Skip to the main content.
Featured resource

Ban the Box Guide

Our new Ban the Box Guide makes it easier than ever to decipher the patchwork of fair chance laws across the country. Check the map to quickly identify what laws apply to you.

Visit the guide ›

Verified Credentials is a leading background screening company. Since 1984, we’ve helped validate and secure relationships through the use of our comprehensive screening solutions. We offer a wide variety of background checks, verifications, and innovative screening tools.

Get to know us ›

Accredited background screening solutions

PBSA Accredited

Our accreditation confirms that our policies, processes, and employee training meet rigorous industry compliance standards.

Learn about our solutions ›

2 min read

Montana’s 2024 Consumer Data Privacy Act

Montana has joined the growing list of consumer data privacy laws enacted throughout the country, creating new guidelines for consumer data privacy. Minnesota, Rhode Island, Connecticut, and other states enacted similar data privacy laws earlier this year. 

The Montana Consumer Data Privacy Act (MCDPA) goes into effect on October 1, 2024. This article covers a few key factors for employers to consider. 

 

What employers need to know

The Act is intended to give consumers more control and privacy over their personal data by regulating businesses across the state. Although this is a positive step for protecting consumer data and privacy in Montana, it comes with new regulations aimed at employers in the state. The MCDPA applies to entities that: 

  • Conduct business in Montana or produce products or services targeting Montana residents. 
  • Control or process the personal data of more than 50,000 consumers, excluding data processed solely for payment transactions. 
  • Control or process the personal data of more than 25,000 consumers and derive over 25% of their gross revenue from the sale of personal data. 

Consumer Rights 

Montana consumers are granted several rights under the MCDPA: 

  • Confirmation of Data Processing: Consumers can confirm if their data is being processed unless it violates trade secrets. 
  • Correction of Data: Consumers can correct inaccuracies in their personal data. 
  • Deletion of Data: Consumers have the right to delete their personal data. 
  • Access to Data: Consumers can request a copy of their personal data under certain circumstances. 
  • Opt-Out Rights: Consumers can opt out of the sale of their personal data, targeted advertising, or profiling for automated decision-making with significant impacts. 
  • Authorized Agents: Consumers can designate an authorized agent to submit opt-out requests on their behalf. 
  • Appeals: Consumers can appeal a controller’s refusal to act on a request within a reasonable timeframe. 

Controller Obligations 

Controllers include employers and businesses responsible for processing personal data. Below is an overview of regulations to which controllers must adhere: 

  • Data Collection and Processing: Limit data collection and process data only for disclosed purposes unless consumer consent is obtained. 
  • Data Security: Maintain administrative, technical, and physical data security practices. 
  • Assessing Data Protection: Conduct assessments for targeted advertising, sale of personal data, and high-risk profiling. 
  • Disclosure: Clearly disclose the sale of personal data or processing for targeted advertising. 
  • Consent for Sensitive Data: Obtain consumer consent before processing sensitive data. 
  • Opt-Out Mechanism: Provide an easy-to-use opt-out mechanism comparable to the consent mechanism. 
  • Universal Opt-Out: By January 1, 2025, allow consumers to opt out of targeted advertising or data sales through a universal mechanism. 
  • Privacy Notices: Post privacy notices with specific content requirements. 
  • Response to Requests: Respond to consumer data requests within 45 days, with a possible 45-day extension. 
  • Notification of Declines: Inform consumers within the same 45-day period if a request is declined. 
  • Authentication: Respond to authenticated requests or notify consumers if more information is needed for authentication. 
  • Appeals: Respond to consumer appeals within 60 days. 
  • Contracts with Processors: Enter into contracts with specific terms regulating data processing. 
  • Children’s Privacy: Comply with the Children’s Online Privacy Protection Act of 1998. 

Employers have until January 1, 2025, to comply with the deadline for universal opt-out mechanisms and new regulations under the law. Take a closer look here to read the full details of Montana’s Data Privacy Act.  

 

Expanding data privacy laws across the country

The MCDPA is one of the latest laws geared toward data and consumer privacy protection. As the topic of data privacy continues to stay in the spotlight, understanding and complying with data privacy regulations in the states where you operate or hire is essential to protecting consumer data, maintaining trust with employees and consumers, and remaining legally compliant. 

With an uptick in data privacy laws seen in 2023 and 2024 following the Executive Order to Protect Sensitive Bulk Data, it is probable that more state-wide data privacy laws may be implemented in the near future. Employers who hire, operate, and target consumer data in Montana or other states with similar data privacy laws should consult their legal counsel to ensure compliance and determine how new data privacy laws apply to them. 

.

Pennsylvania’s Criminal History Record Information Act Protects Job Applicant in Phath v. Central Transport LLC

A recent court ruling by the U.S. Court of Appeals for the Third Circuit upheld Pennsylvania’s Criminal History Record Information Act (“CHRIA”),...

Read More

Maryland Online Data Privacy Act Enforcement Begins on April 1, 2026

Nearly two years after Governor Wes Moore signed the Maryland Online Data Privacy Act (or MODPA), the next milestone some organizations have been...

Read More

California Finalizes Regulations on Automated Decision‑Making Technology

In November 2024, the California Privacy Protection Agency voted to proceed with outlining new rules and regulations regarding automated...

Read More

1 min read

Saddle Up, Montana: Original 2024 State Privacy Laws Get a Makeover in 2025

Montana implemented the Montana Consumer Data Privacy Act (MCDPA) on October 1, 2024. The law regulates businesses that produce products or services...

Read More

1 min read

Oregon’s Consumer Privacy Act: 110 Complaints Filed in 6 Months

In June 2023, the Oregon Legislature passed Senate Bill 619, also known as the Oregon Consumer Privacy Act (OCPA). The law took effect on July 1,...

Read More

1 min read

What Employers Need to Know About Iowa’s 2025 Consumer Privacy Law

Like Nebraska’s data privacy law, Iowa’s Consumer Data Privacy Act (IACDPA) took effect on January 1, 2025. This legislation, signed into law by...

Read More