Mississippi Privacy Law
Mississippi has no comprehensive consumer privacy statute, and the most concrete data-security obligations on its books belong to a single sector: the Insurance Data Security Law, effective July 1, 2019, requires licensees to build a written information security program, report a cybersecurity event to the Insurance Commissioner within three business days, and file an annual compliance certification. The state’s privacy activity outside insurance is driven by the Attorney General’s Consumer Protection Division, which enforces the Consumer Protection Act, the antitrust statutes and the state’s data-breach notification statute, and which in June 2026 announced an agreement with Roblox covering age verification, parental consent and default advertising settings for children.
Sector-Specific Privacy Laws in Mississippi
Insurance Data Security Law (Miss. Code Ann. §§ 83-5-801 to 83-5-825)
The Insurance Department describes the law — signed on April 3, 2019 and effective July 1, 2019 — as requiring every licensee to establish a comprehensive written information security program under § 83-5-807 by July 1, 2020. The reporting duty is short: a licensee must notify the Commissioner no later than three business days after determining that a cybersecurity event involving nonpublic information has occurred, where the statutory criteria are met. The department also imposes an annual certification: beginning February 15, 2021, each domestic Mississippi insurer must submit a written statement certifying that it is in compliance with the § 83-5-807 requirements. The exemptions are sized rather than sectoral in the first instance — a licensee with fewer than fifty employees excluding independent contractors, less than $5 million in gross annual revenue, or less than $10 million in year-end total assets may be exempt, as may an insurance producer or adjuster — with further exemptions for entities complying with HIPAA, entities affiliated with a depository institution meeting Gramm-Leach-Bliley standards, and entities covered by another licensee’s program.
What the Consumer Protection Division enforces
The Attorney General’s Consumer Protection Division states that its attorneys civilly enforce the Mississippi Consumer Protection Act, the Mississippi antitrust statutes, the Mississippi data breach notification statute, and other laws including the federal Fair Debt Collection Practices Act, and that its work includes “protecting consumer privacy and advocacy against illegal robocalls”. The Division also carries the Attorney General’s statutory duties before the Mississippi Public Service Commission. Separately, the Division enforces the Mississippi Telephone Solicitation Act, under which a telephonic solicitor registering in the state must post a $75,000 surety bond payable to the Attorney General’s office and file a plain-text file listing every outgoing telephone number it uses for telemarketing calls, to comply with RP28 100.6.c of the rules implementing that Act.
Outside counsel and the technology docket
Mississippi litigates a substantial part of its consumer-protection work through contingency-fee counsel, and publishes every such contract. The Attorney General’s office states that it retains private attorneys for a fraction of cases, that it maintains full control over the litigation, that it reviews the attorneys’ hourly time sheets and declines to pay hours or expenses it deems excessive, and that contingency counsel are paid only on a successful outcome for the state. The published list of active contingency-fee matters is itself a map of the state’s technology docket: it names Facebook, Meta, TikTok, Google AdTech and Seagate alongside pharmaceutical and industrial defendants. The office also states that before agreeing to such a contract it determines whether the matter has merit and will benefit the state, whether it can be handled internally, and whether private counsel has sufficient resources and skill.
Data Breach Notification in Mississippi
Mississippi’s general breach-notification duty is enforced civilly by the Attorney General rather than by a sector regulator: the Consumer Protection Division lists “the Mississippi data breach notification statute” among the laws its attorneys enforce, alongside the Consumer Protection Act and the state antitrust statutes. The one Mississippi breach-reporting deadline published by a state agency belongs to the insurance sector. The Insurance Department states that under the Insurance Data Security Law a licensee must notify the Commissioner no later than three business days after determining that a cybersecurity event involving nonpublic information has occurred, and that domestic insurers must additionally certify compliance with the information-security-program requirement each year from February 15, 2021. Consumers who believe a business has mishandled their information are directed by the Division to its consumer mediators and its complaint form.
Residents must be notified the Attorney General's Consumer Protection Division identifies the Mississippi data breach notification statute as one of the laws it civilly enforces. No general reporting threshold is described in the Attorney General's published material. Complaints are taken by the Mississippi Attorney General, which enforces the statute.
Recent Enforcement in Mississippi
Roblox — statewide agreement on children’s accounts, June 2026. The Attorney General announced on June 22, 2026 a settlement with the gaming platform Roblox. The office describes terms blocking adult interaction with teens and children, age verification and parental consent, no nighttime notifications, and access limited to age-appropriate content. Parents gain controls over who their children talk to, how long they are online, which games they access and transfers of the platform’s in-game currency, and default settings will not permit personalized advertising or push notifications without parental consent. The agreement also requires heightened standards to detect grooming behaviour, predatory conduct and suspicious communication patterns involving minor users; commits Roblox to continue not encrypting communications involving minors, which the office says lets law enforcement more easily combat child exploitation networks and trafficking; and requires Roblox to hire an in-state law enforcement liaison giving the Attorney General’s Internet Crimes Against Children Task Force real-time or near-real-time access around the clock. The financial terms are $9 million toward digital literacy education and a fully funded parental empowerment and education programme, plus $5 million in liquidated damages securing compliance.
Pending Privacy Legislation
The Attorney General’s account of the Roblox agreement records a gap the settlement was used to fill: $9 million of the payment goes to fund digital literacy education that the office says was “created, but not funded during the 2026 Legislative Session”. Nothing in the Attorney General’s or the Insurance Department’s published material describes a comprehensive Mississippi consumer privacy statute, and Mississippi consumers have no statutory rights of access, correction, deletion or opt-out of the kind enacted in Tennessee and Texas. The state’s enforcement energy has instead gone into litigation: the Attorney General’s published list of active contingency-fee matters includes Meta, Facebook, TikTok and Google AdTech.
Federal Privacy Laws That Apply in Mississippi
Federal privacy law applies in Mississippi by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The state-law counterpart to section 5 is the What the Consumer Protection Division enforces, which the Mississippi Attorney General enforces against businesses whose stated data practices differ from their actual ones.
Industry Rules That Reach Mississippi Businesses
With no comprehensive state statute, most privacy obligations on a Mississippi business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.
Two of those reach Mississippi businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while Mississippi itself has none, and any business holding personal information about Mississippi residents is subject to the state’s breach-notification statute described above.
Mississippi Privacy Law FAQ
Who enforces Mississippi’s data-breach notification statute?
How quickly must a Mississippi insurance licensee report a cybersecurity event?
Which insurance licensees are exempt from Mississippi’s cybersecurity law?
Do Mississippi insurers have to certify their security programs?
What did Mississippi’s 2026 agreement with Roblox require?
Which technology companies is Mississippi currently litigating against?
What does a telemarketer have to file with the Mississippi Attorney General?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- Mississippi Insurance Department — Mississippi Cybersecurity Law (Insurance Data Security Law, §§ 83-5-801 to 83-5-825) agency
- Mississippi Attorney General — Consumer Protection Division agency
- Mississippi Attorney General — Landmark agreement with Roblox to protect children online (June 22, 2026) agency
- Mississippi Attorney General — Press releases index agency
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.