Skip to content
Privacy Regulations

Montana Consumer Data Privacy Act (MTCDPA)

Overview

The Montana Consumer Data Privacy Act (MTCDPA) is a comprehensive data privacy law designed to give Montana residents greater control over their personal data. Signed into law on May 19, 2023, it took effect on October 1, 2024, making Montana one of the latest states to implement broad consumer privacy protections.

MTCDPA is similar to privacy laws in Virginia (CDPA), Connecticut (CTDPA), and Colorado (CPA) but has stronger consumer rights provisions, including opt-in consent for sensitive data and clear opt-out mechanisms for targeted advertising.

Who Must Comply?

The MTCDPA applies to businesses operating in Montana or targeting Montana residents that meet one of the following criteria:

βœ” Process personal data of at least 50,000 Montana consumers annually (excluding data collected for payment transactions)
βœ” Process personal data of at least 25,000 Montana consumers and derive more than 25% of gross revenue from selling personal data

Exemptions:

The law does not apply to:
🚫 Government agencies
🚫 Nonprofits
🚫 Financial institutions subject to GLBA
🚫 HIPAA-covered entities (hospitals, insurers, healthcare providers)
🚫 Higher education institutions

Key Consumer Rights Under MTCDPA

βœ” Right to Access – Consumers can request a copy of their personal data.
βœ” Right to Correct – Consumers can request corrections to inaccurate personal data.
βœ” Right to Delete – Consumers can request the deletion of personal data.
βœ” Right to Data Portability – Consumers can receive their data in a portable format.
βœ” Right to Opt-Out – Consumers can opt out of:

  • Targeted advertising
  • Sale of personal data
  • Profiling that affects legal or financial decisions

Business Compliance Requirements

βœ” Explicit Opt-In for Sensitive Data – Businesses must obtain consumer consent before processing:
πŸ“Œ Racial/ethnic origin
πŸ“Œ Religious beliefs
πŸ“Œ Biometric data
πŸ“Œ Health conditions
πŸ“Œ Children’s data
βœ” Universal Opt-Out Signals (Effective January 1, 2025) – Businesses must recognize Global Privacy Control (GPC) and other automated opt-out signals.
βœ” Privacy Notices & Data Transparency – Companies must provide clear, detailed privacy policies explaining data collection practices.
βœ” Data Protection & Security – Businesses must implement reasonable safeguards to protect consumer data.
βœ” Data Processing Assessments (DPA) – Organizations must conduct risk assessments for:
πŸ“Œ Targeted advertising
πŸ“Œ Data sales
πŸ“Œ Automated decision-making

Real-World Enforcement Cases

The Montana Attorney General is responsible for enforcing MTCDPA. Violations can result in fines of up to $7,500 per violation.

Since MTCDPA enforcement began in October 2024, major enforcement actions are expected in 2025, likely targeting data brokers, ad tech firms, and businesses using AI-driven profiling.

πŸ“Œ Comparison with Other State Privacy Laws
The Montana MTCDPA shares similarities with Colorado’s CPA and Connecticut’s CTDPA, but differs in key areas:
βœ… Smaller Business Scope – Only businesses processing 50,000+ consumers’ data are covered.
βœ… Stronger Opt-Out Requirements – Businesses must honor universal opt-out signals by 2025.
βœ… No Private Right of Action – Consumers cannot sue companies directly for violations.

Future of MTCDPA Regulation

πŸ“Œ Tighter enforcement on AI-based profiling in 2025
πŸ“Œ Increased penalties for non-compliance
πŸ“Œ Potential expansion of opt-in consent requirements for targeted ads

Montana’s MTCDPA is a model for future U.S. state privacy laws, with a focus on consumer control, opt-out mechanisms, and enhanced transparency.

NEW GEN AI

Get answers to even the most complex questions about your data and explore the complexities of your data landscape using Generative AI chat.