Mississippi
Mississippi Data Privacy Laws: Breach Notification & Consumer Rights (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 9, 2026. · 16 primary sources cited on this page. How we verify our legal content

Mississippi has no comprehensive consumer data privacy law. The state's primary data protection requirement is its breach notification statute, Miss. Code Ann. § 75-24-29, which requires businesses holding personal information of Mississippi residents to notify affected individuals without unreasonable delay after a security breach.
Mississippi takes a targeted approach to data privacy rather than enacting a single comprehensive consumer protection law. The state's primary data privacy statute is its data breach notification law, codified at Miss. Code Ann. § 75-24-29, which requires businesses to notify Mississippi residents when their personal information has been compromised.
Beyond breach notification, Mississippi relies on its Consumer Protection Act for deceptive data practices, the Insurance Data Security Act for licensed insurers, the Data Security for Money Transmitters Act for licensed money transmitters, the Walker Montgomery Protecting Children Online Act for minors' data on social platforms, federal privacy frameworks, and criminal statutes addressing computer crimes and identity theft. This page covers every relevant Mississippi data privacy statute, what rights residents have, what obligations businesses must meet, and what penalties apply for noncompliance.
Mississippi has introduced comprehensive privacy legislation in multiple recent sessions, most recently HB 1051 in 2026, but none of these bills have advanced. Until a comprehensive law passes, federal overlay remains the dominant protection for most Mississippians.
Mississippi Data Breach Notification Law (Miss. Code Ann. § 75-24-29)

Mississippi enacted its data breach notification law effective July 1, 2011, through H.B. 583 (2010 Regular Session, Laws 2010, ch. 489, approved April 7, 2010). The statute applies to any person who conducts business in Mississippi and, in the ordinary course of that business, owns, licenses, or maintains personal information of any resident of the state. This scope covers businesses of all sizes, regardless of physical location, as long as they hold personal data belonging to Mississippi residents.
What Qualifies as Personal Information
"Personal information" means an individual's first name or first initial and last name combined with any one or more of the following data elements: Social Security number; driver's license number, state identification card number, or tribal identification card number; or financial account number, credit card number, or debit card number combined with any required security code, access code, or password that would permit access to the individual's financial accounts. Publicly available government records are excluded. The Legislature added tribal identification card numbers to that list in 2021 H.B. 277 (Laws 2021, ch. 378), effective July 1, 2021.
What Constitutes a Breach
A "breach of security" is the unauthorized acquisition of electronic files, media, databases, or computerized data containing personal information when access to that information has not been secured by encryption or other technology that renders it unreadable or unusable. Encrypted data is not subject to the notification requirement, creating a meaningful safe harbor for businesses that encrypt data at rest.
Notification Requirements
When a breach occurs, the business must disclose it to all affected individuals without unreasonable delay, subject to: completion of an investigation to determine the nature and scope of the incident, and restoration of the reasonable integrity of the data system. Notification is not required if the business reasonably determines after an appropriate investigation that the breach will not likely result in harm.
Miss. Code Ann. § 75-24-29 does not require notice to the Mississippi Attorney General's office as part of the breach disclosure process; the Attorney General's role is limited to enforcing the statute against businesses that fail to notify affected individuals.
Permitted Notice Methods
- Written notice sent to the individual's last known address
- Telephone notice with direct personal contact
- Electronic notice, when consistent with the federal E-SIGN Act (15 U.S.C. § 7001)
- Substitute notice, when the cost of direct notice would exceed $5,000, the affected class exceeds 5,000 people, or the business lacks sufficient contact information. Substitute notice requires email to all known email addresses, conspicuous website posting, and notification to statewide media.
Law enforcement may request a delay in notification if the disclosure would impede a criminal investigation.
Compliance Safe Harbors
Entities that maintain their own notification procedures consistent with the statute's timing requirements are deemed compliant if they notify affected individuals under their own policies. Entities subject to and compliant with the notification requirements of a primary federal regulator (such as HIPAA or GLBA) are also deemed compliant.
Penalties for Breach Notification Violations
Failure to comply with Miss. Code Ann. § 75-24-29 constitutes an unfair trade practice under the Mississippi Consumer Protection Act. The Attorney General may seek civil penalties of up to $10,000 per knowing and willful violation under Miss. Code Ann. § 75-24-19, and may obtain temporary or permanent injunctive relief. There is no private right of action for individual consumers.
| Violation | Penalty | Authority |
|---|---|---|
| Failure to notify affected individuals | Unfair trade practice | Miss. Code Ann. § 75-24-29 |
| Knowing and willful unfair trade practice | Up to $10,000 per violation | Miss. Code Ann. § 75-24-19 |
| Attorney General injunctive relief | Temporary or permanent injunction | Miss. Code Ann. § 75-24-9 |
| Computer fraud (damage $100 or more) | Up to $10,000 fine and/or up to 5 years imprisonment | Miss. Code Ann. § 97-45-3 |
| Identity theft ($250 or more) | Up to $10,000 fine and/or 2 to 15 years imprisonment | Miss. Code Ann. § 97-45-19 |
Mississippi Consumer Protection Act and Data Privacy
The Mississippi Consumer Protection Act (Miss. Code Ann. § 75-24-1 et seq.) serves as a broader enforcement tool for data privacy violations beyond breach notification failures. The Act prohibits unfair methods of competition and unfair or deceptive trade practices in commerce. Businesses that make misleading claims about their data security practices, fail to implement safeguards they have promised, or misrepresent how they collect or share consumer data may face enforcement action.
Attorney General Lynn Fitch has been active on data privacy through multi-state enforcement coalitions. In August 2024, Fitch joined a 21-state coalition that sent a demand letter to Temu (PDD Holdings) requesting answers about the company's data collection practices, its connections to the Chinese Communist Party, and potential consumer protection violations. Mississippi residents who believe a business has mishandled their personal data can file a complaint with the Attorney General's Consumer Protection Division at consumer@ago.ms.gov.
Mississippi Insurance Data Security Act (Miss. Code Ann. §§ 83-5-801 to 83-5-825)

Mississippi enacted the Insurance Data Security Act on April 3, 2019, effective July 1, 2019. The law applies specifically to insurance licensees and establishes comprehensive cybersecurity and data protection requirements modeled on the NAIC Insurance Data Security Model Law.
Core Requirements
Each licensee must develop, implement, and maintain a comprehensive written information security program based on a risk assessment. The program must include administrative, technical, and physical safeguards for nonpublic information and the licensee's information systems. Licensees must also maintain a written incident response plan and exercise due diligence in selecting and overseeing third-party service providers.
Incident Reporting
A licensee must notify the Mississippi Insurance Commissioner no later than three business days after determining that a cybersecurity event involving nonpublic information has occurred, when certain criteria are met. This three-day timeline is significantly shorter than the general "without unreasonable delay" standard in the breach notification law.
HB 1220 (2026): Proposed General Cybersecurity Safe Harbor (Died in Committee)
Mississippi HB 1220 (2026 Regular Session) was not an insurance-specific bill. As reported by committee substitute, it would have created a general cybersecurity liability safe harbor: a governmental entity (the state, a county, a municipality, a county hospital, or another political subdivision) would not have been liable in connection with a cybersecurity incident, and a covered commercial entity or its third-party agent would have received a rebuttable presumption against liability, where the entity maintained a security program that substantially aligned with a named framework. The frameworks listed included the NIST Cybersecurity Framework 2.0, NIST SP 800-171 Rev. 3, NIST SP 800-53 and 800-53A, FedRAMP, the CIS Critical Security Controls v8.1, and the ISO/IEC 27000 series, along with the security requirements of HIPAA, the Gramm-Leach-Bliley Act, FISMA, the HITECH Act, and PCI DSS. The bill stated that it did not establish a private cause of action.
The bill reached Miss. Code Ann. § 83-5-803 only in a narrow way: it would have amended that section so that the Insurance Data Security Law's exclusive-standards clause did not govern liability determinations in a civil action under the new safe harbor. The bill passed the House on February 11, 2026, but died on March 3, 2026 in the Senate Accountability, Efficiency, Transparency Committee. It was never signed into law, so Miss. Code Ann. § 83-5-803 remains unamended since its original 2019 enactment.
Exemptions
Exemptions apply for licensees that meet any of the following criteria: fewer than 50 employees (excluding independent contractors); less than $5 million in gross annual revenue; less than $10 million in year-end total assets; or licensed solely as an insurance producer or adjuster.
Annual compliance certification is required from Mississippi-domiciled insurers. Cybersecurity events may be reported to cyberreporting@mid.ms.gov.
Mississippi Data Security for Money Transmitters Act (HB 1596, Effective July 1, 2026)
Mississippi enacted a new sector-specific data security law for money transmitters in the 2026 Regular Session. Governor Tate Reeves signed House Bill 1596, the Data Security for Money Transmitters Act, on April 8, 2026. The law takes effect July 1, 2026.
The Act applies to entities licensed under Mississippi's Money Transmission Modernization Act, including money transmitters and virtual currency kiosk operators. Licensees must maintain a written, risk-based information security program covering access controls, multi-factor authentication, encryption of customer information in transit and at rest, regular penetration testing and vulnerability assessments, a written incident response plan, and annual staff security training. Each licensee must designate a qualified individual to oversee the program.
Licensees must notify the Mississippi Commissioner of Banking and Consumer Finance within 72 hours of discovering unauthorized acquisition of unencrypted customer data. Licensees and their delegates must also display contact information, provide multilingual fraud warnings, and give customers directions for filing complaints with regulators. Entities serving fewer than 5,000 customers are exempt from the risk assessment, penetration testing, and certain documentation requirements.
Walker Montgomery Protecting Children Online Act (HB 1126, 2024)
Mississippi's Walker Montgomery Protecting Children Online Act, enacted in 2024, requires digital service providers to make commercially reasonable efforts to verify a user's age and to obtain parental or guardian consent before a minor can create or maintain an account. It also requires providers to limit collection of a known minor's personal information to what is reasonably necessary to provide the service, prohibits targeted advertising involving harmful material to minors, and bars providers from collecting a known minor's precise geolocation data.
The law has been tied up in litigation almost since enactment. NetChoice, a trade association representing major online platforms, sued to block it, and a federal district court in the Southern District of Mississippi issued a preliminary injunction that kept the law from taking effect. The Fifth Circuit Court of Appeals vacated that injunction on April 17, 2025, and sent the case back to the district court to apply a facial-challenge standard.
The district court granted a new preliminary injunction on June 18, 2025, but the Fifth Circuit stayed that injunction on July 17, 2025, allowing enforcement to resume. NetChoice asked the U.S. Supreme Court to reinstate the injunction on an emergency basis. The Supreme Court denied that request on August 14, 2025.
The Fifth Circuit heard oral argument on the merits of Mississippi's second appeal on February 3, 2026, and has not yet ruled. As of this writing, the law remains in force and enforceable while the appeal is pending.
Mississippi Recording Laws (Miss. Code Ann. § 41-29-531)
Mississippi is a one-party consent state for recording telephone and in-person conversations. Under Miss. Code Ann. § 41-29-531, a person may record a communication if the person is a party to it, or if one party has given prior consent, unless the recording is made for a criminal or tortious purpose. Violations carry criminal penalties of up to $10,000 and one year imprisonment for misdemeanor interception, and up to five years and $10,000 for disclosing the contents of unlawfully intercepted communications. Civil damages of at least $100 per day or $1,000 (whichever is greater) are available to individuals whose communications were illegally recorded. Full details appear on the Mississippi recording laws page.
Pending Comprehensive Privacy Legislation
Mississippi has introduced comprehensive consumer data privacy bills in every recent session. None have been enacted.
HB 1051 (2026): Introduced as the Mississippi Consumer Privacy Protection Act during the 2026 Regular Session. It would have applied to businesses with annual revenues exceeding $25 million that either process personal information of at least 25,000 consumers and derive over 50% of revenue from selling personal information, or process personal information of at least 175,000 consumers annually. The bill would have granted rights to access, correct, delete, and port personal data, and to opt out of data sales, targeted advertising, and profiling. It died in committee on February 3, 2026.
SB 2500 (2025): The Mississippi Consumer Data Protection Act, introduced during the 2025 Regular Session with similar provisions. It also failed to advance.
SB 2080 (2023): An earlier attempt to enact the Mississippi Consumer Data Privacy Act, which also died in committee.
These repeated introductions signal growing legislative interest, but businesses operating in Mississippi should not rely on pending legislation for compliance planning.
Federal Privacy Laws That Apply in Mississippi

Because Mississippi lacks a comprehensive consumer privacy law, federal statutes are the primary source of data protection rights for most residents.
TAKE IT DOWN Act (Pub. L. 119-12, May 19, 2025)
The TAKE IT DOWN Act (Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act) was signed May 19, 2025. The criminal prohibition on publishing nonconsensual intimate visual depictions (NCII), including AI-generated deepfakes, took effect immediately. Starting May 19, 2026, covered platforms (social media, image-sharing, messaging, gaming services, and similar) must: (1) establish a process for consumers to request removal of NCII, and (2) remove the images and known identical copies within 48 hours of a valid request. The FTC enforces Section 3 with civil penalties of up to $53,088 per violation. Mississippi residents whose intimate images have been shared without consent can request removal through a covered platform's notice-and-takedown process and file a complaint with the FTC if the platform does not comply.
HIPAA
The Health Insurance Portability and Accountability Act applies to healthcare providers, health plans, and healthcare clearinghouses operating in Mississippi. HIPAA requires covered entities and their business associates to protect protected health information (PHI) through administrative, technical, and physical safeguards. Mississippi does not impose state-level health privacy requirements stricter than HIPAA. The Mississippi State Department of Health provides guidance to residents on accessing medical records and filing complaints with HHS.
GLBA
The Gramm-Leach-Bliley Act requires financial institutions to explain their information-sharing practices and safeguard sensitive customer data. Mississippi's breach notification law explicitly exempts entities that are in compliance with GLBA notification requirements.
COPPA
The Children's Online Privacy Protection Act applies to operators of websites and online services directed at children under 13 who collect personal information from those children. The Mississippi Department of Education addresses COPPA compliance in its student data privacy guidance.
FERPA
The Family Educational Rights and Privacy Act protects the privacy of student education records in Mississippi schools and universities. Mississippi's Student Data Accessibility, Transparency and Accountability Act of 2015 requires the state Department of Education to comply with FERPA and include privacy and security safeguards in contracts governing student data databases.
FTC Act Section 5
The FTC Act prohibits unfair or deceptive acts or practices in commerce. The FTC has used this authority to bring enforcement actions against companies with inadequate data security practices, regardless of whether a state has its own comprehensive privacy law. Mississippi businesses are subject to FTC jurisdiction for deceptive privacy and security practices.
FCRA and FACTA
The Fair Credit Reporting Act and Fair and Accurate Credit Transactions Act govern consumer reporting agencies and the accuracy, privacy, and security of consumer credit information. Mississippi residents have the right to a free annual credit report, to dispute inaccurate information, and to place security freezes and fraud alerts on their credit files.
Practical Steps for Businesses
Businesses that collect or process personal data from Mississippi residents should maintain a written information security policy and review it annually. If a breach occurs, begin the investigation immediately and prepare to notify affected individuals without unreasonable delay. Mississippi law does not require notifying the Attorney General as part of the breach disclosure process, though the Attorney General may pursue enforcement for noncompliance. If regulated by HIPAA or GLBA, confirm whether the federal safe harbor applies. Insurance licensees must additionally maintain an incident response plan and report qualifying cybersecurity events to the Insurance Commissioner within three business days.
Keep records of breach investigations and notification timelines. If any data is encrypted using industry-standard methods, document that fact explicitly to support an encryption safe harbor defense.
How Mississippi Residents Exercise Their Rights

Mississippi does not yet grant residents broad rights to access, delete, or port their personal data from private companies. Consumer rights under state law are limited to receiving breach notifications, filing complaints with the Attorney General, and pursuing criminal enforcement through the Cyber Crime Division.
Under federal law, Mississippi residents have rights including: the right to access and request corrections to medical records under HIPAA; the right to access and dispute credit reports under the FCRA; the right to a free annual credit report at AnnualCreditReport.com; and the right to place fraud alerts or credit freezes with the major credit bureaus at no cost.
For complaints: file with the Mississippi Attorney General's Consumer Protection Division at consumer@ago.ms.gov or through the online form at attorneygenerallynnfitch.com. For federal violations, file with the FTC at reportfraud.ftc.gov or with HHS for HIPAA complaints at hhs.gov/hipaa/filing-a-complaint.
Explore data privacy laws in other states on our Data Privacy Laws hub page.
This article provides general legal information about Mississippi data privacy laws. It is not legal advice and does not create an attorney-client relationship. Data privacy laws change frequently. Consult with a qualified attorney licensed in Mississippi for advice about your specific situation. Last reviewed: May 2026.
More Mississippi Laws
Frequently Asked Questions
Does Mississippi have a comprehensive consumer data privacy law?
No. As of May 2026, Mississippi does not have a comprehensive consumer data privacy law similar to California's CCPA or Virginia's VCDPA. The state has introduced multiple bills, including HB 1051 in 2026 and SB 2500 in 2025, but none have been enacted. Mississippi relies primarily on its data breach notification law (Miss. Code Ann. § 75-24-29), the Consumer Protection Act, sector-specific insurance regulations, and applicable federal privacy laws.
What are the data breach notification requirements in Mississippi?
Under Miss. Code Ann. § 75-24-29, any business that owns, licenses, or maintains personal information of Mississippi residents must notify affected individuals without unreasonable delay when a security breach occurs. Personal information means name combined with Social Security number, driver's license number, state identification card number, tribal identification card number, or financial account numbers with security codes. The statute does not require notice to the Mississippi Attorney General; only affected individuals must be notified. Notification is not required if the business reasonably determines the breach will not likely cause harm, or if the data was encrypted.
What penalties does Mississippi impose for failing to report a data breach?
Failure to comply with Mississippi's breach notification law is treated as an unfair trade practice under the Consumer Protection Act. The Attorney General can seek civil penalties of up to $10,000 per knowing and willful violation and can obtain injunctive relief. There is no private right of action for individual consumers.
Does Mississippi have specific cybersecurity requirements for insurance companies?
Yes. The Mississippi Insurance Data Security Act (Miss. Code Ann. §§ 83-5-801 to 83-5-825), effective July 1, 2019, requires insurance licensees to develop and maintain written information security programs, conduct risk assessments, maintain incident response plans, and report qualifying cybersecurity events to the Insurance Commissioner within three business days. A separate 2026 bill, HB 1220, would have created a general cybersecurity liability safe harbor for governmental and commercial entities that follow recognized frameworks, reaching this law only to carve civil liability determinations out of its exclusive-standards clause, but it died in a Senate committee in March 2026 and did not become law. Exemptions apply for licensees with fewer than 50 employees, under $5 million in annual revenue, or under $10 million in total assets.
What does the TAKE IT DOWN Act mean for Mississippi residents?
The TAKE IT DOWN Act (Pub. L. 119-12), signed May 19, 2025, is a federal law that criminalizes the publication of nonconsensual intimate images, including AI-generated deepfakes. Starting May 19, 2026, covered platforms must remove such images within 48 hours of a valid consumer request. The FTC enforces compliance and can impose civil penalties of up to $53,088 per violation. Mississippi residents can request removal directly from platforms and file an FTC complaint if the platform does not comply within 48 hours.
Does Mississippi regulate how minors' personal data is collected online?
Yes. The Walker Montgomery Protecting Children Online Act (HB 1126, 2024) requires digital service providers to verify a user's age, obtain parental consent before a minor can create an account, limit collection of a known minor's personal information to what is reasonably necessary, and bar targeted advertising involving harmful material and collection of a minor's precise geolocation data. The law has been challenged in NetChoice v. Fitch. The Fifth Circuit stayed a district court injunction on July 17, 2025, the U.S. Supreme Court declined to reinstate the injunction on August 14, 2025, and the Fifth Circuit heard oral argument on the merits of Mississippi's appeal on February 3, 2026 but has not yet ruled. The law remains in force in the meantime.
Can I sue a company in Mississippi for mishandling my personal data?
Mississippi's breach notification law does not create a private right of action. Only the Attorney General can enforce violations of Miss. Code Ann. § 75-24-29. You can file a complaint with the Attorney General's Consumer Protection Division at consumer@ago.ms.gov. For federal violations, such as HIPAA or FTC Act violations, separate federal enforcement mechanisms apply. The TAKE IT DOWN Act provides a separate civil right of action under 15 U.S.C. § 6851 for victims of nonconsensual intimate image disclosure.
Is Mississippi a one-party consent state for recording calls?
Yes. Under Miss. Code Ann. § 41-29-531, a person may record a phone call or in-person conversation if they are a party to it or if one party has consented, unless the recording is made for a criminal or tortious purpose. This means you can legally record your own conversations without telling the other party. Recording a conversation you are not part of without consent is a criminal violation.
Updates
Corrected the enacting bill for the breach notification law to 2010 H.B. 583, added tribal identification card numbers to the statutory definition of personal information (2021 H.B. 277), and rescoped the failed 2026 H.B. 1220 as a general cybersecurity safe harbor rather than an insurance-only amendment.
Added coverage of two enacted Mississippi statutes the page had omitted: the Walker Montgomery Protecting Children Online Act (age verification and parental consent for minors on social media, currently in force while a Fifth Circuit appeal is pending) and the Data Security for Money Transmitters Act (effective July 1, 2026).
Independently fact-checked against the cited primary sources
Corrected the article's claim that Mississippi HB 1220 (2026) was signed into law and amended the Insurance Data Security Act's cybersecurity standards; the bill actually died in a Senate committee on March 3, 2026 and never became law, so Miss. Code Ann. section 83-5-803 remains unamended since 2019.
Governing law re-checked for recent changes
Removed a fabricated 100-affected-individuals Attorney General notification requirement: Miss. Code Ann. § 75-24-29 requires notice only to affected individuals, and the Attorney General's role is limited to enforcing noncompliance.
Governing law re-checked for recent changes
May 2026 refresh: updated to reflect HB 1051 death in committee (February 3, 2026); added HB 1220 (2026), a proposed general cybersecurity safe harbor that later died in committee; added TAKE IT DOWN Act FTC enforcement live as of May 19, 2026 with current per-violation penalty ($53,088); added AG Fitch / 21-state Temu coalition enforcement action (August 2024); corrected recording statute citation to Miss. Code Ann. § 41-29-531; replaced Justia citations with law.cornell.edu and official .gov sources; added FCRA/FACTA section; added UpdatesLog component.
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Mississippi Code of 1972 Annotated
§ 75-24-29Persons conducting business in Mississippi required to provide notice of a breach of security involving personal information to all affected individuals; enforcement.In forcecited in 3 of our articles
(1) This section applies to any person who conducts business in this state and who, in the ordinary course of the person's business functions, owns, licenses or maintains personal information of any resident of this state. (2) For purposes of this section, the following terms shall have the meaning
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at billstatus.ls.state.ms.us
Also relied on in: Mississippi Biometric Privacy Laws: Collection, Consent & Penalties (2026), Mississippi Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 75-24-19Civil penalties; imposition and recovery.In forcecited in 2 of our articles
(1) Civil remedies. (a) Any person who violated the terms of an injunction issued under Section 75-24-9 shall forfeit and pay to the state a civil penalty in a sum not to exceed Ten Thousand Dollars ($10,000.00) per violation which shall be payable to the General Fund of the State of Mississippi.…
Official text (excerpt) · last checked 2020-07-08 · Read the full text in our law library
Cited in 6 court opinions in our collectionLatest citing opinion in our collection: 2024
Opinions citing this section in our collection:
- Mississippi Medicaid Pharmaceutical Average Wholesale Price Litigation v. State (Mississippi Supreme Court 2015, 190 So. 3d 829)“…was entitled to recover attorneys’ fees under the CPA. See Miss. Code Ann. § 75-24-19(1)(b) (Rev. 2009). ¶28. “Absent some…”
- State v. Yazaki North America, Inc., Leoni Wiring Systems, Inc., Leonische Holding, Inc., G.S.W. Manufacturing, Inc., G.S. Wiring Systems, Inc., Denso International America, Inc., and American Furukawa, Inc. (Mississippi Supreme Court 2020)“…ecovered “[i]n an[] action brought under Section 75-24-9.” Miss. Code Ann. § 75-24-19(1)(b) (Rev. 2016). If there is no acti…”
- In re Standard & Poor's Rating Agency Litigation (District Court, S.D. New York 2014, 23 F. Supp. 3d 378)“…es prohibited by the Mississippi Consumer Protection Act); Miss. Code Ann. § 75-24-19 (l)(b) (granting the state attorney gen…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 83-5-803Article establishes exclusive state standards for data security, investigation of cybersecurity event, and notification to Commissioner of Insurance.In force
(1) Notwithstanding any other provision of law, this article establishes the exclusive state standards applicable to licensees for data security, the investigation of a cybersecurity event as defined in Section 83-5-805, and notification to the Commissioner of Insurance. (2) This article may not…
Official text (excerpt) · last checked 2020-07-08 · Read the full text in our law library
§ 97-45-19Identity theft.In forcecited in 2 of our articles
(1) A person shall not obtain or attempt to obtain personal identity information of another person with the intent to unlawfully use that information for any of the following purposes without that person’s authorization: (a) To obtain financial credit. (b) To purchase or otherwise obtain or lease…
Official text (excerpt) · last checked 2026-09-02 · Read the full text in our law library · Verify at billstatus.ls.state.ms.us
Cited in 3 court opinions in our collectionLatest citing opinion in our collection: 2024
Opinions citing this section in our collection:
- Stephanie Fields v. State of Mississippi (Court of Appeals of Mississippi 2017, 228 So. 3d 942)“…ury indicted Fields on one count of felony identity theft, Miss. Code Ann. § 97-45-19 (Rev. 2006); three counts of felony us…”
- Paul J. Vlasak a/k/a Paul Joseph Vlasak v. State of Mississippi (Court of Appeals of Mississippi 2024)“…(Counts II, III, and IV); and one count of identity theft, Miss. Code Ann. § 97-45-19 (Rev. 2020) (Count V). The circuit cou…”
- Brassfield v. Wells Fargo Bank (District Court, S.D. Mississippi 2023)“…i law rather than a private right of action. [1-1] at 6; Miss. Code Ann. § 97-45-19. And Count 21 cites federal regulation…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Mississippi Identity Theft Laws: What Is Confirmed and What Is Not
United States Code Title 15
§ 7001General rule of validityIn forcecited in 18 of our articles
Notwithstanding any statute, regulation, or other rule of law (other than this subchapter and subchapter II), with respect to any transaction in or affecting interstate or foreign commerce— a signature, contract, or other record relating to such transaction may not be denied legal effect, validity, or enforceability solely because it is in electronic form; and a contract relating to such transaction may not be denied legal effect, validity, or enforceability solely because an electronic signature or electronic record was used in its formation. This subchapter does not— limit, alter, or otherwise affect any requirement imposed by a statute, regulation, or rule of law relating to the rights and obligations of persons under such statute, regulation, or rule of law other than a requirement that contracts or other records be written, signed, or in nonelectronic form; or require any person to agree to use or accept electronic records or electronic signatures, other than a governmental agency with respect to a record other than a contract to which it is a party.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 132 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Metropolitan Regional Information Systems v. American Home Realty Network (2012) applied 15 U.S.C. 7001(a) to hold an electronic assignment process satisfied the signed writing requirement of Copyright Act 204(a). Blatt v. Capital One Auto Finance (2017) held 7001(c) disclosures were not required where the record was delivered on paper.
Opinions citing this section in our collection:
- Metropolitan Regional Information Systems, Inc. v. American Home Realty Network, Inc. (District Court, D. Maryland 2012, 904 F. Supp. 2d 530)✓Subscribers assigned photo copyrights to a real estate database by uploading images under online terms of use; the court relied on E-SIGN, 15 U.S.C. section 7001, to hold those electronic assignments met the Copyright Act signed-writing rule, and denied reconsideration.
- Cutrone v. Mortgage Electronic Registration Systems, Inc. (District Court, E.D. New York 2013, 981 F. Supp. 2d 144)✓Homeowners sued MERS in state court over a second mortgage recording tax on an E-Sign mortgage; MERS removed under 15 U.S.C. section 7001, but the court held that statute gives no private right of action and at most a federal defense, which cannot support removal, and remanded.
- Blatt v. Capital One Auto Finance, Inc. (District Court, M.D. Tennessee 2017, 237 F. Supp. 3d 688)“…legal effect ..solely because it is in electronic form[.]” 15 U.S.C. § 7001 (a)(1).. Furthermore, it mandates that…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Montana Data Privacy Laws: MCDPA Consumer Rights Guide (2026), Nebraska Data Breach Notification Laws: Reporting Rules & Timelines (2026), Nevada Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 6851Civil action relating to disclosure of intimate imagesIn forcecited in 24 of our articles
In this section: The term “commercial pornographic content” means any material that is subject to the record keeping requirements under section 2257 of title 18. The term “consent” means an affirmative, conscious, and voluntary authorization made by the individual free from force, fraud, misrepresentation, or coercion. The term “depicted individual” means an individual whose body appears in whole or in part in an intimate visual depiction and who is identifiable by virtue of the person’s face, likeness, or other distinguishing characteristic, such as a unique birthmark or other recognizable feature, or from information displayed in connection with the visual depiction. The term “disclose” means to transfer, publish, distribute, or make accessible.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 49 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):District courts have begun applying the 15 U.S.C. 6851 private action for nonconsensual disclosure of intimate images. Goodnight v. Hammons (2025) read its unwelcome conduct and public concern exceptions narrowly and let the claim proceed. Parkes v. Walker II (2025) dismissed a claim that did not plead interstate commerce.
Opinions citing this section in our collection:
- TILLE v. KAPLAN (District Court, D. New Jersey 2025)“…iolence Against Women Reauthorization Act of 2022 (“VAWA”), 15 U.S.C. § 6851. Compl., D.E. 1, at 7-8. The allegati…”
- Turner v. Echols (District Court, W.D. Virginia 2025)✓A pretrial detainee sued an FBI agent under 15 U.S.C. 6851 over intimate images found in a warrantless phone search; the court dismissed, finding he never alleged he was depicted, never plausibly alleged disclosure, and that the law enforcement exception applied.
- Goodnight v. Hammons (District Court, W.D. Oklahoma 2025)✓A wife allegedly accessed her husband's devices, took his girlfriend's nude photos and sent them to a coworker; the court let the 15 U.S.C. 6851 claim proceed, rejecting the statute's unwelcome-conduct and public-concern exceptions as covering discovered infidelity.
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: How to File a DMCA Takedown on Xvideos (2026 Guide), What Is the Take It Down Act? The 2025 Federal NCII Law Explained, How to File a Take It Down Request (Step by Step)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Mississippi Code Ann. 75-24-29: Data Breach Notification Requirements(law.justia.com)
- Mississippi Code Ann. 75-24-19: Civil Penalties for Unfair Trade Practices(law.justia.com)
- Mississippi Attorney General: Consumer Protection Division(attorneygenerallynnfitch.com).gov
- Mississippi Insurance Data Security Law(mid.ms.gov).gov
- Mississippi Insurance Data Security Act: Miss. Code Ann. 83-5-801 to 83-5-825(law.justia.com)
- Mississippi Computer Crimes and Identity Theft: Title 97, Chapter 45(law.justia.com)
- Mississippi Identity Theft Statute: Miss. Code Ann. 97-45-19(law.justia.com)
- Mississippi State Department of Health: Privacy and Your Health Information(msdh.ms.gov).gov
- Mississippi Department of Education: Information Security and Data Privacy(mdek12.org).gov
- Mississippi DIT Services: Cybersecurity for Businesses(its.ms.gov).gov
- HB 1051 (2026): Mississippi Consumer Privacy Protection Act(trackbill.com)
- SB 2500 (2025): Mississippi Consumer Data Protection Act(billstatus.ls.state.ms.us).gov
- U.S. Department of Health and Human Services: HIPAA(hhs.gov).gov
- Federal Trade Commission: Gramm-Leach-Bliley Act(ftc.gov).gov
- Federal Trade Commission: COPPA Rule(ftc.gov).gov
- U.S. Department of Education: FERPA(www2.ed.gov).gov
- Mississippi State Auditor: State Agency Cybersecurity Compliance(osa.ms.gov).gov
- Miss. Code Ann. § 75-24-29: Data Breach Notification (Mississippi Legislature)(legislature.ms.gov).gov
- Miss. Code Ann. § 75-24-29: Data Breach Notification (Cornell LII)(law.cornell.edu)
- AG Fitch Demands Accountability for Data Privacy from China-Connected Online Retailer (August 27, 2024)(attorneygenerallynnfitch.com).gov
- HB 1220 (2026): Amendment to Miss. Code Ann. § 83-5-803, Cybersecurity Safe Harbor - Mississippi Legislature(billstatus.ls.state.ms.us).gov
- HB 1051 (2026): Mississippi Consumer Privacy Protection Act - LegiScan(legiscan.com)
- TAKE IT DOWN Act (Pub. L. 119-12): FTC Enforcement Begins May 19, 2026(ftc.gov).gov
- FTC: Complying With the TAKE IT DOWN Act(ftc.gov).gov
- Reporters Committee for Freedom of the Press: Mississippi Recording Laws(rcfp.org)
- Perkins Coie: Mississippi Security Breach Notification Chart(perkinscoie.com)
- Mississippi H.B. 583 (2010): Breach of Security; Require Notice - Bill History (Laws 2010, ch. 489, effective July 1, 2011)(billstatus.ls.state.ms.us)
- Mississippi H.B. 277 (2021): Tribal Identification Cards - Enrolled Text Amending Miss. Code Ann. Section 75-24-29(billstatus.ls.state.ms.us)
- Mississippi H.B. 1220 (2026): Cybersecurity Safe Harbor - Committee Substitute Text(billstatus.ls.state.ms.us)