Missouri

Missouri Privacy Law

Missouri has not enacted a comprehensive consumer privacy law, but it is one of the few states whose constitution names electronic data directly: article I, section 15 secures the people in their “electronic communications and data” against unreasonable searches and seizures. On the commercial side, Missouri’s breach-notification statute counts medical and health-insurance information as personal information and reserves enforcement entirely to the Attorney General.

Sector-Specific Privacy Laws in Missouri

Mo. Const. art. I, § 15 — electronic communications and data

Missouri’s search-and-seizure clause reads that “the people shall be secure in their persons, papers, homes, effects, and electronic communications and data, from unreasonable searches and seizures,” and requires that no warrant issue to “access electronic data or communication” without describing the data or communication to be accessed as nearly as may be, on probable cause supported by written oath or affirmation. The clause governs state action rather than private data handling, which places Missouri’s constitutional text alongside its statutory scheme rather than inside it.

Missouri Merchandising Practices Act (RSMo 407.020)

RSMo 407.020.1 declares unlawful the use of any deception, fraud, false pretense, false promise, misrepresentation, unfair practice or the concealment, suppression or omission of any material fact in connection with the sale or advertisement of merchandise in trade or commerce in or from Missouri, and states that the conduct violates the subsection whether committed before, during or after the sale. Subsection 3 makes willfully and knowingly engaging in such conduct with intent to defraud a class E felony. Subsection 2(2) exempts institutions chartered, licensed or regulated by the director of the Department of Commerce and Insurance, the division of credit unions or the division of finance, unless those directors specifically authorise the Attorney General to act.

Library records — RSMo 182.817

RSMo 182.817.1 bars a library, its employees or agents, or a third party contracted to receive, transmit, maintain or store library records from releasing a library record except on the written request of the person identified in it or on a court order finding disclosure necessary to protect the public safety or prosecute a crime. Subsection 2 lets a person whose privacy was compromised file a written complaint with the Attorney General within 180 days and separately bring a private civil action in the circuit court of the county where the library sits, with discretionary punitive damages and attorney fees for the prevailing party; a prevailing respondent recovers fees only on a showing that the case was without foundation.

Data Breach Notification in Missouri

RSMo 407.1500, enacted by House Bill 62 in 2009, defines personal information more broadly than most breach statutes of its generation: alongside a Social Security number, a government-issued identification number and a financial account number with its access code, subdivision 1(9) counts a unique electronic identifier or routing code with its access credentials, medical information, and health insurance information. Subsection 2(4) prescribes what the notice must describe — the incident in general terms, the type of information obtained, a telephone number for further information if one exists, contact information for the consumer reporting agencies, and advice to review account statements and monitor free credit reports. Subsection 2(5) supplies a risk-of-harm exception: notification is not required where, after an appropriate investigation or consultation with law enforcement, the person determines that identity theft or other fraud is not reasonably likely to occur, provided that determination is documented in writing and the documentation retained for five years. Substitute notice becomes available under subsection 2(6)(d) where notice would cost more than $100,000 or the affected class exceeds 150,000 consumers. Under subsection 4 the Attorney General has exclusive authority to sue for actual damages for a willful and knowing violation and may seek a civil penalty of up to $150,000 per breach, or per series of breaches of a similar nature discovered in a single investigation.

Residents must be notified without unreasonable delay after discovery or notification of the breach. Notify the Attorney General, and the nationwide consumer reporting agencies, when notice is given to more than 1,000 consumers at one time. Complaints are taken by the Missouri Attorney General, which enforces the statute.

Recent Enforcement in Missouri

Blackbaud — $49.5 million multistate settlement, October 2023. The Attorney General announced on October 5, 2023 that Missouri and 49 other states settled with software company Blackbaud over a 2020 ransomware incident, with Missouri receiving over $800,000 of the $49.5 million paid to the states. The office states the settlement resolved allegations that Blackbaud violated state consumer-protection laws, state breach-notification laws and HIPAA by failing to implement reasonable data security, and that the company did not give its customers timely, complete or accurate information about the breach, so that notification to affected consumers was significantly delayed or never occurred. The incident affected more than 13,000 Blackbaud customers, whose data included Social Security numbers, driver’s licence numbers, financial information, donation history and protected health information.

23andMe bankruptcy sale conditions — June 2025. On July 2, 2025 the Attorney General announced that Missouri, as part of a multistate coalition, had secured privacy conditions on the sale of 23andMe. The Eastern District of Missouri Bankruptcy Court approved the $305 million sale to TTAM Research Institute on June 27, 2025 after states objected to the treatment of consumer genetic information in the bankruptcy. The office states that the conditions built into the sale agreement include no transfer of consumer DNA, a continuing right for consumers to delete their data permanently with enforcement mechanisms to verify deletion — overseen in part by the Missouri Attorney General’s Consumer Protection Team — a bar on future resale without full adoption of the privacy commitments, a prohibition on sharing data with entities connected to Countries of Concern as defined by federal law, and creation of a three-person Consumer Privacy Advisory Board.

Pending Privacy Legislation

No comprehensive consumer-privacy statute has been enacted in Missouri. The state’s general data-security obligations continue to run through RSMo 407.1500, unchanged since House Bill 62 took effect on August 28, 2009, and through the Merchandising Practices Act.

Federal Privacy Laws That Apply in Missouri

Federal privacy law applies in Missouri by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

Outside those federal sectors, Missouri obligations run through the state’s breach-notification statute and the Missouri Attorney General’s general consumer-protection authority rather than through a privacy statute of its own.

Industry Rules That Reach Missouri Businesses

With no comprehensive state statute, most privacy obligations on a Missouri business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.

Two of those reach Missouri businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while Missouri itself has none, and any business holding personal information about Missouri residents is subject to the state’s breach-notification statute described above.

Missouri Privacy Law FAQ

Does Missouri’s breach law cover medical information?
Yes. RSMo 407.1500.1(9) includes both “medical information” and “health insurance information” among the data elements that, combined with a name, make up personal information. Subdivision 1(6) defines medical information as any information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional, and subdivision 1(5) defines health insurance information as a policy or subscriber identification number or any unique identifier a health insurer uses to identify the individual.
Can a Missouri resident sue a company for failing to give breach notice?
Not under the breach statute. RSMo 407.1500.4 provides that the Attorney General “shall have exclusive authority to bring an action to obtain actual damages for a willful and knowing violation of this section,” and may seek a civil penalty not to exceed $150,000 per breach of security or series of breaches of a similar nature discovered in a single investigation.
When can a Missouri business decide not to notify after a breach?
RSMo 407.1500.2(5) provides that notification is not required if, after an appropriate investigation by the person or after consultation with the relevant federal, state or local law-enforcement agencies, the person determines that a risk of identity theft or other fraud to any consumer is not reasonably likely to occur as a result of the breach. The statute adds that such a determination shall be documented in writing and the documentation maintained for five years.
What does article I, section 15 of the Missouri Constitution say about data?
It places electronic material alongside the traditional categories. The section secures the people in their “persons, papers, homes, effects, and electronic communications and data” from unreasonable searches and seizures, and provides that no warrant to search a place, seize a person or thing, “or access electronic data or communication” shall issue without describing the data or communication to be accessed as nearly as may be, and without probable cause supported by written oath or affirmation.
Who must Missouri businesses notify besides affected consumers?
RSMo 407.1500.2(8) provides that where a person gives notice to more than one thousand consumers at one time, that person shall notify, without unreasonable delay, the Attorney General’s office and all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis as defined in 15 U.S.C. § 1681a(p), of the timing, distribution and content of the notice.
Are Missouri library records confidential?
RSMo 182.817.1 provides that no library, employee or agent of a library, or third party contracted to receive, transmit, maintain or store library records shall release a library record except in response to a written request of the person identified in that record, or an order of a court of competent jurisdiction finding disclosure necessary to protect the public safety or to prosecute a crime. Subsection 2 gives a person whose privacy was compromised 180 days to complain in writing to the Attorney General and, separately, a private civil action for damages.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.