Key Takeaways
- The MTCDPA has applied since October 1, 2024, and Montana's Senate Bill 297 substantially rewrote it effective October 1, 2025.
- The applicability thresholds are now 25,000 consumers, or 15,000 consumers plus 25%+ of gross revenue from selling personal data, down from the original 50,000 and 25,000 figures. That's the lowest bar of any state privacy law.
- The 60-day cure period no longer exists. SB 297 eliminated it entirely, six months before its own original April 1, 2026 sunset date.
- Civil penalties reach $7,500 per violation, enforced exclusively by the Montana Attorney General. There is no private right of action.
- Montana requires businesses to honor universal opt-out signals like Global Privacy Control, a requirement that took effect January 1, 2025.
- SB 297 also added new minors'-privacy provisions: consent is required before targeted advertising, sale, or precise-geolocation collection involving a known minor under 18.
The Montana Consumer Data Privacy Act (MTCDPA) is Montana's state privacy law, granting consumers rights over their personal data and requiring businesses to meet specific data-handling obligations. It took effect October 1, 2024, and a 2025 amendment, Senate Bill 297, changed several of its core mechanics: who it applies to, whether businesses get a chance to fix a violation before being fined, and what protections minors get. A lot of MTCDPA content still describes the law as it looked at launch. Below is what actually applies today.
Secure Privacy is a cookie and consent management platform that generates MTCDPA-compliant consent flows, including the universal opt-out signal recognition Montana requires, alongside GDPR, CCPA, and 55+ other privacy laws.
Who Does the MTCDPA Apply To?
The MTCDPA applies to businesses that conduct business in Montana, or that produce or deliver commercial products or services intentionally targeted to Montana residents, and that meet at least one of two thresholds. As of October 1, 2025, those thresholds are lower than they were at launch: a business is in scope if it controls or processes the personal data of 25,000 or more Montana consumers in a year (excluding data processed solely to complete a payment transaction), or if it controls or processes the data of 15,000 or more consumers while also deriving more than 25% of its gross revenue from selling personal data.
Both figures dropped from the original 2023 law, which set the bars at 50,000 and 25,000. Montana's population is only slightly over 1 million, so even the original thresholds were already the lowest among state privacy laws; SB 297 made that gap wider. A business doesn't need much Montana traffic before it's processing enough data to fall in scope. Running Google Analytics on a site that draws a modest amount of Montana visitors can be enough on its own.
Who Is Exempt from the MTCDPA?
Government bodies, nonprofit organizations, and higher-education institutions sit outside the MTCDPA's scope entirely. Financial institutions are also exempt, though SB 297 narrowed this to a data-level exemption: a GLBA-regulated institution is only exempt for the specific data GLBA already governs, not for every activity it conducts. Entities and information regulated under HIPAA are exempt as well.
Certain data categories are also carved out regardless of who holds them: data governed by the Fair Credit Reporting Act, FERPA, the Driver's Privacy Protection Act, the Farm Credit Act, and similar federal frameworks; health records; human subjects research data; employment data; de-identified data; and publicly available information.
What Is Personal Data Under the MTCDPA?
Personal data is any information linked to an identified or identifiable Montana resident: obvious identifiers like names, email addresses, and Social Security numbers, and data that can be traced back to a specific person, such as browsing behavior, IP addresses, and purchase history.
A narrower category, sensitive data, carries extra protection: personal data revealing racial or ethnic origin, religious beliefs, a mental or physical health diagnosis, or citizenship or immigration status; genetic or biometric data processed to identify someone; the personal data of a known child; and precise geolocation data.
What Rights Do Montana Consumers Have?
Montana consumers can confirm whether a business is processing their personal data, access it, correct inaccuracies, delete it, and obtain a portable copy. They can also opt out of the sale of their data, its use for targeted advertising, and profiling that produces legal or similarly significant effects, such as decisions about credit, housing, or employment.
Businesses have 45 days to respond to a rights request, with one additional 45-day extension for complex or numerous requests. One restriction SB 297 added: a controller cannot be required to disclose a Social Security number, government ID number, financial account number, or biometric data in response to an access request, even if that data technically falls within its scope.
What Obligations Do Businesses Have?
Controllers, the businesses that decide why and how personal data gets processed, have core duties: process only the minimum data necessary for the stated purpose (data minimization), use it only for the purpose it was collected for (purpose limitation), give consumers a clear privacy notice, honor rights requests, and put a written contract in place with every processor (the service providers, like an email platform or ad network, that process data on the controller's behalf).
The MTCDPA generally runs on an opt-out model: a business can process ordinary personal data without asking permission first, until a consumer opts out. Sensitive data is the exception, requiring opt-in consent before collection, as does a known child's data and a minor's data (13 to 17) used for targeted advertising or sale. The law bans dark patterns, bundling consent into broader terms and conditions, and cookie walls that block content until a user agrees.
A privacy notice has to disclose the categories of data processed, the purposes for processing, which third parties receive data and what categories, and how consumers can exercise their rights. SB 297 added multilingual and accessibility expectations and calls for a clear opt-out mechanism separate from the notice itself, such as a dedicated "Your Privacy Choices" link.
When Is a Data Protection Assessment Required?
The MTCDPA requires a documented data protection assessment before starting any processing activity that presents a heightened risk of harm to consumers: targeted advertising, selling personal data, profiling that could lead to unfair or deceptive treatment or financial, physical, or reputational injury, and processing sensitive data generally. SB 297 extended this requirement to processing that poses a heightened risk to minors. The Attorney General can request any assessment to evaluate compliance, including through a civil investigative demand.
Do Businesses Have to Honor Universal Opt-Out Signals?
Yes. Since January 1, 2025, businesses have had to recognize and honor opt-out preference signals, commonly called universal opt-out mechanisms, with Global Privacy Control being the best-known example. A consumer sets the signal once, typically at the browser or device level, and it functions as a valid opt-out of data sale and targeted advertising across every site visited, rather than requiring a separate opt-out on each one. The signal only counts when the consumer has taken an affirmative step to enable it themselves.
What Protections Do Minors Get?
SB 297 added minors'-privacy provisions that apply to any business conducting business in or targeting Montana, regardless of the general thresholds. Controllers need consent before collecting a known minor's precise geolocation, and before using a minor's data for targeted advertising or sale. The law also expects reasonable care to avoid heightened risk of harm to consumers under 18, including avoiding consent mechanisms or design features built to impair a minor's autonomy or maximize engagement, and conducting a data protection assessment when heightened risk is present.
What Are the Penalties for Violating the MTCDPA?
The Montana Attorney General has exclusive enforcement authority; individual consumers cannot sue a business directly. Civil penalties reach $7,500 per violation, a figure SB 297 formally codified into the statute, and the Attorney General can also seek an injunction and recover attorney fees and investigation costs.
The change that matters most for any business facing enforcement today: the MTCDPA originally gave businesses a 60-day cure period, a window to fix a violation after notice before a fine could be imposed, with its own sunset clause set to expire April 1, 2026. SB 297 closed it early, effective October 1, 2025, six months ahead of schedule. As of that date, the Attorney General can bring an enforcement action without first offering a chance to correct the violation, unlike a violator in 2024 or early 2025.
MTCDPA Compliance Checklist
- Confirm whether you meet either threshold: 25,000+ Montana consumers, or 15,000+ consumers with 25%+ of revenue from data sales.
- Publish a privacy notice covering processing purposes, data categories, third-party sharing, and how to exercise rights, with a separate, clearly labeled opt-out link.
- Build a process to honor consumer requests (confirmation, access, correction, deletion, portability, opt-out) within 45 days, with a documented path to extend by another 45 days for complex requests.
- Recognize Global Privacy Control and similar universal opt-out signals across your site.
- Obtain opt-in consent before processing sensitive data, a known child's data, or a minor's data for targeted advertising or sale.
- Put written data processing agreements in place with every processor you use.
- Run and document a data protection assessment for any high-risk processing activity, including anything affecting minors.
- Treat every violation as unfixable after the fact. Since October 1, 2025, there's no cure period to fall back on.
FAQ
When did the Montana Consumer Data Privacy Act take effect?
October 1, 2024. Senate Bill 297 then amended it effective October 1, 2025, changing the thresholds, eliminating the cure period, and adding minors'-privacy provisions.
Does the MTCDPA still have a cure period?
No. It had a 60-day cure period with a sunset clause set for April 1, 2026, but SB 297 eliminated it early, effective October 1, 2025. Enforcement today comes with no advance notice-and-fix window.
What are the current MTCDPA applicability thresholds?
25,000 or more Montana consumers per year, or 15,000 or more consumers combined with deriving over 25% of gross revenue from selling personal data. Both figures dropped from the original 50,000 and 25,000 when SB 297 took effect.
What is the penalty for violating the MTCDPA?
Up to $7,500 per violation, enforced exclusively by the Montana Attorney General, who can also seek an injunction and recover fees and investigation costs. There is no private right of action.
Does the MTCDPA require honoring Global Privacy Control?
Yes. Since January 1, 2025, businesses have had to honor universal opt-out signals like Global Privacy Control as a valid opt-out of data sale and targeted advertising.
Are nonprofits exempt from the MTCDPA?
Yes, along with government bodies, higher-education institutions, HIPAA-regulated entities, and GLBA-covered financial institutions for the data GLBA already governs.
What did SB 297 change about minors' data?
It requires consent before collecting a known minor's precise geolocation or using a minor's data for targeted advertising or sale, adds a duty to avoid design features that impair a minor's autonomy, and mandates data protection assessments for high-risk processing involving minors.
Sources
- Montana Consumer Data Privacy, Montana Department of Justice, Office of Consumer Protection
- Amendments to the Montana Consumer Data Privacy Act Bring Big Changes to Big Sky Country, Future of Privacy Forum
- Montana Amends Consumer Data Privacy Act, Hunton Andrews Kurth Privacy and Cybersecurity Law Blog
- Montana Enacts Law Amending Consumer Data Privacy Act, Increasing Consumer Protections and Enforcement, Thompson Coburn LLP
- Big Sky, Bigger Privacy: Montana Broadens Its Consumer Data Privacy Act, Bass, Berry & Sims PLC


