Minnesota Consumer Data Privacy Act
Universal Opt-Out Sensitive and Health Data - Minnesota CDPA

Minnesota Consumer Data Privacy Act MN-CDPA-Universal-Opt-Out-GPC-Sensitive-Data-Section-325O-02-Consumer-Health-Data-Children-Known-Child-Transgender: Minnesota CDPA Universal Opt-Out + GPC + Sensitive + Section 325O.02 + Consumer Health Data + Children + Known Child + Transgender

Recognise Universal Opt-Out Mechanism (Global Privacy Control GPC) mandatory from 31 July 2025 + process sensitive data and consumer health data under enhanced conditions. GPC alignment with Colorado + Connecticut + Texas + California + Delaware + Montana + Nebraska + New Hampshire + New Jersey + Oregon. Sensitive Data Section 325O.02 Subdivision 32: racial or ethnic origin + religious beliefs + mental or physical health diagnosis + sexual orientation + citizenship or immigration status + genetic data + biometric data + precise geolocation data + personal data of known child + transgender or nonbinary status (Minnesota-specific addition during legislative process). Affirmative opt-in consent required for sensitive data processing. Consumer Health Data Section 325O.02 Subdivision 10 SEPARATELY defined category covering mental/physical health + reproductive/sexual health + gender-affirming care + diagnoses + treatments + medications + healthcare service use (similar to Washington My Health My Data + Maryland MODPA). Children under 13 require parental consent (FERPA-style). Minors 13-16 processing requires opt-in. Sale of consumer health data + sensitive data of minors restricted. Minnesota Genetic Information Privacy Act parallel application. Minnesota Health Records Act Chapter 144.291-298 coordination.

What else in your programme already covers this

This control maps to 89 controls across 51 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27043 · 4 controls

ISO/SAE 21434 · 4 controls

  • PQC-2 FIPS 203 ML-KEM Implementation - Module-Lattice Key-Encapsulation Mechanism
  • PQC-5 Cryptographic Inventory and PQC Migration Roadmap
  • PQC-7 FIPS Validated Modules, HSM Readiness, and Algorithm Validation
  • PQC-8 Implementation Requirements - RNG, Side-Channel, Key Management, Operations, Incident Response
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection

ISO 13485 · 2 controls

  • 6.6 Confidentiality or non-disclosure agreements
  • 6.7 Conducting Audit Follow-up

ISO 19011 · 2 controls

  • 6.6 Confidentiality or non-disclosure agreements
  • 6.7 Conducting Audit Follow-up

ISO 27799 · 2 controls

ISO 31000:2018 · 2 controls

  • 6.6 Confidentiality or non-disclosure agreements
  • 6.7 Conducting Audit Follow-up

OWASP ASVS · 2 controls

OWASP MASVS · 2 controls

OWASP Top 10:2025 · 2 controls

  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)

APPI · 1 control

  • APPI-A34 Request for Correction, Addition or Deletion
  • ASD37-17 TLS encryption between email servers (Limited)

BSI IT-Grundschutz · 1 control

  • BSI-08 Cryptographic protection of data

Bahrain PDPL · 1 control

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • 62351-9 Cyber security key management

ISO 20000-1 · 1 control

  • 9.1 Risk communication and consultation

ISO 27005 · 1 control

  • 9.1 Risk communication and consultation

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO/IEC 27010:2015 · 1 control

ISO/IEC 27011:2024 · 1 control

ISO/IEC 27400:2022 · 1 control

MITRE ATT&CK · 1 control

MITRE D3FEND · 1 control

Malaysia PDPA 2010 · 1 control

Mauritius DPA · 1 control

Mexico LFPDPPP · 1 control

  • NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment
  • OWASPAPI-6 Security Misconfiguration and Secure API Design
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information

South Korea ISMS-P · 1 control

Turkey KVKK · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 89 it maps to, and the evidence behind each claim, over MCP and REST.