Skip to content

The Letter About Your Information

Minn. Stat. 325E.61 — the most expedient time possible, and the credit bureaus within 48 hours above 500

In Minnesota, a person that must disclose a breach of the security of its data system does so in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and the measures needed to determine the scope of the breach, identify the individuals affected and restore the system.

Email
Who is toldWhen, as the section puts it
Who is toldEach affected individualWhen, as the section puts itThe most expedient time possible and without unreasonable delay
Who is toldThe consumer reporting agencies, if more than 500 persons are notified at one timeWhen, as the section puts itWithin 48 hours
  • The attorney general enforces the section.

What counts as personal information, the forms notice may take, and the exceptions for encrypted data are in the section and are not reproduced in full here. Whether a notice was required or on time is a question for the attorney general, a court, and a licensed Minnesota attorney.

Sources for this section (1)
  1. Minn. Stat. 325E.61 — Data warehouses; notice required for certain disclosures

Legal information, not legal advice. Verified as of September 2026. Applying it to a particular situation is the work of a licensed Minnesota attorney.

On the clock

One period on this page runs out. Each is stated above with its authority; this is the same thing with the date attached.

  • 48 hoursTelling the credit bureaus about a breach of more than 500 persons · from discovering the circumstances requiring notice

From here