Missouri Privacy Law
Missouri has not enacted a comprehensive consumer privacy law, but it is one of the few states whose constitution names electronic data directly: article I, section 15 secures the people in their “electronic communications and data” against unreasonable searches and seizures. On the commercial side, Missouri’s breach-notification statute counts medical and health-insurance information as personal information and reserves enforcement entirely to the Attorney General.
Sector-Specific Privacy Laws in Missouri
Mo. Const. art. I, § 15 — electronic communications and data
Missouri’s search-and-seizure clause reads that “the people shall be secure in their persons, papers, homes, effects, and electronic communications and data, from unreasonable searches and seizures,” and requires that no warrant issue to “access electronic data or communication” without describing the data or communication to be accessed as nearly as may be, on probable cause supported by written oath or affirmation. The clause governs state action rather than private data handling, which places Missouri’s constitutional text alongside its statutory scheme rather than inside it.
Missouri Merchandising Practices Act (RSMo 407.020)
RSMo 407.020.1 declares unlawful the use of any deception, fraud, false pretense, false promise, misrepresentation, unfair practice or the concealment, suppression or omission of any material fact in connection with the sale or advertisement of merchandise in trade or commerce in or from Missouri, and states that the conduct violates the subsection whether committed before, during or after the sale. Subsection 3 makes willfully and knowingly engaging in such conduct with intent to defraud a class E felony. Subsection 2(2) exempts institutions chartered, licensed or regulated by the director of the Department of Commerce and Insurance, the division of credit unions or the division of finance, unless those directors specifically authorise the Attorney General to act.
Library records — RSMo 182.817
RSMo 182.817.1 bars a library, its employees or agents, or a third party contracted to receive, transmit, maintain or store library records from releasing a library record except on the written request of the person identified in it or on a court order finding disclosure necessary to protect the public safety or prosecute a crime. Subsection 2 lets a person whose privacy was compromised file a written complaint with the Attorney General within 180 days and separately bring a private civil action in the circuit court of the county where the library sits, with discretionary punitive damages and attorney fees for the prevailing party; a prevailing respondent recovers fees only on a showing that the case was without foundation.
Data Breach Notification in Missouri
RSMo 407.1500, enacted by House Bill 62 in 2009, defines personal information more broadly than most breach statutes of its generation: alongside a Social Security number, a government-issued identification number and a financial account number with its access code, subdivision 1(9) counts a unique electronic identifier or routing code with its access credentials, medical information, and health insurance information. Subsection 2(4) prescribes what the notice must describe — the incident in general terms, the type of information obtained, a telephone number for further information if one exists, contact information for the consumer reporting agencies, and advice to review account statements and monitor free credit reports. Subsection 2(5) supplies a risk-of-harm exception: notification is not required where, after an appropriate investigation or consultation with law enforcement, the person determines that identity theft or other fraud is not reasonably likely to occur, provided that determination is documented in writing and the documentation retained for five years. Substitute notice becomes available under subsection 2(6)(d) where notice would cost more than $100,000 or the affected class exceeds 150,000 consumers. Under subsection 4 the Attorney General has exclusive authority to sue for actual damages for a willful and knowing violation and may seek a civil penalty of up to $150,000 per breach, or per series of breaches of a similar nature discovered in a single investigation.
Residents must be notified without unreasonable delay after discovery or notification of the breach. Notify the Attorney General, and the nationwide consumer reporting agencies, when notice is given to more than 1,000 consumers at one time. Complaints are taken by the Missouri Attorney General, which enforces the statute.
Recent Enforcement in Missouri
Blackbaud — $49.5 million multistate settlement, October 2023. The Attorney General announced on October 5, 2023 that Missouri and 49 other states settled with software company Blackbaud over a 2020 ransomware incident, with Missouri receiving over $800,000 of the $49.5 million paid to the states. The office states the settlement resolved allegations that Blackbaud violated state consumer-protection laws, state breach-notification laws and HIPAA by failing to implement reasonable data security, and that the company did not give its customers timely, complete or accurate information about the breach, so that notification to affected consumers was significantly delayed or never occurred. The incident affected more than 13,000 Blackbaud customers, whose data included Social Security numbers, driver’s licence numbers, financial information, donation history and protected health information.
23andMe bankruptcy sale conditions — June 2025. On July 2, 2025 the Attorney General announced that Missouri, as part of a multistate coalition, had secured privacy conditions on the sale of 23andMe. The Eastern District of Missouri Bankruptcy Court approved the $305 million sale to TTAM Research Institute on June 27, 2025 after states objected to the treatment of consumer genetic information in the bankruptcy. The office states that the conditions built into the sale agreement include no transfer of consumer DNA, a continuing right for consumers to delete their data permanently with enforcement mechanisms to verify deletion — overseen in part by the Missouri Attorney General’s Consumer Protection Team — a bar on future resale without full adoption of the privacy commitments, a prohibition on sharing data with entities connected to Countries of Concern as defined by federal law, and creation of a three-person Consumer Privacy Advisory Board.
Pending Privacy Legislation
No comprehensive consumer-privacy statute has been enacted in Missouri. The state’s general data-security obligations continue to run through RSMo 407.1500, unchanged since House Bill 62 took effect on August 28, 2009, and through the Merchandising Practices Act.
Federal Privacy Laws That Apply in Missouri
Federal privacy law applies in Missouri by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
Outside those federal sectors, Missouri obligations run through the state’s breach-notification statute and the Missouri Attorney General’s general consumer-protection authority rather than through a privacy statute of its own.
Industry Rules That Reach Missouri Businesses
With no comprehensive state statute, most privacy obligations on a Missouri business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.
Two of those reach Missouri businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while Missouri itself has none, and any business holding personal information about Missouri residents is subject to the state’s breach-notification statute described above.
Missouri Privacy Law FAQ
Does Missouri’s breach law cover medical information?
Can a Missouri resident sue a company for failing to give breach notice?
When can a Missouri business decide not to notify after a breach?
What does article I, section 15 of the Missouri Constitution say about data?
Who must Missouri businesses notify besides affected consumers?
Are Missouri library records confidential?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- RSMo 407.1500 — Notice to consumer for breach of security statute
- RSMo 407.020 — Unlawful practices (Merchandising Practices Act) statute
- RSMo 182.817 — Disclosure of library records statute
- Mo. Const. art. I, § 15 — Unreasonable search and seizure prohibited constitution
- Missouri Attorney General — $49.5 million multistate settlement with Blackbaud (Oct. 5, 2023) agency
- Missouri Attorney General — Privacy protections in the sale of 23andMe (July 2, 2025) agency
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.