Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Consumer Privacy topic

No spam. Unsubscribe anytime.

Minnesota AG outlines enforcement plans under Consumer Data Privacy Act

Minnesota House Commerce Finance and Policy Committee · March 4, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Assistant Attorney General Caitlyn Micco told the Commerce Committee the Minnesota Consumer Data Privacy Act (effective July 31, 2025) gives residents new rights and that the AG’s office is shifting from education to enforcement after an initial warning-letter period expired.

Assistant Attorney General Caitlyn Micco told the House Commerce, Finance and Policy Committee on March 4 that the Minnesota Consumer Data Privacy Act, signed in May 2024 and effective July 31, 2025, gives residents new rights to access, delete and opt out of certain uses of their personal data and imposes duties on businesses to disclose, secure and obtain consent for sensitive categories.

Micco said the AG’s office prioritized outreach and education during the law’s first six months and issued the statutorily required warning letters to potential violators. "For the first six months our priority was to stress education and work with companies through educational outreach," she said, adding that the warning-letter requirement expired Jan. 31 and the office is now moving into an enforcement posture.

Why it matters: The statute establishes enforcement by the attorney general rather than a private right of action and carries civil penalties for violations. Micco said the statute’s scope captures businesses that handle the data of more than 100,000 consumers or that derive more than 25% of gross revenue from selling personal data, while also including entity- and data-level exemptions for already-regulated information such as certain health records.

The AG’s office reported early operational steps: it created a dedicated team, added attorneys and an investigator, launched a privacy complaint portal and handled more than 200 consumer complaints in the statute’s early months—mainly requests to delete data or to exercise other data-rights. Micco said many warning-letter cases led to follow-up and some have grown into preliminary investigations.

Deputy Attorney General Jessica Whitney told lawmakers the office seeks full funding to staff enforcement as originally anticipated in the fiscal note. "We were able to hire some new folks, but not as many as I think we would be necessary," Whitney said, noting a funding reduction in the statute’s second year. She also told members the office has issued subpoenas and civil investigative demands in matters where companies did not respond to statutory obligations.

Committee members asked about timelines and remedies. Micco said companies must respond to consumer rights requests within 45 days, and consumers may escalate disputes to the AG’s office if a company declines to act. The AG’s office indicated enforcement priorities will include cases involving sensitive data, honoring universal opt-out signals that consumers can signal via privacy-protective browsers or extensions, and ensuring businesses are transparent about data uses.

What’s next: Micco said the office expects "meaningful settlements" in the coming years as the agency shifts toward enforcement, and she encouraged collaboration with the Legislature on funding and technical fixes to the law.

The committee moved on to additional agenda items after the presentation.