Clym Logo

2026 Montana Consumer Data Privacy Act (MCDPA) Checklist: 11 Steps for Your Business

Published
AS
AuthorAdam Safar
7 min read

Montana MCDPA checklist

An 11-step action checklist for MCDPA compliance efforts after SB 297: scope, notices, opt-outs, GPC, sensitive data, minors, DPIAs, penalties.

Summarize full article with:

Use this checklist to review your business against the Montana Consumer Data Privacy Act (MCDPA), including the changes introduced by Senate Bill 297. Each step focuses on a specific action you can work through with your team or legal counsel.

For a deeper explanation of what SB 297 changed and how the MCDPA applies, read Clym’s Montana Consumer Data Privacy Act business guide first, then return to this checklist to put those requirements into practice.

Work through the 11 items below in order. Each one explains what to check and what action to take, without repeating the full legal background.

Key takeaways   * Start by reassessing whether the MCDPA applies to your business. SB 297 lowered the thresholds, so an earlier scope assessment may no longer be accurate.
  • The previous cure period has been removed. Any gaps you identify should be addressed promptly rather than relying on an opportunity to fix them after notice.

  • Your privacy notice now needs additional information, including a clear explanation of consumer rights, a last-updated date, and an accessible privacy link on your homepage.

  • Montana requires businesses to recognize and honor qualifying universal opt-out signals, including GPC. Test this functionality on your live site rather than assuming it is working correctly.

  • The law’s duty of care relating to minors applies separately from the general consumer thresholds, so review those requirements even if your business falls outside the main MCDPA scope.

Quick MCDPA applicability check

The MCDPA likely applies if your business meets either of these thresholds:

  1. If you control or process the personal data of 25,000 or more Montana consumers per year

  2. Do you control or process the personal data of 15,000 or more Montana consumers per year, and derive more than 25 percent of your gross revenue from selling personal data?

If either applies, continue through all 11 steps below. Even if neither threshold applies, review Step 10 separately because the minors’ duty of care is not limited by these general thresholds.

Step 1: Confirm scope under the current thresholds

  • Reassess your scope using the current 25,000 and 15,000-plus-revenue thresholds rather than the MCDPA’s original thresholds.

  • Record the date and basis for your determination

  • If you previously relied on a GLBA exemption, confirm whether a specific bank, credit union, or insurer exemption now applies instead

  • Separately confirm whether minors knowingly or unknowingly use your service, since Step 10 applies regardless of your threshold result

Step 2: Map your personal data and apply data minimization

  • List every category of personal data you collect, including whether it is sensitive or belongs to a known child

  • Document the purpose for collecting and processing each category

  • Document which third parties each category is shared with, and why

  • Cut any collection point that gathers more data than the stated purpose requires

Step 3: Update your privacy notice for SB 297

  • Add a clear, plain-language explanation of consumer rights under the MCDPA

  • Add the date the notice was last updated

  • Add a conspicuous hyperlink using the word “privacy” on your homepage

  • Publish the notice in every language you offer a product or service in

  • Confirm the notice is reasonably accessible to people with disabilities

  • Notify consumers and give them a chance to withdraw consent if you make a material change

A privacy and cookie policy solution can manage versioning, update dates, and language variations from one place.

Step 4: Set up opt-out disclosures for sale and targeted advertising

  • Disclose data sales and targeted advertising clearly in your privacy notice

  • Build an opt-out method that is at least as easy to use as your original consent mechanism

  • Confirm the opt-out doesn’t require creating an account or navigating multiple pages

  • Confirm exercising the opt-out doesn’t reduce service quality or pricing for that consumer

Step 5: Turn on GPC and other opt-out signal recognition

  • Confirm your site detects Global Privacy Control (GPC) signals from Montana visitors

  • Confirm a detected signal automatically suppresses sale and targeted-advertising processing, with no extra steps for the visitor

  • Test this on your live site rather than assuming your platform or vendor already handles it

A consent management platform can detect these signals and apply the correct preference automatically.

Step 6: Fix consent for sensitive data and children’s data

Confirm opt-in consent is required, not a pre-checked box or bundled consent, before processing any of the following:

  • Racial or ethnic origin

  • Religious beliefs

  • Mental or physical health diagnosis

  • Sexual orientation or transgender status

  • Citizenship or immigration status

  • Genetic or biometric data used for identification

  • Precise geolocation data

  • Personal data from a known child under 13, with parental consent

Step 7: Build a data subject rights process

  • Set up intake, identity verification, and tracking for consumer requests

  • Confirm you can respond within 45 days, with a documented process for the one-time 45-day extension

  • Confirm your consent revocation method is at least as easy to use as your original consent mechanism

A data subject request workflow helps track intake, deadlines, and documentation without manual spreadsheets.

Step 8: Complete data protection assessments for high-risk processing

  • Complete an assessment before using data for targeted advertising

  • Complete an assessment before selling personal data

  • Complete an assessment before processing sensitive personal data

  • Complete an assessment before profiling with legal or similarly significant effects

  • Store assessments somewhere your team can produce them quickly. The AG can request a copy through a civil investigative demand

Step 9: Review contracts with data processors

  • Confirm each processor contract states clear processing instructions, nature, and purpose

  • Confirm each contract requires security measures appropriate to the risk and sensitivity of the data

  • Confirm each contract requires the processor to assist with your MCDPA obligations

  • Confirm subprocessors are bound by the same obligations

Step 10: Confirm your minors’ duty of care

  • Identify whether your service, product, or feature could reasonably be used by a minor, even if you don’t market to minors

  • If yes, document reasonable care taken to avoid a heightened risk of harm from the service

  • Complete this step regardless of whether you meet the standard consumer thresholds

Step 11: Review your enforcement readiness

  • Confirm your team knows the MCDPA no longer includes a cure period.

  • Make sure relevant teams understand that enforcement penalties can reach $7,500 per violation.

  • Confirm your team knows that the Montana attorney general is responsible for enforcing the MCDPA and that the law does not provide a private right of action.

Common MCDPA checklist mistakes

  • Using the original 2023 thresholds instead of the current, lower SB 297 figures

  • Assuming a GLBA exemption still applies without checking the specific carve-outs

  • Treating GPC as optional now that no cure period is available

  • Skipping the minors’ duty of care because the business doesn’t meet the standard thresholds

  • Publishing a notice without the homepage “privacy” link or a last-updated date

How to stay on top of MCDPA changes

  • Review your privacy notice and data practices at least once a year and whenever processing activities change materially

  • Monitor Montana Department of Justice guidance for how enforcement is being applied

  • Update your data map whenever you add new vendors, tools, or data collection methods

  • If you operate across multiple states, Clym’s U.S. state privacy law comparison guide covers thresholds, cure periods, and enforcement side by side

How Clym can support your MCDPA privacy program

  • Present the right consent or opt-out experience to Montana visitors with geofencing and localization features that detect visitor location automatically

  • Automatically recognize and respond to GPC signals through Clym’s consent management platform

  • Handle data subject requests in a structured workflow with intake, tracking, and documentation

  • Keep privacy notices current, including the rights explanation, last-updated date, and homepage link SB 297 requires

Clym does not guarantee compliance. Your obligations depend on your specific data practices, legal advice, and internal processes. The platform provides tools to support your privacy operations and help you work toward the MCDPA’s requirements.

Conclusion

Work through these 11 steps in order, starting with your thresholds. Since there is no cure period, treat anything you find as a priority rather than something to revisit later.

For the full explanation behind any of these requirements, the reasoning for SB 297’s changes, and how Montana compares to other state privacy laws, go back to Clym’s Montana Consumer Data Privacy Act business guide.

Frequently asked questions

It’s an action checklist for working through Montana Consumer Data Privacy Act requirements as amended by SB 297. Each step tells you what to check and do. For background on what changed and why, see Clym’s Montana Consumer Data Privacy Act business guide.

Any business that operates in Montana or targets Montana residents and meets the current consumer thresholds, plus any business unsure whether minors use its service, since that duty applies regardless of thresholds.

Start with Step 1. Most gaps trace back to using outdated 2023 thresholds, which changes what else on this list actually applies to you.

Yes, before targeted advertising, selling personal data, processing sensitive personal data, or profiling with legal or similarly significant effects. Keep it on file since the attorney general can request it.

45 days, with one additional 45-day extension available when reasonably necessary.

No. It applies to any business offering a service, product, or feature to a consumer it knows or willfully disregards is a minor, regardless of whether the business meets the standard thresholds.

Adam Safar

Head of Digital Marketing

Adam is the Head of Digital Marketing at Clym, where he leverages his diverse expertise in marketing to support businesses with their compliance needs and drive awareness about data privacy and web accessibility. As one of the company’s original team members, Adam has been instrumental in shaping its journey from the very beginning. When he’s not diving into marketing strategies, Adam can be found cheering on his favorite sports teams or enjoying fishing.

Find out more about Adam