Minnesota Consumer Data Privacy Act modified to make consumer health data a form of sensitive data, and additional protections added for sensitive data.
HF2700 amends Minnesota’s Consumer Data Privacy Act to treat consumer health data as a form of sensitive data and to add new restrictions on how businesses may collect, use, share, and sell sensitive information. The bill expands the definition of sensitive data to include health data and certain inferences based on personal data, and it requires separate, clear consent for processing sensitive data, sharing health data, and selling sensitive data. It also strengthens notice requirements for consent, requires consumers to be able to revoke consent easily, and limits targeted advertising and sale of personal data for minors ages 13 to 16 without consent.
The bill also adds a new prohibition on geofencing around in-person health care providers when the geofence is used to identify or track people seeking care, collect health data, or send health-related ads or messages. It requires controllers to maintain privacy policies and conduct data privacy and protection assessments for targeted advertising, sale of data, processing of sensitive data, sharing of health data, and other high-risk processing activities. Enforcement remains with the attorney general, with civil penalties up to $7,500 per violation, and the bill does not create a private right of action.
HF2700 would revise Minnesota Statutes chapter 325M, especially sections governing definitions, scope, consumer consent, small-business obligations, privacy assessments, and attorney general enforcement. It would add health data to the statute’s sensitive-data framework, impose new consent and disclosure rules for health data and other sensitive data, and create a new geofence restriction in section 325M.178. The bill also preserves and cross-references existing exclusions for HIPAA, health records, financial privacy laws, education records, and other regulated data, while extending the consumer privacy regime to covered businesses operating in or targeting Minnesota.
The available record shows no committee transcript excerpts or recorded votes, so there is no direct evidence of debate or partisan division in the materials provided. Based on the bill’s content, the measure appears to be framed as a consumer privacy and health-data protection bill, with a generally protective posture toward consumers and patients. The absence of recorded opposition or vote history in the provided context suggests no documented public controversy in this dataset, though the bill’s added compliance obligations imply likely interest from affected businesses and data-driven industries.
The main likely points of contention are the bill’s expanded consent requirements, the separate consent rules for health data sharing and sensitive-data sales, and the new geofence ban around health care facilities. Businesses that rely on targeted advertising, data brokerage, location-based marketing, or broad data-sharing practices may view the bill as imposing significant operational and compliance burdens. Small businesses are also affected, though the bill narrows their obligations somewhat by limiting the prohibition to selling sensitive data and sharing health data without consent. Health care, technology, advertising, and data-analytics stakeholders would be the most directly affected parties.