Michigan · verified through August 25, 2026

Michigan: law status and evidence context.

Law status, direct attached-library attribution, and public enforcement context are shown separately. A zero direct total does not mean no enforcement exists.

MI · 6 requirements mapped / control outcomes supported

Law status

No verified general comprehensive law

No comprehensive consumer privacy law verified (SB 659 'Personal Privacy Data Act' was a pending bill)

Official name / citation
n.a.
Status / effective date
Bill only
Principal enforcer
Michigan Attorney General

Direct attached-library attribution

0 cases · $0

These totals are assigned solely by the attachment’s state heading. Shared multistate totals are not allocated in full to every state.

The attached library does not enumerate participant-level allocations for every multistate matter; shared settlement totals are presented once at the national level and are not duplicated into state totals.

Official law sources

Other generally applicable PII law

n.a. - Michigan's identity-theft/breach statute was not fetched in this session; the pending breach-notification bill text located was 2019 HIB 4187 - https://www.legislature.mi.gov/documents/2019-2020/billintroduced/House/pdf/2019-HIB-4187.pdf

Public enforcement context

Tier 1

23andMe (bankruptcy claims; trustee)

$150 million in allowed state claims, with actual state recovery limited to $18 million; separate $46.75 million consumer class settlement · July 14, 2026

A coalition of 42 attorneys general settled bankruptcy claims arising from the 2023 breach of 23andMe genetic data affecting about 6.9 million customers worldwide. Michigan share stated as $436,605; 162,865 Michigan residents affected.

Legal basis: State data-privacy, consumer-protection and genetic-information privacy claims asserted in the bankruptcy (no single statute named)

Official case source (opens in a new tab)

Mapped control outcomes

1 personal data inventory/data map; 2 sensitive-data discovery; 3 downstream copy tracking; 8 breach blast-radius analysis; 9 retention/minimization; 10 regulator audit evidence

Kestryl can evidence where regulated personal data actually resides across structured stores and unstructured attachments/images, produce audit rows and evidence packs showing when each location was discovered and reviewed, and apply structured-data remediation modes (mask, vault, strip) to reduce exposure. It does not alter source attachments or documents, and its output is technical evidence supporting controls, not proof of legal compliance.