Montana MCDPA checklist
An 11-step action checklist for MCDPA compliance efforts after SB 297: scope, notices, opt-outs, GPC, sensitive data, minors, DPIAs, penalties.
An 11-step action checklist for MCDPA compliance efforts after SB 297: scope, notices, opt-outs, GPC, sensitive data, minors, DPIAs, penalties.
Use this checklist to review your business against the Montana Consumer Data Privacy Act (MCDPA), including the changes introduced by Senate Bill 297. Each step focuses on a specific action you can work through with your team or legal counsel.
For a deeper explanation of what SB 297 changed and how the MCDPA applies, read Clym’s Montana Consumer Data Privacy Act business guide first, then return to this checklist to put those requirements into practice.
Work through the 11 items below in order. Each one explains what to check and what action to take, without repeating the full legal background.
The previous cure period has been removed. Any gaps you identify should be addressed promptly rather than relying on an opportunity to fix them after notice.
Your privacy notice now needs additional information, including a clear explanation of consumer rights, a last-updated date, and an accessible privacy link on your homepage.
Montana requires businesses to recognize and honor qualifying universal opt-out signals, including GPC. Test this functionality on your live site rather than assuming it is working correctly.
The law’s duty of care relating to minors applies separately from the general consumer thresholds, so review those requirements even if your business falls outside the main MCDPA scope.
The MCDPA likely applies if your business meets either of these thresholds:
If you control or process the personal data of 25,000 or more Montana consumers per year
Do you control or process the personal data of 15,000 or more Montana consumers per year, and derive more than 25 percent of your gross revenue from selling personal data?
If either applies, continue through all 11 steps below. Even if neither threshold applies, review Step 10 separately because the minors’ duty of care is not limited by these general thresholds.
Reassess your scope using the current 25,000 and 15,000-plus-revenue thresholds rather than the MCDPA’s original thresholds.
Record the date and basis for your determination
If you previously relied on a GLBA exemption, confirm whether a specific bank, credit union, or insurer exemption now applies instead
Separately confirm whether minors knowingly or unknowingly use your service, since Step 10 applies regardless of your threshold result
List every category of personal data you collect, including whether it is sensitive or belongs to a known child
Document the purpose for collecting and processing each category
Document which third parties each category is shared with, and why
Cut any collection point that gathers more data than the stated purpose requires
Add a clear, plain-language explanation of consumer rights under the MCDPA
Add the date the notice was last updated
Add a conspicuous hyperlink using the word “privacy” on your homepage
Publish the notice in every language you offer a product or service in
Confirm the notice is reasonably accessible to people with disabilities
Notify consumers and give them a chance to withdraw consent if you make a material change
A privacy and cookie policy solution can manage versioning, update dates, and language variations from one place.
Disclose data sales and targeted advertising clearly in your privacy notice
Build an opt-out method that is at least as easy to use as your original consent mechanism
Confirm the opt-out doesn’t require creating an account or navigating multiple pages
Confirm exercising the opt-out doesn’t reduce service quality or pricing for that consumer
Confirm your site detects Global Privacy Control (GPC) signals from Montana visitors
Confirm a detected signal automatically suppresses sale and targeted-advertising processing, with no extra steps for the visitor
Test this on your live site rather than assuming your platform or vendor already handles it
A consent management platform can detect these signals and apply the correct preference automatically.
Confirm opt-in consent is required, not a pre-checked box or bundled consent, before processing any of the following:
Racial or ethnic origin
Religious beliefs
Mental or physical health diagnosis
Sexual orientation or transgender status
Citizenship or immigration status
Genetic or biometric data used for identification
Precise geolocation data
Personal data from a known child under 13, with parental consent
Set up intake, identity verification, and tracking for consumer requests
Confirm you can respond within 45 days, with a documented process for the one-time 45-day extension
Confirm your consent revocation method is at least as easy to use as your original consent mechanism
A data subject request workflow helps track intake, deadlines, and documentation without manual spreadsheets.
Complete an assessment before using data for targeted advertising
Complete an assessment before selling personal data
Complete an assessment before processing sensitive personal data
Complete an assessment before profiling with legal or similarly significant effects
Store assessments somewhere your team can produce them quickly. The AG can request a copy through a civil investigative demand
Confirm each processor contract states clear processing instructions, nature, and purpose
Confirm each contract requires security measures appropriate to the risk and sensitivity of the data
Confirm each contract requires the processor to assist with your MCDPA obligations
Confirm subprocessors are bound by the same obligations
Identify whether your service, product, or feature could reasonably be used by a minor, even if you don’t market to minors
If yes, document reasonable care taken to avoid a heightened risk of harm from the service
Complete this step regardless of whether you meet the standard consumer thresholds
Confirm your team knows the MCDPA no longer includes a cure period.
Make sure relevant teams understand that enforcement penalties can reach $7,500 per violation.
Confirm your team knows that the Montana attorney general is responsible for enforcing the MCDPA and that the law does not provide a private right of action.
Using the original 2023 thresholds instead of the current, lower SB 297 figures
Assuming a GLBA exemption still applies without checking the specific carve-outs
Treating GPC as optional now that no cure period is available
Skipping the minors’ duty of care because the business doesn’t meet the standard thresholds
Publishing a notice without the homepage “privacy” link or a last-updated date
Review your privacy notice and data practices at least once a year and whenever processing activities change materially
Monitor Montana Department of Justice guidance for how enforcement is being applied
Update your data map whenever you add new vendors, tools, or data collection methods
If you operate across multiple states, Clym’s U.S. state privacy law comparison guide covers thresholds, cure periods, and enforcement side by side
Present the right consent or opt-out experience to Montana visitors with geofencing and localization features that detect visitor location automatically
Automatically recognize and respond to GPC signals through Clym’s consent management platform
Handle data subject requests in a structured workflow with intake, tracking, and documentation
Keep privacy notices current, including the rights explanation, last-updated date, and homepage link SB 297 requires
Clym does not guarantee compliance. Your obligations depend on your specific data practices, legal advice, and internal processes. The platform provides tools to support your privacy operations and help you work toward the MCDPA’s requirements.
Work through these 11 steps in order, starting with your thresholds. Since there is no cure period, treat anything you find as a priority rather than something to revisit later.
For the full explanation behind any of these requirements, the reasoning for SB 297’s changes, and how Montana compares to other state privacy laws, go back to Clym’s Montana Consumer Data Privacy Act business guide.
It’s an action checklist for working through Montana Consumer Data Privacy Act requirements as amended by SB 297. Each step tells you what to check and do. For background on what changed and why, see Clym’s Montana Consumer Data Privacy Act business guide.
Any business that operates in Montana or targets Montana residents and meets the current consumer thresholds, plus any business unsure whether minors use its service, since that duty applies regardless of thresholds.
Start with Step 1. Most gaps trace back to using outdated 2023 thresholds, which changes what else on this list actually applies to you.
Yes, before targeted advertising, selling personal data, processing sensitive personal data, or profiling with legal or similarly significant effects. Keep it on file since the attorney general can request it.
45 days, with one additional 45-day extension available when reasonably necessary.
No. It applies to any business offering a service, product, or feature to a consumer it knows or willfully disregards is a minor, regardless of whether the business meets the standard thresholds.