Montana Consumer Data Privacy Act (MCDPA)
· About Montana Consumer Data Privacy Act (MCDPA)
Key Takeaways
- The Montana Consumer Data Privacy Act (MCDPA) applies to controllers and processors that do business in Montana or target Montana residents, and it was materially amended by SB 297, effective 1 October 2025.[3][6][9]
- As amended, the law generally applies to entities that control or process personal data of 25,000 or more consumers in a year, or 15,000 or more consumers if more than 25% of gross revenue comes from the sale of personal data.[6][11]
- The Montana Attorney General has exclusive enforcement authority, the law provides no private right of action, and the original cure period ended when the 2025 amendments removed it; enforcement may proceed without a statutory cure opportunity.[3][6][13]
- Consumers have rights to access, correct, delete, obtain a copy, and opt out of targeted advertising, sale of personal data, and certain profiling decisions, subject to statutory limits.[3][4][11]
- The amended law adds stricter obligations for minors, including heightened protection against targeted advertising, sale, and profiling where there is a heightened risk of harm.[6][8][11]
- The statute became effective on 1 October 2024, and the 2025 amendment package became effective on 1 October 2025; the original termination clause tied to the temporary cure provision had been scheduled for 1 April 2026 under the 2023 law.[7][13][14]
What It Is
The MCDPA is Montana’s comprehensive consumer privacy law, codified at Montana Code Annotated 30-14-2801 et seq., covering the collection and use of personal data by covered businesses and setting consumer rights, controller duties, and enforcement rules.[3][5][13] It is enforced solely by the Montana Attorney General.[3][13]
Montana enacted the law in 2023, it took effect on 1 October 2024, and the legislature later passed SB 297 to revise the statute, with those amendments taking effect on 1 October 2025.[7][9][14] The 2023 act also included a temporary cure framework that was due to terminate on 1 April 2026, but the 2025 amendments removed the cure period earlier, so the current law contains no statutory cure right.[11][13][14]
Who Must Comply
The amended law applies to persons that conduct business in Montana or produce products or services targeted to Montana residents and that meet the statutory processing thresholds.[6][11] The revised thresholds are generally 25,000 consumers per year, or 15,000 consumers if the controller derives more than 25% of gross revenue from the sale of personal data.[6][11]
The 2025 amendments narrowed some exemptions and revised others, including changes affecting nonprofits and insurers, so exemption analysis must be done under the current text rather than the 2024 version.[6][11] The law retains sectoral carve-outs for data already governed by certain federal regimes and for information handled in specified contexts, so counsel should map data sets against the statute’s exclusions rather than assume enterprise-wide coverage.[3][5][11]
The law has extraterritorial reach in the ordinary state-privacy-law sense: it follows the consumer and the business’s Montana-targeting activity, not just in-state incorporation or physical presence.[6][7][11] That means out-of-state companies can be covered if they process Montana residents’ data and meet the thresholds.[6][11]
Core Requirements
- Provide a compliant privacy notice. Controllers must disclose the categories of personal data processed, the purposes of processing, categories of third parties, categories of data sold or shared, consumer rights, how to exercise them, and updated notice dates under the amended text.[11]
- Honor consumer rights requests. Controllers must provide access, correction, deletion, and data portability rights, and they must tell consumers how to appeal a denial through the required process.[3][11]
- Support opt-outs. Covered businesses must offer a mechanism to opt out of the sale of personal data, targeted advertising, and profiling in furtherance of decisions that produce legal or similarly significant effects.[3][11]
- Limit processing of sensitive and minors’ data. The law requires heightened handling of sensitive data and, after SB 297, stronger protections for consumers under 18, including restrictions tied to targeted advertising, sale, and profiling that pose a heightened risk of harm.[6][8][11]
- Maintain a data protection program. Controllers must implement reasonable administrative, technical, and physical safeguards appropriate to the volume and sensitivity of the data and the risks presented.[3][11]
- Execute and oversee processor contracts. Controllers must use contracts that bind processors to instructions, confidentiality, security, deletion or return of data, and cooperation obligations.[3][11]
- Conduct assessments for high-risk processing. Data protection assessments are required for certain processing activities, especially targeted advertising, sale, profiling, sensitive data processing, and other uses that present a heightened risk to consumers.[3][11]
Deadlines and Penalties
| milestone | date | what applies | |---|---:|---| | Original MCDPA effective date | 1 October 2024 | Core consumer rights and controller duties became enforceable.[7][13] | | SB 297 amendments effective | 1 October 2025 | Lower thresholds, revised exemptions, minors protections, and no cure period.[6][9][11] | | Original cure provision termination | 1 April 2026 | The 2023 temporary cure schedule would have ended, but the 2025 amendments had already removed the cure right.[13][14] |
The Attorney General may seek civil penalties of up to $7,500 per violation under the amended framework, along with injunctive relief and other equitable remedies available through enforcement.[6][8][11] The statute also provides for exclusive public enforcement by the Attorney General and does not create a private right of action.[3][13]
How to Comply
- Run a Montana applicability test. Inventory processing, revenue, and consumer-count metrics against the current 25,000 / 15,000 thresholds and document any exemption basis.[6][11]
- Update your data map and ROPA. Identify categories of personal data, sensitive data, sale/sharing pathways, profiling uses, and third-party disclosures so privacy notices and assessments match actual processing.[3][11]
- Rewrite the privacy notice. Align the notice to the amended disclosure list, add the required contact and rights language, and make the notice accessible and available in each language offered for products or services.[11]
- Build rights-request workflows. Configure intake, identity verification, response, appeal, and recordkeeping processes for access, correction, deletion, portability, and opt-out requests.[3][11]
- Refresh contracts and vendor controls. Insert controller instructions, confidentiality, security, deletion/return, and audit/cooperation clauses into processor agreements and verify downstream compliance.[3][11]
- Perform and retain risk assessments. Use a structured assessment method for targeted advertising, sale, profiling, and sensitive-data use; align the control environment with NIST CSF 2.0 for governance and response, ISO 27001 for security management, and ISO 42001 where automated decisioning or AI-driven profiling is in scope.[3][11]
- Strengthen minors and sensitive-data controls. Add age-aware design, consent/authorization checks where required, and heightened review for any processing that could create a heightened risk of harm.[6][8][11]
- Train and test. Train legal, privacy, product, and customer-support teams on the amended rights and response timelines, then test the end-to-end process with mock requests and incident scenarios.[3][11]
Related Regulations
- Colorado Privacy Act. Colorado’s law is similar in structure, but Montana’s 2025 amendments are more aggressive on enforcement because they remove the cure period and add express minors protections.[6][11]
- Connecticut Data Privacy Act. Connecticut overlaps on consumer rights and controller duties, but its amendment timetable and exemptions differ, so multistate notices cannot be copied verbatim.[10]
- Virginia Consumer Data Protection Act. Virginia is similar on rights and assessments, but Montana’s current enforcement posture is stricter because there is no statutory cure period.[13]
- California Consumer Privacy Act / CPRA. California has broader disclosure and opt-out complexity, and Montana companies subject to both laws should harmonize notices while preserving California-specific disclosures.
- Montana insurance and nonprofit rules. Montana’s 2025 revisions changed how some sectoral exemptions work, so regulated entities must confirm whether they remain outside the general privacy regime under the current text.[6][11]
FAQ
Does the MCDPA apply to companies outside Montana?
Yes. The law can apply to out-of-state companies if they do business in Montana or target Montana residents and meet the statutory processing thresholds.[6][11] Physical presence in Montana is not required.
Does the MCDPA still have a cure period?
No statutory cure period remains in the current law after the 2025 amendments.[6][11] The original 2023 law had a temporary cure framework, but SB 297 removed it before the scheduled termination date.[13][14]
What consumer rights does the MCDPA require?
Consumers can request access, correction, deletion, and portability, and they can opt out of sale, targeted advertising, and certain profiling.[3][11] Controllers must also provide an appeals process when they deny a request.[11]
What are the penalties for violating the MCDPA?
The Attorney General may seek civil penalties up to $7,500 per violation and injunctive relief.[6][8][11] There is no private right of action, so consumers cannot sue directly under the statute.[3][13]
Does the MCDPA protect children and teens more strongly now?
Yes. The 2025 amendments added stronger protections for consumers under 18, particularly around targeted advertising, sale, and profiling that can create a heightened risk of harm.[6][8][11] Those requirements should be treated as a separate review track from ordinary adult-consumer processing.
How does the MCDPA fit with ISO 27001 or NIST CSF 2.0?
The statute does not mandate those frameworks, but they map well to the law’s governance, risk assessment, security, and vendor-management expectations.[3][11] ISO 27001 supports security controls, NIST CSF 2.0 supports governance and operational resilience, and ISO 42001 is useful where AI or automated profiling raises privacy-risk questions.
Sources
- Montana Legislature, Consumer Data Privacy Act, MCA Title 30, chapter 14, part 28
- Montana Department of Justice, Office of Consumer Protection: Montana Consumer Data Privacy
- Montana Session Laws 2023, Chapter 681
- Benesch, Montana Amends Consumer Data Privacy Act To Broaden Applicability And Enhance Protections For Minors
- White & Case, Montana Joins the Growing Number of States with a Comprehensive Data Privacy Law
- Future of Privacy Forum, Amendments to the Montana Consumer Data Privacy Act Bring Big Changes to Big Sky Country
- Cooley, Major Updates to Consumer Privacy Laws in Montana and Connecticut
- Shook, Hardy & Bacon, Montana Revamps its Privacy Law
Put it into practice
- Generate the policy: Montana CDPA policy generator (generatepolicy.com)
- Buy the policy pack: State Privacy Law Checklist (cyberpolicy.shop)
- Build it yourself: 2026 US Privacy Program Workbook (ciso.diy)