EnglishEspañol
Mississippi flag

Mississippi

Mississippi Data Privacy Laws: Breach Notification & Consumer Rights (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 9, 2026. · 16 primary sources cited on this page. How we verify our legal content

Mississippi Data Privacy Laws: Breach Notification & Consumer Rights (2026)

Frequently Asked Questions

Does Mississippi have a comprehensive consumer data privacy law?

No. As of May 2026, Mississippi does not have a comprehensive consumer data privacy law similar to California's CCPA or Virginia's VCDPA. The state has introduced multiple bills, including HB 1051 in 2026 and SB 2500 in 2025, but none have been enacted. Mississippi relies primarily on its data breach notification law (Miss. Code Ann. § 75-24-29), the Consumer Protection Act, sector-specific insurance regulations, and applicable federal privacy laws.

What are the data breach notification requirements in Mississippi?

Under Miss. Code Ann. § 75-24-29, any business that owns, licenses, or maintains personal information of Mississippi residents must notify affected individuals without unreasonable delay when a security breach occurs. Personal information means name combined with Social Security number, driver's license number, state identification card number, tribal identification card number, or financial account numbers with security codes. The statute does not require notice to the Mississippi Attorney General; only affected individuals must be notified. Notification is not required if the business reasonably determines the breach will not likely cause harm, or if the data was encrypted.

What penalties does Mississippi impose for failing to report a data breach?

Failure to comply with Mississippi's breach notification law is treated as an unfair trade practice under the Consumer Protection Act. The Attorney General can seek civil penalties of up to $10,000 per knowing and willful violation and can obtain injunctive relief. There is no private right of action for individual consumers.

Does Mississippi have specific cybersecurity requirements for insurance companies?

Yes. The Mississippi Insurance Data Security Act (Miss. Code Ann. §§ 83-5-801 to 83-5-825), effective July 1, 2019, requires insurance licensees to develop and maintain written information security programs, conduct risk assessments, maintain incident response plans, and report qualifying cybersecurity events to the Insurance Commissioner within three business days. A separate 2026 bill, HB 1220, would have created a general cybersecurity liability safe harbor for governmental and commercial entities that follow recognized frameworks, reaching this law only to carve civil liability determinations out of its exclusive-standards clause, but it died in a Senate committee in March 2026 and did not become law. Exemptions apply for licensees with fewer than 50 employees, under $5 million in annual revenue, or under $10 million in total assets.

What does the TAKE IT DOWN Act mean for Mississippi residents?

The TAKE IT DOWN Act (Pub. L. 119-12), signed May 19, 2025, is a federal law that criminalizes the publication of nonconsensual intimate images, including AI-generated deepfakes. Starting May 19, 2026, covered platforms must remove such images within 48 hours of a valid consumer request. The FTC enforces compliance and can impose civil penalties of up to $53,088 per violation. Mississippi residents can request removal directly from platforms and file an FTC complaint if the platform does not comply within 48 hours.

Does Mississippi regulate how minors' personal data is collected online?

Yes. The Walker Montgomery Protecting Children Online Act (HB 1126, 2024) requires digital service providers to verify a user's age, obtain parental consent before a minor can create an account, limit collection of a known minor's personal information to what is reasonably necessary, and bar targeted advertising involving harmful material and collection of a minor's precise geolocation data. The law has been challenged in NetChoice v. Fitch. The Fifth Circuit stayed a district court injunction on July 17, 2025, the U.S. Supreme Court declined to reinstate the injunction on August 14, 2025, and the Fifth Circuit heard oral argument on the merits of Mississippi's appeal on February 3, 2026 but has not yet ruled. The law remains in force in the meantime.

Can I sue a company in Mississippi for mishandling my personal data?

Mississippi's breach notification law does not create a private right of action. Only the Attorney General can enforce violations of Miss. Code Ann. § 75-24-29. You can file a complaint with the Attorney General's Consumer Protection Division at consumer@ago.ms.gov. For federal violations, such as HIPAA or FTC Act violations, separate federal enforcement mechanisms apply. The TAKE IT DOWN Act provides a separate civil right of action under 15 U.S.C. § 6851 for victims of nonconsensual intimate image disclosure.

Is Mississippi a one-party consent state for recording calls?

Yes. Under Miss. Code Ann. § 41-29-531, a person may record a phone call or in-person conversation if they are a party to it or if one party has consented, unless the recording is made for a criminal or tortious purpose. This means you can legally record your own conversations without telling the other party. Recording a conversation you are not part of without consent is a criminal violation.

Updates

Corrected the enacting bill for the breach notification law to 2010 H.B. 583, added tribal identification card numbers to the statutory definition of personal information (2021 H.B. 277), and rescoped the failed 2026 H.B. 1220 as a general cybersecurity safe harbor rather than an insurance-only amendment.

Added coverage of two enacted Mississippi statutes the page had omitted: the Walker Montgomery Protecting Children Online Act (age verification and parental consent for minors on social media, currently in force while a Fifth Circuit appeal is pending) and the Data Security for Money Transmitters Act (effective July 1, 2026).

Independently fact-checked against the cited primary sources

Corrected the article's claim that Mississippi HB 1220 (2026) was signed into law and amended the Insurance Data Security Act's cybersecurity standards; the bill actually died in a Senate committee on March 3, 2026 and never became law, so Miss. Code Ann. section 83-5-803 remains unamended since 2019.

Governing law re-checked for recent changes

Removed a fabricated 100-affected-individuals Attorney General notification requirement: Miss. Code Ann. § 75-24-29 requires notice only to affected individuals, and the Attorney General's role is limited to enforcing noncompliance.

Governing law re-checked for recent changes

May 2026 refresh: updated to reflect HB 1051 death in committee (February 3, 2026); added HB 1220 (2026), a proposed general cybersecurity safe harbor that later died in committee; added TAKE IT DOWN Act FTC enforcement live as of May 19, 2026 with current per-violation penalty ($53,088); added AG Fitch / 21-state Temu coalition enforcement action (August 2024); corrected recording statute citation to Miss. Code Ann. § 41-29-531; replaced Justia citations with law.cornell.edu and official .gov sources; added FCRA/FACTA section; added UpdatesLog component.

Reviewed and approved by an editor

Sources and References

  1. Mississippi Code Ann. 75-24-29: Data Breach Notification Requirements(law.justia.com)
  2. Mississippi Code Ann. 75-24-19: Civil Penalties for Unfair Trade Practices(law.justia.com)
  3. Mississippi Attorney General: Consumer Protection Division(attorneygenerallynnfitch.com).gov
  4. Mississippi Insurance Data Security Law(mid.ms.gov).gov
  5. Mississippi Insurance Data Security Act: Miss. Code Ann. 83-5-801 to 83-5-825(law.justia.com)
  6. Mississippi Computer Crimes and Identity Theft: Title 97, Chapter 45(law.justia.com)
  7. Mississippi Identity Theft Statute: Miss. Code Ann. 97-45-19(law.justia.com)
  8. Mississippi State Department of Health: Privacy and Your Health Information(msdh.ms.gov).gov
  9. Mississippi Department of Education: Information Security and Data Privacy(mdek12.org).gov
  10. Mississippi DIT Services: Cybersecurity for Businesses(its.ms.gov).gov
  11. HB 1051 (2026): Mississippi Consumer Privacy Protection Act(trackbill.com)
  12. SB 2500 (2025): Mississippi Consumer Data Protection Act(billstatus.ls.state.ms.us).gov
  13. U.S. Department of Health and Human Services: HIPAA(hhs.gov).gov
  14. Federal Trade Commission: Gramm-Leach-Bliley Act(ftc.gov).gov
  15. Federal Trade Commission: COPPA Rule(ftc.gov).gov
  16. U.S. Department of Education: FERPA(www2.ed.gov).gov
  17. Mississippi State Auditor: State Agency Cybersecurity Compliance(osa.ms.gov).gov
  18. Miss. Code Ann. § 75-24-29: Data Breach Notification (Mississippi Legislature)(legislature.ms.gov).gov
  19. Miss. Code Ann. § 75-24-29: Data Breach Notification (Cornell LII)(law.cornell.edu)
  20. AG Fitch Demands Accountability for Data Privacy from China-Connected Online Retailer (August 27, 2024)(attorneygenerallynnfitch.com).gov
  21. HB 1220 (2026): Amendment to Miss. Code Ann. § 83-5-803, Cybersecurity Safe Harbor - Mississippi Legislature(billstatus.ls.state.ms.us).gov
  22. HB 1051 (2026): Mississippi Consumer Privacy Protection Act - LegiScan(legiscan.com)
  23. TAKE IT DOWN Act (Pub. L. 119-12): FTC Enforcement Begins May 19, 2026(ftc.gov).gov
  24. FTC: Complying With the TAKE IT DOWN Act(ftc.gov).gov
  25. Reporters Committee for Freedom of the Press: Mississippi Recording Laws(rcfp.org)
  26. Perkins Coie: Mississippi Security Breach Notification Chart(perkinscoie.com)
  27. Mississippi H.B. 583 (2010): Breach of Security; Require Notice - Bill History (Laws 2010, ch. 489, effective July 1, 2011)(billstatus.ls.state.ms.us)
  28. Mississippi H.B. 277 (2021): Tribal Identification Cards - Enrolled Text Amending Miss. Code Ann. Section 75-24-29(billstatus.ls.state.ms.us)
  29. Mississippi H.B. 1220 (2026): Cybersecurity Safe Harbor - Committee Substitute Text(billstatus.ls.state.ms.us)
Share: