Orange textured background

US state law

MCDPA and browser fingerprinting

How the Montana Consumer Data Privacy Act (Senate Bill 384, 2023) regulates device fingerprinting, why its 50,000-consumer threshold is the lowest in the Virginia-cluster patchwork, and what to do before the cure-period window closes in April 2026.

Reviewed

RegionMontana, USA
RegulatorMontana Attorney General - Office of Consumer Protection
Effective1 October 2024
Max penaltyUp to $7,500 per violation (Mont. Code Ann. §30-14-142)
Status in-force

The 50,000-consumer floor: why Montana catches controllers others miss

Montana Senate Bill 384 was signed into law in May 2023 and took effect on 1 October 2024, codified at Mont. Code Ann. §30-14-2801 through §30-14-2823. The statute follows the Virginia-cluster template on most substantive rules, but one threshold choice makes Montana meaningfully different from every other law in its peer group.

Montana's applicability floor is 50,000 consumers in a calendar year under §30-14-2802(1)(a), or 25,000 consumers AND more than 25% of gross revenue from the sale of personal data under §30-14-2802(1)(b). The 50,000 floor is half the 100,000-consumer threshold in Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and Texas (TDPSA). A mid-size SaaS, a regional e-commerce operator, or a B2C analytics platform that comfortably sits below the 100k mark in other states can still be inside Montana's scope.

For fingerprinting specifically, this matters because Montana consumers are counted individually. Each returning user recognised by a fingerprint hash who is a Montana resident acting in an individual or household context counts toward the threshold. A controller that has accurately concluded it is outside VCDPA and CPA should run a separate Montana threshold analysis before assuming it has no obligations here.

What MCDPA says about fingerprinting

Montana's statute does not use the words 'fingerprinting', 'browser fingerprint', or 'device identifier'. It does not need to. Section §30-14-2803(17) defines personal data as 'any information that is linked or reasonably linkable to an identified or identifiable natural person'. A device or browser fingerprint - composed of canvas rendering, installed fonts, GPU model strings, audio context behaviour, screen dimensions, time zone, and similar device-level signals - satisfies that definition the moment a controller uses it to recognise a returning Montana consumer across sessions. The hash does not need to be paired with a name, an email address, or a payment token. Linkability through recognition is enough.

The practical consequence is the same as under every Virginia-cluster law: fingerprinting is not banned, but it is regulated personal-data processing. The obligations that follow depend entirely on the purpose for which the fingerprint is used. Fraud prevention and anti-bot use sit in a low-friction lane. Targeted advertising, sale, and significant-effect profiling sit in a higher-friction lane that requires opt-out handling, UOOM compliance, and a Data Protection Assessment.

When MCDPA applies to you

Section §30-14-2802 applies the statute to any controller that conducts business in Montana or produces products or services intentionally targeted to Montana residents, and that meets one of the two consumer-count thresholds. Physical presence is not required. A New York or international controller that ships a consumer-facing product to Montana residents and crosses 50,000 Montana consumers in a calendar year owes Montana obligations.

The 25% gross-revenue leg under §30-14-2802(1)(b) is worth examining for data brokers and ad-tech vendors. A controller that processes 30,000 Montana consumers and earns more than 25% of its gross revenue from selling personal data is inside MCDPA even though it falls below the 50,000-consumer primary floor.

Consumer means a Montana resident acting in an individual or household capacity under §30-14-2803(6). Employees, contractors, and individuals acting on behalf of a business are excluded. A fingerprint captured on an internal admin tool, a B2B SaaS, or a business-facing API does not count toward the threshold and does not trigger MCDPA obligations.

The three opt-out rights that touch fingerprinting

Section §30-14-2807 grants Montana consumers five rights: access, correction, deletion, portability, and opt-out. The opt-out right divides into three categories that directly intersect with fingerprinting.

Targeted advertising under §30-14-2803 means displaying advertisements to a consumer where the advertisement is selected based on personal data obtained from the consumer's activities across non-affiliated websites or online applications over time. Recognising a returning visitor by fingerprint hash and serving cross-site behavioural ads is the core case. First-party retargeting on your own domain, frequency capping on your own service, and contextual advertising are excluded from the definition.

Sale of personal data under MCDPA is defined at §30-14-2803 as the exchange of personal data for monetary or other valuable consideration. The 'or other valuable consideration' language mirrors Colorado's broad definition and departs from Virginia's monetary-only rule. Sharing fingerprint hashes with an ad-tech partner in a mutual data-exchange arrangement - even without a direct dollar payment - is more likely to qualify as sale under Montana law than under VCDPA.

Profiling under §30-14-2803 covers automated processing of personal data to evaluate, analyse, or predict personal aspects related to an identified or identifiable natural person. The opt-out applies when profiling produces legal or similarly significant effects on a consumer, such as decisions related to credit, employment, insurance, housing, healthcare, or education. A marketing segmentation model that processes fingerprints does not trigger this opt-out. A creditworthiness model that uses a fingerprint as one input signal does.

Common fingerprinting purposes under MCDPA

PurposePersonal data under MCDPA?DPA required?Opt-out right applies?
Anti-fraud at login or payment stepYesNo (not a heightened-risk processing category)No
Account-takeover detectionYesNoNo
Bot mitigation on a public form or APIYesNoNo
Cross-site targeted advertisingYesYesYes (targeted advertising; UOOM/GPC must be honoured)
Sharing fingerprint hashes with ad-tech partnersYesYesYes (likely sale under the 'other valuable consideration' clause)
Selling fingerprint-derived audience segments to a data brokerYesYesYes (sale for monetary consideration)
Profiling for credit, insurance, or employment decisionsYesYesYes (profiling with legal or similarly significant effect)
Frequency capping or session continuity on your own domainYesNo (first-party carve-out)No
Product analytics on your own service onlyYesNoNo
Fingerprinting employees on an internal toolNo (employee carve-out under §30-14-2803(6))NoNo

Universal Opt-Out Mechanisms and Global Privacy Control

Section §30-14-2811 requires controllers to provide a clear and conspicuous mechanism for consumers to opt out of targeted advertising, sale, and covered profiling. From 1 January 2025, Montana mandates recognition of Universal Opt-Out Mechanisms, and the Montana AG has confirmed that the Global Privacy Control browser signal satisfies the UOOM requirement.

A fingerprinting deployment that fires before checking the GPC header is in violation of §30-14-2811 with respect to any Montana browser that has GPC enabled - even if the consumer has never seen or clicked an on-site opt-out control. The check must happen at the application layer, upstream of the call to the fingerprinting SDK, for any purpose that triggers the opt-out right.

The UOOM obligation applies to targeted advertising and sale. Anti-fraud and session-continuity fingerprinting are not opt-out purposes, so the GPC gate is not required on those flows. Keeping those flows architecturally separate - not sharing retention tables, access controls, or downstream recipients - is the practical safeguard that lets the controller defend the distinction.

Data Protection Assessments

Section §30-14-2809 requires a controller to conduct and document a Data Protection Assessment before engaging in four categories of processing: targeted advertising, sale of personal data, processing of sensitive data, and profiling that presents a reasonably foreseeable risk of substantial injury to consumers. The assessment must weigh the benefits of the processing against the risks to consumers.

The assessment is an internal record; it is not filed with the AG or made public. The AG can compel its production during an investigation, and the absence of a documented assessment is itself a citable violation separate from any underlying processing failure. For a fingerprinting deployment used to power targeted advertising, an adequate Montana DPA should name the signal categories collected, the hash construction method, the retention window, the downstream recipients, any de-identification or pseudonymisation claims, and the consumer-facing transparency mechanism including UOOM handling.

The statute does not specify the level of prescriptiveness required by Montana's assessments, unlike Colorado's Rule 8 under 4 CCR 904-3, which mandates specific content fields. Montana's standard is a reasonable-weighing-of-benefits-and-risks test. Controllers with an existing VCDPA or CPA Data Protection Assessment for a fingerprinting deployment can adapt that document rather than starting from scratch, updating the threshold analysis, penalty figures, and cure-period section for Montana's specific rules.

Montana AG enforcement context

  • MCDPA only took effect on 1 October 2024 and the published enforcement record is thin. The Montana Office of Consumer Protection sits inside the AG's office rather than operating as a stand-alone privacy unit, as Colorado's Privacy Unit does. This means enforcement prioritisation is shared with the broader consumer-protection caseload and the AG's overall docket.
  • The Office of Consumer Protection has historically focused Montana enforcement on consumer-facing deception, data-security failures, and unfair business practices. MCDPA gives that office a new statutory hook for privacy matters, and the signal from comparable offices in other states is that early enforcement concentrates on documentation failures - missing privacy notices, unimplemented UOOM handling, and absent DPAs - rather than on substantive processing bans.
  • Montana's cure period through 1 April 2026 gives the AG's office an informal enforcement posture tool: it can send cure notices and monitor follow-through without escalating to civil penalty proceedings. Controllers should treat any pre-April-2026 AG contact as a structured cure opportunity, not a resolved matter - the AG can initiate penalty proceedings if the cure is inadequate.
  • There is no private right of action under MCDPA. Class-action plaintiff firms that have built practices around CCPA's limited private right of action have no parallel hook under Montana law. The only enforcement avenue is the Montana AG.

How the cure period works in practice

Section §30-14-2818 provides that before the Montana AG initiates a civil action for a violation, the AG must give the controller 60 days written notice of the alleged violation and an opportunity to cure. If the controller cures the violation within the 60-day window and provides the AG with an express written statement that the violation has been cured and that no further violations will occur, the AG may not pursue civil penalties for that violation.

This cure window sunsets on 1 April 2026 under §30-14-2818(2). After that date the AG can proceed directly to civil action with no cure notice required. The statute does not specify whether pre-sunset violations that are cured in good faith carry carry-forward protection after the sunset - that is an interpretive question that Montana courts have not yet addressed.

The practical planning implication: complete a threshold analysis, UOOM audit, and Data Protection Assessment review before 1 April 2026. If the audit uncovers gaps, the cure period still provides a structured path to compliance without civil penalty exposure. After 1 April 2026, each gap is potentially a first-strike violation.

How Benny the Doorman fits into an MCDPA-aware deployment

Benny is a fingerprinting SDK and API, not a consent management platform or Universal Opt-Out Mechanism. The separation is deliberate: Benny is engineered to be invoked after the controller has resolved the gating question - whether the processing is permitted for this consumer, on this request, for this purpose. Three integration steps shape a Montana-aware deployment.

First, install a GPC header check upstream of every Benny call used for targeted advertising or sale-flagged purposes. The GPC check belongs at the application layer. A Benny call that fires before the GPC check, on a Montana browser with GPC enabled, is a violation of §30-14-2811 regardless of whether the consumer ever saw an opt-out link.

Second, produce a Data Protection Assessment under §30-14-2809 for each regulated purpose before going live. Benny's documentation enumerates the signal categories, the hash construction, the default retention window, and the per-call data flows - the technical detail needed to populate the processing-activity and risk-weighting sections of a Montana DPA. If you already have a VCDPA or CPA DPA for the same deployment, a Montana-specific addendum updating the threshold analysis, penalty figures, and cure-period section is usually sufficient.

Third, architect the anti-fraud and analytics flows separately from the targeted-advertising flow. The §30-14-2807 opt-out must be honoured on the regulated flow without disrupting the anti-fraud flow. Separate retention tables, access scopes, and downstream recipients are the implementation pattern that makes the purpose distinction defensible to the AG.

Frequently asked questions

Is browser fingerprinting illegal under MCDPA?

No. Browser fingerprinting is not banned under the Montana Consumer Data Privacy Act. It is regulated as personal data when the fingerprint hash can be reasonably linked to an identified or identifiable Montana consumer under §30-14-2803(17). Lawful use requires honouring opt-out requests for targeted advertising, sale, and covered profiling, recognising the Global Privacy Control browser signal from 1 January 2025, and completing a Data Protection Assessment before deploying fingerprinting for any of those regulated purposes.

Does MCDPA apply to my business if I have fewer than 100,000 customers?

Possibly yes, and that is Montana's most important differentiator. MCDPA's primary applicability floor is 50,000 Montana consumers in a calendar year - half the 100,000-consumer threshold used by Virginia, Colorado, and Connecticut. If you have already determined that you fall outside VCDPA or CPA based on the 100,000-consumer threshold, you should run a separate Montana analysis. You may still be inside MCDPA if you process between 50,000 and 100,000 Montana consumers, or if you process 25,000 Montana consumers and derive more than 25% of gross revenue from selling personal data.

Do I need to honour Global Privacy Control (GPC) under MCDPA?

Yes, from 1 January 2025. Montana mandates recognition of Universal Opt-Out Mechanisms and the Montana AG has confirmed GPC satisfies that requirement. A fingerprinting deployment that fires before checking the GPC header on a Montana browser - for targeted advertising or sale purposes - is in violation of §30-14-2811, even if the consumer never interacted with an on-site opt-out control.

What is the cure period and when does it end?

Under §30-14-2818, the Montana AG must give controllers 60 days written notice of an alleged violation and an opportunity to cure before initiating a civil action. If the controller cures the violation and provides a written statement of cure and non-recurrence, the AG may not pursue civil penalties for that violation. This cure period sunsets on 1 April 2026. After that date the AG can pursue first-strike enforcement with no prior cure notice.

Is sharing fingerprint hashes with an ad-tech partner a 'sale' under MCDPA?

Potentially yes. Montana's sale definition, like Colorado's, covers 'monetary or other valuable consideration' - not just direct monetary payment. Sharing fingerprint-derived identifiers with an ad-tech partner for mutual data lift, audience extension, or matching services, even without a direct dollar payment, is more likely to qualify as sale under MCDPA than under Virginia's monetary-only VCDPA definition. Controllers should assess whether their ad-tech data-sharing arrangements meet the 'other valuable consideration' threshold.

What is a Data Protection Assessment and when do I need one for fingerprinting?

A Data Protection Assessment under §30-14-2809 is an internal documented analysis that weighs the benefits of a processing activity against the risks to consumers. It is required before deploying fingerprinting for targeted advertising, sale of personal data, processing of sensitive data, or profiling that presents a reasonably foreseeable risk of substantial injury. The assessment is not filed with any regulator but must be made available to the Montana AG on request during an investigation. Its absence is itself a citable violation.

Does MCDPA apply to anti-fraud fingerprinting?

Anti-fraud fingerprinting is personal data under MCDPA when the hash is linkable to a Montana consumer, but the opt-out rights for targeted advertising, sale, and profiling do not apply to anti-fraud processing, and a Data Protection Assessment is generally not required unless the processing carries a reasonably foreseeable risk of substantial injury. Narrowly-scoped anti-fraud and bot-mitigation fingerprinting sit in the lowest-friction lane under the law, provided the data flows are kept architecturally separate from regulated-purpose flows.

How is MCDPA different from VCDPA for fingerprinting?

Three key differences. First, MCDPA's primary applicability floor is 50,000 Montana consumers, half VCDPA's 100,000-consumer threshold - Montana catches mid-size controllers that VCDPA does not. Second, MCDPA's sale definition includes 'other valuable consideration', making non-monetary data sharing more likely to qualify as sale than under VCDPA's monetary-only definition. Third, MCDPA's cure period runs through 1 April 2026, giving controllers a structured remediation window that VCDPA's narrower cure guidance does not equally offer. Maximum civil penalty is the same at $7,500 per violation.

What are the fines for non-compliant fingerprinting under MCDPA?

Civil penalties under Mont. Code Ann. §30-14-142 reach up to $7,500 per violation, enforced exclusively by the Montana Attorney General through the Office of Consumer Protection. There is no private right of action. The cure period through 1 April 2026 means that controllers who receive and respond to a cure notice before that date cannot be penalised for the cured violation. After 1 April 2026, first-strike civil penalty exposure applies.

Tooling

Benny the Doorman is built for this compliance posture.

Free, cookieless fingerprinting that defers to your consent management platform, runs on Indian infrastructure, and ships with a DPA addendum sized for the jurisdiction above.

Last reviewed 2026-06-06