US State Law 2026 · 5 min read

Minnesota’s MCDPA: Confirming Sensitive Data Without Disclosing It

Access responses in Minnesota must withhold the requester’s own SSNs, account numbers, and IDs while confirming they were collected. That is a redaction requirement.

The Minnesota Consumer Data Privacy Act, in effect since July 31, 2025, contains a requirement no other state law states quite so directly: when a consumer asks for access to their data, certain sensitive items must not be included in the copy you return. You confirm, with sufficient particularity, that you have collected that type of information, and you withhold the values themselves. In practice that is a redaction requirement sitting inside the access response, and it inverts the reflex most access workflows are built on, which is that the requester gets their own data back.

What Must Be Confirmed but Not Disclosed

The categories the response must not reveal are the highest-consequence identifiers a file can contain: Social Security numbers, driver’s license and other government-issued identification numbers, financial account numbers, health insurance and medical identification numbers, account passwords and security questions and answers, and biometric data. The logic is loss prevention: an access response is a document that leaves your control, travels by email or portal, and can be intercepted or mis-delivered, and Minnesota decided the requester’s own crown-jewel identifiers should never ride in it. The response instead states that the category was collected, so the consumer still learns what you hold.

The Rest of the Response Framework

Around that mechanic sits a familiar structure. Controllers respond within 45 days, extendable by a further 45 where reasonably necessary with notice to the consumer, and must operate an appeal process for refusals, with an explanation and a route to complain to the Minnesota Attorney General. Small businesses as defined by the SBA are largely exempt, though they may not sell sensitive data without consent. Enforcement belongs to the Attorney General, whose office has confirmed the law is in full effect; the initial right-to-cure period has expired, and civil penalties can reach 7,500 dollars per violation, so a systematically wrong access template is not a theoretical exposure.

What This Means for the Access Workflow

For a multi-state operation the Minnesota mechanic means your access pipeline needs a redaction pass over the requester’s own records before anything ships: find every Social Security number, account number, ID number, and credential in the responsive set, remove the values, and note the categories in the cover response. That is detection work, and the failure modes are exactly the ones DSAR teams already know. Identifiers hide in free text, in scanned attachments, and in spreadsheet columns nobody remembers, and a response that leaks one SSN is worse than the request it answers. Teams handling European subject access alongside US state requests can run the same detect, review, redact, deliver pipeline for both; what changes is which people’s data gets removed, third parties under UK GDPR and the requester’s own listed identifiers under Minnesota.

How SafeRedact Fits

The identifiers Minnesota lists are core detection targets: Social Security numbers, government ID numbers, financial account numbers, and health identifiers are precisely what the detection engine is built to find in documents, spreadsheets, and email exports. Every detection is reviewed by a human before export, and the processing summary and audit trail record what was found and removed, which is the evidence base if a consumer appeals or the Attorney General asks how the response was produced.

Files never leave your browser: documents are processed client-side, only extracted text is sent for AI detection, and no documents are stored on servers. Detection text is never used for training and is deleted within 30 days. A Data Processing Agreement is available, and enterprise cases are priced per case, with the price set with you and shown before you download. See the enterprise overview or the enterprise FAQ for how cases run end to end.

Redact the Identifiers Before the Response Ships

Detection of SSNs, account numbers, and government IDs across documents, spreadsheets, and mail exports, with human review of every decision.

Start Your Evaluation
The DSAR practitioner briefing
One email a month on subject access, redaction, and the rules changing around them. No tracking pixels. Unsubscribe anytime.

Related Guides

This page is informational, not legal advice; the statute, the Minnesota Attorney General’s guidance, and your counsel govern.

Found this useful?
Link copied!