Back to Blog
Education July 21, 2025 5 min read

Tennessee and Minnesota Privacy Laws: A Guide for Finance and Health Publishers

Tennessee's privacy law took effect July 1 and Minnesota's takes effect July 31. Both give residents the right to opt out of targeted ads. Here is what publishers, especially in finance and health, should check.

HR
HBDR Research
July 21, 2025

The US state privacy map keeps filling in. The Tennessee Information Protection Act took effect on July 1, and the Minnesota Consumer Data Privacy Act takes effect on July 31. Both follow the broad model other states have adopted: residents get rights to access, correct and delete their data, and to opt out of targeted advertising, the sale of personal data and certain profiling. Both require opt-in consent to process sensitive data.

For most publishers, these laws do not require a new playbook so much as a check that the existing one covers two more states. For finance and health publishers, where content itself can reveal sensitive information about a reader, they are a good prompt to look harder at how audience data flows into advertising.

This is not legal advice. Use it to structure the conversation with your privacy counsel.

Who is covered

Tennessee

According to a Covington summary of the July laws, Tennessee's law applies to businesses processing personal data of at least 175,000 Tennessee consumers a year, or 25,000 if the business derives more than half its revenue from selling personal data. Tennessee also sets a revenue threshold of $25 million. Enforcement sits with the state Attorney General, with a 60-day cure period. Tennessee is also notable for giving businesses an affirmative defense if they maintain a written privacy program that conforms to the NIST Privacy Framework or comparable standards.

Minnesota

The Minnesota statute applies to businesses that control or process personal data of 100,000 or more Minnesota consumers in a year, excluding data processed solely to complete payments, or that derive over 25% of gross revenue from selling personal data and process data of 25,000 or more consumers. Minnesota adds some provisions other states lack, including a right to question the result of profiling that produces legal or similarly significant effects, and a requirement to maintain an inventory of the personal data a business manages as part of its security practices. Consumers can send opt-out requests through technology such as a browser setting, browser extension or global device setting, and controllers must comply. Until January 31, 2026, the Attorney General must give a 30-day warning letter and cure period before bringing an enforcement action.

Why finance and health publishers need extra care

Both laws treat certain categories as sensitive data, including information revealing mental or physical health conditions or diagnoses. Processing sensitive data requires consent. For most publishers, that is a question about forms and accounts. For health and personal finance publishers, it is a question about pageviews.

A reader who visits a page about managing a specific condition, or about debt relief, is not necessarily disclosing a diagnosis or financial hardship. But if your data practices turn those visits into audience segments, such as “interested in diabetes treatment,” and share them with advertising partners, you are much closer to the line. Regulators and plaintiffs across the US have been paying attention to health-related tracking in particular.

A practical checklist

1. Confirm opt-outs work in both states

  • Make sure your “Do Not Sell or Share” or equivalent opt-out link covers Tennessee and Minnesota residents, not just California.
  • Confirm your CMP or privacy tooling applies opt-outs to targeted advertising, including signals passed to Prebid and your ad server.
  • Honor browser-based opt-out signals such as Global Privacy Control. Minnesota's law explicitly contemplates opt-outs sent through browser settings and extensions.

2. Pass the right signals to your ad stack

An opt-out on your site only matters if your ad partners receive it. Most publishers now pass US privacy choices through the IAB's Global Privacy Platform (GPP). Check that your CMP supports the state sections that apply to you, that Prebid's GPP module is reading and forwarding the string, and that your ad server and SSPs are configured to honor it.

3. Audit your audience segments

  • List every audience segment you create or pass to partners, including through key-values, data management tools or curation partners.
  • Flag segments derived from health, financial hardship or other sensitive topics.
  • For flagged segments, decide with counsel whether to remove them, restrict them to consented users, or switch to contextual targeting that does not build a profile of the individual.

4. Lean into contextual

Contextual targeting, selling the page rather than the person, is the most durable approach for sensitive verticals. A pharmaceutical or insurance advertiser can still reach readers of relevant content through page-level signals without your stack building individual health profiles. Make sure your content taxonomy is detailed and accurately passed in bid requests so contextual buyers can find it.

5. Document your program

Tennessee's affirmative defense rewards a documented privacy program aligned with a recognized framework. Minnesota requires a data inventory. Even if your counsel concludes you are below a threshold today, a documented data map, vendor list and policy for sensitive data are the foundation for complying with the next state, and the one after that.

6. Review vendor contracts

Opt-out rights only work if the partners who receive data are bound to respect them. Check that contracts with SSPs, data partners and measurement vendors include the processor or third-party terms these laws expect, and that partners commit to honoring opt-out signals they receive from you. Ask each partner how they handle the Global Privacy Platform string and whether they support the state sections relevant to your audience.

The bigger picture

Each new state law adds a little complexity, but the direction is consistent: opt-outs must work, sensitive data needs consent, and businesses need to know what data they hold and where it goes. Publishers who build for that pattern once, rather than state by state, spend less time scrambling every July 1. A managed partner like HBDR can make sure privacy signals reach every bidder, while your privacy counsel decides what those signals need to say.

Tags: privacy law targeted advertising consent health publishers finance publishers

Ready to maximize your ad revenue?

Get Started