Minnesota Consumer Data Privacy Act (MCDPA) Compliance
Pandectes GDPR Compliance helps Shopify stores meet Minnesota MCDPA requirements by managing cookie consent, honoring opt-out signals and handling consumer privacy requests.
Start Free
The #1 cookie consent app for Shopify, trusted by 185k stores
What is MCDPA?
The Minnesota Consumer Data Privacy Act (MCDPA) is Minnesota’s comprehensive consumer privacy law. It gives Minnesota residents rights over their personal data and sets obligations for the businesses that collect and process it. Montana’s privacy law shares the same acronym, but this page covers the Minnesota law only.
The Minnesota law follows the general model of other US state privacy laws, with a few features that go further. Minnesota residents have the right to:
- Confirm whether a business processes their personal data, and access that data
- Correct inaccurate personal data
- Delete personal data
- Obtain a portable copy of their personal data
- Opt out of targeted advertising, the sale of their personal data, and certain types of profiling
- Obtain a list of the specific third parties to which the business has disclosed their personal data
- Question the result of a profiling decision that has legal or similarly significant effects, learn the reasons behind it, and have it reevaluated if it was based on inaccurate data
Businesses also have to obtain consent before processing sensitive data, such as health data, precise geolocation, biometric data, or data revealing racial or ethnic origin. They must limit data collection to what is adequate, relevant, and reasonably necessary for the purposes they disclose, and keep an inventory of the personal data they manage as part of their data security practices.

Who does the MCDPA apply to?
The Minnesota law applies to businesses that operate in Minnesota or offer products or services targeted to Minnesota residents, and that in a calendar year control or process the personal data of at least 100,000 Minnesota consumers (not counting data used only to complete a payment), or of at least 25,000 consumers while earning more than 25% of gross revenue from selling personal data. Small businesses as defined by the US Small Business Administration are exempt, but they still may not sell a consumer’s sensitive data without prior consent.

What happens if I don’t comply with the MCDPA?
The Minnesota Attorney General enforces the law. Key points about enforcement:
- A business that violates the law can face an injunction and a civil penalty of up to $7,500 per violation.
- The law does not create a private right of action, so consumers cannot sue businesses directly under it.
- Until January 31, 2026, the Attorney General had to send a warning letter and allow 30 days to fix a violation before taking action. That cure period has expired, so the Attorney General can now bring enforcement actions without prior notice.
When did the MCDPA go into effect?
Minnesota’s law took effect on July 31, 2025. Postsecondary institutions were given until July 31, 2029 to comply, but online stores and other businesses that meet the thresholds are already covered.
Complying with the MCDPA
If your online store sells to Minnesota residents and meets the thresholds above, most of your practical work involves cookies and tracking. Marketing pixels, analytics tags, and advertising cookies often count as targeted advertising or a “sale” of personal data under state privacy laws, so they need to respect each visitor’s choices.
Practical steps for a Shopify store include:
- Offer a clear opt-out. Give visitors an easy way to opt out of targeted advertising and the sale of their personal data, such as a “Do not sell or share my personal information” link, and make sure tracking stops once they do.
- Honor universal opt-out signals. The Minnesota law requires businesses to let consumers opt out through a universal opt-out mechanism sent by their browser or device, such as Global Privacy Control (GPC).
- Get consent for sensitive data. Do not process sensitive data without the consumer’s consent, and review your apps and forms for anything that collects it.
- Keep a data inventory. Document what personal data your store collects, where it is stored, and which apps and partners receive it. This also makes it easier to give customers the list of specific third parties they are entitled to request.
- Update your privacy notice. Explain what personal data you collect, why, who receives it, how long you keep it, and how consumers can exercise their rights, including their right to question profiling decisions.
- Handle consumer requests. Set up a reliable way for customers to request access, correction, deletion, or a copy of their data, and respond within the required timeframe.
A consent management platform makes these steps much easier to maintain. Pandectes GDPR Compliance is built for Shopify stores and provides a cookie banner with opt-out options for US states, a “Do not sell or share my personal information” link, and support for the Global Privacy Control signal. It automatically scans and classifies the cookies on your store, generates a cookie declaration, keeps consent logs, and helps you handle data subject requests. Region-specific banner settings use geolocation to show the right experience to visitors from Minnesota and other states.
Privacy laws differ in their details and continue to change, so review your setup with legal counsel where appropriate.














