Minnesota · verified official-source register

Minnesota Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

Minnesota case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

23andMe

Date
2026-07-14
Amount
$18 million paid out of available bankruptcy funds; Minnesota will receive $514,871; separate $47M class-action settlement for consumers
Legal basis
Minnesota’s Genetic Information Privacy Act; general consumer protection and privacy laws

Why the action was brought

23andMe’s 2023 credential-stuffing breach compromised genetic and other customer data, affecting 6.9 million consumers worldwide, including 92,385 Minnesotans; some data was published for sale on the dark web. The coalition alleged unreasonable security practices, including inadequate safeguards, rate limiting, monitoring, investigation of unusual logins, vulnerability remediation, and design testing.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Marriott International, Inc.

Date
2024-10-09
Amount
$52 million payment to states; Minnesota will receive $814,847.00
Legal basis
State consumer protection laws, personal information protection laws, and, where applicable, breach notification laws

Why the action was brought

From July 2014 through September 2018, intruders went undetected in Starwood’s computer network, exposing 131.5 million United States guest records, including contact information, dates of birth, reservation details, limited unencrypted passport numbers, and unexpired payment card information. Marriott allegedly failed to implement reasonable data security and remediate deficiencies, particularly while integrating Starwood into its systems.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Inmediata

Date
2023-10-23
Amount
$1.4 million payment to 32 states; Minnesota's share: $93,157
Legal basis
state consumer-protection laws, breach-notification laws, and HIPAA

Why the action was brought

Inmediata exposed protected health information of approximately 1.5 million Americans, including 113,208 Minnesotans, online and indexed by search engines for almost three years. It allegedly failed to implement reasonable data security, including secure code review, then delayed breach notification for over three months and sent misaddressed, unclear notices, exposing consumers to identity-theft risks.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.