Skip to content

Cyber Liability by state

Minnesota data breach notification law and cyber insurance

Direct answer

What is Minnesota's data breach notification law?

Minnesota's breach notification law (Minn. Stat. sect. 325E.61) requires businesses to notify affected residents in the most expedient time possible and without unreasonable delay after a breach of personal information. Minnesota requires businesses to notify affected residents of breaches of unencrypted personal information without unreasonable delay.

Reviewed by Cornerstone Staff28 years of financial services state licensing experienceLast verified July 29, 2026

What the statute requires

Minnesota requires businesses to notify affected residents of breaches of unencrypted personal information without unreasonable delay. Cyber liability insurance typically covers the forensics, notification, and legal review this statute requires.

Consumer notification deadline
In the most expedient time possible and without unreasonable delay
Credit bureau notice
Notify consumer reporting agencies within 48 hours when a breach requires notice to more than 500 residents.
Safe harbor
Notification is not required if the compromised data was encrypted and the encryption key was not acquired.
Enforcement
Violations are enforceable by the Attorney General under the state's consumer protection authority.

Statutes and sources

  • Minnesota Breach of Security Systems Law

    Minn. Stat. sect. 325E.61

Regulator: Minnesota Attorney General . Last verified 2026-07-29 from the official source .

Get Minnesota coverage handled

Share a few details and an agent will respond within one business day.