Mississippi

Mississippi Privacy Law

Mississippi has no comprehensive consumer privacy statute, and the most concrete data-security obligations on its books belong to a single sector: the Insurance Data Security Law, effective July 1, 2019, requires licensees to build a written information security program, report a cybersecurity event to the Insurance Commissioner within three business days, and file an annual compliance certification. The state’s privacy activity outside insurance is driven by the Attorney General’s Consumer Protection Division, which enforces the Consumer Protection Act, the antitrust statutes and the state’s data-breach notification statute, and which in June 2026 announced an agreement with Roblox covering age verification, parental consent and default advertising settings for children.

Sector-Specific Privacy Laws in Mississippi

Insurance Data Security Law (Miss. Code Ann. §§ 83-5-801 to 83-5-825)

The Insurance Department describes the law — signed on April 3, 2019 and effective July 1, 2019 — as requiring every licensee to establish a comprehensive written information security program under § 83-5-807 by July 1, 2020. The reporting duty is short: a licensee must notify the Commissioner no later than three business days after determining that a cybersecurity event involving nonpublic information has occurred, where the statutory criteria are met. The department also imposes an annual certification: beginning February 15, 2021, each domestic Mississippi insurer must submit a written statement certifying that it is in compliance with the § 83-5-807 requirements. The exemptions are sized rather than sectoral in the first instance — a licensee with fewer than fifty employees excluding independent contractors, less than $5 million in gross annual revenue, or less than $10 million in year-end total assets may be exempt, as may an insurance producer or adjuster — with further exemptions for entities complying with HIPAA, entities affiliated with a depository institution meeting Gramm-Leach-Bliley standards, and entities covered by another licensee’s program.

What the Consumer Protection Division enforces

The Attorney General’s Consumer Protection Division states that its attorneys civilly enforce the Mississippi Consumer Protection Act, the Mississippi antitrust statutes, the Mississippi data breach notification statute, and other laws including the federal Fair Debt Collection Practices Act, and that its work includes “protecting consumer privacy and advocacy against illegal robocalls”. The Division also carries the Attorney General’s statutory duties before the Mississippi Public Service Commission. Separately, the Division enforces the Mississippi Telephone Solicitation Act, under which a telephonic solicitor registering in the state must post a $75,000 surety bond payable to the Attorney General’s office and file a plain-text file listing every outgoing telephone number it uses for telemarketing calls, to comply with RP28 100.6.c of the rules implementing that Act.

Outside counsel and the technology docket

Mississippi litigates a substantial part of its consumer-protection work through contingency-fee counsel, and publishes every such contract. The Attorney General’s office states that it retains private attorneys for a fraction of cases, that it maintains full control over the litigation, that it reviews the attorneys’ hourly time sheets and declines to pay hours or expenses it deems excessive, and that contingency counsel are paid only on a successful outcome for the state. The published list of active contingency-fee matters is itself a map of the state’s technology docket: it names Facebook, Meta, TikTok, Google AdTech and Seagate alongside pharmaceutical and industrial defendants. The office also states that before agreeing to such a contract it determines whether the matter has merit and will benefit the state, whether it can be handled internally, and whether private counsel has sufficient resources and skill.

Data Breach Notification in Mississippi

Mississippi’s general breach-notification duty is enforced civilly by the Attorney General rather than by a sector regulator: the Consumer Protection Division lists “the Mississippi data breach notification statute” among the laws its attorneys enforce, alongside the Consumer Protection Act and the state antitrust statutes. The one Mississippi breach-reporting deadline published by a state agency belongs to the insurance sector. The Insurance Department states that under the Insurance Data Security Law a licensee must notify the Commissioner no later than three business days after determining that a cybersecurity event involving nonpublic information has occurred, and that domestic insurers must additionally certify compliance with the information-security-program requirement each year from February 15, 2021. Consumers who believe a business has mishandled their information are directed by the Division to its consumer mediators and its complaint form.

Residents must be notified the Attorney General's Consumer Protection Division identifies the Mississippi data breach notification statute as one of the laws it civilly enforces. No general reporting threshold is described in the Attorney General's published material. Complaints are taken by the Mississippi Attorney General, which enforces the statute.

Recent Enforcement in Mississippi

Roblox — statewide agreement on children’s accounts, June 2026. The Attorney General announced on June 22, 2026 a settlement with the gaming platform Roblox. The office describes terms blocking adult interaction with teens and children, age verification and parental consent, no nighttime notifications, and access limited to age-appropriate content. Parents gain controls over who their children talk to, how long they are online, which games they access and transfers of the platform’s in-game currency, and default settings will not permit personalized advertising or push notifications without parental consent. The agreement also requires heightened standards to detect grooming behaviour, predatory conduct and suspicious communication patterns involving minor users; commits Roblox to continue not encrypting communications involving minors, which the office says lets law enforcement more easily combat child exploitation networks and trafficking; and requires Roblox to hire an in-state law enforcement liaison giving the Attorney General’s Internet Crimes Against Children Task Force real-time or near-real-time access around the clock. The financial terms are $9 million toward digital literacy education and a fully funded parental empowerment and education programme, plus $5 million in liquidated damages securing compliance.

Pending Privacy Legislation

The Attorney General’s account of the Roblox agreement records a gap the settlement was used to fill: $9 million of the payment goes to fund digital literacy education that the office says was “created, but not funded during the 2026 Legislative Session”. Nothing in the Attorney General’s or the Insurance Department’s published material describes a comprehensive Mississippi consumer privacy statute, and Mississippi consumers have no statutory rights of access, correction, deletion or opt-out of the kind enacted in Tennessee and Texas. The state’s enforcement energy has instead gone into litigation: the Attorney General’s published list of active contingency-fee matters includes Meta, Facebook, TikTok and Google AdTech.

Federal Privacy Laws That Apply in Mississippi

Federal privacy law applies in Mississippi by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The state-law counterpart to section 5 is the What the Consumer Protection Division enforces, which the Mississippi Attorney General enforces against businesses whose stated data practices differ from their actual ones.

Industry Rules That Reach Mississippi Businesses

With no comprehensive state statute, most privacy obligations on a Mississippi business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.

Two of those reach Mississippi businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while Mississippi itself has none, and any business holding personal information about Mississippi residents is subject to the state’s breach-notification statute described above.

Mississippi Privacy Law FAQ

Who enforces Mississippi’s data-breach notification statute?
The Attorney General’s Consumer Protection Division. The Division’s own description of its work states that its attorneys civilly enforce “the Mississippi Consumer Protection Act, Mississippi antitrust statutes, the Mississippi data breach notification statute, and other laws such as the federal Fair Debt Collection Practices Act”, and describes protecting consumer privacy as part of its remit. Consumers are directed to the Division’s consumer mediators and its online complaint form.
How quickly must a Mississippi insurance licensee report a cybersecurity event?
Three business days. The Mississippi Insurance Department states that under the Insurance Data Security Law a licensee must notify the Commissioner no later than three business days after determining that a cybersecurity event involving nonpublic information has occurred and the statutory criteria are met. That is the shortest published breach-reporting deadline applying to a Mississippi business.
Which insurance licensees are exempt from Mississippi’s cybersecurity law?
The Insurance Department describes exemptions turning first on size: a licensee with fewer than fifty employees excluding independent contractors, less than $5 million in gross annual revenue, or less than $10 million in year-end total assets, and insurance producers and adjusters, may be exempt from certain requirements. Further exemptions cover entities complying with HIPAA, entities affiliated with a depository institution that meets Gramm-Leach-Bliley standards, and entities covered under another licensee’s information security program.
Do Mississippi insurers have to certify their security programs?
Yes, annually. The Insurance Department states that each domestic Mississippi insurer must, beginning February 15, 2021 and each year thereafter, submit a written statement certifying that the insurer is in compliance with the information security program requirements of § 83-5-807 — the program the department says had to be established in comprehensive written form by July 1, 2020.
What did Mississippi’s 2026 agreement with Roblox require?
The Attorney General’s office describes an agreement blocking adult interaction with teens and children, requiring age verification and parental consent, barring nighttime notifications and limiting access to age-appropriate content. Default settings may not permit personalized advertising or push notifications without parental consent, and parents gain controls over their children’s contacts, time online, games and transfers of in-game currency. The agreement also requires detection standards for grooming and predatory conduct, a commitment not to encrypt communications involving minors, an in-state law enforcement liaison for the Attorney General’s Internet Crimes Against Children Task Force, $9 million for digital literacy education and a parental education programme, and $5 million in liquidated damages to secure compliance.
Which technology companies is Mississippi currently litigating against?
The Attorney General’s office publishes its active contingency-fee contracts, and the list names Facebook, Meta, TikTok, Google AdTech and Seagate among the matters being handled with outside counsel. The office states that it retains full control over such litigation, reviews the private attorneys’ hourly time sheets and declines to pay hours or expenses it deems excessive, and pays contingency counsel only in the event of a successful outcome for the state.
What does a telemarketer have to file with the Mississippi Attorney General?
A telephonic solicitor registering under the Mississippi Telephone Solicitation Act must submit a completed registration application, a $75,000 surety bond payable to the Attorney General’s office (or verification that a prior bond remains current), contracted-company forms where applicable, and a plain-text file listing every outgoing telephone number used for telemarketing calls, formatted one record per line as digits only. The office states that the file requirement implements RP28 100.6.c of the rules implementing that Act, and that non-text files are returned as unacceptable.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.