Montana Consumer Data Privacy

Montana Senate Bill 297 Rights and Responsibilities Information

The Montana Office of Consumer Protection (“OCP”) has prepared the following summaries to help consumers and businesses understand SB 297’s changes, as the below is not exhaustive. The MCDPA is codified at MCA 30-14-2801, et seq. Interested parties are encouraged to read the statute to understand their respective rights and responsibilities.

Senate Bill 297 (“SB 297”) revises portions of Montana’s Consumer Data Privacy Act (“MCDPA”) and was effective October 1, 2025.

Consumer Rights

The MCDPA grants Montana consumers certain rights over the control and processing of their personal data. Montanans have a right to know what personal data is collected and processed, a right to correct inaccuracies in personal data, a right to delete personal data about the consumer, and a right to obtain a copy of the consumer’s personal data. Consumers also have the right to opt out of the sale of personal data, use of personal data for targeted advertisements, or use of personal data for profiling purposes.

Controllers and processors must provide consumers with clear and conspicuous means to exercise their rights under the MCDPA.

Applicability of MCDPA

The MCDPA applies to those that conduct business in the State of Montana and control or process the personal data of 25,000 consumers (formerly 50,000). However, if the company makes more than 25 percent of its revenue from the sale of “personal data”, then the threshold is 15,000 consumers (formerly 25,000).

SB 297 also states the MCDPA applies to those that conduct business in the State of Montana or deliver commercial products/services that are intentionally targeted at Montana residents.

“Personal data” means any information that is linked or reasonably linkable to an identified or identifiable individual and does not include de-identified data or publicly available information.

A “controller” is an individual or legal entity that, alone or with others, determines the purpose and means of processing personal data. A “processor” is an individual or legal entity that processes personal data on behalf of a controller. A contract between a controller and a processor must satisfy the requirements of MCA § 30-14-2813.

Revised Applicability Exemptions

SB 297 eliminates the Gramm-Leach Bliley Act-entity (“financial institution”) exemption but keeps the data exemption. The bill adds exemptions for banks, credit unions, insurers, and insurance producers. SB 297 also limits the nonprofit exemption to nonprofit organizations that detect/prevent fraud in connection with insurance.

Controller and Processor Responsibilities

The MDCPA requires entities only collect and process personal data that is related to the purposes for which the personal data is processed, as disclosed to the consumer. Controllers must provide an effective mechanism for consumers to exercise their rights, or revoke consent, that is at least as easy to use as the mechanism for the consumer to give consent.

SB 297 revises the privacy notice requirements by obligating controllers to include an explanation of rights under the MDCPA as well as the date the privacy notice was last updated. When a material change is made to a controller’s privacy notice or practices, the controller shall notify consumers and provide a reasonable opportunity for consumers to withdraw consent. The privacy notice must be posted online through a conspicuous hyperlink using the word “privacy” on the controller’s website homepage. Controllers must also make the privacy notice available to the public in each language in which the controller provides a product or service and in a manner that is reasonably accessible to and useable by individuals with disabilities.

SB 297 requires a controller that sells personal data to third parties or processes personal data for targeted advertising to clearly and conspicuously disclose the processing in its privacy notice and provide access to a clear and conspicuous method for a consumer to opt out of the sale or processing of personal data.

With regard to minors, SB 297 requires a controller offering an online service, product, or feature to a consumer whom the controller knows or willfully disregards is a minor to use reasonable care to avoid a “heightened risk of harm” to the minor caused by the online service, product, or feature.

A processor must adhere to the instructions of a controller and shall assist the controller in meeting the controller’s obligations under the MDCPA. The processor shall assist the controller by: (1) taking appropriate technical and organizational measures for the fulfillment of the controller’s obligations; and (2) providing information to enable the controller to conduct and document data protections assessments.

Civil Penalties

SB 297 adds a maximum civil penalty of up to $7,500 per violation and allows the Attorney General to seek an injunction as well as reasonable attorney fees and costs related to investigation and enforcement.