Missouri
Missouri Data Privacy Laws: Breach Notification & Consumer Rights (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 16 primary sources cited on this page. How we verify our legal content

Missouri does not have a comprehensive consumer data privacy law. The state relies instead on a patchwork of targeted statutes: the data breach notification law (Mo. Rev. Stat. Section 407.1500), identity theft protections, Social Security number restrictions, and the Missouri Merchandising Practices Act. A new Insurance Data Security Act (HB 974) took effect January 1, 2026, adding cybersecurity obligations for insurers and their licensees.
This guide covers every current Missouri law that affects data privacy, explains how federal statutes fill the remaining gaps, and identifies what Missouri residents can do to protect themselves in the absence of comprehensive state privacy rights.
Missouri takes a sectoral approach to data privacy rather than adopting a single comprehensive consumer privacy statute. The state relies on several targeted laws to protect residents' personal information, with the data breach notification statute (Mo. Rev. Stat. Section 407.1500) serving as the primary privacy protection for most consumers.
This guide covers every major Missouri law that touches data privacy, from breach notification requirements to identity theft penalties to Social Security number protections. It also explains how federal privacy laws fill the gaps where Missouri does not have state-level protections.
Missouri Has No Comprehensive Consumer Privacy Law
As of May 2026, Missouri has not enacted a comprehensive consumer data privacy law. States like California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), and Connecticut (CTDPA) have passed laws granting residents broad rights over their personal data, including the right to access, correct, delete, and opt out of the sale of personal information.
Missouri residents do not currently have these broad statutory rights under state law.
Legislative Efforts That Have Not Succeeded
Missouri lawmakers have introduced privacy legislation across multiple recent sessions, but none has advanced to the governor's desk.
In 2024, Senate Bill 731 proposed creating consumer data protection rights similar to those in other states, including rights to access and delete personal data and opt out of data sales. The bill died in committee.
In the 2025 session, Senator Nick Schroer introduced SB 554, the Missouri Biometric Data Privacy Act. The bill would have created written-policy requirements for private entities collecting biometric information and provided a private right of action for violations, modeled on Illinois' BIPA. As of the close of the 2025 session, SB 554 remained in the Senate Judiciary and Civil and Criminal Jurisprudence Committee and did not become law.
Until the legislature acts, Missouri residents must rely on the state's existing patchwork of privacy-related statutes and federal law for data protection.
AG Algorithmic Freedom Regulation (January 2025)
In January 2025, then-Attorney General Andrew Bailey promulgated a regulation under the Missouri Merchandising Practices Act requiring social media platforms to offer users a choice of third-party content moderation algorithms rather than requiring use of the platform's own algorithm. The regulation defined operating a social media platform without offering that algorithmic choice as an unfair practice under the MMPA.
This regulation does not function as a comprehensive data privacy law, but it represents an active use of the MMPA as an enforcement tool against large technology platforms. Attorney General Bailey resigned effective September 8, 2025, after being appointed co-deputy director of the FBI. Governor Mike Kehoe appointed Catherine Hanaway as the new Attorney General in August 2025; she took office on September 8, 2025.
Missouri Data Breach Notification Law (Mo. Rev. Stat. Section 407.1500)
The Missouri data breach notification statute is the state's most significant data privacy protection. Enacted in 2009, it establishes mandatory notification requirements when personal information is compromised in a security breach.

Who Must Comply
The law applies to two categories of entities:
Data owners and licensees: Any person that owns or licenses personal information of residents of Missouri, or any person that conducts business in Missouri that owns or licenses personal information in any form of a Missouri resident, must notify affected consumers following a breach.
Data custodians: Any person that maintains or possesses records or data containing personal information of Missouri residents that the person does not own or license must notify the owner or licensee of the information immediately following discovery of a breach.
This broad scope means the law covers businesses of all sizes, government contractors, service providers, and any other entity that handles Missouri residents' personal data.
What Qualifies as a Breach of Security
Under Section 407.1500, a "breach of security" is defined as unauthorized access to and unauthorized acquisition of personal information maintained in computerized form by a person that compromises the security, confidentiality, or integrity of the personal information.
Two conditions must be present for an event to constitute a breach: there must be unauthorized access, and there must be unauthorized acquisition. Simply accessing data without acquiring it may not trigger the notification requirement.
Good-faith acquisition of personal information by an entity or its employee or agent for a legitimate purpose is not considered a breach of security, provided the personal information is not used in violation of applicable law or in a manner that harms or poses an actual threat to the security, confidentiality, or integrity of the personal information.
What Personal Information Is Protected
The statute defines "personal information" as an individual's first name or first initial and last name in combination with any one or more of the following data elements, when the data elements are not encrypted, redacted, or otherwise rendered unreadable or unusable:
| Data Element | Examples |
|---|---|
| Social Security number | Full SSN |
| Driver's license or government ID number | MO driver's license, state ID |
| Financial account number with security code | Bank account + PIN, credit card + CVV |
| Unique electronic identifier or routing code with security code | Online banking credentials |
| Medical information | Medical history, diagnoses, treatment records |
| Health insurance information | Policy number, subscriber ID, insurer identifiers |
Missouri's definition is broader than some states because it includes medical information and health insurance information as protected data elements. If any of these data elements are encrypted, redacted, or otherwise rendered unreadable, a breach involving those elements does not trigger the notification requirement.
Notification Timeline
Missouri requires notification to be made "without unreasonable delay." The statute does not specify a fixed number of days, unlike states such as Colorado (30 days) or Florida (30 days).
The notification timeline accounts for the legitimate needs of law enforcement and any measures necessary to determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system.
Attorney General Notification
When a breach affects more than 1,000 consumers at one time, the entity must also notify the Missouri Attorney General's office without unreasonable delay. This notification must include the timing, distribution, and content of the consumer notice.
The Attorney General's office maintains resources for both businesses reporting breaches and consumers who have received breach notifications.
What the Notice Must Include
Breach notifications to affected consumers must include advice that directs the consumer to remain vigilant by reviewing account statements and monitoring free credit reports. While Missouri's content requirements are less detailed than some other states, best practices suggest including:
- A description of the incident
- The types of personal information compromised
- Steps the consumer can take to protect themselves
- Contact information for the notifying entity
- Information about credit monitoring and fraud alerts
Methods of Notification
Entities may provide notice through any one of the following methods:
Written notice: Sent to the consumer's postal address in the entity's records.
Electronic notice: Permitted for consumers who have valid email addresses on file and have agreed to receive communications electronically. Electronic notice must be consistent with the provisions of the federal Electronic Signatures in Global and National Commerce Act (E-SIGN Act, 15 U.S.C. Section 7001).
Telephonic notice: Permitted if the contact is made directly with the affected consumers.
Substitute notice: Available when the cost of providing notice would exceed $100,000, when the class of affected consumers exceeds 150,000, when the entity lacks sufficient contact information or consent for the other methods, or when the entity is unable to identify particular affected consumers. Substitute notice consists of all of the following: email notice where the entity has an email address for the affected consumer, conspicuous posting of the notice or a link to it on the entity's website if the entity maintains one, and notification to major statewide media.
Exceptions to Notification
Notification is not required if, after an appropriate investigation or after consultation with relevant federal, state, or local law enforcement agencies, the entity determines that a risk of identity theft or other fraud to any consumer is not reasonably likely to occur as a result of the breach. This determination must be documented in writing and maintained for five years.
Entities regulated by state or federal law that maintain breach notification procedures under their primary or functional regulator are deemed in compliance with the Missouri statute if they notify affected consumers under those existing procedures.
Penalties for Noncompliance
The Missouri Attorney General has exclusive authority to enforce the breach notification law. The Attorney General may bring an action to obtain actual damages for a willful and knowing violation and may seek civil penalties not to exceed $150,000 per breach of the security system, or per series of breaches of a similar nature discovered in a single investigation.
There is no private right of action under the breach notification statute. Individual consumers cannot sue businesses directly for failure to provide breach notification.
Missouri Insurance Data Security Act (HB 974, Effective January 1, 2026)
Missouri enacted the Insurance Data Security Act in 2025 (HB 974). The law took effect January 1, 2026, and applies to insurance companies and other entities licensed by the Missouri Department of Commerce and Insurance.

Who Must Comply
The law covers insurers and all other entities licensed under Missouri insurance law, including insurance producers, premium finance companies, and other licensees. It does not apply to entities with fewer than 10 employees or those with annual revenue below certain thresholds, as set out in the statute.
Information Security Program Requirements
Licensees must develop, implement, and maintain a comprehensive written information security program. The program must be based on a risk assessment and include:
- Administrative, technical, and physical safeguards appropriate to the size and complexity of the licensee
- Employee training on cybersecurity risks and controls
- An incident response plan that addresses investigation, containment, and recovery
- Oversight of third-party service providers with access to nonpublic information
Breach Notification to the Department
When a licensee determines that a cybersecurity event has occurred that could materially harm consumers or the licensee's operations, it must notify the Missouri Director of the Department of Commerce and Insurance within four business days. This timeline is more precise than the general "without unreasonable delay" standard in Section 407.1500.
Consumer notification under the Insurance Data Security Act follows the requirements of Section 407.1500 for any covered breach of personal information.
Relationship to Section 407.1500
The Insurance Data Security Act operates alongside Section 407.1500. Licensed insurers must comply with both. The Insurance Data Security Act adds a layer of cybersecurity program requirements that Section 407.1500 does not impose; Section 407.1500 governs consumer notification obligations that apply whether or not an entity is licensed in the insurance industry.
Missouri Merchandising Practices Act and Data Privacy
The Missouri Merchandising Practices Act (MMPA), codified at Mo. Rev. Stat. Sections 407.010 through 407.130, provides a broader consumer protection framework that can apply to data privacy violations.
How the MMPA Applies to Privacy
Section 407.020 declares it unlawful for any person to use deception, fraud, false pretense, false promise, misrepresentation, unfair practice, or the concealment, suppression, or omission of any material fact in connection with the sale or advertisement of merchandise in trade or commerce.
This broad prohibition can apply to data privacy in several ways:
False privacy promises: A company that promises in its privacy policy not to sell consumer data but then sells it could face MMPA liability for misrepresentation.
Concealment of data practices: Failing to disclose material data collection or sharing practices could violate the prohibition against concealment or omission of material facts.
Deceptive data security claims: Representing that consumer data is secured by specific measures when it is not could constitute deception under the MMPA.
Technology platform conduct: The January 2025 Algorithmic Freedom Regulation, promulgated under the MMPA, illustrates how Missouri has extended the MMPA's reach to platform data practices and content moderation. That regulation requires social media platforms to offer users algorithmic choice rather than imposing a single proprietary algorithm.
Enforcement and Penalties
The Missouri Attorney General administers and enforces the MMPA. The AG can investigate potential violations, issue subpoenas for documents, and bring enforcement actions.
Local prosecuting attorneys may also bring criminal charges for intentional MMPA violations. A person who willfully and knowingly violates the MMPA with the intent to defraud may face felony charges.
Consumers have a private right of action under the MMPA, which distinguishes it from the breach notification statute. Consumers who suffer an ascertainable loss due to a prohibited practice can sue for actual damages, punitive damages, and attorney's fees.
Identity Theft Protections in Missouri
Missouri has robust criminal and civil statutes addressing identity theft, providing both penalties for offenders and remedies for victims.

Criminal Identity Theft (Mo. Rev. Stat. Section 570.223)
Under Section 570.223, a person commits identity theft if they knowingly and with the intent to deceive or defraud obtain, possess, transfer, use, or attempt to obtain, transfer, or use one or more means of identification not lawfully issued for their use.
Penalty Structure
The penalties for identity theft in Missouri are tiered based on the value of credit, money, goods, services, or other property obtained:
| Value of Theft | Classification | Potential Penalty |
|---|---|---|
| No financial gain | Class B misdemeanor | Up to 6 months in jail |
| Up to $750 | Class A misdemeanor | Up to 1 year in jail |
| $750 to $25,000 | Class D felony | Up to 7 years in prison |
| $25,000 to $75,000 | Class C felony | Up to 10 years in prison |
| Over $75,000 | Class B felony | 5 to 15 years in prison |
Repeat offenders face enhanced penalties. A person previously convicted of identity theft who commits another identity theft involving property valued at $750 or less is guilty of a class E felony rather than a misdemeanor.
Restitution
Courts may order defendants to pay restitution to victims, including costs incurred in clearing the victim's credit history or credit rating and costs connected with any civil or administrative proceeding to satisfy any debt, lien, or other obligation arising from the defendant's actions.
Civil Remedies for Identity Theft Victims
Victims of identity theft in Missouri have access to significant civil remedies under Section 570.223:
Statutory damages: Up to $5,000 per incident, or three times the amount of actual damages, whichever is greater.
Injunctive relief: Victims may seek a court order to prevent future violations.
Attorney's fees: Courts may award reasonable attorney's fees to the plaintiff.
Statute of limitations: Civil actions must be brought within five years from the date the identity of the wrongdoer was discovered or reasonably should have been discovered.
Deceased persons: If the identifying information of a deceased person is used unlawfully, the deceased person's estate has the right to recover damages.
Trafficking in Stolen Identities (Mo. Rev. Stat. Section 570.224)
Section 570.224 creates a separate offense for trafficking in stolen identities. A person commits this offense if they manufacture, sell, transfer, or possess with intent to sell or transfer means of identification for the purpose of committing identity theft.
Possession of five or more means of identification of the same person, or possession of means of identification of five or more separate persons, is evidence of intent to traffic. This offense is classified as a class B felony, carrying a potential sentence of 5 to 15 years in prison.
Social Security Number Protections
Missouri has specific protections for Social Security numbers under multiple statutes.
Private Sector SSN Restrictions (Mo. Rev. Stat. Section 407.1355)
Section 407.1355 prohibits entities from publicly posting or displaying an individual's Social Security number. It also specifically restricts employers:
- Employers may not require an employee to use their SSN as an employee number for any employment-related activity.
- Employers may not require the use of the last four digits of a SSN as an employee number (effective since December 31, 2015).
These restrictions do not prevent the collection, use, or release of SSNs as required by state or federal law, or the use of SSNs for internal verification or administrative purposes.
Personal Privacy Protection Act (Mo. Rev. Stat. Section 105.1500)
Section 105.1500 is not a Social Security number statute. Known as the Personal Privacy Protection Act, it protects the identity of donors, members, and volunteers of tax-exempt 501(c) organizations: a public agency generally may not compel disclosure of that information, and any such personal information in a public agency's possession is a closed record under Chapter 610. A person alleging a violation may bring a civil action for injunctive relief and damages of at least $2,500 per violation, or up to three times that amount for an intentional violation.
Court Filing Protections (Mo. Rev. Stat. Section 509.520)
Section 509.520 prohibits the inclusion of full Social Security numbers in court pleadings, attachments, exhibits, judgments, or orders. This protection helps prevent identity theft through public court records.
Credit Report Security Freezes
Missouri's security freeze law (Mo. Rev. Stat. Sections 407.1380 through 407.1384) allows consumers to restrict access to their credit reports, which is an important tool for preventing identity theft after a data breach.
How Security Freezes Work
Under Section 407.1382, a consumer may request that a consumer credit reporting agency place a security freeze on the consumer's credit report. Once a freeze is in place, the credit reporting agency may not release the consumer's credit report or any information from it without the consumer's express authorization.
Security freezes are free for all consumers nationwide under federal law (the Economic Growth, Regulatory Relief, and Consumer Protection Act of 2018), superseding any state-law fee provisions.
Enforcement
Under Section 407.1384, any consumer credit reporting agency that knowingly fails to comply with the security freeze provisions is liable to the consumer for actual damages, court costs, and reasonable attorney's fees. Courts may also award equitable relief to restore a damaged consumer's credit.
Student Data Privacy Protections
Missouri protects student data through Mo. Rev. Stat. Section 161.096, which regulates the state's longitudinal data system and student data accessibility.

Key protections include:
- Access to personally identifiable student data is restricted to authorized staff, district administrators, teachers, school personnel with a legitimate need, and students and their parents for their own records.
- Contracts with private vendors that handle student data must include provisions prohibiting the sale of student data or its use for advertising purposes, with penalties for noncompliance.
- The Missouri Department of Elementary and Secondary Education (DESE) must comply with all relevant state and federal privacy laws, including the federal Family Educational Rights and Privacy Act (FERPA).
Federal Privacy Laws Covering Missouri Residents
Because Missouri lacks a comprehensive state privacy law, federal statutes play a particularly important role in protecting Missouri residents' data in specific sectors.

TAKE IT DOWN Act (Pub. L. 119-12, Signed May 19, 2025)
The TAKE IT DOWN Act (Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act) was signed into law on May 19, 2025. Its criminal prohibition on publishing nonconsensual intimate images (NCII), including AI-generated deepfakes, took effect immediately on signing.
Platform takedown obligations under Section 3 of the Act became effective May 19, 2026. Covered platforms must maintain a notice-and-removal process. When a platform receives a valid request, it must remove the specified content and any known identical copies within 48 hours. The FTC began enforcing Section 3 compliance as of May 19, 2026, with potential civil penalties of $53,088 per violation.
This law provides direct federal protection for Missouri residents against the nonconsensual publication of intimate images online.
Health Information: HIPAA
The Health Insurance Portability and Accountability Act (HIPAA) protects the health information of Missouri residents held by covered entities (healthcare providers, health plans, and healthcare clearinghouses) and their business associates. HIPAA establishes a federal floor for health data privacy, and states are free to enact stricter protections. HIPAA does not preempt state laws that provide greater privacy protections.
Missouri's breach notification law complements HIPAA by including medical information and health insurance information in its definition of protected personal information under Section 407.1500.
Financial Information: GLBA and FCRA
The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to explain their information-sharing practices to customers and to safeguard sensitive financial data. Missouri residents who are customers of banks, credit unions, securities firms, and insurance companies receive privacy protections under GLBA. Financial institutions subject to GLBA that maintain their own breach notification procedures are deemed in compliance with Missouri's breach notification statute.
The Fair Credit Reporting Act (FCRA) regulates how consumer reporting agencies collect, access, use, and share information about consumers. Missouri residents have the right to dispute inaccurate information in their credit files, access their credit reports, and receive notice when adverse action is taken based on a consumer report. FCRA overlaps directly with Missouri's credit freeze statute: the federal Economic Growth Act of 2018 made credit freezes free nationwide, supplementing Missouri's Section 407.1382.
Education Records: FERPA
The Family Educational Rights and Privacy Act (FERPA) protects the education records of Missouri students at institutions that receive federal funding. Parents and eligible students (age 18 and older) have the right to access education records, request corrections, and control disclosures of personally identifiable information from those records.
Consumer Data: FTC Act Section 5
The Federal Trade Commission enforces Section 5 of the FTC Act, which prohibits unfair or deceptive acts or practices in commerce. The FTC has used this authority to bring enforcement actions against companies with inadequate data security practices or those that misrepresent their privacy practices. This provides a baseline level of privacy protection for all Missouri consumers.
Children's Online Privacy: COPPA
The Children's Online Privacy Protection Act (COPPA) requires websites and online services directed at children under 13 to obtain verifiable parental consent before collecting personal information from children. This federal law provides important protections for Missouri's youngest residents online.
Federal Comprehensive Privacy Legislation: APRA
Congress has debated federal comprehensive privacy legislation in recent years. The American Privacy Rights Act (APRA) was introduced in bipartisan form in 2024 but did not become law. A revised version, sometimes called APRA 2.0, was introduced in 2025 and similarly had not passed as of May 2026. Missouri residents should not assume comprehensive federal privacy rights exist; as of the date of this guide, no general federal consumer data privacy law has been enacted.
Missouri Attorney General: Consumer Privacy Resources
The Missouri Attorney General's office provides several resources for consumers dealing with data privacy issues. Attorney General Catherine Hanaway took office on September 8, 2025, succeeding Andrew Bailey.
Identity Theft Assistance
The AG's office operates a hotline for identity theft victims at 800-392-8222. Complaint investigators help advise victims on steps to take after identity theft occurs.
Data Breach Checklist
The AG's office publishes a checklist for consumers who have received a data breach notice. This resource guides consumers through steps such as reviewing the breach notice carefully, placing fraud alerts on credit reports, monitoring financial statements, and filing complaints.
Statutory Guide
The Statutory Guide to Privacy and Data Breach Laws maintained by the AG's office provides an overview of all privacy-related statutes in Missouri, organized by type of protected information.
How Missouri Compares to Other States
Missouri's approach to data privacy differs significantly from states that have enacted comprehensive privacy laws.
| Feature | Missouri | California | Virginia | Colorado |
|---|---|---|---|---|
| Comprehensive privacy law | No | Yes (CCPA/CPRA) | Yes (VCDPA) | Yes (CPA) |
| Right to access data | No | Yes | Yes | Yes |
| Right to delete data | No | Yes | Yes | Yes |
| Right to correct data | No | Yes | Yes | Yes |
| Right to opt out of sales | No | Yes | Yes | Yes |
| Breach notification law | Yes | Yes | Yes | Yes |
| Breach notification deadline | No fixed deadline | 30 days | Without unreasonable delay | 30 days |
| AG notification required | Over 1,000 consumers | Over 500 residents | Required | Over 500 residents |
| Maximum breach penalty | $150,000 per breach | $7,500 per intentional violation | $150,000 per breach | $20,000 per violation |
| Private right of action (breach) | No | Yes (limited) | No | No |
| Identity theft civil remedies | Yes ($5,000 or 3x damages) | Yes | Yes | Yes |
Practical Steps for Missouri Residents
Without a comprehensive privacy law, Missouri residents should take proactive steps to protect their personal information.
Monitor your credit reports. Request free annual credit reports from each of the three major credit bureaus through AnnualCreditReport.com. Review them for unauthorized accounts or inquiries.
Place security freezes. Use Missouri's security freeze law to restrict access to your credit reports. Freezes are free under federal law and do not affect your credit score.
Review breach notifications carefully. If you receive a breach notification, follow the AG's checklist and take advantage of any free credit monitoring offered.
Report identity theft promptly. Contact the Missouri AG's identity theft hotline at 800-392-8222 and file a report with local law enforcement. Document all unauthorized transactions and communications.
Act on NCII takedown requests. If nonconsensual intimate images of you appear online, you now have a direct federal right under the TAKE IT DOWN Act to request removal from covered platforms within 48 hours. You can also report violations to the FTC.
Read privacy policies. Since Missouri does not require businesses to provide specific data rights, understanding what data companies collect and how they use it is especially important.
More Missouri Laws
Missouri's data privacy protections are part of a broader set of legal protections for residents. Explore other Missouri legal topics:
- State Data Privacy Laws Overview
- Missouri AI Meeting Recording Laws
- Missouri Alimony Laws
- Missouri At-Will Employment Laws
- Missouri Car Accident Laws
- Missouri Car Seat Laws
- Missouri Child Custody Laws
- Missouri Child Support Laws
- Missouri Common Law Marriage Laws
- Missouri Deepfake Laws
- Missouri Divorce Laws
- Missouri Dog Bite Laws
- Missouri Emancipation Laws
- Missouri Expungement Laws
- Missouri Hit and Run Laws
- Missouri Landlord-Tenant Laws
- Missouri Lemon Laws
- Missouri Whistleblower Laws
- Missouri Police Bodycam Laws
- Missouri Employee Monitoring Laws
More Missouri Laws
Updates
Corrected the date Attorney General Catherine Hanaway took office, clarified that treble damages under the Personal Privacy Protection Act are a ceiling rather than automatic, and completed the breach notification methods to include telephonic notice and the full substitute notice conditions.
Corrected the cross-state comparison table's maximum breach-notification penalty for Virginia from $7,500 per violation to $150,000 per breach, matching Va. Code Section 18.2-186.6(I).
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected a mislabeled statute: Mo. Rev. Stat. Section 105.1500 is the Personal Privacy Protection Act, which shields 501(c) nonprofit donor identities, not a Social Security number disclosure statute as the article previously stated. Also corrected the MMPA felony standard to require willful conduct and intent to defraud, not mere knowing conduct.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Revised Statutes of Missouri, Title XXVI (TRADE AND COMMERCE), Chapter 407
§ 407.1500Definitions — notice to consumer for breach of security, procedure — attorney general may bring action for damages.In forcecited in 4 of our articles
1. As used in this section, the following terms mean: (1) "Breach of security" or "breach", unauthorized access to and unauthorized acquisition of personal information maintained in computerized form by a person that compromises the security, confidentiality, or integrity of the personal information. Good faith acquisition of personal information by a person or that person's employee or agent for a legitimate purpose of that person is not a breach of security, provided that the personal information is not used in violation of applicable law or in a manner that harms or poses an actual threat to the security, confidentiality, or integrity of the personal information; (2) "Consumer", an individual who is a resident of this state; (3) "Consumer reporting agency", the same as defined by the federal Fair Credit Reporting Act, 15 U.S.C.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at revisor.mo.gov
Also relied on in: Missouri Biometric Privacy Laws: Collection, Consent & Penalties (2026), Missouri Data Breach Notification Laws: Reporting Rules & Timelines (2026), Missouri Identity Theft Laws: Penalties, Civil Remedies, and Reporting
§ 407.1355Social Security numbers, prohibited actions involving.In force
1. Except as provided in this section a person or entity, not including a state or local agency, shall not do any of the following: (1) Publicly post or publicly display in any manner an individual's Social Security number. "Publicly post" or "publicly display" is defined in this section to intentionally communicate or otherwise make available to the general public or to an individual's co-workers; (2) Require an individual to transmit his or her Social Security number over the internet, unless the connection is secure or the Social Security number is encrypted; (3) Require an individual to use his or her Social Security number to access an internet website, unless a password, unique personal identification number, or other authentication device is also required to access the internet website; (4) Require an individual to use his or her Social Security number as an employee number for any type of employment-related activity; (5) Require an individual to use the last four digits of his or her Social Security number as an employee number for any type of employment-related activity.
Official text (excerpt) · last checked 2026-07-31 · Read the full text in our law library · Verify at revisor.mo.gov
§ 407.020Unlawful practices, penalty — exceptions.In forcecited in 3 of our articles
1. The act, use or employment by any person of any deception, fraud, false pretense, false promise, misrepresentation, unfair practice or the concealment, suppression, or omission of any material fact in connection with the sale or advertisement of any merchandise in trade or commerce or the solicitation of any funds for any charitable purpose, as defined in section 407.453, in or from the state of Missouri, is declared to be an unlawful practice. The use by any person, in connection with the sale or advertisement of any merchandise in trade or commerce or the solicitation of any funds for any charitable purpose, as defined in section 407.453, in or from the state of Missouri of the fact that the attorney general has approved any filing required by this chapter as the approval, sanction or endorsement of any activity, project or action of such person, is declared to be an unlawful practice. Any act, use or employment declared unlawful by this subsection violates this subsection whether committed before, during or after the sale, advertisement or solicitation.
Official text (excerpt) · last checked 2026-07-31 · Read the full text in our law library · Verify at revisor.mo.gov
Cited in 210 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Missouri Health Care Ass'n v. Attorney General (Supreme Court of Missouri 1997, 953 S.W.2d 617)“…egulate the way in which these facilities conduct business. Sec. 407.020, RSMo Supp. 1996. No speculation or additiona…”
- State Ex Rel. Mobile Home Estates, Inc. v. Public Service Commission (Missouri Court of Appeals 1996, 921 S.W.2d 5)“…conduct which constitutes a violation of the provisions of section 407.020, RSMo; (5) Failing to comply with the…”
- Planned Parenthood Great Plains v. State of Missouri ex rel. Attorney General Andrew Bailey (Missouri Court of Appeals 2025)“…engaging in any practices declared to be unlawful by § 407.020, RSMo.” The [Attorney General] further stated…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Revised Statutes of Missouri, Title XXXVIII (CRIMES AND PUNISHMENT; PEACE OFFICERS AND PUBLIC DEFENDERS), Chapter 570
§ 570.223Identity theft — penalty — restitution — other civil remedies available — exempted activities.In forcecited in 2 of our articles
1. A person commits the offense of identity theft if he or she knowingly and with the intent to deceive or defraud obtains, possesses, transfers, uses, or attempts to obtain, transfer or use, one or more means of identification not lawfully issued for his or her use. 2. The offense of identity theft is a class B misdemeanor unless the identity theft results in the theft or appropriation of credit, money, goods, services, or other property: (1) Not exceeding seven hundred fifty dollars in value, in which case it is a class A misdemeanor; (2) Exceeding seven hundred fifty dollars and not exceeding twenty-five thousand dollars in value, in which case it is a class D felony; (3) Exceeding twenty-five thousand dollars and not exceeding seventy-five thousand dollars in value, in which case it is a class C felony; (4) Exceeding seventy-five thousand dollars in value, in which case it is a class B felony.
Official text (excerpt) · last checked 2026-09-02 · Read the full text in our law library · Verify at revisor.mo.gov
Cited in 6 court opinions in our collectionLatest citing opinion in our collection: 2016
In the courts (editorial summary, independently checked):Missouri courts have applied section 570.223 to convictions for using another person's identifying data. State v. Young (2012) affirmed an identity theft conviction, treating evidence of an uncharged entry and theft of personal papers as relevant to show how the defendant obtained the means of identification.
Opinions citing this section in our collection:
- State v. Young (Missouri Court of Appeals 2012, 367 S.W.3d 641)✓A woman used an ex-partner's name, Social Security number and birthdate, allegedly taken from papers removed from his home, to obtain a $50,000 line of credit; the court affirmed her Section 570.223 conviction, holding evidence of the uncharged break-in was relevant.
- State v. DILDINE-MARTIN (Missouri Court of Appeals 2009, 295 S.W.3d 555)“…e after a jury convicted her of felony identity theft under section 570.223 RSMo 2000. Defendant argues that the trial c…”
- State v. Smith (Missouri Court of Appeals 2009, 278 S.W.3d 717)“…ter a jury found him guilty of one count of identity theft, § 570.223 RSMo. (2000). Smith’s sole claim of error is…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 570.224Trafficking in stolen identities — possession of documents, exemptions — penalty.In force
1. A person commits the offense of trafficking in stolen identities if he or she, for the purpose of committing identity theft, manufactures, sells, transfers, or possesses with intent to sell or transfer means of identification. 2. Possession of five or more means of identification of the same person or possession of means of identification of five or more separate persons shall be evidence that the identities are possessed with intent to manufacture, sell, or transfer means of identification for the purpose of committing identity theft. In determining possession of five or more means of identification of the same person, or possession of means of identification of five or more separate persons for the purposes of evidence pursuant to this subsection, the following do not apply: (1) The possession of his or her own identification documents; (2) The possession of the identification documents of a person who has consented to the person at issue possessing his or her identification documents. 3. The offense of trafficking in stolen identities is a class B felony.
Official text (excerpt) · last checked 2026-07-31 · Read the full text in our law library · Verify at revisor.mo.gov
Revised Statutes of Missouri, Title XI (EDUCATION AND LIBRARIES), Chapter 161
§ 161.096Statewide longitudinal data system, regulation on student data accessibility, transparency, and accountability required — regulation requirements — data not to be reported — rulemaking authority — violation, penalty — attorney general to enforce.In force
1. The state board of education shall promulgate a rule relating to student data accessibility, transparency, and accountability relating to the statewide longitudinal data system. This rule shall mandate that the department of elementary and secondary education do the following: (1) Create and make publicly available a data inventory and index of data elements with definitions of individual student data fields in the student data system to include, but not be limited to: (a) Any personally identifiable student data required to be reported by state and federal education laws; and (b) Any other individual student data which has been proposed for inclusion in the student data system with a statement regarding the purpose or reason for the proposed collection; (2) Develop policies to comply with all relevant state and federal privacy laws and policies, including but not limited to the federal Family Educational Rights and Privacy Act (FERPA) and other relevant privacy laws and policies. These policies shall include, but not be limited to the following requirements: (a) Access to personally identifiable student data in the statewide longitudinal data system shall be…
Official text (excerpt) · last checked 2026-07-31 · Read the full text in our law library · Verify at revisor.mo.gov
Revised Statutes of Missouri, Title XXXV (CIVIL PROCEDURE AND LIMITATIONS), Chapter 509
§ 509.520Court records, required redactions — confidential case file sheet, contents.In force
1. Notwithstanding any provision of law to the contrary, beginning August 28, 2023, pleadings, attachments, exhibits filed with the court in any case, as well as any judgments or orders issued by the court, or other records of the court shall not include the following confidential and personal identifying information: (1) The full Social Security number of any party or any child; (2) The full credit card number, financial institution account number, personal identification number, or password used to secure an account of any party; (3) The full motor vehicle operator license number; (4) Victim information, including the name, address, and other contact information of the victim; (5) Witness information, including the name, address, and other contact information of the witness; (6) Any other full state identification number; (7) The name, address, and date of birth of a minor and, if applicable, any next friend; or (8) The full date of birth of any party; however, the year of birth shall be made available, except for a minor.
Official text (excerpt) · last checked 2026-07-31 · Read the full text in our law library · Verify at revisor.mo.gov
Cited in 65 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- Cheri Nabil El-Halawany, M.D. and Lien Pham Russell, M.D. vs. The Children's Mercy Hospital (Missouri Court of Appeals 2025)“…5 until April 6, 2021.3 3 Pursuant to section 509.520, RSMo. (2024), this opinion only includes par…”
- State of Missouri v. Richard E. Calvin (Missouri Court of Appeals 2025)“…court’s judgment. 1 Names are redacted pursuant to § 509.520, RSMo (Cum. Supp. 2023).…”
- 3018 Pershall, LLC v. Outfront Media, LLC (Missouri Court of Appeals 2025)“…ation of victims and witnesses has been omitted pursuant to RSMo § 509.520 (Supp. 2023).…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Revised Statutes of Missouri, Title VIII (PUBLIC OFFICERS AND EMPLOYEES, BONDS AND RECORDS), Chapter 105
§ 105.1500Citation of law — definitions — public agencies, personal information disclosures, not required, when — exceptions — violations, remedies — inapplicability, when.In force
1. This section shall be known and may be cited as "The Personal Privacy Protection Act". 2. As used in this section, the following terms mean: (1) "Personal information", any list, record, register, registry, roll, roster, or other compilation of data of any kind that directly or indirectly identifies a person as a member, supporter, or volunteer of, or donor of financial or nonfinancial support to, any entity exempt from federal income taxation under Section 501(c) of the Internal Revenue Code of 1986, as amended; (2) "Public agency", the state and any political subdivision thereof including, but not limited to, any department, agency, office, commission, board, division, or other entity of state government; any county, city, township, village, school district, community college district; or any other local governmental unit, agency, authority, council, board, commission, state or local court, tribunal or other judicial or quasi-judicial body.
Official text (excerpt) · last checked 2026-07-31 · Read the full text in our law library · Verify at revisor.mo.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Mo. Rev. Stat. Section 407.1500: Data Breach Notification(revisor.mo.gov).gov
- Mo. Rev. Stat. Section 407.020: Missouri Merchandising Practices Act(revisor.mo.gov).gov
- Mo. Rev. Stat. Section 570.223: Identity Theft Statute(revisor.mo.gov).gov
- Mo. Rev. Stat. Section 570.224: Trafficking in Stolen Identities(revisor.mo.gov).gov
- Mo. Rev. Stat. Section 407.1355: Social Security Number Protections(revisor.mo.gov).gov
- Mo. Rev. Stat. Section 105.1500: Personal Privacy Protection Act(revisor.mo.gov).gov
- Mo. Rev. Stat. Section 509.520: Court Filing SSN Protections(revisor.mo.gov).gov
- Mo. Rev. Stat. Sections 407.1380-407.1384: Credit Report Security Freezes(revisor.mo.gov).gov
- Mo. Rev. Stat. Section 161.096: Student Data Privacy(revisor.mo.gov).gov
- Missouri Attorney General: Data Breaches(ago.mo.gov).gov
- Missouri Attorney General: Identity Theft and Data Security(ago.mo.gov).gov
- Missouri Attorney General: Statutory Guide to Privacy and Data Breach Laws(ago.mo.gov).gov
- Missouri Attorney General: Data Breach Checklist(ago.mo.gov).gov
- Missouri DESE: Data Access, Sharing, and Privacy(dese.mo.gov).gov
- HHS: HIPAA Preemption of State Law(hhs.gov).gov
- Missouri Senate: SB 731 (2024 Privacy Bill)(senate.mo.gov).gov
- St. Louis Public Radio: Catherine Hanaway sworn in as Missouri attorney general (September 8, 2025)(stlpr.org)