HF 2700 Minnesota House · 2025-2026 Regular Session

Minnesota Consumer Data Privacy Act modified to make consumer health data a form of sensitive data, and additional protections added for sensitive data.

HF 2700 modifies Minnesota's Consumer Data Privacy Act by explicitly classifying consumer health data as a type of sensitive data requiring heightened protections. The bill adds new consent requirements for businesses processing health information and strengthens safeguards for all sensitive data, including health, genetic, and biometric information. It directly affects Minnesota residents whose health data is collected by businesses and requires those businesses to obtain clear, specific consent before using such data. The law amends key sections of Minnesota Statutes (325M.11-325M.20) to implement these changes, repealing the previous section that defined health data protections.
Bill status in committee 1 of 4 stages cleared
Introduction
Mar 2025
Committee Review
Floor Vote
Governor
Introduced Mar 24, 2025 Last action May 7, 2026
Maddy AI version diff · 2 comparisons

What changed between versions

1st Engrossment 2nd Engrossment · 7 edits · Apr 7, 2026
MODERATE
The bill was renumbered from the 1st to the 2nd Engrossment with an updated posting date. Substantively, the definition of 'health data' was expanded to include data used to identify health status, and 'geofence' technology was refined to remove a specific accuracy threshold. The list of sensitive data categories was reorganized, adding inferences derived from personal data as a new category while removing specific clauses about seeking health care services. The distinction between 'sensitive data' and 'health data' was clarified, with new rules prohibiting the sale of sensitive data and the sharing of health data without consent. The effective date of the law was moved forward from July 31, 2026, to January 1, 2027, and the exemption for postsecondary institutions was shortened from 2030 to 2029.
Scope change
The bill's scope regarding data definitions was broadened to cover inferred data and specific types of health-related information, while the timeline for compliance was accelerated for all entities, including postsecondary institutions.
DEFINITION

The definition of 'health data' was modified to explicitly include data that a controller uses to identify a consumer's health status, broadening the scope beyond just data that identifies status.

The definition of 'geofence' was modified by removing a specific accuracy threshold (more than three decimal degrees) and clarifying the technology's function.

A new sensitive data category was added for 'inferences made by a controller' based on personal data that indicate health status or services.

Specific clauses defining data that identifies a consumer's seeking or obtaining of health care services were removed from the list of sensitive data categories.

REQUIREMENT

New requirements were added to prohibit controllers from selling sensitive data and sharing health data without specific consumer consent.

The requirements for consent revocation were modified to include a 15-day limit on how long a controller can continue processing data after a consumer requests to stop.

TIMELINE

The effective date of the act was changed from July 31, 2026, to January 1, 2027, and the compliance deadline for postsecondary institutions was moved from July 31, 2030, to July 31, 2029.

Floor votes

How they voted

No floor votes recorded yet.
Full legislative history

Actions timeline

Total actions
6
Key actions
2
Committee
2
Apr 7, 2026
Lower · Passed
Committee report, to adopt as amended
lower
Mar 5, 2026
Lower · Passed
Committee report, to adopt as amended and re-refer to Judiciary Finance and Civil Law
lower
Mar 24, 2025
Introduced
Introduction and first reading, referred to Judiciary Finance and Civil Law
lower
1 primary · 6 co-sponsors

Sponsors