General's office could do with this law in year two is bring a case and publish it. One enforcement action, well-chosen and public, teaches every data company operating in Minnesota that the law is real. Right now they have every reason to believe it isn't. I'd make the profiling-transparency right the test case, because it's the provision that most distinguishes Minnesota — and the one most worth defending.
Publish the numbers. Connecticut proves this is easy: an annual report showing complaints received, cure notices sent, and actions taken. Minnesotans paid for this law; they're entitled to know whether it's doing anything. Publishing the record is a one-page administrative decision, not a new statute.
Give the people standing. The Legislature should add a private right of action, at least for the most serious violations. A privacy law enforceable by one office is only as strong as that office's attention in any given year. A privacy law that also lets an injured Minnesotan into court is enforceable even when the state is looking elsewhere. That's the difference between a right and a favor.
And close the government gap. The exemption that keeps this law away from police surveillance should be narrowed, so the strongest privacy tool in Minnesota reaches the place Minnesotans are actually watched.
I ran for Attorney General because I believe that office is the People's Lawyer, and this is precisely the kind of law the People's Lawyer exists to wield. Minnesota did the hard part — it passed a privacy law worth bragging about. The easy part, and the part that's missing, is using it.
First the facts. Then the fix.
Sources
Minnesota Consumer Data Privacy Act, Minn. Stat. §§ 325M.10–.21, verified verbatim against the official Minnesota Statutes 2025 text at revisor.mn.gov — including the consumer rights at § 325M.14 (access, correction, deletion, portability, and opt-out at subd. 1(b)–(f)); the Minnesota-distinctive right to question and reevaluate a profiling decision at subd. 1(g); the right to a list of specific third parties at subd. 1(h); the universal-opt-out-signal requirement at subd. 3; data minimization, the data-inventory duty, and sensitive-data consent (including precise geolocation and immigration status as sensitive data) at §§ 325M.16 and 325M.11; the privacy-officer and assessment duties at § 325M.18; the Attorney-General-only enforcement, the $7,500-per-violation penalty, the express absence of a private right of action, and the 30-day cure period that expired January 31, 2026, at § 325M.20; the government-entity exemption and the bank/insurer/GLBA/HIPAA/small-business carve-outs at § 325M.12; and the July 31, 2025 effective date. Legislative history: chief author Rep. Steve Elkins, enacted as article 5 of 2024 Minn. Laws ch. 121. Enforcement record: the Attorney General's Data Privacy page (privacymn.com, redirecting to ag.state.mn.us/Data-Privacy/), which as of September 2026 publishes no enforcement statistics, complaint counts, or actions; no public MCDPA enforcement action, settlement, or press release could be located. Comparative enforcement: California's Sephora settlement ($1.2 million, 2022) and the California Privacy Protection Agency's Honda ($632,500) and Todd Snyder ($345,178) actions (2025); Texas v. Allstate/Arity (January 2025), described as the first state-attorney-general enforcement action under a comprehensive privacy law; Connecticut's annual privacy enforcement reports and cure-notice practice.
Because warning letters issued during the cure period are not necessarily public, this article states that no enforcement was located rather than asserting none occurred; complaint counts and the Attorney General office's privacy staffing could not be independently confirmed and are not asserted. Corrections: campaign@madgettformn.com.