Minnesota Consumer Data Privacy Act modified to make consumer health data a form of sensitive data, and additional protections added for sensitive data.
What changed between versions
The definition of 'health data' was modified to explicitly include data that a controller uses to identify a consumer's health status, broadening the scope beyond just data that identifies status.
The definition of 'geofence' was modified by removing a specific accuracy threshold (more than three decimal degrees) and clarifying the technology's function.
A new sensitive data category was added for 'inferences made by a controller' based on personal data that indicate health status or services.
Specific clauses defining data that identifies a consumer's seeking or obtaining of health care services were removed from the list of sensitive data categories.
New requirements were added to prohibit controllers from selling sensitive data and sharing health data without specific consumer consent.
The requirements for consent revocation were modified to include a 15-day limit on how long a controller can continue processing data after a consumer requests to stop.
The effective date of the act was changed from July 31, 2026, to January 1, 2027, and the compliance deadline for postsecondary institutions was moved from July 31, 2030, to July 31, 2029.