Law & regulation

Minnesota's data privacy law exempts small businesses — from most of it, not all of it

The thresholds are high enough that most new businesses fall outside chapter 325M. But the one duty that survives the small-business exclusion applies to everyone, and it has teeth.

This is information, not advice

This article describes Minnesota law and filing practice in general terms. It is not legal advice about your business, and reading it does not create a lawyer-client relationship.

Every few months a Minnesota business owner gets an email from a vendor warning that the state’s new consumer data privacy law will cost them a compliance program. For most small businesses that is wrong, and the reason is worth understanding precisely — because the part that does apply is the part the email never mentions.

The thresholds are high

Minn. Stat. § 325M.12 applies the Act to legal entities conducting business in Minnesota that meet one or more of:

  • controlling or processing the personal data of 100,000 consumers or more in a year, excluding data processed solely to complete a payment transaction; or
  • deriving over 25 percent of gross revenue from the sale of personal data and processing or controlling the personal data of 25,000 consumers or more.

Note what the second one requires: both halves. Selling data is not enough; it has to be a quarter of your revenue and reach 25,000 people.

A restaurant with a mailing list, a contractor with a customer database, a shop with an e-commerce site — none of these are close to 100,000 consumers, and none of them sell data at all. The Act is aimed at data brokers and large platforms, and the numbers say so.

The exclusions are broad

Section 325M.12 also excludes, among others:

  • government entities and federally recognized Indian tribes;
  • entities and data covered by HIPAA;
  • consumer reporting agencies under the Fair Credit Reporting Act;
  • financial institutions covered by Gramm-Leach-Bliley, along with banks and credit unions and their affiliates;
  • insurance companies and producers;
  • small businesses as defined by the U.S. Small Business Administration;
  • education records under FERPA;
  • employment data — job applicant and employee data is outside the Act entirely;
  • data collected under the Driver’s Privacy Protection Act; and
  • air carriers within the scope of the Airline Deregulation Act.

Two of those matter disproportionately for a new business. The employment data exclusion means your HR files are not the Act’s concern. And the SBA small business exclusion means that if you meet the federal size standard for your industry, you are outside most of the Act’s machinery.

But read § 325M.17 before you relax

The small-business exclusion is not a complete pass. Section 325M.17 imposes a standalone obligation: a small business must not sell a consumer’s sensitive data without the consumer’s prior consent.

And small businesses remain subject to the same “[p]enalties and attorney general enforcement procedures under section 325M.20” as everyone else. The exclusion narrows the duties; it does not remove the enforcement.

So the practical rule for a small Minnesota business is short: you probably do not need a consent management platform, a data protection assessment, or a rights-request workflow. You absolutely do need to not sell sensitive data about your customers without asking them first.

What counts as selling

The trap here is that “sell” in privacy statutes is often broader than a cash transaction for a list. Handing data to a partner in exchange for something of value can qualify depending on how the arrangement is structured. If a marketing vendor, lead generator, or “data enrichment” service has proposed something that involves your customer data flowing outward, that is the moment to look at the arrangement carefully — not because you are likely a covered entity, but because § 325M.17 does not care whether you are.

What to actually do

  • Check your size against the SBA standard for your industry code. It is a specific federal number, not a vibe.
  • Do the arithmetic on 100,000 consumers before assuming you are under it. If you run a consumer app or an e-commerce operation at scale, you may be closer than you think.
  • Do not sell sensitive data. If any vendor arrangement involves your customer data leaving your control for value, get it reviewed.
  • Publish an honest privacy policy anyway. Not because chapter 325M compels it at your size, but because misrepresenting what you do with customer data is its own problem under consumer protection law, entirely independent of this Act.

This article covers scope and the small-business rule. It does not cover the consumer rights, controller responsibilities, or assessment requirements in §§ 325M.14 through 325M.18, which matter a great deal if you are over the thresholds.

Sources

Every source below was retrieved and checked against this page on August 7, 2026.

  1. Minn. Stat. § 325M.12 (scope; exclusions) — Minnesota Office of the Revisor of Statutes
  2. Minn. Stat. § 325M.17 (requirements for small businesses) — Minnesota Office of the Revisor of Statutes