Montana Consumer Data Privacy Act
Scope and Authority - Montana CDPA

Montana Consumer Data Privacy Act MT-CDPA-Scope-SB-384-Gianforte-19-May-2023-Effective-1-October-2024-MCA-30-14-2801-AG-Knudsen-50K-Threshold: Montana CDPA Scope + SB 384 + Gianforte 19 May 2023 + Effective 1 October 2024 + MCA 30-14-2801 + AG Knudsen + 50K Threshold

Establish the legal foundation of Montana Consumer Data Privacy Act + Senate Bill 384 (SB 384) sponsored by Senator Daniel Zolnikov + signed by Governor Greg Gianforte 19 May 2023 + codified at Montana Code Annotated Title 30 Chapter 14 Part 28 (MCA 30-14-2801 through 30-14-2818) + effective 1 October 2024 + 9th US state to enact comprehensive consumer privacy law. Constitutional anchor Montana Constitution Article II Section 10 right of individual privacy (one of strongest state constitutional privacy protections in US). Montana Attorney General (Austin Knudsen) Office of Consumer Protection EXCLUSIVE enforcement - NO private right of action. **LOWEST THRESHOLD OF US STATE PRIVACY LAWS**: 50,000 Montana consumers controlled/processed (excluding payment transactions) OR 25,000 consumers AND 25% revenue from sale of personal data + reflecting Montana population ~1.1M + emphasizes Montana legislative intent to capture mid-size businesses serving Montana residents. Carve-outs HIPAA + GLBA + FCRA + DPPA + FERPA + Air Carrier + Montana state/local government + small businesses (under 25 FTE with exemptions) + tax-exempt nonprofits + Montana Insurance Code privacy entities. Coordinate with Montana Genetic Information Privacy Act 2023 (separately enacted) + Montana Online Personal Information Theft Prevention Act + Montana Consumer Protection Act (Mont. Code Ann. 30-14-101 et seq).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 118 controls across 44 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 5 controls

  • GDPR-Art.10 Processing of personal data relating to criminal convictions
  • GDPR-Art.11 Processing which does not require identification
  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction
  • GDPR-Art.9 Processing of special categories of personal data

APPI · 3 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing

Bahrain PDPL · 3 controls

  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer

ISO/IEC 29100:2024 · 3 controls

ISO/IEC 29134:2023 · 3 controls

Malaysia PDPA 2010 · 3 controls

South Korea ISMS-P · 3 controls

  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)

ISO/IEC 27014:2020 · 2 controls

ISO/IEC 27400:2022 · 2 controls

Mauritius DPA · 2 controls

Mexico LFPDPPP · 2 controls

  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data
  • DS-2 Ensure software supply chain security
  • CA-10 Selects and Develops Control Activities

ISO/IEC 23894:2023 · 1 control

  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)

South Korea PIPA · 1 control

  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Turkey KVKK · 1 control

  • USCOPPA-3 Data Minimisation, Retention, Erasure (Eraser Button)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 118 it maps to, and the evidence behind each claim, over MCP and REST.