As a business professional, you’re likely aware of the fact that your customers expect to maintain their privacy and be informed about how you are using their data. But this becomes more challenging as technology evolves and new regulations come into effect. The Montana Consumer Data Privacy Act (MCDP) is one law that could have a major impact on the financial services sector in particular, so it’s important to understand its implications for your company. In this blog post, we’ll provide an overview of MCDP’s requirements and explain why businesses need to pay attention if they operate in or collect information from residents within Montana state boundaries.
Overview of the Montana Consumer Data Privacy Act
On May 19, 2023, Montana Governor Greg Gianforte signed the Montana Consumer Data Privacy Act (MTCDPA). Act will go into effect October 1, 2024.The law grants Montana’s consumers the right to control their personal information and provides businesses with a framework for how they must collect, use, store, secure and share that data.
further, The Montana bill needs the controllers to implement universal opt-out mechanisms for data subjects “to opt out of any processing of the consumer’s personal data for the purposes of targeted advertising, or any sale of such personal data through an opt-out preference signal sent with the consumer’s consent, to the controller by a platform, technology” by January 1, 2025.
To Whom Does the Montana Consumer Data Privacy Act Apply?
The MCDPA applies to businesses who do business in Montana or sell products or services to Montana residents.and,
– Control or process 50,000 or more Montana customers’ personal data (except personal data managed or processed merely for the purpose of executing a payment transaction); or
– Control or process the personal data of 25,000 or more Montana customers and generate more than 25% of revenue from the sale of such data.
Who Is Exempt under MCDPA?
The MCDPA does not apply to government bodies, nonprofit organizations, or institutes of higher education.
MCDPA Enforcement
The Montana Consumer Data Privacy Act is enforced by the Montana Attorney General. The Montana Attorney General must first give violators an opportunity to fix violations within 60 days of receiving notice of a violation before filing an action for a violation of the MCDPA. This right to cure, however, expires on April 1, 2026.
How does MBDPL Protect Consumers and their Data
The MBDPL provides consumers with a range of rights to protect their personal data. These include the right to:
– Know what information is being collected, stored and used;
– Access their personal data;
– Request deletion or correction of incorrect information;
– Object to processing of their data for marketing purposes.
The law also requires businesses to take reasonable steps to protect consumer data through administrative, technical and physical safeguards. These include implementing a security program, conducting regular risk assessments and encrypting personal information in storage or transit. In addition, businesses must notify consumers of any potential data breaches within 45 days after the incident occurs.
Sensitive Personal Information under Montana’s Consumer Data Privacy Act
The MBDPL considers certain types of personal information to be “sensitive” and therefore requires additional protections. These include biometric data, health records, financial account information and Social Security numbers, Citizenship status, Children’s data, Geolocation, Racial or ethnic origin, Religious beliefs and Sexual orientation. Businesses must put in place stronger security measures when collecting and storing this type of data.
Types of data that MCDPA does not apply to
Personal data used for research, health records, data protected under HIPAA, Any personal information collected or utilized for consumer credit scoring and reporting is protected by the federal Fair Credit Report Act (FCRA), Personal information covered by the federal Family Educational Rights and Privacy Act (FERPA),Personal information kept for employment records.
Privacy notice under MBDPL
Under MCDPA, businesses must provide a Privacy Notice to their customers. The Notice should include the following information:
-The types of personal data collected, stored and used by the business;
-How the data will be used (e.g. marketing);
-How consumers can access, delete or correct any incorrect information;
-How the business will protect customer data;
-What rights consumers have to opt out of any data sharing and/or sale;
-Whether or not the business is subject to the GDPR or another similar law;
-Which third parties, if any, the business shares personal information with.
The MBDPL also requires businesses to provide a link to their Privacy Notice on their website, as well as in any email communication. Write the notice in plain, easily understandable language, and provide it in both English and Spanish.
Penalties for Violation of Montana’s Consumer Data Privacy Act
Violations of the MBDPL may result in civil penalties up to $7,500 per violation. Because there is no private right of action, only the AG can file actions against companies that do not comply with the regulation.
What Requirements Does MBDPL Place on Businesses Collecting or Processing Personal Information of Montana Residents?
Businesses that are subject to the MBDPL must meet certain requirements regarding notice, data security, and breach notification. These include:
– Providing a clear and conspicuous privacy notice to consumers about their personal information;
– Putting in place adequate administrative, technical, and physical protections to protect consumer data
– Promptly notifying consumers of any data breaches;
– Refraining from using consumer data for certain marketing purposes.
Consumer Rights under Montana’s Consumer Data Privacy Act
In addition to the above requirements, the MBDPL grants consumers certain rights regarding their personal data. These include the right to:
– Know what information you are collecting, storing, and using
– Access their personal data;
– Request deletion or correction of incorrect information;
– Object to processing of their data for marketing purposes.
– right for getting a copy of their data
The MBDPL also requires businesses to obtain explicit consent from consumers before collecting or processing sensitive personal information.
How Businesses Can Prepare for MBDPL Compliance
In order to be compliant with the MBDPL, businesses should take steps such as:
– Conducting an internal audit of their data practices;
– Developing a comprehensive privacy policy;
– Making sure their website and emails contain links to the Privacy Notice;
– Offering consumers the option to opt out of any data sharing and/or sale;
– Establishing internal procedures for responding to consumer access, deletion and correction requests;
– Updating their security measures to ensure customer information is protected.
By taking the necessary steps to comply with the MBDPL, businesses can protect themselves from potential penalties and help ensure they are protecting the privacy of their customers.